One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds
A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

Key points
- Claroty analysed more than 750,000 data centre assets and found approximately 32,000 infrastructure devices (18%) are one network hop from internet-exposed systems.
- 41% of power distribution units and 32% of HVAC (heating, ventilation and air-conditioning) systems sit within that one-hop risk zone.
- 88% of building management systems, the software platforms that control physical facilities, communicate over insecure protocols that do not encrypt data in transit.
- 11,000 operational technology control systems carry vulnerabilities that hackers are already known to exploit in real-world attacks.
- Claroty recommends continuous exposure monitoring, network segmentation and updated firmware as first steps for operators.
What did researchers actually find?
Security firm Claroty studied more than 750,000 devices inside large data centres and found a significant slice of the physical infrastructure is far more reachable by outside attackers than the industry assumes.
Of the 174,000 infrastructure assets examined, fewer than 1,000 (0.4%) connect directly to the public internet. That sounds reassuring. The problem is the next layer: around 32,000 devices are just one internal network connection away from a system that does face the internet. An attacker who breaks into one internet-facing machine may need only a single additional step to reach a cooling unit or a fire-suppression controller.
Why should ordinary people care about data centre hardware?
Data centres are the physical buildings that store and process the data behind online banking, hospital systems and cloud storage. Cooling failure means servers overheat and shut down; disrupted power management means outages follow.
The consequences Claroty describes are concrete: successful attacks could disrupt cooling, affect how electricity is distributed across a facility, interfere with backup generators, and knock out environmental controls that protect sensitive equipment. Those outcomes can cascade into service outages that affect customers or businesses with no visibility into what caused the problem. The pattern isn't new: our 29 July report on the coordinated attack that knocked out automated controls at more than 30 Minnesota water utilities showed how quickly physical infrastructure failures ripple outward.
Where are the biggest gaps?
| Asset type | Risk finding |
|---|---|
| Power distribution units | 41% are one hop from the internet |
| HVAC systems | 32% are one hop from the internet |
| Building management systems | 88% use insecure (unencrypted) communication protocols |
| Building management systems | 40% run outdated firmware (software that runs the device itself) |
| OT control systems (SCADA/PLC devices) | 11,000 carry known, actively exploited flaws |
SCADA and PLC devices are industrial controllers, the specialised computers that physically operate machinery such as pumps and electrical switchgear. The 11,000 flagged by Claroty carry what the security industry calls KEVs, known exploited vulnerabilities, meaning real attackers are already using these flaws in live attacks elsewhere.
What should data centre operators do now?
Claroty's report urges four practical steps: map and continuously monitor every device for new exposures; apply zero trust network segmentation, meaning each system is walled off so a breach in one can't easily spread; harden building management systems by updating firmware and switching to encrypted protocols; and deploy detection tools that understand the specific communication languages these industrial devices use.
Operators waiting for regulatory pressure won't wait long. Frameworks including CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act, a US federal law requiring operators of critical infrastructure to report significant cyber incidents to the government) and the EU's NIS2 Directive (a European law setting baseline security requirements for operators of essential services, with enforcement beginning in late 2024) both reach data centre operators. Neither rule excuses unpatched physical infrastructure from scope.
The blunt read: this research shows the segmentation problem is worse than vendors tend to admit, and the firmware numbers are an embarrassment for an industry that sells itself on resilience. If you rely on cloud services or online banking, the fix sits entirely with the companies running these facilities. Noting unexplained outages and asking providers in writing what happened is a reasonable first move.



