AI Is Transforming OT Cybersecurity, but Industrial Autonomy Still Needs Strong Guardrails

Artificial intelligence is rapidly becoming part of the cybersecurity strategy for industrial organizations.

From threat detection and anomaly analysis to vulnerability management and security operations, AI can help security teams process large volumes of operational data and identify suspicious activity faster.

But when it comes to allowing AI systems to make autonomous security decisions, industrial organizations remain cautious.

A new 2026 OT Cybersecurity Benchmark Report from Honeywell Technologies provides a useful view of this transition.

The report surveyed more than 600 cybersecurity, risk, compliance, and operations leaders across critical infrastructure sectors including energy, oil and gas, healthcare, maritime, and manufacturing. While 88% of respondents described their OT cybersecurity programs as mature, only 21% reported having a complete inventory of their OT assets.

At the same time, 99% of respondents expect AI to affect OT security within the next two to three years, while only 23% reported using autonomous or agentic operations for threat detection.

These findings highlight an important reality:

Industrial organizations are increasingly comfortable using AI to assist cybersecurity teams, but they are not yet ready to hand over complete decision making to autonomous systems.

Why AI Is Becoming Important in OT Security

Operational Technology environments generate enormous amounts of information.

Industrial networks can contain:

  • Programmable logic controllers
  • Human machine interfaces
  • Engineering workstations
  • Industrial control systems
  • Sensors
  • Cameras
  • Network equipment
  • Building management systems
  • Remote access infrastructure
  • Connected IoT devices

Monitoring all of these systems manually can be extremely difficult.

AI and machine learning can help security teams identify patterns across large amounts of telemetry.

Potential applications include:

  • Anomaly detection
  • Threat identification
  • Alert correlation
  • Behavioral analysis
  • Vulnerability prioritization
  • Threat hunting
  • Incident investigation
  • Security operations automation
  • Compliance monitoring
  • Risk analysis

Honeywell’s own OT cybersecurity portfolio includes AI driven capabilities designed to correlate and prioritize security signals in industrial environments.

The value of AI in this environment is therefore not simply about replacing security analysts.

It is about helping them understand complex industrial environments more effectively.

Why Full Autonomy Is Still Rare

Industrial cybersecurity is different from many traditional IT environments.

An automated decision in an enterprise application may cause inconvenience.

An incorrect automated action in an industrial environment could potentially affect:

  • Production
  • Equipment
  • Worker safety
  • Environmental controls
  • Energy availability
  • Product quality
  • Business continuity

That changes the risk calculation.

Security teams therefore need to balance automation with operational safety.

An AI system may correctly identify suspicious behavior but still require human validation before taking an action that could interrupt a production process.

This helps explain why organizations are adopting AI for detection and analysis faster than they are adopting fully autonomous response.

The Difference Between AI Assistance and AI Autonomy

There is an important distinction between using AI to assist security teams and allowing AI to independently make operational decisions.

AI Assisted Security

The AI system can:

  • Analyze alerts
  • Identify anomalies
  • Correlate events
  • Prioritize risks
  • Recommend actions
  • Summarize incidents
  • Support investigations

A human security professional remains responsible for the final decision.

Autonomous Security

The AI system can potentially:

  • Detect an event
  • Determine whether it is malicious
  • Select a response
  • Execute containment
  • Modify security controls
  • Block communications
  • Isolate systems

This can dramatically reduce response time.

It can also introduce additional operational risk if the AI makes an incorrect decision.

For OT environments, the second model requires significantly stronger governance.

OT Visibility Remains a Major Challenge

One of the most notable findings from Honeywell’s report is the gap between perceived cybersecurity maturity and actual visibility.

While 88% of respondents described their OT cybersecurity programs as mature, only 21% reported having a complete inventory of OT assets.

This matters because AI cannot reliably protect assets that an organization does not know exist.

A security team cannot effectively monitor an unknown PLC.

It cannot assess the risk of an undocumented engineering workstation.

It cannot identify unusual behavior from an unmanaged IoT device.

Asset visibility is therefore the foundation for AI enabled OT security.

Before organizations focus heavily on autonomous response, they need to establish a reliable understanding of their environment.

OT and IT Security Are Converging

Industrial environments are increasingly connected to enterprise IT networks, cloud platforms, remote access solutions, and third party systems.

This convergence creates operational benefits.

It also expands the attack surface.

A compromise that begins in an enterprise environment can potentially move toward OT systems if segmentation and access controls are weak.

Similarly, an exposed industrial device can become an entry point into broader organizational infrastructure.

Security teams therefore need visibility across:

IT + OT + IoT + Cloud + Identity + Remote Access

AI can help correlate activity across these domains, but the underlying data and architecture need to be reliable.

Critical Infrastructure Cannot Rely on a Single Security Layer

The increasing use of AI should not replace foundational cybersecurity controls.

Industrial organizations still need:

  • Network segmentation
  • Asset inventory
  • Identity management
  • Privileged access controls
  • Secure remote access
  • Vulnerability management
  • Endpoint security
  • Network monitoring
  • Incident response
  • Backup and recovery
  • Secure configuration management
  • Continuous security testing

AI should operate as another layer within this broader architecture.

This is particularly important because AI systems can themselves become targets.

AI Systems Need to Be Secured Too

Organizations often focus on how AI can improve cybersecurity.

They also need to consider how AI itself could introduce new risks.

Industrial AI deployments may interact with:

  • Operational data
  • Engineering systems
  • Production information
  • Cloud services
  • Security platforms
  • Industrial control systems
  • Enterprise applications

Organizations should therefore evaluate:

  • AI model security
  • Access controls
  • Data protection
  • Model validation
  • Prompt and input security
  • API security
  • Authentication
  • Logging
  • AI governance
  • Third party AI dependencies

The security of an AI enabled OT environment should be considered alongside the security benefits the technology provides.

The Importance of Human Oversight

Human oversight remains particularly important when AI systems can influence operational environments.

A practical architecture can separate actions into different levels.

Low Risk Actions

AI may be able to automate tasks such as:

  • Alert classification
  • Log analysis
  • Threat intelligence enrichment
  • Security reporting
  • Risk prioritization
Medium Risk Actions

AI can recommend actions such as:

  • Blocking a suspicious connection
  • Isolating a noncritical endpoint
  • Resetting a compromised credential
  • Updating a detection rule

Human approval can be required before execution.

High Risk Actions

Actions involving production systems, safety controls, critical infrastructure, or major network changes should generally receive stronger authorization and operational validation.

This type of graduated autonomy allows organizations to benefit from automation without treating every AI decision as equally safe.

OT Cybersecurity Is Also a Business Continuity Issue

Cybersecurity incidents in industrial environments can have consequences far beyond information security.

Honeywell’s 2026 report found that organizations experienced an average of 16.2 hours of downtime from their most significant cybersecurity incidents, with reported losses reaching as much as $500,000 per hour.

This demonstrates why OT security should be connected to business continuity and operational resilience.

A cyber incident can potentially affect:

  • Production schedules
  • Supply chains
  • Customer commitments
  • Revenue
  • Worker safety
  • Equipment availability
  • Regulatory obligations

Security leaders therefore need to communicate OT cybersecurity risk in operational and business terms.

Industry Findings Highlight Different Risk Profiles

Honeywell’s research also shows that OT cybersecurity challenges vary between industries.

The report found that 91% of energy and utilities respondents reported experiencing a significant OT cybersecurity incident during the previous 12 months, while 87% of maritime respondents reported similar experiences. In healthcare, only 19% of respondents said facility and building systems were fully integrated into cybersecurity monitoring and protection.

These differences demonstrate why OT security programs should be tailored to the operational environment.

There is no single security architecture that works equally well for a power plant, hospital, refinery, manufacturing facility, or maritime organization.

Manufacturing

Manufacturing environments increasingly depend on connected production systems, engineering workstations, industrial networks, sensors, and cloud platforms.

AI can help identify abnormal activity across these environments, but organizations need strong segmentation and monitoring before introducing automated response.

Security programs should include:

  • OT asset discovery
  • Network segmentation
  • Industrial protocol monitoring
  • Vulnerability management
  • Secure remote access
  • Incident response
  • OT penetration testing
Energy and Utilities

Energy infrastructure represents a particularly important OT security environment.

Power generation, transmission, distribution, and utility systems depend on interconnected control environments.

Organizations should prioritize:

  • Continuous monitoring
  • Identity security
  • Remote access controls
  • Network segmentation
  • Threat detection
  • Incident response
  • Regulatory compliance
  • Recovery planning

AI can support threat detection while human and operational controls remain important for high impact actions.

Oil and Gas

Oil and gas organizations operate complex industrial environments across production, processing, transportation, and distribution.

Security assessments should consider both enterprise IT and OT environments.

Key areas include:

  • Industrial network security
  • Remote access
  • Control system protection
  • Cloud security
  • Third party risk
  • Asset visibility
  • Vulnerability management
  • Incident response
Healthcare

Healthcare facilities increasingly depend on connected building systems, medical technology, IoT devices, clinical applications, and enterprise networks.

The integration of these environments creates additional security requirements.

Organizations need to understand how facility systems and connected devices interact with broader cybersecurity infrastructure.

Maritime

Maritime organizations rely on connected operational systems, communications infrastructure, navigation technology, logistics platforms, and remote services.

Cybersecurity programs should account for both onboard systems and supporting enterprise infrastructure.

The Role of OT Penetration Testing

As organizations adopt AI driven security tools, they still need to validate whether their underlying defenses actually work.

OT penetration testing can help identify realistic attack paths across industrial environments.

Testing may evaluate:

  • Network segmentation
  • Remote access
  • Engineering workstations
  • Human machine interfaces
  • Industrial protocols
  • Authentication
  • Privilege boundaries
  • Cloud connectivity
  • IT to OT pathways

Honeywell’s own guidance describes OT penetration testing as a way to identify attack paths that could move from IT environments toward systems supporting production or safety.

The objective is not simply to find vulnerabilities.

It is to understand how individual weaknesses could combine into a broader operational risk.

What Organizations Should Do Now

Organizations preparing for AI enabled OT security should focus on several foundational priorities.

Build a Complete Asset Inventory

Know what is connected to the industrial environment.

Improve OT Network Visibility

Monitor communications, devices, protocols, and abnormal behavior.

Integrate OT With Security Operations

Honeywell reported that only 33% of surveyed organizations had fully integrated OT into a centralized security operations center.

Organizations should work toward better coordination between IT security operations and OT security teams.

Secure Remote Access

Remote access should use strong authentication, least privilege, segmentation, and continuous monitoring.

Establish AI Governance

Define what AI systems can see, what they can recommend, and what actions they are permitted to perform.

Introduce Graduated Autonomy

Not every security decision needs the same level of human involvement.

Organizations can automate low risk activities while requiring approval for high impact operational actions.

Validate Security Controls

Regular assessments and penetration testing can help determine whether security investments actually reduce risk.

Prepare for Incident Response

Security teams should rehearse scenarios involving both cyber and operational consequences.

The Bigger Lesson

The transition toward AI enabled OT cybersecurity is not simply a technology upgrade.

It is an architectural and governance challenge.

Organizations need to answer several questions before increasing AI autonomy:

Do we know what assets we have?

Can we see what those assets are doing?

Can we distinguish normal operational behavior from malicious activity?

Do we understand the consequences of an automated response?

Can we stop an AI system if it behaves unexpectedly?

Who is accountable for the final decision?

These questions are essential because cybersecurity in an industrial environment ultimately supports more than data protection.

It supports safety, reliability, availability, and business continuity.

Conclusion

The latest Honeywell OT cybersecurity research highlights an important transition.

Industrial organizations are increasingly adopting AI to improve threat detection, monitoring, analysis, and security operations. At the same time, fully autonomous cybersecurity operations remain relatively uncommon.

That caution is understandable.

In OT environments, cybersecurity decisions can have direct consequences for production, safety, equipment, and continuity of operations.

The path toward AI enabled OT security should therefore focus on visibility first, governance second, automation third, and autonomy only where the risk is understood and controlled.

Organizations should build strong asset inventories, improve IT and OT visibility, strengthen identity and segmentation, secure remote access, validate security controls, and establish clear governance for AI driven decisions.

AI can become a powerful force multiplier for industrial cybersecurity.

But the strongest OT security strategy will combine AI capabilities with experienced security professionals, operational expertise, well tested controls, and clear accountability.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations strengthen IT and OT cybersecurity through:

• OT and ICS security assessments
• OT penetration testing and security validation
• Industrial network architecture and segmentation assessments
• IT to OT attack path analysis
• Industrial control system vulnerability assessments
• Secure remote access assessments
• Identity and privileged access management reviews
• IoT and connected device security assessments
• AI security assessments and adversarial testing
• AI governance and secure AI architecture reviews
• Continuous threat monitoring and detection
• Incident response and cyber resilience assessments
• Secure Software Development Lifecycle reviews
• Cybersecurity compliance and risk assessments

For manufacturing and industrial organizations, COE Security helps assess production networks, industrial control systems, engineering workstations, connected devices, cloud environments, and IT to OT pathways while helping organizations strengthen segmentation, monitoring, and incident response.

For energy, utilities, and oil and gas organizations, we help secure critical infrastructure through OT security assessments, network segmentation reviews, vulnerability assessments, remote access testing, penetration testing, continuous monitoring, and incident response planning.

For healthcare organizations, we help protect connected facility systems, medical and IoT environments, clinical applications, enterprise networks, sensitive data, and cloud infrastructure while supporting security and compliance requirements.

For financial services organizations, we help protect enterprise infrastructure, data centers, cloud environments, identity systems, connected facilities, and AI enabled security operations through security assessments, penetration testing, monitoring, and compliance programs.

For retail and e-commerce organizations, we help secure connected stores, payment environments, IoT devices, cloud platforms, APIs, corporate networks, and third party technology ecosystems.

For government and public sector organizations, we help strengthen critical infrastructure security, OT environments, identity controls, network protection, cloud security, monitoring, penetration testing, and compliance readiness.

COE Security helps organizations adopt AI and modern cybersecurity technologies while maintaining appropriate human oversight, strong governance, operational resilience, and compliance.

Our goal is to help organizations identify security gaps, validate their defenses, reduce cyber risk, strengthen resilience, and securely adopt AI across increasingly connected IT, OT, IoT, and cloud environments.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption, OT cybersecurity, AI security, threat intelligence, critical infrastructure protection, and practical cybersecurity strategies to help your organization stay updated and cyber safe.

Click to read our LinkedIn feature article