One in Five Data Centre Systems Is One Step Away From Hackers, Research Finds
A study of 174,000 data centre infrastructure devices found that roughly 32,000 sit just one network hop from the open internet, putting cooling, power and fire systems within easier reach of attackers than most operators realise.

Key points
- Claroty analysed more than 750,000 data centre assets and found approximately 32,000 infrastructure devices (18%) are one network hop from internet-exposed systems.
- 41% of power distribution units and 32% of HVAC (heating, ventilation and air-conditioning) systems sit within that one-hop risk zone.
- 88% of building management systems, the software platforms that control physical facilities, communicate over insecure protocols that do not encrypt data in transit.
- 11,000 operational technology control systems carry vulnerabilities that hackers are already known to exploit in real-world attacks.
- Claroty recommends continuous exposure monitoring, network segmentation, and updated firmware as first steps for operators.
What did researchers actually find?
Security firm Claroty studied more than 750,000 devices inside large data centres and found a significant slice of the physical infrastructure, the systems that keep buildings cool, lit and powered, is far more reachable by outside attackers than the industry assumes.
Of the 174,000 infrastructure assets examined, fewer than 1,000 (0.4%) connect directly to the public internet. That sounds reassuring. The problem is the next layer: around 32,000 devices are just one internal network connection away from a system that does face the internet. In practice, that means an attacker who breaks into one internet-facing machine may only need a single additional step to reach a cooling unit, a power switch, or a fire-suppression controller.
Why should ordinary people care about data centre hardware?
Data centres are the physical buildings that store and process the data behind online banking, hospital records, retail websites and cloud storage. If their cooling fails, servers overheat and shut down. If power management is disrupted, outages follow.
The consequences Claroty describes are concrete: successful attacks could disrupt cooling, affect how electricity is distributed across a facility, interfere with backup generators, and knock out environmental controls that protect sensitive equipment. Any of those outcomes can cascade into service outages that affect customers, patients or businesses with no visibility into what caused the problem.
Where are the biggest gaps?
| Asset type | Risk finding |
|---|---|
| Power distribution units | 41% are one hop from the internet |
| HVAC systems | 32% are one hop from the internet |
| Building management systems | 88% use insecure (unencrypted) communication protocols |
| Building management systems | 40% run outdated firmware (software that runs the device itself) |
| OT control systems (SCADA/PLC devices) | 11,000 carry known, actively exploited flaws |
SCADA and PLC devices are industrial controllers, the specialised computers that physically operate machinery such as pumps, valves and electrical switchgear. The 11,000 flagged by Claroty carry what the security industry calls KEVs, known exploited vulnerabilities, meaning security researchers have confirmed real attackers are already using these flaws in live attacks elsewhere.
What should data centre operators do now?
Claroty's report urges four practical steps: map and continuously monitor every device for new exposures; apply zero trust network segmentation, meaning each system is walled off so a breach in one cannot easily spread to others; harden building management systems by updating firmware and switching to encrypted protocols; and deploy detection tools that understand the specific communication languages these industrial devices use.
Operators waiting for regulatory pressure may not wait long. Frameworks including CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act, a US federal law requiring operators of critical infrastructure to report significant cyber incidents to the government) and the EU's NIS2 Directive (a European law setting baseline security requirements for operators of essential services, with enforcement beginning in late 2024) both reach data centre operators. Neither rule excuses unpatched physical infrastructure from scope.
If you rely on cloud services, online banking or digital health records, the fix is in the hands of the companies running these facilities, not you. What you can reasonably do is note any unexplained outages from services you depend on and ask providers, in writing, what happened.



