Rush to Build Data Centers Leaves OT Security Behind
Data Breach TodayArchived Aug 13, 2026✓ Full text saved
Siloed Systems Leaves OT Devices Only 'One Hop Away' From the Internet In the rush to get servers on the ground, and especially to cater to the artificial intelligence boom, data center owners have neglected security and left vulnerable operational technology devices dangerously close to the public internet, according to experts and recent research.
Full text archived locally
✦ AI Summary· Claude Sonnet
Governance & Risk Management , Operational Technology (OT)
Rush to Build Data Centers Leaves OT Security Behind
Siloed Systems Leaves OT Devices Only 'One Hop Away' From the Internet
Shaun Waterman • August 12, 2026
Credit Eligible
Get Permission
An industrial data center with multiple cooling towers and HVAC equipment on a commercial rooftop. (Image: Snehit Photo/Shutterstock)
In the rush to get servers on the ground, and new compute up and running, especially to cater to the artificial intelligence boom, data center owners have neglected security and left vulnerable operational technology devices dangerously close to the public internet, according to experts and recent research.
See Also: Airlines and Airports: Visibility Across OT, IoT, and IT
Total U.S. capital expenditure on data centers is expected to top $700 billion this year, according to Moody's Investor Services, as tech giants and their smaller rivals race to power ever larger and more complex large language models and meet the predicted mushrooming demand from business. Over the next five years, predicts market intelligence firm Industrial Info Resources, data center developers and big tech firms plan to start construction on 2,913 data centers at a cost of about $2.4 trillion by 2030.
"We have clients that are putting a data center in the dirt every three months," said Sean Tufts, field CTO for OT security specialists Claroty, and that rush had consequences. "With speed goes inefficiency," he added, "The faster you go, the less best practices are followed." Different contractors working to different deadlines were building siloed networks that, in many cases, connected more or less directly to the public internet, the company's research had found.
"The HVAC guy doesn't care about the power guy. Those are two different teams, two different people, two different contractors," Tufts told ISMG, "And that's turning out to be a big cyber problem that's starting to unfold in front of our eyes."
OT systems like power distribution units, temperature control systems and uninterruptible power supply, could cause data center downtime if successfully attacked, he added.
No Verified Attacks So Far
There have not been any verified attacks on data center OT systems to date. In April, KillNet - the Russian hacktivist group with a reputation for braggadocious and unfounded claims - said on Telegram it had achieved "direct control" of 3,400 OT networks through a successful cyberattack on a data center belonging to the French cloud services and infrastructure hosting provider Stor Solutions. The claim was reported by threat intelligence company Vecert, which labelled it "unverified."
But experts say the risk and exposure being courted by hasty data center construction is real, especially in the midst of the ongoing conflict with Iran, which has struck data centers in the region with missile and drone attacks, making it clear Tehran sees them as legitimate military targets.
Data centers were being targeted by nation-state cyberespionage groups and criminal ransomware gangs even before the war with Iran. The National Telecommunications and Information Administration, or NTIA, in 2024 started an inquiry process by soliciting industry comments about the resiliency, supply-chain integrity and cybersecurity of data centers to protect the cutting edge AI technology they were working on (see: US NTIA Probes Data Center Security Risks).
"There may be an amplified need to fortify security measures within these facilities," the agency stated in its request for comments. "Heightened safeguards and robust security protocols may be necessary to protect the large volumes of data being processed and analyzed in support of cutting-edge applications" like AI. A total of 58 companies responded to the request. Last year, the agency held a "listening session" for industry representatives but has not completed work or published its report.
Consequences of the AI 'Gold Rush'
The AI gold rush also means that contractors are often forgoing traditional systems of systems analysis, said former U.S. Cybersecurity and Infrastructure Security Agency Senior Advisor Allan Friedman, now technologist-in-residence at the TPO Group, a defensive cyber consultancy.
"Because these are happening so fast, there hasn't been a lot of the traditional project engineering that you would expect for such large infrastructure," he told ISMG.
Each system must secure in itself, but also in relation to the other systems in the center. That is especially important for OT, where secure architecture is essential to minimize attack surfaces. "A system of systems approach works to integrate all of it," Friedman said, but is harder to do when racing the clock.
Friedman also warned that there exists a security attention deficit when it came to control systems. "There's a lot of attention paid to security in the chips, the bandwidth, the memory. These are things that are engineered incredibly well, with security and integrity as an important consideration. Less so with some other parts of the infrastructure," he said.
When it comes to cooling, or power management, "That's where the engineering focus is on the underlying raw ingredients, but often there isn't as much expertise in security and resilience around the control systems of those [capabilities.]"
Anonymized data collected from client networks by Claroty's platform and analyzed by the company's Israeli-based threat intelligence outfit, Team82, shows the consequences of that headlong rush to spin up computing power: Vulnerable OT devices left "one hop" from the open internet.
The data set is 191,000 "real spinning assets" in data centers, Tufts said. Not all of them were literally spinning. "Among that is everything you could imagine, from VoIP phones and soda machines to HVAC or BMS, chip-level cooling systems, PDUs, even old school PLCs."
By sifting through the Claroty platform data, the analysis identified vulnerabilities in outdated firmware and insecure communications protocols and highlighted hidden potential attack paths. Only 3% of OT assets were directly accessible from the internet, but roughly a fifth were only "one hop from interconnected IT or networking infrastructure," according to the report.
Those competing and siloed networks sometimes had a business case for needing internet connectivity, Tufts said. Heating, ventilation and air conditioning controllers, building management systems, on-chip cooling systems, - "they're going to reach back home to their maker and get firmware updates. They're going to send data about the operation of their device to their manufacturer. They're going to be beaming data back towards the client's environments," for remote monitoring and control or other uses.
"Unfortunately, those legitimate use cases also offer an attack path," he said. Hackers could reach the IT network via phishing or other attacks and then pivot to OT devices.
Owners and operators should ensure they had a separate subnet, said Tufts. A so-called demilitarized zone is just "two firewalls facing in opposite directions," one facing up and the other down, keeping the two networks isolated from each other, but creating a zone where data can be safely shared.