1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Nearly 18% of data center cyber-physical systems (CPS) are "one hop" away from internet exposure, creating significant attack vectors. Only 0.4% of infrastructure assets are directly exposed to the internet, but proximity to exposed systems creates substantial risk. Building management systems show critical vulnerabilities: 88% use insecure protocols and 40% run outdated firmware. Power distribution units (41%) and HVAC systems (32%) are disproportionately vulnerable to one-hop attacks. Over 11,
Analysis
TL;DR
- Nearly 18% of data center cyber-physical systems (CPS) are "one hop" away from internet exposure, creating significant attack vectors.
- Only 0.4% of infrastructure assets are directly exposed to the internet, but proximity to exposed systems creates substantial risk.
- Building management systems show critical vulnerabilities: 88% use insecure protocols and 40% run outdated firmware.
- Power distribution units (41%) and HVAC systems (32%) are disproportionately vulnerable to one-hop attacks.
- Over 11,000 OT control devices contain known exploited vulnerabilities (KEVs), posing serious operational risks.
Why It Matters
This research reveals a critical security gap in data center infrastructure where physical systems controlling cooling, power, and environmental functions remain dangerously accessible through network proximity rather than direct exposure. For AI practitioners and infrastructure operators, this highlights that securing AI data centers requires more than just protecting compute clusters—it demands comprehensive OT/IoT security strategies that address the interconnected nature of cyber-physical systems. The findings underscore the urgent need for zero-trust architectures and continuous monitoring as AI-driven workloads expand data center footprints.
Technical Details
- Claroty analyzed over 750,000 data center assets including approximately 191,000 OT assets and 174,000 infrastructure components covering HVAC, power monitoring/distribution, fire management, and UPS systems.
- The study identified that while only 1,000 infrastructure assets (0.4%) have direct internet exposure, roughly 32,000 assets (18%) reside within a single network hop from exposed systems, creating exploitable attack paths.
- Vulnerability assessment revealed specific weaknesses: building management systems predominantly communicate via insecure protocols (88%), operate with outdated firmware (40%), and include thousands of devices affected by known exploited vulnerabilities in OT control systems like SCADA and PLCs.
- Attack vectors include insecure communication protocols, unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications that could enable disruption of cooling, power distribution, environmental controls, and backup generation systems.
Industry Insight
Data center operators must prioritize network segmentation and zero-trust architectures to isolate critical cyber-physical systems from potential attack pathways, recognizing that proximity to exposed systems creates equivalent risk to direct exposure. The high prevalence of insecure protocols and outdated firmware in building management systems indicates an urgent need for automated vulnerability management and protocol-aware threat detection solutions specifically designed for OT environments. As AI data centers continue expanding at unprecedented rates, integrating continuous exposure management into operational resilience frameworks will become essential to prevent cascading failures that could compromise both digital services and physical infrastructure stability.
Disclaimer: The above content is generated by AI and is for reference only.