The Data Center Operator's BMS Exposure Playbook | Insane Cyber
OT Cybersecurity for Data Centers

75% of Data Centers Have Known Exploited Vulnerabilities on Their BMS. Is Yours One of Them?

The building systems that keep your data center running — BMS, DCIM, cooling, power, physical access — are part of your attack surface. Most cybersecurity programs do not fully cover them. This playbook shows you how to diagnose and fix the exposure in 90 days.

The Data Center Operator's BMS Exposure Playbook
75% have BMS with known exploited vulnerabilities
51% have those vulnerabilities internet-exposed
55% use 4+ remote access tools in OT
The Coverage Gap

Most data center security programs cover half the real attack surface.

Server, network, and cloud security usually gets the attention. The facility itself — the thing that physically keeps the lights on and the air cold — runs on systems most security programs do not explicitly cover. While nobody was looking, the building became a computer. And that computer is running on protocols from the 1990s, reachable through remote access tools installed by vendors, and sitting on a quiet list of devices ransomware operators are actively scanning for.

The systems nobody owns.

BMS, DCIM, UPS and PDU management, CRAC and chiller controllers, fire suppression, physical access, CCTV. Each from a different vendor. Each with its own remote access tool. Each running firmware that has not been audited since commissioning.

The ownership gap is documented and consistent. These systems sit between IT, facilities, and security. When nobody clearly owns them, nobody secures them.

The four findings we see most

  • Internet-exposed BMS and management interfaces
  • Ransomware-linked KEVs on production devices
  • Vendor remote access proliferation (4 to 16 tools)
  • Legacy protocols running under the covers
What's Inside

A 26-page playbook. Part reference, part diagnostic, part operational plan.

Built by operators, for operators. The diagnostic section is fillable. The 90-day plan is prescriptive. The downtime math section translates exposure into dollars so you can build the internal business case.

The OT stack in a data center

A clear map of what counts as OT in your facility. BMS, DCIM, power, cooling, fire, physical access. For many operators, seeing this laid out is the first time they realize how much attack surface sits outside IT security scope.

The four findings deep-dive

Internet exposure, ransomware-linked KEVs, remote access proliferation, and legacy protocols. Each with a how-to-find-it checklist you can run this week.

A fillable exposure diagnostic

Walk through your facility section by section. Fill in the gaps. The questions you cannot answer are the findings.

The downtime math

Translate exposure into expected annual loss using your facility's actual downtime cost. Build the internal business case in 10 minutes.

A 90-day hardening plan

Week by week, prescriptive actions. Close the highest-impact findings first. Designed to run with internal facility and IT teams, not require a consulting engagement.

A tear-off BMS Exposure Quick Check

20-question self-assessment. 10 minutes. Print it, walk the facility, share with your team, share with leadership.

13-19%
of serious data center outages are cooling-related
Source: Uptime Institute
20%
of data center outages cost more than $1M
Source: Uptime Institute
500K+
BMS devices analyzed in the research behind this playbook
Source: Claroty Team82
Who This Is For

Operators running the critical environment.

Written for the people who actually own uptime at regional colos, enterprise data centers, and specialty providers. Not for 50-person security teams at hyperscalers, although they are welcome to use it.

  • Directors of Critical Environments, Infrastructure, or Operations

    Just inherited BMS cybersecurity as an additional responsibility and are not sure where to start.

  • Facility Managers and Lead Operations Engineers

    Know the plant better than anyone but have been told to coordinate with IT security and are not sure what to ask.

  • Shared IT security leads at enterprise data centers

    Understand server environments cold but have never looked at BACnet or LonTalk before this year.

  • VPs and senior leadership

    Read the Digital Realty news and want to know whether their own facility is exposed in the same way.

Inside the Playbook

26 pages. Built to be used, not just read.

Exposure Diagnostic

Fillable sections for device inventory, internet exposure, vulnerability, remote access, and segmentation.

Pages 14 to 16

Downtime Math

Translate exposure level into expected annual loss. Build the business case for OT security investment.

Pages 17 to 18

Quick Check

Printable tear-off. 20 questions across 4 categories. 10 minutes to complete, usable on any facility.

Page 25
Get the Playbook

26 pages. Fillable. Sent to your inbox.

Download it, walk your facility with it, fill in the diagnostic with your team. If we can help from there, there is a calendar link at the back. No aggressive sales calls.

  • Full 26-page PDF delivered immediately
  • Fillable exposure diagnostic (print or use on-screen)
  • Printable BMS Exposure Quick Check
  • Optional 30-minute OT Exposure Review, you control the next step
  • One-click unsubscribe, always

Download the playbook

Fill out the form and we will send the PDF to your inbox within two minutes.

We will never share your email. You can unsubscribe from any follow-up with one click.

About the Author

Written by people who do this work.

Photo

[Author Name]

[Title, Insane Cyber]

[Short bio: background in OT cybersecurity, specific data center or critical infrastructure experience. 2 to 3 sentences, factual and personal, not corporate.]

Common Questions

Quick answers before you download.

Is this for hyperscale operators or mid-market?

Written primarily for regional colocation and enterprise data center operators — the segment that tends to have less dedicated OT security coverage than hyperscalers. Hyperscale teams are welcome to use it, but the content assumes you do not have a 50-person security team.

Do I need to be technical to use this playbook?

No. The diagnostic and the 90-day plan are written in plain language. Where technical detail matters (specific ports, protocols, vulnerability catalogs), we include the exact references your team can work from. The playbook is designed to be shared up and down the org chart.

How does this compare to what Claroty, Armis, or Nozomi are putting out?

Those platforms are focused on enterprise-grade CPS protection. This playbook is more operator-focused and practical. The risk data we cite comes from Claroty's excellent research. The positioning is different: we work with operators who do not have hyperscale-level resources.

Is this regulatory driven?

No. Data center OT cybersecurity is not currently regulated the way water or defense manufacturing is. This is driven by economic reality: downtime costs money, BMS compromise causes downtime, and the threat landscape has shifted. The Digital Realty incident in 2025 made that shift visible.

Will someone call me after I download?

Only if you want them to. The follow-up is email-only unless you book a call. If you want a conversation, there is a calendar link at the back of the playbook. If you do not, you will never hear from sales.

Your facility is probably in the 75 percent. The question is what you do about it.

Download the playbook. Walk your facility. Run the diagnostic with your team. If we can help from there, we are one email away.

Send Me the Playbook