1 in 5 Data Center Assets Are Within Easy Reach of Attackers

Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty.

Claroty, which specializes in securing OT, IoT, and other CPS, has analyzed more than 750,000 data center assets, including roughly 191,000 OT assets and 174,000 infrastructure assets. The data center infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems. 

Claroty’s analysis found that of the total of 174,000 infrastructure assets, less than 1,000 (0.4%) are directly exposed to the internet. However, approximately 32,000 (18%) are “one hop” away from internet-exposed systems that provide a potential access vector to attackers. 

[ Read: AI Data Centers Are Being Built Faster Than They Can Be Secured ]

“Attack paths may then lead threat actors to exploitable CPS weaknesses such as insecure communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications,” Claroty explained. 

It added, “Gaining access to operational infrastructure that controls critical data center functions poses serious consequences. Successful attacks against CPS inside data centers can disrupt cooling operations, affect power distribution, compromise environmental controls, interfere with backup generation systems, and degrade overall operational resilience.”

Advertisement. Scroll to continue reading.

The security firm found that 41% of power distribution units and 32% of HVAC systems are one hop away from a risky connection to the internet. 

The company identified other types of security risks as well, including ones related to building management systems, which in 88% of cases communicate over insecure protocols, and in 40% of cases use outdated firmware.

Claroty researchers also detected thousands of devices affected by vulnerabilities that are known to have been exploited in the wild. In the case of OT control systems, which include SCADA and PLC devices, 11,000 had known exploited flaws. 

Claroty’s report outlines practical steps for strengthening data center operational resilience, urging operators to adopt continuous exposure management, zero trust network segmentation, hardening of building management systems, and protocol-aware threat detection.

Related: US and Allies Update SBOM Guidance

Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure

Related: Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *