Houston Industrial Cybersecurity Threats: Key Findings from Honeywell’s 2025 Cyber Threat Report
Honeywell 2025 Report Reveals Evolving Industrial Cybersecurity Threats – Manufacturing and Healthcare Face Exponential Increase in Cyber Attacks
Honeywell's 2025 Cyber Threat Report analyzed 253 billion logs. Here are the findings that matter for industrial businesses - and a checklist to respond.
Honeywell's 2025 report shows cyberattacks moving into operational technology - the systems that run factories, utilities, and critical infrastructure.
For years, "cybersecurity" mostly meant protecting IT: email, files, and business apps. Honeywell's data makes clear that the front line has moved. Attackers are now going after the operational technology that runs physical processes - and a breach there can halt production, disrupt a utility, or endanger safety. For any Houston-area business with industrial systems, these findings are a direct warning and a to-do list.
What the Report Found
The scale is large, and the trend line points at OT.
Attacks on operational technology dominated 2024, ransomware jumped 46%, and CL0P led a wave that pushed documented payments past $1 billion.
CL0P - operated by the long-running group TA505 - drove much of the ransomware surge, adding 2,472 new victims in Q1 2025 on top of 6,130 in 2024. Manufacturing, construction, healthcare, and technology took the heaviest hits, and agriculture and food production saw exponential increases in targeting.
The Standout Threats
Three findings that industrial operators should not ignore.
A banking trojan surging in OT, USB-borne malware, and exposed critical infrastructure define the year's biggest risks.
- Ramnit repurposed for OT. The Ramnit banking trojan jumped 3,000% in Q4 2024 and made up 37% of files blocked by Honeywell's media-scanning system - a sign attackers are adapting IT malware to steal control-system credentials.
- USB and removable media. A quarter of the top 10 incidents involved USB plug-and-play events, with new worms like Sohanad spreading via removable media and even a Stuxnet-era shortcut flaw (CVE-2010-2568) still being exploited.
- Critical infrastructure exposed. The EPA warned that drinking water for roughly 193 million Americans is vulnerable, a large multi-state water utility was breached, and transit and airline systems faced ransomware and denial-of-service attacks.
CL0P's toolkit shows how these threats connect: the group exploits widely used enterprise software - Citrix, Windows, SolarWinds, Accellion, PaperCut, and Progress products - to reach the environments where OT lives.
Your OT-Security Checklist
IT security is not enough - operational technology needs its own controls.
These are the measures the report points to for defending industrial environments.
- Segment your network. Separate OT from IT so a breach in one cannot flow freely into the other.
- Monitor OT specifically. Deploy security monitoring built for operational technology, not just traditional IT tools.
- Control USB and removable media. Scan and restrict removable media, still a leading way malware enters industrial systems.
- Patch industrial systems. Run vulnerability assessment and patch management tailored to OT, including the enterprise software attackers exploit.
- Keep air-gapped, immutable backups. So a ransomware hit cannot encrypt or delete your recovery point.
- Plan incident response for operations. Build response procedures that account for physical processes and minimize disruption.
- Assess IT and OT together. Run risk assessments that treat both environments as one connected system, and cover new SEC reporting requirements.
Security Built for Industrial Environments
CinchOps secures both IT and OT with segmentation, media controls, OT-aware monitoring, and air-gapped backups - so an attack on your machinery cannot stop production - as part of everyday cybersecurity and managed IT.
Explore CinchOps cybersecurity →How CinchOps Helps Secure Your Business
CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, with security built for both IT and operational technology.
- OT threat monitoring. 24/7 detection designed for operational technology environments.
- Vulnerability and patch management. Tailored to industrial systems and the software attackers target.
- Segmentation and access control. Protecting critical OT assets from lateral movement.
- Media and USB security. Controls to keep malware off removable media and out of your systems.
- Air-gapped, immutable backups. Plus incident response and IT-and-OT risk assessments.
Do not wait for an incident to disrupt operations. Contact CinchOps to protect your industrial environment.
The line that should get every operator's attention is 55% - more than half of reported breaches now hit operational technology. That is a fundamental shift. Protecting the office network is no longer enough when the target is the machinery that runs your business.
Frequently Asked Questions
What is the Honeywell 2025 Cyber Threat Report?
It is Honeywell's annual analysis of threats to industrial and operational technology (OT) environments, built from 253.2 billion logs, 79.2 million scanned files, and 4,600 triaged events. Its central finding is that attackers are increasingly targeting OT - the systems that run physical processes.
Why is operational technology (OT) such a big target now?
Because attacking OT can halt production, disrupt utilities, or endanger safety - giving attackers strong pressure to extort. The report found that 55% of cyber incidents reported to the SEC in 2024 were direct attacks on OT systems, a sharp shift from purely IT-focused attacks.
Why did the Ramnit banking trojan appear in industrial systems?
Ramnit is traditionally used to steal banking credentials, but Honeywell saw a 3,000% spike in OT environments. The likely explanation is that attackers are repurposing IT-focused malware to harvest control-system credentials - a concerning evolution in how OT is attacked.
Are USB drives still a real cybersecurity risk?
Yes. A quarter of the top incidents Honeywell tracked involved USB plug-and-play events, with worms spreading via removable media and even a Stuxnet-era vulnerability still being exploited. Physical media controls and scanning remain essential in industrial settings.
How can an industrial business protect its OT?
Segment OT from IT, deploy OT-specific monitoring, control removable media, patch industrial and enterprise software, keep air-gapped immutable backups, plan incident response around physical operations, and assess IT and OT together. A managed security partner can implement these controls.