Honeywell 2026 OT Cybersecurity Benchmark: What Houston Should Fix
OT Security For Small And Mid-Sized Houston Businesses – What The 2026 OT Benchmark Says About Compliance And Recovery
Honeywell released its first OT benchmark from Houston on September 22. Here is what it means for a 10 to 200 person business.
The Honeywell Technologies 2026 OT Cybersecurity Benchmark Report puts a number on a gap CinchOps runs into on onboarding network scans across Houston: 88% of 603 industrial and critical-infrastructure security leaders describe their OT security programs as planned or design-led, yet only 21% report a complete inventory of the systems those programs are supposed to protect.
OT, or operational technology, is the hardware and software that controls physical things. On a pipeline that means PLCs and SCADA. In a 60-person office in Katy it means the chiller or mini-split keeping the server closet cold, the badge reader on the back door, the camera recorder in the break room and the smart thermostat the office manager runs from a phone app. Honeywell released the report on September 22, 2026 under a Houston dateline, and its findings apply as much to a Sugar Land medical practice or a Cypress machine shop as to a refinery.
CinchOps provides network security and managed IT specifically for Houston oil and gas, manufacturing and energy services companies with 10 to 200 employees, with IT/OT segmentation at the boundary between the shop floor or field network and the corporate network. That boundary matters locally: 602 of the 954 Houston-area manufacturers graded in the CinchOps Houston Area Security Index score a D on network posture.
What Did the Honeywell 2026 OT Cybersecurity Benchmark Find?
The confidence numbers and the coverage numbers from 603 respondents, side by side.
The Honeywell 2026 OT Cybersecurity Benchmark found a wide gap between how organizations rate their OT security and what they can actually see. Among 603 respondents surveyed in May and June 2026, 92% placed themselves in the top two tiers of recovery readiness, but only 31% said they were fully ready and only 21% reported a complete asset inventory.
The respondents were CISOs, OT security leaders, compliance and risk executives, plant and operations managers and security architects in oil and gas, energy and utilities, maritime, healthcare and manufacturing, spread across the Americas, Europe and Asia-Pacific. The answers are self-reported, which makes the gaps more telling: these are the organizations grading themselves.
The gap has a price. For their most significant OT incident, respondents reported an average of 16.2 hours of downtime, and 13% of incident-affected organizations were down for at least a full day. Among incident-affected respondents, 21% put downtime costs above $100,000 an hour and 4% above $500,000. More than half (54%) reported operational downtime and production disruption, and 38% reported direct financial loss.
Visibility was the variable that moved outcomes. Among incident-affected respondents, organizations with stronger asset visibility identified the root cause very effectively 41% of the time versus 10% with weaker visibility, and 11% of them were down a day or more versus 19%.
Honeywell reads that as the discipline behind audits, such as tested backups, written procedures and named owners, paying off during recovery. We agree, and it is the part of an audit a smaller Houston company should copy first.
AI shows up everywhere in the data and in charge of very little. 72% use AI-enabled threat detection, but only 23% let it operate autonomously, and 99% expect AI to affect OT security within two to three years. Autonomous asset inventory appeared at 22% of organizations with strong visibility and 8% with weak visibility. An automated tool pointed at an incomplete device list automates the blind spot, so the inventory still comes first.
For Most Houston Businesses, the OT Risk Is the Building
Cameras, badge readers, thermostats and HVAC controllers are the operational technology a 50-person company actually owns.
Building systems are operational technology: HVAC and chiller controls, badge readers, camera recorders, smart thermostats, fire panels and elevator controllers all run software and often share a network with email and accounting. Honeywell's 2026 benchmark found only 16% of organizations continuously monitor more than three-quarters of their building automation systems, and only 20% do so for cameras, thermostats and other IoT devices.
Honeywell opens its report with a scenario every Houston business owner should read twice. A plant depends on an on-site data center. The servers stay up only while the chillers keep them cool. The chiller controller sits on a facility network with a remote-access path left open for the maintenance team's convenience. Shut down the cooling and the servers fail, without anyone touching a server.
More organizations now put these systems in scope on paper: 64% of respondents include safety systems in the OT security program, 57% include physical security systems and 56% include facility infrastructure such as chillers, switchgear and fire panels. Being named in a program document and being watched are separate measurements, and the distance between 57% and 20% is where a camera recorder with a default password lives for years.
Houston adds two local pressures. The first is heat: from May through October the air conditioning in a server closet or small data room runs near full load, so a controller that can be switched off remotely is an outage path, not a comfort setting.
The second is hurricane season. After a storm, generator transfer switches, UPS cards and building controls get reset and reconnected in a hurry, often by vendors who re-enable remote access to get the job done and never close it again. In 35+ years doing this, I've learned to ask who controls the air conditioning before I ask who controls the firewall.
Third-party access is the other soft spot. Honeywell found 35% of respondents still use manual or procedural controls to secure third-party access to OT and facility systems. For a small business that usually looks like one of these, and our onboarding network scans in the Houston area turn up versions of this list regularly:
- A camera recorder installed by the alarm company, with a port forwarded on the office router so the owner can watch from a phone.
- The badge-reader controller on the same flat network as the accounting PCs.
- An HVAC contractor's cellular modem or remote-support box that nobody on staff remembers approving.
- Smart thermostats and building controls that phone home to a vendor cloud under a shared login.
- UPS and PDU network cards still on factory credentials.
Exposed cameras are a documented problem well beyond Houston; the 40,000 exposed security cameras finding showed how many sit open to anyone who looks. Healthcare makes the stakes plain in Honeywell's own numbers: only 19% of healthcare respondents say facility and building systems are fully integrated into security monitoring, while 67% say a significant incident could severely affect patient or caregiver safety or damage equipment.
Six moves close most of that gap for a Houston office or plant, and each one lines up with a Honeywell finding:
- List every connected device and write down who owns each one: IT, facilities, the landlord or the vendor. Only 21% of Honeywell's respondents said their inventory was complete.
- Give cameras, badge readers and HVAC controls their own network segment. Among incident-affected respondents, 33% of those back within six hours credited segmentation with cutting downtime, versus 24% of slower recoverers.
- Replace always-on vendor modems and port forwards with brokered, logged, time-limited access.
- Change default passwords on camera recorders and on badge and HVAC portals, and add MFA wherever the portal supports it.
- Monitor the building along with the PCs. 42% of fast recoverers credited continuous monitoring and alerting, versus 29%, and 34% credited backup and recovery capabilities, versus 23%.
- Rehearse one outage, such as the server-room cooling failing on an August afternoon, with the HVAC vendor at the table. Reactive or tool-by-tool programs were down a day or more 21% of the time, versus 12% for planned ones.
Houston timing makes the rehearsal the one to schedule first. The business continuity plan most companies wrote for hurricanes covers files and phones, and rarely covers the building controls that have to come back before anyone can work.
Do You Know What Is on Your Building Network?
CinchOps can map the cameras, controllers and vendor connections on your network and show which ones can reach your business systems.
Talk to CinchOpsWhat Cybersecurity Does a Houston Oil and Gas Company Need?
The oil and gas numbers in Honeywell's benchmark point at recovery, not visibility, as the weak link.
A Houston oil and gas company needs tested recovery more than another monitoring dashboard. In Honeywell's 2026 benchmark, 91% of oil and gas respondents reported a complete or mostly complete asset inventory, above the 80% full-sample figure, yet only 52% said they could restore critical OT systems within 24 hours and only 28% called themselves fully recovery-ready.
Compare the four sectors Honeywell profiled. Energy and utilities respondents reported the highest incident rate and the highest recovery confidence. Oil and gas reported fewer incidents than either energy and utilities or transportation, but the weakest expected recovery of the four. Water and wastewater reported the fewest incidents. Honeywell calls these sector findings directional because the samples are small (67 oil and gas respondents), and they should be read that way.
Spread is the other oil and gas signal. Among incident-affected oil and gas respondents, 28% saw effects across multiple regions, against 10% in energy and utilities. That fits the way Houston's small and mid-sized energy companies are built: a downtown or Energy Corridor office, a yard in Katy or Rosenberg, field offices in the Permian or Eagle Ford, and wellsite telemetry tied back over cellular. One shared account or one flat VPN turns a field-office problem into a company-wide one.
Legacy equipment is the constraint underneath all of it. Across the survey, 48% named legacy systems and infrastructure as the top barrier to better OT security, and 45% of respondents in oil and gas, power grid and other energy categories cited aging or legacy infrastructure. A controller that cannot be patched without a shutdown needs compensating controls around it: its own network segment, monitored access and a documented way to rebuild it. The same logic runs through the Dragos OT/ICS findings for Houston energy and manufacturing, and through Honeywell's 2025 Cyber Threat Report before this benchmark.
For a Houston oil and gas operator with 10 to 200 employees, the practical answer to the question in this section's heading is four things: segmentation between field or SCADA networks and the office network, brokered and logged vendor access, continuous monitoring that includes the OT side, and a restore plan someone has actually run. CinchOps covers the IT half of that stack for oil and gas companies and works alongside the controls vendor on the OT half.
Every Houston business I walk into has OT, even the ones who swear they don't. It's the camera system the alarm company installed, the thermostat app on the office manager's phone and the AC unit keeping the server closet alive in August.
Get the Building Onto Your Security Map
CinchOps maps the cameras, badge systems, HVAC controllers and vendor connections on your network, separates them from the office segment and backs the whole network with 24/7 threat monitoring alongside your PCs and servers.
See CinchOps cybersecurity services →How CinchOps Can Help Houston Businesses Secure OT and Building Systems
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
- Through cybersecurity services, CinchOps runs 24/7 threat monitoring and segments the network so building and IoT devices sit apart from laptops and servers.
- With managed IT support, help desk requests are answered in under 15 minutes by an engineer who knows your network, including which vendor owns which box.
- Business continuity and disaster recovery keeps immutable, verified backup copies geo-redundant outside the Gulf Coast flood zone.
- vCIO guidance turns those six moves into a dated plan, including the legacy-device replacement list.
- Industry work covers oil and gas, energy services and utilities, manufacturing and engineering firms.
- Service areas include Houston, Katy, Sugar Land and Cypress.
Honeywell's benchmark was written for refineries, grids and hospitals, and its sharpest lesson fits a 40-person office just as well: the systems that keep the lights, the cooling and the doors working belong on the security map. If you cannot list every connected device in your building today, start there, and talk to CinchOps about getting the list and the segmentation done before the next outage.
Frequently Asked Questions
What is the Honeywell 2026 OT Cybersecurity Benchmark Report?
It is Honeywell Technologies' first OT security benchmark, released September 22, 2026. It surveyed 603 security, compliance and operations leaders in oil and gas, energy and utilities, maritime, healthcare and manufacturing in May and June 2026. Its headline gap: 88% call their OT programs planned or design-led, while only 21% report a complete asset inventory.
Does a small Houston business really have OT security risk?
Yes. Any business with networked cameras, badge readers, smart thermostats, HVAC controllers or a vendor remote-access box has operational technology. Honeywell found only 20% of organizations continuously monitor most connected IoT devices. For a Houston office, a reachable cooling controller or camera recorder is a real path to downtime or to the office network.
What does OT and building-system security cost in Houston?
CinchOps prices managed IT and security at a flat monthly rate per user, $100 to $250 per user per month, with no long-term contracts, no hidden fees and no cancellation penalties. Backup and recovery are included in the top-tier plan.
Should building systems share a network with office computers?
No. Cameras, badge readers and HVAC controls belong on their own network segment behind the firewall, with vendor access brokered and logged. Then a compromised device cannot reach accounting or file servers. In Honeywell's data, 33% of organizations that recovered within six hours credited segmentation with reducing downtime, compared with 24% of slower recoverers.
Does passing a compliance audit mean our OT is secure?
Not by itself. Honeywell found clean-audit organizations reported significant incidents at almost the same rate as others, 74% versus 73%. The difference showed up in recovery: 44% of clean-audit respondents were fully recovery-ready versus 26%. The tested backups, written procedures and named owners behind a good audit are what speed the restore.
Discover More
Resource
Sources
- Honeywell Technologies, 2026 OT Cybersecurity Benchmark Report (survey of 603 respondents, fielded May-June 2026)
- Honeywell Technologies press release, "Honeywell Technologies report reveals significant gaps in industry's OT cybersecurity protection," Houston, September 22, 2026
- CinchOps Houston Area Security Index (954 Houston-area manufacturers graded, updated August 8, 2026)