Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
OT Security in Hyperscale Data CentersTechnical Controls
4 min readFor Risk Managers

OT Security in Hyperscale Data Centers

Scope - What This Guide Covers

This guide focuses on operational technology security in data centers, specifically addressing vulnerabilities that arise when construction timelines compress security planning. You'll find practical steps for securing power distribution units, building management systems, HVAC controllers, and uninterruptible power supplies against network-based attacks.

This isn't a general OT security primer. It's targeted guidance for teams managing or auditing data center facilities where speed-to-deployment has created segmentation gaps between IT and OT networks.

Key Concepts and Definitions

Operational Technology (OT): Physical control systems managing data center infrastructure, including power distribution units, temperature control systems, building management systems, chip-level cooling controllers, and UPS devices.

One Hop Proximity: A network architecture condition where OT devices connect to IT infrastructure through a single routing decision or firewall rule, rather than through properly segmented zones with inspection controls.

System of Systems Analysis: An engineering approach that evaluates how individual subsystems interact and where those interaction points create security exposure. This is critical in environments where multiple contractors deploy independent networks on compressed timelines.

Demilitarized Zone (DMZ) for OT: A network segment positioned between IT and OT networks using dual firewalls with opposing inspection policies. It allows necessary data exchange while preventing lateral movement.

Requirements Breakdown

Network Segmentation

Your OT environment must be isolated from general IT networks to prevent facility-wide outages.

Minimum control: Separate subnets for OT devices with firewall enforcement at the boundary. The dual-firewall DMZ architecture creates a controlled data exchange zone without direct connectivity.

Why this matters: Research analyzing 191,000 data center OT assets found roughly 20% were only one hop from interconnected IT or networking infrastructure. That proximity means a successful phishing attack on your IT network becomes a potential path to power or cooling systems.

Vendor Access Controls

HVAC controllers, building management systems, and on-chip cooling systems often need internet connectivity for firmware updates, operational data transmission to manufacturers, and remote monitoring.

Control requirement: Document every vendor callback requirement. Establish dedicated access paths that don't traverse your production IT network. Use Jump servers or secure remote access gateways with session logging.

Implementation detail: Your contracts with HVAC vendors, power system integrators, and BMS providers should specify exactly which devices need outbound connectivity, to which destinations, and on which protocols. Anything not documented gets blocked.

Contractor Coordination

Different contractors working to different deadlines often build independent networks without considering how those networks interconnect.

Mitigation approach: Require all contractors to submit network architecture diagrams before deployment. Your security team reviews for segmentation violations, internet exposure, and cross-system dependencies. This review happens before equipment goes live, not after.

Implementation Guidance

Step 1: Asset Inventory Across Contractor Boundaries

You can't secure what you don't know exists. When multiple contractors deploy systems simultaneously, you need a consolidated inventory process.

Action: Deploy network discovery tools that identify all IP-addressable devices, regardless of which contractor installed them. Tag each asset with its responsible contractor, business function, and network zone.

Step 2: Establish Segmentation Standards

Create a reference architecture that all contractors must follow. This document defines your network zones, firewall requirements, and approved connectivity patterns.

Specific requirements:

  • OT devices do not connect directly to IT networks
  • Internet-facing services for vendor callbacks route through dedicated DMZ segments
  • Cross-zone communication requires explicit firewall rules with documented business justification

Step 3: Protocol Hardening

Many OT devices use insecure protocols because they were designed for air-gapped environments. When you compress deployment timelines, those protocol weaknesses become exploitable.

Action items:

  • Disable unnecessary services on building management controllers
  • Replace cleartext protocols with encrypted alternatives where supported
  • For legacy devices that can't support modern protocols, enforce network-layer controls that compensate

Step 4: Continuous Monitoring

Traditional vulnerability scanning often misses OT-specific risks. You need visibility into outdated firmware, insecure protocol usage, and unexpected network connections.

Implementation: Deploy OT-aware monitoring that passively observes network traffic to identify vulnerable devices and unauthorized connections without disrupting operational systems.

Common Pitfalls

Assuming Physical Isolation Equals Security

Your data center's physical access controls don't protect against network-based attacks. The 3% of OT assets directly accessible from the internet represent obvious exposure, but the 20% one hop away are equally vulnerable if your IT network gets compromised.

Treating All Contractors as Trusted

The contractor installing your HVAC system has different security priorities than you do. They want systems that work and can be remotely managed. You need systems that work securely. Without explicit requirements, you'll get the former.

Delaying Security Reviews Until After Deployment

When you're racing to bring compute online, it's tempting to defer security hardening. But retrofitting segmentation after systems are operational is significantly harder than building it correctly from the start.

Overlooking Firmware Management

OT devices reaching back to manufacturers for updates create legitimate internet connectivity requirements. If you block those connections without establishing secure alternatives, you'll end up with outdated firmware and frustrated facility teams who bypass your controls.

Quick Reference Table

Control Area Minimum Requirement Verification Method
Network Segmentation Separate OT subnet with firewall enforcement Network diagram review, firewall rule audit
Internet Exposure Zero direct connections; vendor callbacks via DMZ External scanning, connection monitoring
Contractor Coordination Pre-deployment architecture review Design document approval process
Protocol Security Disable cleartext protocols where alternatives exist Network traffic analysis
Asset Visibility Complete inventory of IP-addressable OT devices Automated discovery scans
Vendor Access Documented, monitored remote access paths Session logs, access request records
Firmware Currency Scheduled update process for all OT devices Version tracking, patch compliance reports
Cross-Zone Communication Explicit firewall rules with business justification Firewall rule documentation audit

When you're deploying data centers on three-month cycles, security engineering can't be an afterthought. The system of systems approach takes more upfront coordination, but it's substantially easier than explaining how a compromised HVAC controller took down your entire facility.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like