One in Five Data Center Assets Accessible to Attackers, Claroty Warns
New research from Claroty reveals that 20% of cyber-physical systems in large data centers are just one network hop away from internet-exposed pathways, posing significant risks.
A substantial portion of critical infrastructure within major data centers remains vulnerable to cyberattacks, with nearly one in five cyber-physical systems (CPS) just a single network connection away from potential compromise. This alarming finding comes from new research conducted by Claroty, a firm specializing in securing operational technology (OT), Internet of Things (IoT), and other CPS.
Claroty's analysis, which examined over 750,000 data center assets including approximately 191,000 OT assets and 174,000 infrastructure assets, highlights a critical gap in network segmentation and access control for these vital systems. While less than 1,000 (0.4%) of infrastructure assets were found to be directly exposed to the internet, a staggering 32,000 (18%) were identified as being "one hop" away from internet-facing systems, creating a potential entry point for threat actors.
These accessible systems control essential data center functions such as HVAC, power monitoring and distribution, fire management, and uninterruptible power supply (UPS) systems. The research indicates that attackers could leverage these pathways to exploit weaknesses in CPS, including insecure communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access technologies, flat network architectures, weak authentication, and misconfigurations.
The consequences of a successful attack against these operational infrastructure components could be severe, potentially leading to disruptions in cooling operations, power distribution failures, compromised environmental controls, interference with backup power systems, and an overall degradation of operational resilience. Claroty specifically noted that 41% of power distribution units and 32% of HVAC systems are within one hop of a risky internet connection.
Beyond network proximity, the study also uncovered other significant security risks. For instance, 88% of building management systems communicate over insecure protocols, and 40% are running outdated firmware. Furthermore, thousands of devices, including 11,000 OT control systems like SCADA and PLC devices, were found to have known exploited vulnerabilities, increasing their susceptibility to active threats.
Claroty's report emphasizes the urgent need for data center operators to bolster their defenses. The firm recommends adopting a strategy of continuous exposure management, implementing zero trust network segmentation to limit lateral movement, hardening building management systems, and deploying protocol-aware threat detection capabilities.
These findings underscore the growing challenge of securing complex, interconnected environments like data centers, where the convergence of IT and OT systems creates new attack surfaces. As data centers become increasingly critical to global operations, particularly with the rise of AI infrastructure, ensuring the security and resilience of their cyber-physical assets is paramount.
The research serves as a critical wake-up call for the industry, urging a proactive approach to identifying and mitigating risks before they can be exploited by malicious actors. The findings align with broader industry concerns about the security of critical infrastructure and the need for robust cybersecurity practices.