One in Five Data Center Devices One Hop From Internet
Claroty analyzed more than 750,000 data center assets and found about 32,000 infrastructure devices-roughly 18%—are one network hop from internet-exposed systems.
Claroty’s recent analysis found that nearly one in five data center infrastructure devices is one network hop from systems exposed to the internet. The firm examined more than 750,000 data center assets as part of the study.
The dataset included about 191,000 operational technology assets and 174,000 infrastructure devices. Of the infrastructure group, fewer than 1,000 devices (about 0.4%) were directly exposed to the internet. Approximately 32,000 devices, roughly 18%, were reachable through one intermediary networked system.
Being one hop away means an attacker who compromises an internet-facing system could reach those devices without additional network barriers.
The analysis identified asset types at higher risk: 41% of power distribution units and 32% of heating, ventilation and air conditioning systems were one hop from an internet-exposed connection. Building management systems showed that 88% use insecure communication protocols and 40% run outdated firmware. The firm also found about 11,000 operational control systems, including SCADA and PLC devices, with vulnerabilities listed as known exploited flaws.
The report states: “Attack paths may then lead threat actors to exploitable CPS weaknesses such as insecure communication protocols, known exploited vulnerabilities (KEVs), unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications.” It adds that attackers with access to operational infrastructure can disrupt cooling operations, affect power distribution, compromise environmental controls, interfere with backup generation systems and degrade overall operational resilience.
Recommended measures include continuous exposure management to track which assets are reachable, zero trust network segmentation to limit lateral movement, hardening building management systems, protocol-aware threat detection that understands OT communications, prioritizing remediation for devices with known exploited vulnerabilities, and reducing unnecessary remote access paths.
The report provides data and specific areas for data center operators to assess and secure to limit the chance that an internet-facing compromise could reach critical infrastructure controls.








