Data centers are the backbone of the digital economy. Yet as operators expand capacity to accommodate artificial intelligence, cloud computing and hyperscale workloads, the infrastructure supporting those services is becoming increasingly complex – and increasingly exposed to cyber risk. According to cybersecurity specialist Claroty, around one in five cyber-physical systems has significant security vulnerabilities. The challenge extends far beyond conventional IT: power, cooling, building automation and other operational technologies have become integral components of the data center attack surface.
The global data center industry is entering a period of exceptional growth. Cloud services continue to expand, while the computational demands of generative AI are accelerating investment in high-density infrastructure. At the same time, the availability of a modern data center depends on far more than servers, storage and network equipment.
Power distribution, uninterruptible power supplies, backup generators, cooling systems, sensors, physical access controls and building management systems all contribute to operational continuity. Many of these technologies fall within the category of cyber-physical systems (CPS), where digital control mechanisms interact directly with physical processes.
From a security perspective, this convergence has profound implications. A successful cyberattack may no longer result solely in data theft or disruption of digital services. If operational systems are compromised, attackers may interfere with the physical processes required to keep computing infrastructure running – potentially affecting cooling, power availability or other mission-critical functions.
OT and Building Automation Expand the Attack Surface
One of the fundamental challenges is visibility. Data center environments often evolve over many years, combining newly deployed technologies with legacy equipment from different generations and vendors. Operators, facility teams, manufacturers, contractors and maintenance providers may all require access to different parts of this ecosystem.
Operational technology also follows very different lifecycle patterns from traditional enterprise IT. Industrial and building systems may remain in service for decades, including equipment that has reached the end of its supported lifecycle but cannot easily be replaced without significant cost or operational disruption.
This makes conventional patch management difficult. Applying a security update to an office endpoint is one thing; modifying a system responsible for cooling or electrical distribution is another. Even a routine intervention may introduce operational risk if it requires downtime or affects the stability of critical processes.
Claroty estimates that approximately one in five cyber-physical systems contains significant security weaknesses. For operators, the task is therefore not simply to identify vulnerabilities. They must determine which vulnerabilities pose a meaningful operational threat and prioritise remediation according to the potential impact on availability.
Third-Party Access Becomes a Security Priority
External connectivity represents another significant area of exposure. Data centers depend on specialist contractors and technology providers for maintenance, diagnostics and technical support. These activities frequently require remote access to operational systems.
Traditional VPN-based access can create excessive privileges, potentially exposing more of the network than a contractor needs for a specific task. In highly interconnected environments, compromised third-party credentials can therefore become an entry point into critical infrastructure.
Zero Trust architectures offer an alternative by replacing implicit network trust with tightly controlled access based on identity, asset, purpose and duration. A contractor servicing a cooling component, for example, should receive access only to the systems required for that particular maintenance operation – not to adjacent operational environments.
Segmentation is equally important. Power, cooling and automation systems should communicate through defined and authorised pathways. Restricting unnecessary connectivity reduces the possibility that a compromise in one part of the infrastructure can be used for lateral movement into other critical systems.
Availability Changes the Rules of Incident Response
Incident response in cyber-physical environments requires a different mindset from conventional enterprise IT.
When an endpoint is compromised, isolating it from the network may be an obvious containment measure. In a data center, however, disconnecting an operational asset without understanding its function could itself trigger an outage.
Security Operations Centers therefore need more than alerts indicating the presence of a vulnerability or suspicious activity. They require operational context: What function does the affected asset perform? Which systems depend on it? What does it communicate with? And what could happen if it is isolated, restarted or taken offline?
This changes the relationship between cybersecurity and operational resilience. A technically successful containment action is of little value if it inadvertently disrupts a mission-critical process. Security teams, IT departments and facility operators must consequently develop common processes for evaluating threats and coordinating responses.
Cybersecurity and operational availability can no longer be managed as separate disciplines.
NIS2 Raises the Compliance Stakes
Regulatory pressure adds another dimension to the challenge. Operators of critical and important infrastructure are increasingly expected not only to implement cybersecurity controls but also to demonstrate that those controls are effective.
Claroty points to requirements associated with the EU’s NIS2 framework as well as ISA/IEC 62443, the international standards series addressing cybersecurity for industrial automation and control systems. Customer requirements and cyber-insurance underwriting are adding further pressure for demonstrable risk management and operational transparency.
As a result, vulnerability management is becoming a business-risk discipline. A list of technical weaknesses alone provides limited value to executive decision-makers. Operators need to understand which assets are essential to availability, which exposures represent the greatest operational risk and what the financial consequences of disruption could be.
This context is also necessary when prioritising investment. Not every vulnerability carries the same business impact, and not every legacy system can be replaced immediately. Risk-based decisions are therefore essential.
Asset Visibility as the Foundation of Data Center Security
Effective protection begins with knowing what is present in the environment. Operators need comprehensive visibility into OT, IoT, building management and other cyber-physical assets, including software and firmware versions, communication relationships, vulnerabilities and lifecycle status.
Claroty addresses these requirements through its xDome platform, designed to provide visibility across CPS environments, continuously assess risk and enable controlled remote access. According to the company, its portfolio secures more than 40 million cyber-physical systems across over 8,000 sites worldwide and supports more than 450 CPS protocols.
These figures also illustrate the scale of the wider challenge. Data center cybersecurity no longer stops at the boundary of the IT network. As facilities become more automated and interconnected, power infrastructure, cooling equipment, building management and physical systems increasingly become part of the cybersecurity equation.
For operators, resilience will therefore depend on treating cyber and operational security as interconnected priorities. As data centers become ever more critical to AI, cloud services and the wider digital economy, the consequences of disruption will grow accordingly.
Comprehensive asset visibility, tightly controlled access, effective segmentation and risk-based lifecycle management are becoming fundamental requirements for maintaining both security and uptime.
Further Guidance on Data Center Cybersecurity
For organizations seeking a more detailed examination of the issue, Claroty provides “The Ultimate Buyer’s Guide for Data Center Cybersecurity.” The guide focuses on protecting OT, IoT, Building Management Systems (BMS) and other cyber-physical technologies within data center environments. It covers areas including asset visibility, cyber risk management and the protection of critical operational processes.
The guide is available to download from Claroty.
Download The Ultimate Buyer’s Guide for Data Center Cybersecurity


