Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Data Center Exposures and the Pathways Putting Data Center Assets at Risk

/ / 6 min read
Featured image for our blog: Data Center Exposures and the Pathways Putting Data Center Assets at Risk

Skyrocketing artificial intelligence (AI) demands in businesses worldwide are fueling unprecedented data center growth. As more business outcomes rely on AI, the stakes for keeping data center facilities secure and resilient in the face of inevitable cybersecurity incidents will become just as great. Any interruption of services or disruption among data center assets or infrastructure could lead to cascading consequences impacting uptime and service availability.

This fueled Claroty Team82’s research into how exposed critical data center assets and infrastructure are to advanced adversaries in cyberspace, in particular, the cyber-physical systems (CPS) ecosystem supporting data centers

In this blog, we’ll explain:

  • The key findings of Team82’s latest research into data center exposures

  • How exposures in data center assets and infrastructure are “one hop” away from connected IT or remote management systems

  • The outcomes attackers hope to achieve by exploiting data center exposures

  • What controls we recommend to reduce the risk of data center exposures

CPS and data center infrastructure such as building management systems (BMS), building automation systems (BAS), power distribution, monitoring and control systems, uninterruptible power supplies (UPS), generators, cooling infrastructure, environmental monitoring platforms, and data center infrastructure management (DCIM) solutions maintain facilities’ health. They keep critical servers and networking infrastructure cool, ensure power remains consistent—even in the face of outages—and provide the foundations for facilities’ economic viability. 

Team82’s latest State of CPS Security: Data Center Exposures report examines data center exposures from an extensive data set of more than 750,000 assets. While it’s rare that assets are directly connected to the internet, they are not inherently protected from cyberattacks. Direct connectivity is not always a prerequisite for compromise. 

Quantifying Data Center Exposures

Instead, attackers can often find success moving laterally after the compromise of an asset that is usually no more than one hop from an exposed CPS asset. Data center asset exposures are reached via indirect pathways into operational environments through interconnected IT systems, third-party remote access, remote management services, and trusted network relationships.

An attacker intent on disruption or damage can use these indirect attack paths to reach data center assets or infrastructure, which contain a bevy of exploitable CPS weaknesses, including insecure legacy communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications. 

To quantify some of these exposures:

  • 18% (32,000+) of more than 174,000 data center infrastructure assets are no more than one hop away from a system making risky outbound connections to the public internet

  • Power distribution units (41%) and HVAC/cooling systems (32%) have the highest percentage of assets one hop away from a risky connection to the public internet or directly exposed 

  • BMS contain some of the riskiest exposures, with 88% communicating over insecure protocols and 40% containing outdated firmware

  • More than 80% of OT control systems, power monitoring, and IoT systems communicate over legacy, insecure protocols such as BACnet and MODBUS

  • 23% of IoT devices such as environmental sensors, asset tracking tags, and IoT gateways are vulnerable known exploited vulnerabilities (KEVs) 

Successful attacks against CPS inside data centers can disrupt cooling operations, affect power distribution, compromise environmental controls, interfere with backup generation systems, and degrade overall operational resilience. 

KEVs, Weak Protocols Top Exposures

Facility operators and engineers must be aware of these exposures and attack paths at the disposal of determined and often advanced attackers. Our report goes into depth on these exposures, and provides actionable recommendations to lock down CPS assets inside the data center, starting with an exposure management strategy that not only has visibility into, and controls around exposures, but also understands the pathways available to attackers. 

KEVs and insecure protocol communication are the most serious exposures. KEVs are software and firmware vulnerabilities that have been exploited in publicly disclosed attacks, and legacy protocols such as MODBUS and BACnet, while foundational to OT and BMS communications, often lack fundamental security protections such as authentication and encryption. 

How to Maintain a Secure Data Center

Data center operators must strive for operational resilience to ensure uptime, compliance, and their ability to meet business outcomes. Many of these connected devices and infrastructure are not traditional computing assets, and require a security approach that fits the unique complexities of the cyber-physical systems (CPS) pervasive in these environments. 

We recommend four approaches to minimize the impact of data center exposures:

1. Exposure Management for Data Center Assets

Exposure management for data center infrastructure and assets should prioritize mitigation and remediation of outdated firmware and legacy protocols in use on the assets most important to meeting business outcomes and uptime requirements. 

Legacy firmware and software for which there are known exploited vulnerabilities expands the window of time these assets are exposed to compromise. Unpatched vulnerabilities can allow an attacker to disrupt or damage data center assets, or further move laterally among infrastructure and the enterprise network. Legacy protocols also pose a significant risk since most lack fundamental security capabilities and exposes traffic to sniffing, manipulation, and other threats. 

2. Implement Zero-Trust Segmentation

Segmentation—and microsegmentation—are the primary controls limiting the blast radius of a cyberattack. Implementing strict, zero-trust network segmentation between IT and facility systems is paramount. With our research demonstrating the reachability of data center infrastructure via internal communication with adjacent systems and the exposures putting that infrastructure at risk, segmentation is the fundamental cybersecurity control we recommend. 

Zero-trust segmentation, meanwhile, further isolates key assets and infrastructure by putting strict access controls in place. Operators can enforce restrictive security policies that enforce least-privilege approaches to zero-trust, ensuring that identities are validated for each request. 

3. Harden BMS

Zero-trust segmentation is a key control that limits accessibility to BMS in the event of an incident. Isolating BMS keeps an attacker from manipulating key environmental controls that are so fundamental to data center asset uptime and viability. 

Our research shows that BMS also often operates on outdated firmware and legacy operating systems that are no longer supported with security updates. A combination of segmentation and zero-trust further hardens BMS that can no longer be easily patched. 

4. Detect Threats, Monitor Networks

Threat detection for CPS in a data center involves continuously monitoring the physical facility infrastructure and the digital systems that control them. The goal is to detect, isolate, and mitigate malicious attacks and operational anomalies before they disrupt server operations.

Threat detection relies on dependable and available asset inventories of CPS assets and data center infrastructure. Solutions must be protocol-aware and listen for CPS-specific machine-to-machine communication. Any deviation from baseline traffic should trigger alerts. 

To read the full report, download Team82’s State of CPS Security: Data Center Exposures report.

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook