20% of Data Center Assets Vulnerable to Cyber Attacks
Nearly one in five cyber-physical systems (CPS) critical to data center operations are positioned within a single network hop of potential attack vectors, according to findings from Claroty. The firm, which focuses on securing operational technology (OT), IoT, and other CPS environments, analyzed over 750,000 data center assets, including 191,000 OT components and 174,000 infrastructure systems. These infrastructure assets encompass heating, ventilation, and air conditioning (HVAC) systems, power monitoring and distribution units, fire management tools, and uninterruptible power supply (UPS) devices. Claroty’s investigation revealed that while less than 1,000 (0.4%) of the 174,000 infrastructure assets are directly accessible via the internet, approximately 32,000 (18%) are connected through systems that could serve as entry points for malicious actors. Attackers leveraging these pathways might exploit weaknesses such as unsecured communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access tools, flat network designs, weak authentication methods, and improperly configured device interactions. Compromising operational infrastructure that governs essential data center functions could lead to severe consequences, including disruptions to cooling systems, power distribution failures, environmental control breaches, and interference with backup power mechanisms. These vulnerabilities could significantly undermine the resilience of data center operations. The research highlighted specific risks tied to power distribution units and HVAC systems, with 41% and 32% respectively located within a single network hop of potentially vulnerable connections. Building management systems also presented significant risks, as 88% of them rely on insecure communication protocols and 40% operate with outdated firmware. Additionally, thousands of devices were identified with vulnerabilities that have been actively exploited in real-world attacks. In the realm of OT control systems, which include supervisory control and data acquisition (SCADA) and programmable logic controller (PLC) devices, 11,000 units were found to have known exploited flaws. Claroty’s report emphasizes the need for proactive measures to enhance operational resilience, including continuous exposure management, zero trust network segmentation, strengthening building management system security, and implementing protocol-aware threat detection strategies.
