Recent findings by cybersecurity firm Claroty have revealed alarming vulnerabilities within data centers worldwide. Nearly 20% of the cyber-physical systems that power the largest data centers are just a single network connection away from being compromised by attackers. Such proximity to potential threats highlights significant security concerns for these critical infrastructures.
Understanding Data Center Asset Vulnerabilities
Claroty’s comprehensive analysis of over 750,000 data center assets, including nearly 191,000 OT assets and 174,000 infrastructure components, sheds light on these vulnerabilities. The infrastructure elements examined include vital systems such as HVAC, power monitoring, fire management, and uninterruptible power supplies. While less than 0.4% of these assets are directly exposed to the internet, approximately 32,000 or 18% are just ‘one hop’ from internet-exposed systems, providing easy access for potential attackers.
The report emphasizes that such attack vectors can exploit weaknesses in CPS through insecure communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access, flat network architectures, and weak authentication. Once attackers gain entry, the consequences can be severe, risking disruptions to cooling and power systems, compromising environmental controls, and degrading overall operational resilience.
Critical Risks and Potential Impacts
Among the findings, Claroty identified that 41% of power distribution units and 32% of HVAC systems are precariously close to internet-accessible pathways. These vulnerabilities extend to building management systems, where 88% use insecure protocols and 40% operate on outdated firmware. Such risks not only threaten the integrity of the data centers but also highlight the urgent need for enhanced security measures.
Furthermore, thousands of devices, including SCADA and PLC systems, are affected by vulnerabilities already exploited in real-world scenarios. Approximately 11,000 OT control systems are at risk due to these known flaws, underscoring the need for immediate action to fortify security protocols and protect critical infrastructure.
Enhancing Data Center Security
In response to these findings, Claroty has outlined strategic measures to bolster data center resilience. Recommendations include implementing continuous exposure management, adopting zero trust network segmentation, and strengthening the security of building management systems. Additionally, protocol-aware threat detection is advised to mitigate potential risks effectively.
As data centers continue to evolve, securing these critical infrastructures becomes ever more vital. By addressing the identified vulnerabilities and adopting robust security practices, operators can better safeguard their assets against potential cyber threats and ensure the ongoing reliability of their operations.
For more information and related guidance, readers are encouraged to review updates from the US and its allies on SBOM guidance and OT isolation strategies for critical infrastructure protection.
