Data centers play a crucial role in supporting sectors of all kinds and are frequently referred to as the backbone of the digital economy.
Housing the cloud platforms that enable global communications, drive digital innovation, support artificial intelligence, and power modern commerce, entertainment, and everyday services, to increase resilience, operators have made significant investments in power efficiency and redundancy.
Yet an overlooked consideration of risk remains: The cybersecurity of the building systems that make these facilities safe and functional.
Cooling is the most visible example, but only one piece of a broader ecosystem. Heating, ventilation, fire suppression, water treatment, power distribution, and access controls are all managed through building management systems (BMS) and data center infrastructure management (DCIM) platforms. These systems were designed for performance and efficiency. Increasingly, they are integrated to maximize uptime and sustainability. But this integration also creates an attack surface that adversaries have begun to exploit.
Modern BMS and DCIM platforms are highly connected, often bridging operational technology (OT) and IT environments. They rely on common industrial protocols such as BACnet, Modbus, and OPC UA, which generally prioritise interoperability over security. If compromised, an attacker does not need to steal data to cause harm.
They can hypothetically cause direct operational impact by changing temperature set points, turning off alarms, or interfering with water treatment. The most obvious example is cooling: server rooms can quickly reach dangerous temperatures in the absence of efficient airflow or chilled water circulation.
But the same logic applies to fire and life safety systems, power distribution units, or access control. Any disruption in these building systems risks downtime, degraded service, and potentially even physical safety.
There is mounting evidence that adversaries recognise this leverage. Campaigns have already surfaced in which stolen data center staff credentials were used to gain access to management devices with operational capability.
ShadowPad malware has been deployed against building automation systems by exploiting Microsoft Exchange vulnerabilities, providing attackers a foothold inside critical environments. Malware linked to the WASSONITE threat group has included features to target configuration management databases that are frequently tied into DCIM platforms, allowing reconnaissance of operational networks.
In Europe, communications have been observed between DCIM devices and the Karakurt extortion group, underscoring how data centers are being treated as high-value targets for disruption and ransom. More sophisticated malware like PIPEDREAM, linked to the CHERNOVITE threat group, has modules that have the potential to interact with the protocols common in data centre environments. Additionally, leaked documents linked to the Iranian government in 2021 showed research into building management technologies.
Furthermore, numerous recent non-cyber incidents make the operational stakes evident.
With repercussions that lasted for days, a lightning strike in Australia in 2023 caused chiller shutdowns at a number of hyperscale sites, causing operators to turn down equipment and cut off services for almost twelve hours. Millions of clients' banking services were interrupted that year because a malfunction at an Equinix facility in Singapore caused temperature levels to rise over safe limits.
Those were accidental incidents, but they illustrate the real-world impact if attackers deliberately manipulate building systems. As operators embrace waterless cooling, AI-driven thermal management, and tightly integrated DCIM platforms to improve efficiency, they simultaneously expand the surface adversaries can exploit.
Thankfully, defending these systems does not require starting from scratch. Operators can draw on widely recognised frameworks such as the Five Critical Controls for World-Class OT Cybersecurity developed by the SANS Institute. These emphasize incident response plans designed for operational environments, the creation of defensible architectures that separate IT and OT networks, continuous monitoring of industrial protocols to spot suspicious behaviour, secure methods of remote access for vendors and contractors, and risk-based approaches to vulnerability management where patching is difficult. Together, these steps provide a roadmap for securing building systems without hindering innovation.
As the global buildout of data center capacity accelerates to meet the demand of AI workloads and digital transformation, resilience can no longer be defined solely by power metrics or sustainability goals. The cybersecurity of the operational systems that provide safe functioning must also be taken into consideration for resilience. Uptime, customer confidence, and national infrastructure are all at risk from a compromised BMS or DCIM platform, which is more than just an engineering problem.
The core of the digital economy will continue to be data centers. However, in order to maintain their dependability, cybersecurity needs to go beyond the servers and racks to the building systems that allow them to run continuously. By recognizing these systems as part of the resilience equation, operators can ensure that growth in capacity is matched by growth in security, safeguarding not just infrastructure but the industries and communities that depend on it.
Comments