Building Management Systems Emerge as a Blind Spot in AI Data Centre Security

August 19, 2026

TrendAI identifies thousands of publicly accessible control systems near US data centres – with implications for Europe’s AI infrastructure

As artificial intelligence drives a new wave of data centre construction, cybersecurity strategies are increasingly focused on protecting servers, networks and data. Yet another critical layer of infrastructure receives considerably less attention: the building and operational technology that keeps data centres running.

A recent investigation by TrendAI, Trend Micro’s enterprise cybersecurity business, highlights the potential risks associated with internet-accessible building automation and industrial control systems in the vicinity of data centres.

For its report, “An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers,”TrendAI threat researchers Stephen Hilt and Numaan Huq examined industrial control protocols around more than 1,000 data centres in the United States. Using the Shodan search engine, they searched within a one-kilometre radius of each facility for internet-connected building automation and industrial control systems.

The researchers identified approximately 6,300 publicly accessible devices. These included BACnet controllers and Niagara-based systems that can be used to monitor and control functions such as cooling, power distribution and environmental conditions.

Although the research was conducted in the United States, the findings are highly relevant for Europe. Major data centre hubs such as Frankfurt, Amsterdam, Dublin and Paris are experiencing rapid expansion as demand for cloud services and AI computing capacity continues to grow. The underlying risk pattern identified in the study is therefore considered transferable to European infrastructure environments.

At the same time, geographical proximity alone does not prove that every identified system belongs directly to a nearby data centre. The findings should therefore not be interpreted as evidence that thousands of data centres are directly exposed. They do, however, illustrate the potential scale of the attack surface surrounding densely concentrated digital infrastructure – a reality increasingly relevant for European AI and cloud ecosystems.

Newer facilities show higher exposure rates

Publicly accessible building management or industrial control systems were identified near approximately 100 of the 1,063 data centres examined.

One of the most notable findings concerns facility age. Among data centres built since 2021, the researchers calculated an exposure rate of 13.1 per cent. For facilities dating from before 2010, the corresponding figure was 4.9 per cent.

TrendAI interprets this as a possible indication that the rapid expansion of AI-driven infrastructure is placing pressure on security-by-design principles. This is particularly relevant in Europe, where NIS2 and related critical infrastructure regulations are increasing expectations for security governance across both IT and operational technology environments.

The researchers also identified software versions associated with a total of 53 known vulnerabilities, some of which carry the maximum Common Vulnerability Scoring System rating of 10.0.

While internet accessibility does not automatically imply compromise, it significantly increases exposure and can simplify reconnaissance for potential attackers.

Another key finding relates to multi-protocol gateways. Of approximately 3,991 IP addresses identified, 143 were classified as such gateways. These systems can act as central integration points for multiple building automation protocols, meaning that a compromise could potentially affect several connected subsystems simultaneously.

Cyberattacks could directly affect data centre operations

Building automation systems perform functions that are essential to data centre availability, including cooling, air conditioning, power management and environmental monitoring.

Manipulation of these systems could therefore have direct operational consequences.

Attackers could interfere with cooling systems or alter temperature and humidity controls, potentially forcing servers to operate outside safe environmental thresholds. This could lead to service degradation, emergency shutdowns or physical hardware damage.

In addition, manipulated alarm systems could create operational confusion. False alerts may distract facility teams, while genuine warnings could be suppressed. If access control or facility management systems are also affected, incident response capabilities could be significantly reduced.

“Servers in data centres are among the most heavily protected digital environments in the world – but the physical infrastructure keeping them alive often sits almost entirely outside those protections. If an attacker gains access to building systems, they have another path towards achieving the same objective as a conventional cyberattack: taking services offline,” says Stephen Hilt, Principal Threat Researcher at TrendAI.

According to TrendAI, the systems identified during the investigation were discovered exclusively through passive research using publicly available internet data. The researchers did not actively penetrate or manipulate any systems.

“Our researchers found these 6,300 systems through passive internet research alone – without hacking, simply by using a public search engine for internet-connected devices. If these weaknesses can already be identified this easily, it raises the question of what may exist in areas that are not externally visible,” says Udo Schneider, Governance, Risk & Compliance Lead Europe at TrendAI.

A growing European critical infrastructure challenge

For European operators, the findings highlight a broader structural issue: the convergence of IT, operational technology and physical infrastructure security.

Under frameworks such as NIS2, the EU Critical Entities Resilience (CER) Directive and guidance from ENISA, data centre operators and cloud providers are increasingly expected to treat operational technology as part of their core cybersecurity perimeter.

This is particularly relevant for Europe’s AI infrastructure strategy. High-density computing environments require significant energy and advanced cooling systems, making them heavily dependent on building management systems and industrial control technologies.

As a result, the resilience of digital services is no longer determined solely within the server room. It increasingly depends on the security of interconnected facility systems that manage power, cooling and environmental stability.

For European hyperscalers, colocation providers and energy operators, the implication is clear: OT security must be integrated into the same governance and risk frameworks as traditional IT security.

The traditional separation between IT, operational technology and physical infrastructure is becoming increasingly difficult to maintain. A technically secure server environment offers limited protection if attackers can disrupt the systems that supply its electricity, cooling or environmental controls.

As Europe continues to expand its AI and cloud infrastructure footprint, the security of data centres will depend not only on digital resilience, but on the ability to secure the entire operational ecosystem that keeps them running.

Related Articles

One in Four German Companies Fears Losing Competitiveness

Structural pressure is reaching the security industry German industry continues to lose ground in the eyes of its own companies. The challenge is particularly pronounced in markets outside the European Union: 25.4% of companies in Germany report that their competitive...

EUDEX Brings Europe’s Security and Defence Industry Together in Essen

International matchmaking formats with companies from the Visegrád countries and the Netherlands aim to initiate new technology, development, and supply partnerships at the Euro Defence Expo in September. Cross-border cooperation is becoming increasingly important for...

Share This