Report
Claroty Team82 presents its research on the riskiest data center asset and infrastructure exposures, and the attack paths available to threat actors that put data centers at risk.
We researched more than 750,000 data center cyber-physical systems assets and core infrastructure, exploring how attackers exploit interconnected digital ecosystems to access operational infrastructure.
18% (32,000+) of more than 174,000 data center infrastructure assets are one hop away from a system making risky outbound connections to the public internet
Power distribution units (41%) and HVAC/ cooling systems (32%) have the highest percentage of assets one hop away from a risky connection to the public internet
Building management systems contain some of the riskiest exposures, with 88% communicating over insecure protocols and 40% containing outdated firmware
More than 80% of OT control systems, power monitoring, and loT systems communicate over legacy, insecure protocols such as BACnet and MODBUS
23% of loT devices such as environmental sensors, asset tracking tags, and loT gateways contain known exploited vulnerabilities (KEVs)
Many times, adversaries are no more than “one hop” from an exposed CPS asset, after having gained a foothold inside the data center. Data center asset exposures are reached via indirect pathways into operational environments through interconnected IT systems, third-party remote access, remote management services, and trusted network relationships.
Total Data Center Infrastructure Assets
174,577
Number of exposed assets one hop away
32,157
Percentage of exposed assets one hop away
18%
Power systems, such as power monitoring and uninterruptible power supplies (UPS), OT and BMS inside the data center also pose risks to uptime, reliability, and safety should an attacker successfully make the one hop and laterally reach these infrastructure assets. We found consequential numbers of assets with KEVs, outdated firmware, and insecure communication protocols.
30,610
Total Devices
0
Internet-Exposed Devices
833
Devices Containing KEVs
82%
Percentage of Devices Communicating over Insecure Protocols
59%
Percentage of Devices Running Outdated Firmware
16,057
Total Devices
86
Internet-Exposed Devices
101
Devices Containing KEVs
86%
Percentage of Devices Communicating over Insecure Protocols
23%
Percentage of Devices Running Outdated Firmware
81,420
Total Devices
613
Internet-Exposed Devices
11,498
Devices Containing KEVs
85%
Percentage of Devices Communicating over Insecure Protocols
48%
Percentage of Devices Running Outdated Firmware
66,395
Total Devices
369
Internet-Exposed Devices
800
Devices Containing KEVs
88%
Percentage of Devices Communicating over Insecure Protocols
40%
Percentage of Devices Running Outdated Firmware
Please complete the form to view the Report.