New research from industrial cybersecurity firm Claroty finds that data center operators have largely succeeded in keeping cyber-physical systems (CPS) off the open internet, but a significant portion of that infrastructure remains dangerously close to exposed pathways attackers could exploit.

Claroty analyzed more than 750,000 data center assets, including roughly 191,000 operational technology (OT) assets and 174,000 infrastructure assets such as HVAC, power monitoring and distribution, fire management, and uninterruptible power supply (UPS) systems. Of the 174,000 infrastructure assets examined, fewer than 1,000 (0.4 percent) were found directly exposed to the internet. However, approximately 32,000 assets, or 18 percent, sit just one network hop away from internet-facing systems that could serve as an entry point for attackers.

Where the risk concentrates

The exposure is not evenly distributed. Claroty found that 41 percent of power distribution units and 32 percent of HVAC systems are one hop away from a risky internet connection. Building management systems carry additional weaknesses: 88 percent communicate over insecure protocols, and 40 percent run outdated firmware.

Claroty also identified thousands of devices affected by vulnerabilities known to have been exploited in the wild. Among OT control systems, including SCADA and PLC devices, 11,000 were found to carry known exploited flaws.

Why it matters

Claroty warned that attack paths originating from internet-adjacent systems can lead threat actors to exploitable weaknesses including insecure communication protocols, unmanaged remote access tools, flat network architectures, weak authentication, and misconfigured asset communications. Successful compromise of operational infrastructure inside a data center could disrupt cooling, affect power distribution, compromise environmental controls, interfere with backup generation, and degrade overall operational resilience, the company said.

Recommended mitigations

  • Adopt continuous exposure management across OT and infrastructure assets
  • Implement zero trust network segmentation to limit lateral movement
  • Harden building management systems and replace outdated firmware
  • Deploy protocol-aware threat detection tailored to CPS environments

The findings arrive as data centers expand rapidly to support AI workloads, often outpacing the security controls needed to protect the physical systems that keep them running.