XML 99 R36.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We maintain a cybersecurity risk management program designed to assess, identify, manage, and govern material risks from cybersecurity threats. Our cybersecurity risk management program is a key component of our overall enterprise risk management program. We maintain cybersecurity policies and procedures in accordance with industry standard control frameworks and applicable regulations, laws, and standards. We maintain oversight of our cybersecurity risk management program via a corporate structure that includes a Cybersecurity Disclosure Committee, a Security Governance Council, the Audit Committee, and the Board.
We assess and evaluate cybersecurity-related risks on a quarterly basis or as needed, to determine whether any such risks have the potential to materially impact our business operations, revenue, and expenditures and to understand the degree of such risks relative to other risks faced by Honeywell. Our Chief Security Officer served in various roles in IT and information security for over 30 years, including security-related roles in technology deployments, product development, product security, supply chain, and operations. He holds a Bachelor of Science in computer science from the Georgia Institute of Technology.
Our Security Governance Council, which meets quarterly or as needed, is led by our Chief Security Officer, and includes members of senior executive leadership. Our Security Governance Council maintains a security program designed to monitor and track key security performance indicators, and provides regular updates to the Audit Committee for review and oversight. Our Chief Security Officer also provides updates directly to the full Board once a year and directly to the Audit Committee at least twice a year or as needed. These updates cover topics related to information security, privacy, cyber risks and risk management processes, including the status of significant cybersecurity incidents, the emerging threat landscape, and the status of projects to strengthen the Company’s information security posture.
Honeywell’s Cybersecurity Disclosure Committee receives updates at least quarterly or as needed from Honeywell’s global security organization regarding cybersecurity incidents. The Cybersecurity Disclosure Committee includes Honeywell’s Chief Information Security Officer, Chief Security Officer, and senior representatives from finance, controllership, internal audit, investor relations, tax, and legal. Our governance, risk and compliance team, which is part of Honeywell’s enterprise security team, works in partnership with the Company’s internal audit team to review cybersecurity and IT-related internal controls as part of our overall internal controls process. The Cybersecurity Disclosure Committee informs the Security Governance Council and the Audit Committee of any cybersecurity incidents (if any) that have the potential to materially adversely impact the Company or our information systems.
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Our Chief Information Security Officer reports to our Chief Security Officer and oversees the global enterprise security team responsible for leading enterprise-wide information security strategy, architecture, and processes. The global enterprise information security team is responsible for infrastructure defense and security controls, performing vulnerability assessments, security incident management, and defining the parameters and standards of our information security risk management program. Our cybersecurity and information security risk management program includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and security monitoring. The risk management program leverages International Organization for Standardizations (ISO) 22301 standard for business continuity, ISO 27001 standard for information security management systems, and the National Institute of Standards and Technology (NIST) Cyber Security Framework (NIST 800-171) for measuring overall readiness to respond to cyber threats. Our Chief Information Security Officer has more than 20 years of experience in IT and information security, particularly in the engineering and technology industries. Our information security organization has more than 300 members, with expertise in: (i) application security, (ii) governance and compliance, (iii) program and vulnerability management, (iv) security engineering, (v) identity and access management, (vi) security operations security assurance, (vii) threat intelligence and security architecture, and (viii) incident response.
From time to time, we engage a third-party to perform periodic, internal security reviews/audits, as well as assess the adequacy of our risk management program, with the last such engagement occurring during the second half of 2024.
We rely on third-party service providers for certain critical or key infrastructure, solutions, and services across our operations. Honeywell has a third-party risk management program that assesses risks from vendors and suppliers that provide, amongst other things, key information and supply chain services to Honeywell. In addition, the Company maintains business continuity and disaster recovery plans as well as a cybersecurity insurance policy.
Honeywell maintains cybersecurity and information security awareness training programs for employees. Formal training on topics relating to the Company’s cybersecurity, data privacy and information security policies and procedures is mandatory for all employees with access to the Company’s network. Training is administered and tracked through online learning modules. Additionally, Honeywell periodically engages in cyber crisis response table-top simulations to assess our ability to adapt to security-related threats. Improper or illegitimate use of the Company’s information system resources or violation of the Company’s information security policies and procedures may result in disciplinary action.
To date, no risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, materially affected or are reasonably likely to materially affect our business, our business strategy, our results of operations or financial condition. Refer to “Our business, reputation, and financial performance may be materially impacted by cybersecurity attacks on our IT infrastructure and products” in the section titled Risk Factors of this Annual Report for further information on our cybersecurity risks. In the event an attack or other intrusion were to be successful, we have a response team of internal and external resources engaged and prepared to respond.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We maintain a cybersecurity risk management program designed to assess, identify, manage, and govern material risks from cybersecurity threats. Our cybersecurity risk management program is a key component of our overall enterprise risk management program. We maintain cybersecurity policies and procedures in accordance with industry standard control frameworks and applicable regulations, laws, and standards. We maintain oversight of our cybersecurity risk management program via a corporate structure that includes a Cybersecurity Disclosure Committee, a Security Governance Council, the Audit Committee, and the Board.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Our Chief Information Security Officer reports to our Chief Security Officer and oversees the global enterprise security team responsible for leading enterprise-wide information security strategy, architecture, and processes. The global enterprise information security team is responsible for infrastructure defense and security controls, performing vulnerability assessments, security incident management, and defining the parameters and standards of our information security risk management program. Our cybersecurity and information security risk management program includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and security monitoring. The risk management program leverages International Organization for Standardizations (ISO) 22301 standard for business continuity, ISO 27001 standard for information security management systems, and the National Institute of Standards and Technology (NIST) Cyber Security Framework (NIST 800-171) for measuring overall readiness to respond to cyber threats.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Our Chief Information Security Officer reports to our Chief Security Officer and oversees the global enterprise security team responsible for leading enterprise-wide information security strategy, architecture, and processes. The global enterprise information security team is responsible for infrastructure defense and security controls, performing vulnerability assessments, security incident management, and defining the parameters and standards of our information security risk management program. Our cybersecurity and information security risk management program includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and security monitoring. The risk management program leverages International Organization for Standardizations (ISO) 22301 standard for business continuity, ISO 27001 standard for information security management systems, and the National Institute of Standards and Technology (NIST) Cyber Security Framework (NIST 800-171) for measuring overall readiness to respond to cyber threats.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
Our Security Governance Council, which meets quarterly or as needed, is led by our Chief Security Officer, and includes members of senior executive leadership. Our Security Governance Council maintains a security program designed to monitor and track key security performance indicators, and provides regular updates to the Audit Committee for review and oversight. Our Chief Security Officer also provides updates directly to the full Board once a year and directly to the Audit Committee at least twice a year or as needed. These updates cover topics related to information security, privacy, cyber risks and risk management processes, including the status of significant cybersecurity incidents, the emerging threat landscape, and the status of projects to strengthen the Company’s information security posture.
Honeywell’s Cybersecurity Disclosure Committee receives updates at least quarterly or as needed from Honeywell’s global security organization regarding cybersecurity incidents. The Cybersecurity Disclosure Committee includes Honeywell’s Chief Information Security Officer, Chief Security Officer, and senior representatives from finance, controllership, internal audit, investor relations, tax, and legal. Our governance, risk and compliance team, which is part of Honeywell’s enterprise security team, works in partnership with the Company’s internal audit team to review cybersecurity and IT-related internal controls as part of our overall internal controls process. The Cybersecurity Disclosure Committee informs the Security Governance Council and the Audit Committee of any cybersecurity incidents (if any) that have the potential to materially adversely impact the Company or our information systems.
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Cybersecurity Risk Role of Management [Text Block]
Our Security Governance Council, which meets quarterly or as needed, is led by our Chief Security Officer, and includes members of senior executive leadership. Our Security Governance Council maintains a security program designed to monitor and track key security performance indicators, and provides regular updates to the Audit Committee for review and oversight. Our Chief Security Officer also provides updates directly to the full Board once a year and directly to the Audit Committee at least twice a year or as needed. These updates cover topics related to information security, privacy, cyber risks and risk management processes, including the status of significant cybersecurity incidents, the emerging threat landscape, and the status of projects to strengthen the Company’s information security posture.
Honeywell’s Cybersecurity Disclosure Committee receives updates at least quarterly or as needed from Honeywell’s global security organization regarding cybersecurity incidents. The Cybersecurity Disclosure Committee includes Honeywell’s Chief Information Security Officer, Chief Security Officer, and senior representatives from finance, controllership, internal audit, investor relations, tax, and legal. Our governance, risk and compliance team, which is part of Honeywell’s enterprise security team, works in partnership with the Company’s internal audit team to review cybersecurity and IT-related internal controls as part of our overall internal controls process. The Cybersecurity Disclosure Committee informs the Security Governance Council and the Audit Committee of any cybersecurity incidents (if any) that have the potential to materially adversely impact the Company or our information systems.
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Our Chief Information Security Officer reports to our Chief Security Officer and oversees the global enterprise security team responsible for leading enterprise-wide information security strategy, architecture, and processes. The global enterprise information security team is responsible for infrastructure defense and security controls, performing vulnerability assessments, security incident management, and defining the parameters and standards of our information security risk management program. Our cybersecurity and information security risk management program includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and security monitoring. The risk management program leverages International Organization for Standardizations (ISO) 22301 standard for business continuity, ISO 27001 standard for information security management systems, and the National Institute of Standards and Technology (NIST) Cyber Security Framework (NIST 800-171) for measuring overall readiness to respond to cyber threats. Our Chief Information Security Officer has more than 20 years of experience in IT and information security, particularly in the engineering and technology industries. Our information security organization has more than 300 members, with expertise in: (i) application security, (ii) governance and compliance, (iii) program and vulnerability management, (iv) security engineering, (v) identity and access management, (vi) security operations security assurance, (vii) threat intelligence and security architecture, and (viii) incident response.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] We maintain oversight of our cybersecurity risk management program via a corporate structure that includes a Cybersecurity Disclosure Committee, a Security Governance Council, the Audit Committee, and the Board.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our Chief Security Officer served in various roles in IT and information security for over 30 years, including security-related roles in technology deployments, product development, product security, supply chain, and operations. He holds a Bachelor of Science in computer science from the Georgia Institute of Technology. Our Chief Information Security Officer has more than 20 years of experience in IT and information security, particularly in the engineering and technology industries. Our information security organization has more than 300 members, with expertise in: (i) application security, (ii) governance and compliance, (iii) program and vulnerability management, (iv) security engineering, (v) identity and access management, (vi) security operations security assurance, (vii) threat intelligence and security architecture, and (viii) incident response.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
Our Security Governance Council, which meets quarterly or as needed, is led by our Chief Security Officer, and includes members of senior executive leadership. Our Security Governance Council maintains a security program designed to monitor and track key security performance indicators, and provides regular updates to the Audit Committee for review and oversight. Our Chief Security Officer also provides updates directly to the full Board once a year and directly to the Audit Committee at least twice a year or as needed. These updates cover topics related to information security, privacy, cyber risks and risk management processes, including the status of significant cybersecurity incidents, the emerging threat landscape, and the status of projects to strengthen the Company’s information security posture.
Honeywell’s Cybersecurity Disclosure Committee receives updates at least quarterly or as needed from Honeywell’s global security organization regarding cybersecurity incidents. The Cybersecurity Disclosure Committee includes Honeywell’s Chief Information Security Officer, Chief Security Officer, and senior representatives from finance, controllership, internal audit, investor relations, tax, and legal. Our governance, risk and compliance team, which is part of Honeywell’s enterprise security team, works in partnership with the Company’s internal audit team to review cybersecurity and IT-related internal controls as part of our overall internal controls process. The Cybersecurity Disclosure Committee informs the Security Governance Council and the Audit Committee of any cybersecurity incidents (if any) that have the potential to materially adversely impact the Company or our information systems.
Honeywell’s Board is responsible for cybersecurity risk oversight and delegated such oversight to the Audit Committee. The Audit Committee, a committee comprised of independent Board members, four of whom have notable experience related to the oversight of cybersecurity issues, is responsible for oversight of Honeywell’s IT and cybersecurity risks and regularly reports to the Board on IT and cybersecurity matters. The Audit Committee oversees risk related to the protection of customer and employee data, trade secrets, and other proprietary information, the security of data on the cloud, persistent threats, and cybersecurity risks associated with the Company’s own products and facilities.
Our Chief Information Security Officer reports to our Chief Security Officer and oversees the global enterprise security team responsible for leading enterprise-wide information security strategy, architecture, and processes. The global enterprise information security team is responsible for infrastructure defense and security controls, performing vulnerability assessments, security incident management, and defining the parameters and standards of our information security risk management program. Our cybersecurity and information security risk management program includes risk assessment and mitigation through a threat intelligence-driven approach, application controls, and security monitoring. The risk management program leverages International Organization for Standardizations (ISO) 22301 standard for business continuity, ISO 27001 standard for information security management systems, and the National Institute of Standards and Technology (NIST) Cyber Security Framework (NIST 800-171) for measuring overall readiness to respond to cyber threats. Our Chief Information Security Officer has more than 20 years of experience in IT and information security, particularly in the engineering and technology industries. Our information security organization has more than 300 members, with expertise in: (i) application security, (ii) governance and compliance, (iii) program and vulnerability management, (iv) security engineering, (v) identity and access management, (vi) security operations security assurance, (vii) threat intelligence and security architecture, and (viii) incident response.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true