New research from Claroty’s Team82 finds that while data center infrastructure is rarely connected directly to the internet, thousands of power, cooling, and building management systems remain dangerously close to compromise.
Data centers rarely expose their power, cooling, and building-management systems directly to the internet. New research suggests that this apparent isolation offers far less protection than facility operators may assume.
According to a report published by Claroty’s research division Team82, titled “State of CPS Security: Data Center Exposures,” 18 percent — more than 32,000 — of over 174,000 analyzed data center infrastructure assets are exactly one network hop away from a system with a risky outbound connection to the public internet. The analysis covers more than 750,000 cyber-physical system (CPS) assets across some of the world’s largest data center facilities, including building management systems (BMS), power distribution units (PDUs), uninterruptible power supplies (UPS), HVAC/cooling equipment, and IoT sensors.
Direct internet exposure across this asset class remains low, at just 0.4 percent, the researchers found. However, attackers rarely need direct connectivity. Once inside a data center’s IT environment — via third-party remote access, interconnected enterprise systems, or trusted network relationships — adversaries can pivot laterally toward operational infrastructure that controls critical physical functions.
Power distribution units carry the highest relative risk in the data set, with 41 percent of the 6,486 analyzed PDUs sitting one hop from an internet-exposed system. Because PDUs feed power directly to server racks, Team82 warns that an attacker reaching this layer could cycle power, trigger abrupt shutdowns, or cause hardware damage across large numbers of customer workloads. HVAC and cooling systems followed at 33 percent, while building management and automation systems, the “central hub” overseeing environmental controls, fire suppression, and backup generators, showed 14 percent exposure one hop away.
The report also highlights deeper structural weaknesses once an attacker reaches these systems directly. More than 80 percent of OT control systems, power monitoring equipment, and IoT devices communicate over legacy, insecure protocols such as MODBUS and BACnet, which lack basic authentication and transmit data in cleartext. Within BMS specifically, Team82 recorded that 88 percent of devices communicate over insecure protocols and 40 percent run outdated firmware. Among IoT devices such as environmental sensors and asset-tracking tags, 23 percent contain known exploited vulnerabilities (KEVs), and 66 percent transmit data in plaintext over HTTP — a higher share than for any other OT or IT asset category examined.
The researchers frame these findings against a backdrop of real-world attacks. In April 2026, threat intelligence firm Vecert reported that the pro-Russian hacktivist group Killnet had targeted France’s STOR data center and backup-power supplier Alpha Technologies, exfiltrating energy and monitoring data and claiming access to roughly 120,000 UPS devices spanning 6,000 networks, according to the report.
Team82 attributes the rising stakes partly to the scale of current data center expansion, driven by demand for AI and large-language-model training, with several gigawatt-class campuses set to come online this year in the United States alone. Any disruption to power, cooling, or environmental controls at that scale, the researchers note, can cascade into service-level failures, regulatory exposure, and significant financial losses.
To reduce risk, the report recommends four measures: implementing exposure management that maps internal communication pathways rather than focusing solely on perimeter defense; enforcing zero-trust network segmentation between IT and operational systems, particularly on flat networks; hardening BMS platforms through isolation and strict authentication; and deploying protocol-aware threat detection capable of monitoring lateral movement across BACnet, MODBUS, and SNMP traffic. Hardware redundancy alone, the researchers caution, is not a substitute for addressing these underlying exposures, since backup systems frequently share the same vulnerabilities as the primary infrastructure they are meant to protect.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de