Skip to content

Cybersecurity

OT Security in Industrial Data Centers: BMS, DCIM, and Operational Continuity

Data centers are cyber-physical environments with OT systems often ignored by IT security programs. BMS, PDUs, cooling systems, and UPS units are critical assets with real vulnerabilities.

3 min read
Industrial data center with racks, BMS, and cooling systems

Data Centers as Cyber-Physical Environments

Data centers are perceived as quintessentially IT environments. Servers, storage, networking — all digital, all managed by specialized IT teams with mature security processes. But this perception obscures an important reality: a data center is also a complex physical environment, with dozens of OT systems that keep it operational.

Cooling, electrical power, fire protection, physical access control, environmental monitoring — all of these systems are managed by operational technologies (BMS, SCADA, PLCs, distributed control systems) that have the same security problems as any other industrial environment. The difference is that in a data center these OT systems are deeply integrated with the IT infrastructure they support, and are often managed by different teams with separate processes.

BMS, DCIM, PDUs: OT Assets in the Data Center

Building Management System (BMS): the operational brain of the data center. It controls HVAC systems, chillers, in-row cooling units, and humidification systems. A compromised BMS can alter operating temperatures, trigger emergency shutdowns due to overtemperature, or create conditions that accelerate hardware degradation.

Data Center Infrastructure Management (DCIM): DCIM software aggregates data from all physical systems in the data center — energy consumption, temperatures, capacity, UPS availability. These are systems with access to critical operational data and often with control capabilities over underlying systems.

Intelligent Power Distribution Units (PDUs): modern PDUs do not simply distribute power — they are networked devices with web interfaces, SNMP, and APIs. They can be managed remotely to selectively power down racks. This capability, in the wrong hands, becomes a direct attack vector against IT infrastructure.

Networked UPS systems: emergency power systems are a critical target. Compromising a UPS means being able to force a failover, degrade its performance, or in some cases cause physical damage to batteries through abnormal charge/discharge cycles.

Environmental monitoring systems: temperature sensors, humidity sensors, water leak detectors, fire suppression systems. These devices are often connected on protocols like BACnet or Modbus, rarely updated, and frequently neglected by patch management programs.

Specific Vulnerabilities of Building Automation Systems

Building automation systems in data centers present a characteristic vulnerability profile:

Legacy protocols: BACnet, LonWorks, Modbus are protocols designed for reliability, not security. Absent or weak authentication, cleartext communications, no integrity control mechanisms.

Exposed web interfaces: many building control systems have web interfaces accessible from the internal network with default credentials or known vulnerabilities. The convergence between the building automation network and the data center's IT network creates unintended attack paths.

Rare updates: BMS systems have long lifecycles and complex update processes that often require vendor involvement. The result is that many systems run with obsolete firmware and known unpatched vulnerabilities.

Organizational silos: the facilities management team manages BMS and physical systems; the IT team manages servers and networks; the security team focuses on the IT side. Building automation system security frequently falls through the cracks.

Operational Impact: When an Attack Turns Off the Lights

The risk is not theoretical. In recent years several incidents have occurred where building automation systems or PDUs were compromised as a first step toward impacts on IT infrastructure.

The typical pattern: an attacker enters through a vulnerability in an exposed BMS or PDU system, gains visibility into the data center architecture, and uses this position to move laterally toward more critical IT systems or to directly cause a service disruption.

For an organization that has built its availability strategy around hardware redundancy and disaster recovery, an attack that bypasses these measures by acting on the underlying physical systems is an unpleasant surprise.

Security Approach for Data Center Environments

An OT security program for data centers must integrate the physical systems perspective into the IT one:

Unified inventory: enumerate all OT systems present in the data center (BMS, PDUs, UPS, monitoring systems) with the same discipline applied to IT inventory.

Building automation network segmentation: the BACnet/Modbus network must be physically or logically separated from the IT network. There should be no direct paths between an HVAC system and server infrastructure.

Credential management: remove all default credentials, implement centralized password management for OT systems, monitor privileged access.

OT traffic visibility: extend network monitoring to BACnet and Modbus protocols, define a baseline of expected traffic, and alert on anomalies.

Clear ownership: define who is responsible for building automation system security (IT team, facilities team, or a shared function) and ensure this responsibility is covered in vulnerability management and incident response processes.

The MON5 Angle

BMS, PDUs, and networked UPS units are OT assets in every sense, and as such they need to be inventoried and monitored. MON5's DISCOVER phase builds the inventory of these systems with passive discovery, without interfering with plants that cannot be stopped, and reconstructs their topology — who communicates with whom, on which protocols, through which paths toward the IT network.

With ANALYZE, building automation system vulnerabilities are correlated with EPSS scores and real exposure, giving both IT and facilities teams shared data to close the responsibility grey zone. To understand how many OT assets live in your data center, start with an OT assessment.

OTICSdata centeroperational continuityBMS

Related articles

Abstract illustration: artificial intelligence and vulnerability discovery in OT systems

Cybersecurity

AI changed vulnerability discovery: but there is an OT gap you cannot ignore

New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

2 min read
OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read
Representation of a compromised industrial PLC affected by a chain of CODESYS vulnerabilities

Cybersecurity

CODESYS Under Attack: Three Chained Flaws to Plant a Backdoor in a PLC

Three chained CVEs in the CODESYS Control runtime let a Service user replace the PLC application with a backdoored version and run code as root.

3 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna