1 in 5 Data Center Assets Are Within Easy Reach of Attackers
1 in 5 data center cyber-physical systems are one network hop from internet-exposed systems.
Summary
Claroty's analysis of over 750,000 data center assets reveals that approximately 18% of cyber-physical systems are one network hop away from internet-exposed pathways, posing a significant risk. These systems, including HVAC and power distribution units, are vulnerable to exploitation through insecure protocols, known exploited vulnerabilities, and weak authentication, potentially disrupting critical data center operations.
Full text
Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways that could let attackers reach them, according to new research from Claroty. Claroty, which specializes in securing OT, IoT, and other CPS, has analyzed more than 750,000 data center assets, including roughly 191,000 OT assets and 174,000 infrastructure assets. The data center infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems. Claroty’s analysis found that of the total of 174,000 infrastructure assets, less than 1,000 (0.4%) are directly exposed to the internet. However, approximately 32,000 (18%) are “one hop” away from internet-exposed systems that provide a potential access vector to attackers. [ Read: AI Data Centers Are Being Built Faster Than They Can Be Secured ] “Attack paths may then lead threat actors to exploitable CPS weaknesses such as insecure communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications,” Claroty explained. It added, “Gaining access to operational infrastructure that controls critical data center functions poses serious consequences. Successful attacks against CPS inside data centers can disrupt cooling operations, affect power distribution, compromise environmental controls, interfere with backup generation systems, and degrade overall operational resilience.”Advertisement. Scroll to continue reading. The security firm found that 41% of power distribution units and 32% of HVAC systems are one hop away from a risky connection to the internet. The company identified other types of security risks as well, including ones related to building management systems, which in 88% of cases communicate over insecure protocols, and in 40% of cases use outdated firmware. Claroty researchers also detected thousands of devices affected by vulnerabilities that are known to have been exploited in the wild. In the case of OT control systems, which include SCADA and PLC devices, 11,000 had known exploited flaws. Claroty’s report outlines practical steps for strengthening data center operational resilience, urging operators to adopt continuous exposure management, zero trust network segmentation, hardening of building management systems, and protocol-aware threat detection. Related: US and Allies Update SBOM Guidance Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Related: Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI’s Rogue AI Ventured Beyond Hugging FaceDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksCyera Acquiring Oasis Security in $1 Billion DealApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Origin Energy Data Breach Affects 900,000 AustraliansNvidia and Tech Giants Launch AI Security AllianceCoca-Cola Confirms Data Breach After Fairlife Ransomware Attack Latest News Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms US and Allies Update SBOM GuidanceChrome 151 Patches 370 VulnerabilitiesCisco Secure FMC Zero-Day Exploited in the WildUS Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityMate Security Raises $35 Million for Agentic SOCThreatLocker Raises $190 Million in Series F FundingCritical VM Escape Vulnerability Patched in VMware ESXi Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAlex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- mitre_attack — T1190
- mitre_attack — T1071
- mitre_attack — T1550