18% of Data Center Physical Infrastructure Assets Sit One Hop From Public Internet
- CVE ID
- N/A
- Affected Products / Orgs
- Data Center OT, Building Management Systems (BMS), Power Distribution Units (PDUs), HVAC, SCADA/PLCs
Modern data centers are expanding rapidly to meet cloud and AI computing demands, but their operational technology (OT) and cyber-physical systems (CPS) continue to lag behind corporate IT in security posture. Recent telemetry from Claroty analyzing over 750,000 cyber-physical systems across major global data center facilities reveals that while direct internet exposure remains low, roughly 18% of critical infrastructure assets sit just a single network hop away from publicly accessible systems.
This exposure gap spans the physical devices that keep data centers operational, including HVAC units, power distribution networks, backup uninterruptible power supplies (UPS), and fire management systems. Out of 174,000 infrastructure assets analyzed, fewer than 1,000 (0.4%) were directly accessible over the public internet. However, approximately 32,000 assets are positioned on flat or poorly segmented networks adjacent to internet-exposed systems, presenting threat actors with a low-friction pivot pathway into physical infrastructure.
Anatomy of the ‘One Hop’ Pivot
The primary driver behind this systemic exposure is the convergence of IT and OT environments, frequently compounded by unmanaged remote access and flat network architectures. A “one-hop” exposure typically occurs when an infrastructure control system resides on the same broadcast domain or routing segment as a dual-homed server, a vendor remote-management appliance, or an internet-facing jump box.
Claroty’s research indicates that 41% of analyzed power distribution units (PDUs) and 32% of HVAC systems reside just one hop away from a risky internet connection. Once an attacker establishes an initial foothold on an internet-facing asset—whether through an unpatched perimeter vulnerability, compromised credentials, or a weak remote access mechanism—they can move laterally directly into the internal control environment without encountering additional network access controls or authentication checks.
+-------------------+ Compromised +-----------------------+ Unsegmented +--------------------------+
| Internet-Exposed | ---------------------> | Dual-Homed Server / | --------------------> | Physical OT / CPS |
| System / Access | Initial Access | Vendor Remote Jump | Lateral Movement | (HVAC, PDU, BMS, UPS) |
+-------------------+ +-----------------------+ (One Hop) +--------------------------+
Protocol Weaknesses and Legacy OT Vulnerabilities
Once inside the OT or Building Management System (BMS) network, attackers rarely need sophisticated zero-day exploits to achieve execution. Legacy operational protocols were designed for reliable physical delivery rather than adversarial environments, leaving them inherently unauthenticated and unencrypted.
- Insecure Protocol Usage: 88% of analyzed Building Management Systems communicate over inherently insecure legacy protocols such as standard BACnet, Modbus, or plain-text SNMP. These protocols lack cryptographic verification, enabling any device on the network segment to issue direct commands to physical controllers.
- Outdated Firmware: 40% of BMS devices run obsolete firmware containing known security flaws.
- Known Exploited Vulnerabilities: Across specialized OT control systems—such as Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) systems—researchers identified 11,000 devices harboring vulnerabilities already present in known-exploited threat catalogs.
When unmanaged remote access and legacy protocols intersect, threat actors can map out physical device topologies, manipulate setpoints, or override automated safeties using basic industrial control command sets.
Operational Blast Radius and Physical Consequences
Compromising cyber-physical systems in a data center carries operational risks that extend far beyond data exfiltration or host encryption. Physical infrastructure controls govern the tight environmental and electrical tolerances required to keep high-density server hardware online.
Manipulating cooling systems like HVAC or chillers can trigger rapid thermal runaway in high-density server halls. If ambient temperatures breach critical operating thresholds, servers will initiate thermal shutdowns or suffer permanent hardware failure. Similarly, tampering with intelligent PDUs, power monitoring networks, or backup UPS switchgear can cause phase imbalances, drop power feeds, or prevent emergency diesel generators from taking over during utility outages. In extreme cases, misconfiguring environmental or fire suppression systems can cause false agent discharges or trigger emergency power-off (EPO) switches, taking entire facilities offline instantly.
Strengthening Data Center OT and CPS Security
Mitigating exposure across data center facilities requires enforcing strict boundary controls between administrative IT networks, vendor access paths, and physical OT networks.
- Zero Trust Network Segmentation: Eliminate flat networks bridging IT and OT domains. Isolate BMS, HVAC, and power management assets into dedicated VLANs protected by internal firewalls, preventing direct lateral movement from internet-adjacent hosts.
- Protocol-Aware Inspection: Deploy network monitoring solutions capable of deep packet inspection (DPI) for industrial protocols (e.g., Modbus TCP, BACnet/IP) to detect unauthorized write commands or unusual control traffic patterns.
- Hardening Remote Access and BMS: Ban unmanaged jump boxes and incoming direct serial-to-IP gateways. Require multi-factor authentication (MFA) and granular session monitoring for all vendor remote management connections, update legacy BMS firmware, and transition to secure protocol variants (such as BACnet/SC) where hardware supports it.
- Continuous Exposure Management: Implement continuous asset discovery to identify rogue dual-homed devices, untracked IP addresses on infrastructure networks, and unpatched KEVs in PLC/SCADA devices.
Related content
Files Related to India's Largest Nuclear Plant Exposed in Data Breach
AdvisoryCisco FMC Hard-Coded Password Flaw (CVE-2026-20316): Attack Paths & Triage
Security NewsThe Non-Human Identity Trap: Why Broad AI Agent Permissions Guarantee Breaches
Security NewsCisco Secure FMC Zero-Day Exploited via Static Credentials (CVE-2026-20316)
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call