Skip to content

Security1 publisher2 min readPublished

Honeywell's survey finds the chillers and badge readers outside most OT monitoring programs

Honeywell asked 603 critical infrastructure leaders what they actually watch. The chillers, elevators and badge readers that keep the controllers alive mostly sit outside continuous view, and teams with thinner inventories reported longer outages.

The Watch · Security desk

Illustration accompanying Honeywell's survey finds the chillers and badge readers outside most OT monitoring programs

What happened

  • By early August, attackers had hit water systems in at least seven U.S. states, where operators lost monitoring or control and water operations degraded in some cases.
  • Honeywell surveyed 603 security, risk and operations leaders in critical infrastructure in May and June, and 16% continuously monitor more than three-quarters of their building automation systems.
  • Twenty-one percent report a complete asset inventory, a full list of what is connected, while 88% describe their programs as planned or design-led.
  • Most significant incidents averaged 16.2 hours of downtime, and 42% of respondents with comprehensive or substantial inventories were back up within six hours against 25% of the rest.
  • Organizations that passed every compliance audit reported significant incidents at 74%, against 73% for those with audit failures or findings.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The equipment outside continuous monitoring supplies the equipment inside it, so a stalled chiller controller reaches the server room before anyone has an asset record for it.
  • contradiction Audit status tracked confidence in recovery, not who got hit. A clean compliance file is no evidence that the building layer is watched.
  • decision A budget holder funding inventory work on the six-hour recovery split is acting on a correlation drawn from 91 respondents, and the survey calls that an association, not proof.

Continuous monitoring means something watches a device's traffic and behavior all the time, not only during an audit [8]. Chillers, fire panels, badge readers, elevators and cameras sit one layer above the controllers that OT programs were built to protect [22][24]. They run physical conditions and access [22]. When a chiller stops cooling, it takes down the servers it was keeping alive [23].

The recovery split rests on a small base. Honeywell's weaker-inventory group is 91 respondents against roughly 350 in the stronger one [13]. Add the two and about 441 of the 603 surveyed had been through a significant incident, or roughly 73% [25]. Seventeen points separate the two groups on six-hour recovery, and the smaller group under that spread is 91 people [26][13]. The survey shows an association, not proof that an inventory shortens an outage, and organizations with good inventories may simply do many other things well [13][14]. A responder who does not know a device exists cannot isolate it, and one who does not know what depends on it cannot predict what shutting it off will break [15].

Honeywell does not push its own audit finding to the stronger reading. Audit status did not separate who reported an incident, and the report says that is not the same thing as compliance having no preventive value [17]. Clean-audit organizations were more confident they could recover [18].

Old equipment is the most-cited barrier [20]. Many legacy controllers were built to run in isolation and use protocols with no authentication or encryption, and patching them can mean planned downtime or a call to the vendor [21]. For that equipment, monitoring is the control a team can add without scheduling an outage first. Thirty-one percent of respondents call themselves fully ready, and most of the rest say mostly ready, meaning some part of the plan has not been put in place or tested [19].

The water-system intrusions went at the layer these programs do cover. The FBI and EPA said the intruders remotely accessed internet-facing programmable logic controllers, the small industrial computers that run pumps and valves [2]. Federal investigators are examining possible links to Iran-backed hackers [4]. For the layer above those controllers, 84% of the surveyed organizations do not continuously monitor more than three-quarters of their building automation [27].

What to watch

  • Whether federal investigators confirm the Iran-backed link in the water-system intrusions, or drop it.
  • Whether Honeywell publishes the recovery split with a weak-inventory base larger than 91 respondents.
  • Whether federal advisories extend PLC guidance to the building automation and connected IoT layers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories