Data Center OT Risks: 6,300 ICS Devices Exposed Online in US

Data Center OT Risks: 6,300 ICS Devices Exposed Online in US

The cloud and AI economy runs on data centers, but a new study suggests the physical systems that keep them cool, powered, and operational are dangerously exposed. Research published by TrendAI on August 18, 2026 identified 6,300 high-confidence industrial control systems (ICS) and building automation systems (BAS) devices directly reachable from the internet within one kilometer of 1,063 U.S. data centers. The finding sharpens an escalating operational technology (OT) security debate across the PLC and industrial automation ecosystem.

Analyst Insight: Data centers have long treated operational technology as a back-office concern. This research reframes it as a primary attack surface, where a single exposed BACnet controller or Niagara platform can become a foothold into the cooling and power systems that keep an entire facility online.

The Exposure Landscape: 6,300 ICS Devices Inside the Perimeter

TrendAI's researchers scanned ICS-specific protocols and cross-referenced results against a catalog of U.S. data center locations. The exposed inventory includes BACnet controllers, Niagara (Tridium) platforms, and Vertiv and Liebert data-center equipment — the very systems that manage cooling, power distribution, and environmental control.

Most striking is the geography. The devices were internet-accessible not in far-flung industrial plants but within 1 kilometer (0.62 miles) of active data center campuses. That proximity means an attacker who compromises an exposed building controller can move laterally toward the critical infrastructure it was designed to serve.

TrendAI scan methodology and key figures
  • 73,847 raw Shodan records from ICS-specific protocol scans
  • 14,510 unique device-port combinations after filtering and deduplication
  • 8,458 unique IP addresses responding on ICS protocols
  • 6,300 high-confidence ICS devices (43.4% of filtered results)
  • 3,991 unique IP addresses tied to those high-confidence devices
  • 1,063 U.S. data centers in the research catalog
Market Trend: ENISA's 2025 Threat Landscape recorded 4,875 cybersecurity incidents between July 2024 and June 2025, with operational technology accounting for 18.2% of cases. Meanwhile, exposure of Modbus and S7/CODESYS PLC protocols continues to climb, compounding the attack surface described by TrendAI.

Why OT Security Falls Short at the Data Center Edge

Traditional industrial cybersecurity relies on the Purdue Model, which isolates control-system Levels 1 through 3 behind a demilitarized zone (DMZ). TrendAI's findings indicate that these 6,300 devices bypass that DMZ entirely, creating direct pathways from the public internet to process-control layers.

When a BACnet controller managing cooling or a Niagara framework coordinating building automation is directly reachable through tools such as Shodan, the carefully designed security boundaries collapse. For PLC infrastructure, the lesson is blunt: segmentation is only as strong as the least-protected device on the adjacent OT network.

Analyst Insight: The Purdue Model assumes a clean hierarchy between IT, DMZ, and control layers. Internet-facing BAS devices break that assumption before a single firewall rule is evaluated. Operators should treat building automation as part of the PLC/ICS threat surface, not as an isolated facility system.

Closing the Gap: A Playbook for PLC and OT Teams

The remediation path is not exotic, but it is urgent. Asset discovery must extend beyond the IT network to every BACnet, Modbus, and Niagara device on campus, followed by aggressive removal of internet-facing interfaces where remote access is not strictly required.

Where connectivity cannot be eliminated, operators should enforce multi-factor authentication, protocol-aware monitoring, and network micro-segmentation. Offline backups of engineering workstation software and controller configurations remain the last line of defense against ransomware that targets process control.

Frequently Asked Questions

What are ICS and BAS devices?

Industrial control systems (ICS) manage physical processes such as power, cooling, and automation, while building automation systems (BAS) coordinate environmental controls like HVAC. Both increasingly run on internet-connected protocols such as BACnet and Modbus, which were not designed with strong native security.

Why are data centers a growing OT target?

Data centers concentrate high-value compute and depend on continuous cooling and power. An attacker who disrupts environmental controls can force thermal shutdowns or degrade availability, converting a single compromised controller into a facility-wide outage.

How can operators reduce ICS and BAS exposure?

Prioritize complete asset discovery, disable unnecessary internet-facing interfaces, segment OT networks, enforce multi-factor authentication for remote access, and deploy protocol-aware monitoring that can detect anomalous commands on control protocols.

Bottom Line: TrendAI's 6,300-device count is less a headline than a warning. As IT and OT converge, the industrial automation sector must extend its security perimeter to building controllers and facility systems — or leave a documented doorway into the data center floor.

Related Articles

Back to blog