Blog

91% Reported an OT Cybersecurity Incident. Are Your Critical Systems Protected?

What Honeywell’s 2026 benchmark reveals about legacy infrastructure, remote access, and the cost of being unprepared.

91% of respondents in the energy and utilities sector reported a significant OT cybersecurity incident in the past year. That figure comes from Honeywell’s 2026 OT Security Benchmark. In operational technology (OT), an incident can mean more than compromised data. It can interrupt production, delay maintenance, affect essential services, and put safety and uptime at risk.

Yet the same report found that while 88% of respondents described their OT cybersecurity programs as mature, only 21% reported having a complete inventory of their OT assets. Organizations may trust their security programs while still lacking a full picture of the systems those programs are supposed to protect.

For teams responsible for keeping critical operations running, the questions are immediate: Which systems are exposed? Who can access them? And does a person who needs to work on one asset also have unnecessary reach beyond the assets which they have been granted permission to access. Can they also see the surrounding OT network?

Why Does Incomplete OT Asset Visibility Put Operations at Risk?

OT asset visibility means knowing which operational systems exist, how they are connected, and where they fit within critical processes. Security teams often struggle to identify exposure, prioritize protection, and investigate incidents without a visibility platform.

The challenge extends beyond production equipment. Industrial environments also include connected facility infrastructure, building controls, and other technologies that support critical operations.

An incomplete inventory makes it harder to answer basic questions:

  • Which systems could be affected by an incident?
  • What needs to be investigated?
  • Which assets are essential to keeping operations running?
  • Who can access those assets?
  • Who has accessed those assets recently?
  • Were there users accessing these assets prior to incident? What did they do?

Even a complete inventory does not answer the access question on its own. Knowing that an asset exists is different from knowing who can reach it, whether that access is authorized, and what happens during a remote session.

How Do Legacy OT Systems Complicate Cybersecurity?

Industrial systems often remain in service for decades. Replacing them may require downtime, substantial investment, or major changes to existing processes that cannot be interrupted without months of planning. Organizations must improve cybersecurity while continuing to operate infrastructure that may not have been designed for today’s connectivity requirements. Engineers still need to troubleshoot equipment. Vendors still need to provide support. Contractors and internal teams still need to perform maintenance across sites.

The work cannot simply stop because the underlying systems are old. The challenge is providing necessary access for each remote user to specific assets without giving them unnecessary and broad access to the OT network.

Traditional VPNs and jump servers can provide remote users OT network access but often does not control the users' access to a specific OT asset. Organizations also need to govern who receives access, what they can reach, when access is permitted, and what happens during the session.

For teams maintaining legacy infrastructure, remote access is not just an IT convenience. It is a control that directly affects how critical systems are exposed to users outside the OT environment.

Why Should Remote Access Not Mean Remote Network Access?

An engineer troubleshooting one controller needs access to that controller. A vendor servicing a particular system needs access to that system. Neither task inherently requires broad connectivity to the OT network. Secure OT remote access should give an authorized person controlled access to the specific asset required for their work, without unnecessarily extending network access to their endpoint.

Organizations should be able to determine:

  • Who is requesting access?
  • Which OT asset do they need?
  • Is access approved for that person and task?
  • How long should access remain available?
  • Should they be able to interact with the OT asset, or should it be read-only?
  • What activity occurred during the session?

The objective is to preserve the access operations depend on while limiting access that the work does not require.

What Makes Third-Party OT Access Difficult to Control?

Industrial organizations often depend on equipment manufacturers, service providers, and contractors to maintain critical systems. Those users may need temporary or recurring access to specific assets, sometimes across multiple facilities.

A vendor servicing one piece of equipment should not automatically receive access to unrelated systems. Access granted for a maintenance window should not remain available indefinitely simply because the work is complete.

Organizations need a consistent way to authorize third-party users, limit them to the assets they need, and retain evidence of their activity. Controlled third-party OT access connects the right person to the right asset for the required work, under conditions the organization can manage.

How Does Xona Provide Controlled Access to Critical OT Systems?

Xona provides identity-based secure remote access to critical OT assets without allowing remote vendors and/or employee endpoints to interface directly with the OT network assets. Rather than treating network connectivity as the goal, Xona enables organizations to control access to specific assets according to user identity and operational requirements. In addition, Xona employs a protocol break at the OT network to ensure users do not directly interface with critical OT assets.

An engineer can be given access to the system they need to troubleshoot. A vendor can be authorized to work on a designated asset without receiving unnecessary reach into the surrounding OT environment.

Organizations can apply controls around that access, including:

  • Multifactor authentication with SSO or local credentials to verify user identity.
  • Asset-specific access to limit users to the systems required for their work.
  • Approval and time-based controls to govern when access is available.
  • Session evidence for activity managed through the platform.

For organizations managing multiple sites, legacy infrastructure, and third-party support, the approach helps make remote access more consistent and easier to govern. It also allows teams to strengthen access controls around existing operational systems without requiring wholesale infrastructure replacement.

4a5822f0-a2ab-47ec-a655-588330f42339

What Should Organizations Examine in Their 2027 OT Cybersecurity Plans?

Honeywell’s findings offer a reason to look beyond whether a cybersecurity program is considered mature and examine how its controls work in practice. For organizations planning their next investments, four questions deserve attention:

  1. Do we have a current inventory and complete view of our critical OT assets?
  2. Can we give employees and third parties access to specific assets without giving network access?
  3. Can we approve, limit, revoke, and review user access?
  4. Can we reduce risks associated with legacy systems while keeping necessary maintenance and support work moving?

Asset visibility, incident response, and recovery planning remain essential. Controlled, managed and governed remote vendor and employee access addresses a different but closely related problem: ensuring that the people who need to work on critical systems can do so without receiving access beyond their specific tasks. Critical systems must remain accessible to the right people. The rest of the OT network should not have to come along for the ride.

Explore the Xona Platform

Source: Honeywell, 2026 OT Security Benchmark, as covered by Industrial Cyber.