September 15, 2026
September 15, 2026
Claroty’s analysis of more than 750,000 cyber-physical systems found that nearly one in five data-center infrastructure assets is only a single network connection away from an internet-exposed system. Although just 0.4% of the 174,000 examined infrastructure assets were directly accessible online, approximately 32,000—or 18%—could potentially be reached through an exposed intermediary. The risk is particularly significant for systems supporting essential operations: 41% of power distribution units and 32% of heating, ventilation and air-conditioning equipment were one hop from a risky internet connection. Attackers reaching these environments could disrupt cooling, electricity distribution, environmental controls, backup generators and overall data-center availability.
The research also identified insecure protocols, outdated firmware, weak authentication, unmanaged remote-access tools, flat network architectures and misconfigured communications as common weaknesses. Eighty-eight percent of building-management systems communicated through insecure protocols, 40% used outdated firmware, and approximately 11,000 OT control systems—including SCADA devices and programmable logic controllers—contained vulnerabilities known to have been exploited in real attacks. Claroty recommends continuous exposure management, zero-trust segmentation, stronger building-management-system security and protocol-aware threat detection to prevent attackers from moving from conventional IT entry points into the physical systems that sustain data-center operations.
Source: SecurityWeek