By Paul Smith, Global Portfolio Director, Cybersecurity at Honeywell Technologies Process Automation
Recent cyber incidents have highlighted that cyber risks extend far beyond the loss of data. During the first six months of 2026, approximately 385 major healthcare breaches impacted nearly 34 million individuals, underscoring the scale and frequency of attacks across the sector alone. As organizations become increasingly interconnected, cybersecurity resilience is not only a technology concern but also a supply chain, safety, and continuity imperative.
Manufacturing operators already design for failure in the physical world. Equipment can malfunction, connections fail, processes move outside expected conditions. Facilities are built to accommodate these unknowns with safeguards, redundancy and recovery procedures intended to prevent one failure from becoming a larger operational crisis.
Cybersecurity increasingly requires the same mindset.
In short, cybersecurity needs to be engrained into critical infrastructure design as opposed to being relied on selectively when incidents occur.
Autonomy raises the stakes
The movement toward greater automation and industrial AI makes that shift even more consequential.
Intelligent systems are moving from analyzing operations toward recommending or taking action. As their authority grows, the integrity of the data, networks and systems supporting those decisions becomes more important. The more responsibility organizations give these systems, the more confidence they need in the environment surrounding them.
This includes defining what different types of systems AI can access, which actions it has agency over and what happens when it steps out of line.
But decentralized, disconnected progression creates a more accident-prone operational environment. Increased autonomy must be developed in step with stronger cyber resilience.
Resilience begins before the attack
Building that resilience starts well before an incident occurs. Prevention is foundational to security, but in today’s age of complex attacks, process-oriented environments need an agile and adaptable cybersecurity strategy in the event those measures fail.
Infrastructure and industrial operators need a clear understanding of their operating environment. Teams need to know which assets are connected, how they communicate, where critical dependencies exist and what normal behavior looks like.
A suspicious connection or compromised credential has a different significance depending on which systems it can reach, which processes depend on those systems and what consequences a disruption could create.
Operational context allows security teams to distinguish abnormal activity more quickly, understand its potential impact and determine where intervention is most urgent. It also gives operators a clearer picture of how a cyber event could affect the physical processes they are responsible for maintaining.
This is where the principles already used to engineer reliable infrastructure become relevant to cybersecurity. Organizations do not rely on a single safeguard to protect a critical process. They establish layers of protection and prepare for the possibility that individual controls may fail.
IT and OT can’t function on different tracks
That need for context becomes even more important as the lines between information technology and operational technology continue to blur.
There’s immense value in connecting industrial systems to enterprise networks, remote services and advanced analytics. However, in doing so, new dependencies also appear. A compromise or integration that appears in an IT environment may have consequences for operational technology, while activity originating in an industrial network may create risks elsewhere across business functions. What appears to initially be a contained digital event can quickly grow into a critical operational problem with real effects on production, safety and infrastructure if organizations do not understand these concerns.
Securing these environments requires more than technical integration. Security teams need visibility into operational risks, while operations teams need a clear understanding of how cyber threats could affect physical processes.
This requires shared visibility, clearly defined responsibilities and coordinated response. When IT and OT operate from different views of risk, organizations lose valuable time determining what has happened, what is affected and what needs to be protected first.
Cyber resilience is an operational requirement
Traditional measures of cybersecurity performance are still important. We still need to prevent attacks by closing vulnerabilities and detecting threats quickly. But for critical infrastructure, these metrics simply don’t tell the full story.
The stronger measure is what happens when preventive controls are tested or fail. Can an organization isolate the affected systems? Can operators understand what the incident means for physical operations? Can essential functions continue safely? Can a localized cyber event be prevented from becoming a broader operational crisis?
Over the coming months and years, the strongest cybersecurity programs will ultimately be measured by how well the entire operating ecosystem withstands disruption. As cyber threats become more advanced, the vitality of infrastructure across the operating environment will outshine individual metrics like the number of attacks prevented or threats detected.
Critical infrastructure has long been engineered around the principle that individual components can fail without bringing down the systems around them. Cybersecurity now needs to be designed with the same expectation.
##
ABOUT THE AUTHOR
Paul Smith, Global Portfolio Director | Cybersecurity, Honeywell Technologies Process Automation

Paul has spent 20+ years in the Automation Control space, tackling the “red herring” problems thrown his way. Unique issues include measurement imbalances resulting from flare sensor saturation, database migration mishaps, EEPROM production line failures, and many more. This ultimately led to the later part of his career, where he has been spending most of his time in the Industrial Cybersecurity space, pioneering the use of new security technology in the energy, utility and critical infrastructure sectors and helping develop cybersecurity strategies through the use of red team/pentest engagements, cybersecurity risk assessments, and tabletop exercises for some of the world’s largest government contractors, industrial organizations, and municipalities.






