AI Boom Overwhelms Data Center OT Security, Experts Warn
The rapid expansion of data centers to meet AI demand is creating significant operational technology (OT) security risks, leaving critical infrastructure vulnerable.

The insatiable demand for artificial intelligence is fueling an unprecedented construction boom for data centers, but this rush to deploy compute power is leaving operational technology (OT) security dangerously neglected. Experts warn that in the haste to build, siloed systems are being implemented, placing critical OT devices like power and cooling controls just a single network hop away from the public internet, creating a significant attack surface.
Total U.S. capital expenditure on data centers is projected to exceed $700 billion this year, with plans for nearly 3,000 new facilities costing approximately $2.4 trillion by 2030. This aggressive expansion, driven by the need to power large language models and other AI applications, means speed is often prioritized over best practices. Contractors working on different deadlines and with different specializations are creating fragmented networks that, in many cases, lack robust segmentation from external access points.
"The HVAC guy doesn't care about the power guy. Those are two different teams, two different people, two different contractors," explained Sean Tufts, field CTO for OT security specialists Claroty. "And that's turning out to be a big cyber problem that's starting to unfold in front of our eyes." The consequences of a successful attack on these OT systems could range from data center downtime to more severe disruptions, impacting the very infrastructure designed to support modern digital services.
While there have been no verified attacks specifically targeting data center OT systems to date, the risk is palpable. Threat intelligence firms have noted unverified claims of attacks, but the potential for exploitation remains high. The geopolitical climate also adds a layer of concern, with nation-states increasingly viewing data centers as legitimate targets, as evidenced by recent missile and drone attacks on facilities in conflict zones.
Government agencies are also taking notice. The National Telecommunications and Information Administration (NTIA) initiated an inquiry into data center resiliency, supply-chain integrity, and cybersecurity to protect AI technologies. The agency solicited industry comments, highlighting the amplified need for fortified security measures and robust protocols to safeguard the vast amounts of data processed within these facilities.
Compounding the issue is a departure from traditional systems engineering approaches. The accelerated pace of data center development means that comprehensive analysis of how different systems interact and secure each other is often bypassed. "Because these are happening so fast, there hasn't been a lot of the traditional project engineering that you would expect for such large infrastructure," noted Allan Friedman, technologist-in-residence at TPO Group. This lack of integrated security design leaves vulnerabilities that can be exploited.
Furthermore, there's a notable attention deficit regarding the security of control systems within data centers. While significant engineering effort is dedicated to the core computing components like chips, bandwidth, and memory, the security and resilience of supporting infrastructure, such as cooling and power management control systems, often receive less focus. This disparity creates blind spots where attackers can find entry points.
Claroty's analysis of anonymized data from client networks reveals the tangible results of this rapid build-out: vulnerable OT devices are left exposed, just "one hop" from the open internet. This situation underscores the urgent need for a paradigm shift in how data centers are secured, ensuring that the infrastructure supporting the AI revolution is not itself a critical vulnerability.