HomeMalware & ThreatsRush to Build Data Centers Neglects OT Security

Rush to Build Data Centers Neglects OT Security

Published on

spot_img

Governance & Risk Management,
Operational Technology (OT)

Siloed Systems Leave OT Devices Only ‘One Hop Away’ From the Internet

Rush to Build Data Centers Neglects OT Security
An industrial data center with multiple cooling towers and HVAC equipment on a commercial rooftop. (Image: Snehit Photo/Shutterstock)

In an era marked by rapid advancements in artificial intelligence, experts have raised alarming concerns about the security of operational technology (OT) devices in data centers. New research suggests that, amid a frantic rush by data center operators to set up servers and computing power, critical security protocols have been overlooked, leaving these vulnerable OT systems perilously close to the public internet.

Understanding the Financial Landscape

Total capital expenditure on data centers in the United States is projected to exceed $700 billion in a single year, according to insights from Moody’s Investor Services. With both major tech companies and smaller enterprises competing to meet the burgeoning demand for powerful artificial intelligence algorithms, a staggering 2,913 new data centers are expected to break ground, representing an investment of approximately $2.4 trillion by 2030, as predicted by Industrial Info Resources.

Sean Tufts, field CTO for OT security specialists Claroty, emphasized that the rapid pace of data center construction is coming at a cost. “We have clients that are putting a data center in the dirt every three months,” he stated. As deadlines loom, he noted, “With speed comes inefficiency,” leading to a breakdown in best practices. Different contractors working on separate timelines are constructing siloed networks, which often connect directly to the public internet, creating significant vulnerabilities.

Tufts elaborated that disparate teams involved in construction—such as those responsible for HVAC systems and power management—are creating a complex web of networks that do not communicate seamlessly. “The HVAC guy doesn’t care about the power guy,” he pointed out, highlighting a growing cyber threat that remains largely unaddressed.

Operational technology systems—including power distribution units, temperature control systems, and uninterruptible power supplies—are especially vulnerable. Should these systems be compromised, the potential for widespread data center downtime exists, underscoring the critical need for enhanced security precautions.

No Confirmed Attacks Yet

Despite the precarious situation, experts note that verified cyberattacks targeting data center OT systems have yet to materialize. In an April incident, the Russian hacktivist group KillNet claimed to have gained “direct control” over 3,400 OT networks via an attack on Stor Solutions, a French cloud service provider. However, this assertion was categorized as unverified by threat intelligence companies.

Nonetheless, the risks associated with hurried data center construction cannot be understated. The geopolitical landscape, especially the ongoing conflict with Iran, has placed data centers under heightened scrutiny. Recent missile and drone strikes targeting such facilities signify that they are viewed as legitimate military objectives. Even prior to the conflict, data centers were already under siege from state-sponsored cyber-espionage groups and ransomware gangs.

The National Telecommunications and Information Administration (NTIA) initiated an inquiry into data center resilience and cybersecurity in 2024, encouraging industry input on safeguarding cutting-edge AI technologies. The NTIA stressed the urgency of fortifying security measures within these facilities, indicating that advanced protocols may be necessary to protect vast quantities of sensitive data.

The AI Gold Rush and Its Implications

The pressing demand for AI capabilities has led to instances where contractors skimp on traditional project engineering analysis. Allan Friedman, a former advisor with the U.S. Cybersecurity and Infrastructure Security Agency, now affiliated with the TPO Group, highlighted that the rapid pace of construction is compromising the thoroughness typically expected for such large-scale infrastructures.

“Each system must not only be secure in isolation but also integrate securely with others,” Friedman asserted. This system-of-systems approach is crucial for minimizing available attack surfaces, particularly for OT. However, implementing such strategies becomes increasingly challenging as project urgency escalates.

Friedman further emphasized the disparity in security resources, noting that while substantial attention is given to the more developed components such as chips and bandwidth, other critical areas like cooling and power management often receive inadequate security scrutiny. These oversight gaps render these control systems particularly susceptible.

Data compiled from Claroty’s client networks illustrates the depth of this issue. An analysis focused on 191,000 operational assets revealed that while only 3% were directly accessible from the internet, around 20% were merely “one hop” away, hailing from interconnected IT or networking infrastructures. Such findings indicate a troubling trend that underscores the urgent need for a reevaluation of security strategies.

Tufts suggested that to bolster security, owners and operators should implement a subnet configuration often referred to as a demilitarized zone (DMZ). This approach establishes two firewalls positioned in opposite directions, effectively preserving isolation between networks while permitting safe data exchanges.

Source link

Latest articles

Edtech Faces Challenges from Third-Party Cyber Threats

Edtech Faces Rising Cyber Threats Amid Historic Attacks The landscape of education technology has become...

Lazarus Employs Post-Quantum Key Exchange to Launch Zero-Day Attack

North Korea's Lazarus Group Leverages Advanced Techniques in Cyber Attacks Against Defense and Aerospace...

Vega Unveils Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense

Vega Unveils Detection Skills: A Groundbreaking Open Standard for AI-Powered Cyber Defense In a significant...

Axonius CEO Cautions That AI Exacerbates Asset Visibility Gaps

Diamond: AI Agents Can Interact With Cloud Apps and Endpoints Across the Enterprise By Michael...

More like this

Edtech Faces Challenges from Third-Party Cyber Threats

Edtech Faces Rising Cyber Threats Amid Historic Attacks The landscape of education technology has become...

Lazarus Employs Post-Quantum Key Exchange to Launch Zero-Day Attack

North Korea's Lazarus Group Leverages Advanced Techniques in Cyber Attacks Against Defense and Aerospace...

Vega Unveils Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense

Vega Unveils Detection Skills: A Groundbreaking Open Standard for AI-Powered Cyber Defense In a significant...