Claroty has published research on cyber security exposures in global data centres. The study found that nearly one in five operational assets is one network step away from systems that attackers could reach.
The findings are based on an analysis of more than 750,000 cyber-physical systems assets across large data centre facilities. These assets include power distribution equipment, cooling systems, building management systems, uninterruptible power supplies, generators and infrastructure management tools that support day-to-day operations.
The "one hop" finding points to a common weakness in data centre environments. Operational systems may not be directly exposed to the public internet, but an attacker that compromises an internet-connected device could move laterally through a network and reach systems that control electricity, cooling or building automation.
This matters because data centres rely on operational technology often designed for reliability and continuity rather than modern cyber defence. As operators expand facilities to meet demand for cloud services and artificial intelligence workloads, these older systems are becoming part of larger, more connected environments.
Key exposures
The research identified power and cooling as the most exposed areas within the operational estate. Power distribution units had the highest share of assets that were either directly exposed or one hop away from a risky public internet connection, at 41%. HVAC and cooling systems followed at 32%.
Building management systems also emerged as a weak point. Claroty found that 88% of these systems communicated over insecure protocols, while 40% contained outdated firmware.
Legacy technology remained common across several categories. More than 80% of operational technology control systems, power monitoring tools and Internet of Things devices used older protocols such as BACnet and MODBUS. Both are widely deployed in industrial and building environments but were not created with current threat conditions in mind.
The report also found evidence of known software weaknesses in connected devices. Nearly a quarter, or 23%, of Internet of Things devices in data centres contained known exploited vulnerabilities, meaning publicly identified flaws that attackers have already used elsewhere.
Broader concern
The figures add to a growing debate over whether data centres should be treated more explicitly as critical infrastructure. Their role has expanded beyond housing servers. They now underpin cloud platforms, public services, logistics systems, banking networks and a widening range of artificial intelligence applications.
In Australia, the findings are likely to draw attention because of the pace of data centre construction and the policy focus on digital infrastructure. The research suggests this build-out may also be creating a security blind spot if operators do not bring supporting operational systems up to the same standard of scrutiny applied to core IT environments.
Corporate attention often centres on applications, customer data and perimeter defence, but the operational systems that keep a facility running can present a different route for disruption. A breach affecting cooling, power delivery or automation controls could interrupt availability even if core computing systems remain intact.
That distinction is important in a sector where uptime is central to contracts and customer trust. Even a short loss of cooling or electrical stability can affect equipment, workloads and service continuity, making operational technology security a business issue as well as a technical one.
Operational divide
Security specialists have long argued that operational technology and traditional information technology are governed differently, often by separate teams with different priorities. In data centres, this divide can leave building and facility systems outside the main cyber security programme, especially where equipment is ageing, difficult to patch or managed by third parties.
Claroty's data points to that gap. Building management systems, environmental monitoring platforms and power controls may be essential to keeping facilities online, yet they can sit on networks that still use insecure communications and older firmware because operators fear downtime from changes or upgrades.
Claroty said operators should focus on exposure management, tighter network segmentation, hardening building management systems, and monitoring that can detect anomalous traffic and lateral movement. These steps reflect a broader shift in industrial and facilities security towards limiting internal pathways rather than assuming perimeter controls alone will hold.
A warning from the study came from Amir Preminger, Chief Technology Officer and Head of Team82 at Claroty. "Data centres have evolved into critical infrastructure globally, and much like electric utilities or transportation, threat actors will see the high value in disrupting their operations," Preminger said.
"As data centre protection is vitally important on a societal scale in terms of the AI boom and economic and national security, building operational resilience is the best path forward for operators safeguarding these complex CPS ecosystems," he said.