The scariest thing in a data center is not always the blinking server rack. Sometimes it is the HVAC controller quietly living one network connection away from the internet, minding its own business like a side character in a disaster movie. According to SecurityWeek’s report on Claroty research, nearly one in five cyber-physical systems that keep major data centers running are close enough to internet-exposed pathways to be reachable by threat actors. Translation: the breach scoreboard does not start with the biggest CVE number. It starts with what an attacker can actually reach. ## The One Hop Problem SecurityWeek Put on the Map SecurityWeek reports that Claroty analyzed more than 750,000 data center assets across some of the world’s largest facilities, including roughly 191,000 OT assets and 174,000 infrastructure assets. Those infrastructure assets include HVAC, power monitoring and distribution, fire management, and UPS systems, which is a polite way of saying the machinery that keeps the cloud from becoming a very expensive space heater. SecurityWeek says less than 1,000 of the 174,000 infrastructure assets, or 0.4%, are directly exposed to the internet. The more interesting number is approximately 32,000, or 18%, that sit one hop away from internet-exposed systems. That is the part defenders should tape to the wall, preferably next to the incident response plan nobody has opened since the last tabletop exercise. Direct exposure is bad, obviously, but near exposure is where a lot of practical risk hides. If a reachable system can become a stepping stone to operational technology, the question is no longer whether the sensitive asset has a public IP address. The question is whether the network has drawn a meaningful line between internet-facing services and the systems that keep power, cooling, and safety controls alive. ## Why Vulnerability Counts Are the Wrong Main Character OffSeq Threat Radar summarizes the same Claroty finding as an exposure problem, not just a vulnerability problem, noting that around 18% of infrastructure assets are one network hop from internet-exposed systems while less than 0.4% are directly exposed. It also identifies the relevant asset classes as HVAC, power distribution units, and building management systems. That matters because these are not interchangeable laptops waiting for Tuesday’s patch parade. They are operational systems where uptime, vendor constraints, and change windows turn simple remediation into a small opera. OffSeq’s analysis points to insecure protocols, outdated firmware, known exploited vulnerabilities, unmanaged remote access, and weak authentication as attack vectors. None of those are exotic. They are the familiar gremlins of enterprise security, only now they are loitering near cooling and power systems instead of another forgotten test VM. Threat actors do not need cinematic genius when the plot offers them an internet-facing foothold, a flat-enough network, and a legacy protocol that predates everyone’s current password policy. ## Exposure Management Means Following the Path The broader exposure management lesson lines up with XM Cyber’s State of Exposure Management in 2024 report, which describes the discipline as identifying how an organization is exposed, understanding how adversaries could exploit those exposures, and prioritizing remediation to reduce risk effectively. XM Cyber says its report draws on hundreds of thousands of attack path assessments conducted through its Continuous Exposure Management platform during 2023. The assessments uncovered over 40 million exposures affecting 11.5 million entities deemed critical to business operations, with anonymized data provided to Cyentia Institute for independent analysis. That is why this data center story should make security teams reach for path analysis, not just another spreadsheet sorted by severity. A critical vulnerability on an isolated asset is still a problem, but a medium-looking weakness on a system that bridges into power or cooling can be the more urgent fire. Patch notes may be dramatic, and believe me, I cherish a good CVSS jump scare. But reachability is the plot twist that decides whether a weakness is merely ugly or operationally dangerous. ## What It Actually Means For You For operators, SecurityWeek’s Claroty coverage turns asset inventory from housekeeping into threat modeling. You need to know which systems are directly exposed, which are one hop away, and which pathways lead into HVAC, power monitoring and distribution, fire management, UPS systems, and other cyber-physical infrastructure. If that sounds tedious, congratulations, you have discovered the part of security that prevents press releases beginning with the usual ritual apology. My unofficial scoreboard for we take security seriously statements remains undefeated, and I would love data center operators to stop feeding it. OffSeq’s mitigation summary points in the right direction: continuous exposure management, zero trust network segmentation, and protocol-aware threat detection. The practical move is to rank fixes by reachable impact, tighten remote access, separate internet-facing systems from operational networks, and monitor the protocols your normal IT tools barely understand. For readers outside the data center bunker, the takeaway is simple: the services you rely on are only as resilient as the less glamorous systems beneath them. Watch for operators and cloud providers to talk less about vulnerability volume and more about attack paths, because the next serious resilience story may begin with one quiet network hop. ## Sources - 1 in 5 Data Center Assets Are Within Easy Reach of Attackers - SecurityWeek

Sources