Blog
Aug 27, 2026
6 min read

The Overlooked OT Security Risks in AI Data Centers

TrendAI researchers identified thousands of internet-exposed cyber-physical devices near U.S. data centers. Their findings underscore the importance of securing not just servers and networks but also the operational systems and remote access pathways that keep AI workloads running.

When we think about AI data center security, we tend to picture the obvious targets: servers, networks, applications, and the increasingly valuable AI workloads running on them.

But as TrendAI researchers put it in a recent report: “Data centers are, at their core, climate-controlled warehouses for computing equipment.”

This simple observation has big implications for data center security.

Behind every rack of GPUs is physical infrastructure responsible for keeping those machines powered, cool, and operating within safe limits. Building automation systems (BAS), industrial control systems (ICS), cooling equipment, power management systems, and other operational technology (OT) all play a role.

Securing a data center therefore means securing not only its IT systems, but also the cyber-physical systems (CPS) that keep the facility running. If those systems are exposed or compromised, the availability of the compute infrastructure they support can be at risk.

Which raises an important question: Modern data centers dedicate significant resources to securing their digital infrastructure. But are they giving the same attention to the cyber-physical systems that power that infrastructure?

New research from TrendAI offers some uncomfortable answers.

Thousands of Exposed ICS and Building Automation Systems

The TrendAI team used Shodan data to investigate ICS, BAS, and SCADA systems near more than 1,000 U.S. data centers. After filtering and validation, they identified 6,300 high-confidence industrial and building automation devices accessible from the public internet.

Building automation dominated the results. BACnet devices, commonly associated with HVAC, lighting, access control, and fire systems, represented 58% of the findings. Another 23% used the Fox protocol associated with the Niagara Framework, a widely used building management platform. Researchers also identified equipment from Vertiv/Liebert, a manufacturer of precision cooling, uninterruptible power supply (UPS), and power distribution equipment used in data center environments.

A notable caveat to this data is that TrendAI used IP geolocation, which cannot establish the precise physical location of each device. In light of this, researchers can’t say definitively that all 6,300 devices were inside data centers. What they can say is that the devices were real, internet-accessible industrial or building automation systems whose ISP-registered locations placed them in the same geographic markets as the data centers studied.

Even with this limitation, the research points to a clear security concern: operational systems supporting critical facilities can be reachable directly from the public internet.

When OT Falls Outside the Security Boundary

One of the more revealing findings in TrendAI’s report is how these operational systems connect to the internet.

Many legitimate ICS devices used business-class internet connections rather than data center networks. The researchers offer a practical explanation: building automation is often installed by facilities teams and may use separate connectivity, management practices, and security controls.

These systems may also be deployed or maintained by landlords, contractors, OEMs, or system integrators. As a result, their connections can sit outside the security team’s normal field of view — even when the organization depends on those systems for critical operations.

This creates a form of shadow OT: operational technology and connectivity that exist outside normal IT security governance.

It’s more evidence that a facility can have sophisticated cybersecurity solutions protecting its digital infrastructure but still leave its critical operational systems outside those protections.

New Equipment Doesn't Eliminate Old Security Problems

The TrendAI team also found an unexpected correlation related to facility age.

Data centers permitted from 2021 onward had a 13.1% rate of nearby ICS exposure in the analysis, compared with 4.9% for facilities permitted before 2010.

This does not prove that newer data centers are less secure. Geolocation limitations still apply, and correlation does not establish cause. But the data nonetheless challenges the common assumption that modern equipment automatically means modern security — or, conversely, that aging technology is where most OT risk is concentrated.

Legacy systems deserve scrutiny, as older machines and protocols may lack modern authentication, encryption, and other key security capabilities. But replacing old systems with newer equipment doesn’t eliminate risks created by how that technology is connected, accessed, and managed.

A new controller with unnecessary internet exposure or poorly governed remote access can introduce many of the same risks as a legacy controller. Simply stated, OT security relies on not just the age or capabilities of the technology, but on the architecture, access controls, and governance surrounding it.

This is worth remembering as the AI boom drives rapid construction, greater automation, and increased dependence on remote operations.

Remote Access Is Where the Operational Reality Meets the Security Risk

Remote connectivity is a practical necessity for many operational systems.

Whether a cooling specialist needs to troubleshoot a chiller or an equipment manufacturer must provide ongoing maintenance, sending a technician onsite for every issue would be expensive, slow, and sometimes operationally impractical.

The security question isn't whether remote access should exist. It's how that access is provided.

Direct internet exposure creates a fundamentally different risk profile from controlled remote access. TrendAI's findings included devices that responded publicly on industrial protocols, sometimes revealing vendor information, firmware versions, equipment names, and other operational details.

Remote maintenance should give an authorized user a controlled path to the specific resource required for the job. It should not make the underlying OT environment unnecessarily discoverable or provide broad network access as a side effect.

For privileged operational access, organizations should verify identity, limit permissions according to role and task, restrict access to required systems or applications, and maintain appropriate visibility into activity during the session.

Four Questions Data Center Operators Should Ask

TrendAI's findings give operators a reason to examine the less-visible parts of their attack surface:

  1. What operational systems are reachable from outside the environment? Look beyond traditional IT inventory to BAS, ICS, remote management interfaces, and vendor- or contractor-maintained connectivity.

  2. Who owns each access path? Responsibility may cross IT, facilities, security, landlords, integrators, and equipment providers. Every path into a critical operational system needs a clear owner.

  3. How much access does each user receive? A technician servicing one system should not automatically gain connectivity to a wider OT network.

  4. Can we see what happens after access is granted? Authentication establishes who is connecting. This is essential, but teams also need visibility into what users do once connected.

Why Secure Access Is Key to Operational Resilience

The AI boom is driving enormous investment in compute infrastructure. TrendAI's research is a reminder that securing a modern data center requires looking beyond servers, networks, and applications to the operational infrastructure the facility relies on.

That means knowing what systems are exposed, who is responsible for them, and who can connect to them. It also means ensuring that employees, vendors, and other third parties can perform necessary work without gaining access to the broader OT environment.

This is the challenge Cyolo PRO (Privileged Remote Operations) is designed to address: providing secure, controlled access to critical operational systems without exposing them to unnecessary risk. Because as AI infrastructure scales, the ability to secure connectivity between people and critical systems needs to scale along with it.

Jennifer Tullman-Botzer

Author

Jennifer Tullman-Botzer has over a decade of experience in cybersecurity marketing and is as tired as you are of hackers-in-hoodies stock images. She joined Cyolo in 2021 and currently serves as director of content marketing.

Subscribe to Our Newsletter