Dive Brief:
- More than 40% of power distribution units and more than 30% of HVAC or cooling systems have assets that are either directly exposed or are “one hop away” from a risky connection to the public internet, according to research by Claroty.
- The security firm’s Team82, which looks for cyber risk to help companies stay ahead of bad actors, analyzed 750,000 data center assets and found 18% of these assets were one hop away from exposure. Assets can be exposed via indirect pathways into operational pathways through interconnected IT systems, third-party remote access, remote management services and trusted network relationships, the report says.
- “A disruption affecting any of these systems can have cascading effects on facility operations, potentially resulting in widespread and costly service interruptions,” Claroty says in its report.
Dive Insight:
The convergence of information and operational technology, like building management systems, has expanded the attack targets of cyber-physical systems, the report says.
Data center organizations are increasingly integrating operational systems with enterprise applications and cloud-based services to automate functions, improve efficiency and give operators increased visibility, Claroty says. But combining these applications open paths for attackers to access environments that were, previously, largely isolated, the company says.
With this new exposure, although only 0.4% of data center infrastructure devices are directly exposed to the internet, almost 20% are one hop away from an exposed system, the analysis finds.
Building management systems are one of the biggest problem areas, according to the company: 88% of them are communicating over insecure protocols and 40% contain outdated firmware.
In addition to BMS, the type of infrastructure examined in the report include power monitoring systems, power distribution units and HVAC and cooling systems.
Power distribution units, or PDUs, provide power to the technology backbone that supports critical services inside the facility, like servers, storage systems and networking gear. PDUs were found to represent the highest risk in Claroty’s analysis, with 41% of devices one hop away from an internet-exposed system.
“Because PDUs physically distribute power directly to individual server racks, an attacker breaching the outer perimeter can pivot into the PDU layer to cycle power, abruptly shut down racks, or cause systemic hardware damage across thousands of customer payloads,” the report stated.
About a third of HVAC and cooling systems, which account for close to half of a data center’s electricity consumption, were one hop away from internet-exposed systems.
Although relatively few BMS analyzed were directly exposed to the public internet, Claroty found that close to 90% communicated over insecure protocols and 40% had outdated firmware. For example, more than 40% use BACnet implementations that lack authentication and encryption.
“An attacker able to access a BMS has a central view of many critical processes, and would have a lethal tool at their disposal in causing disruptions or physical damage to a facility,” Claroty says. “While these assets are not directly connected to the internet, attackers do have pathways to target critical data center infrastructure systems because these internal systems communicate with internet-facing components.”
Once attackers move within critical infrastructure, they wreak havoc in a number of ways, the company says. They can jump to operational technology control systems, which gather data from sensors and are subject to known exploitable vulnerabilities, or KEVs. Attackers can shut down controls that collect data or physical actions that keep processes stable, Claroty says.
“Any lateral leap into these unpatched KEV devices gives an attacker the ability to trigger exploits that could effectively knock a data center offline without touching a single server,” it says.
Power systems within data centers, including power monitoring and UPS, contained the most KEVs among data infrastructure assets.
Among these devices, 82% of power monitoring devices used insecure protocols, mainly MODBUS, while 59% ran outdated firmware. A larger percentage, 86%, of uninterruptible power supply, or UPS, ran insecure protocols but had fewer devices running outdated firmware, at 23%.
IoT and smart sensor devices are also insecure, with some lacking processing capabilities to support security features like encryption, while others might not have the ability to accept firmware updates, the report says. Nearly a quarter of IoT devices contain KEVs, while 72% communicated over insecure protocols, presenting “real risk to facilities,” the company said.