Seven Stops:  A Walkthrough Guide to Data Center OT Assets  

data center ot assets

Most data center asset inventories are accurate. They are also incomplete.

That is not a knock on anyone’s asset management program. The inventory usually reflects what IT bought, racked, and put under a support contract. What it tends to miss is everything the facilities group purchased, everything the controls contractor commissioned before the building opened, and the one-off gear a single tenant asked for inside their own cage.

All that equipment has some form of compute; most of them have network interfaces, and there is a good chance of vendor remote access that is not entirely tracked by your security operations team. How do you thoroughly track these assets if there is reasonable doubt? Well, an unparalleled method to find these is to put on a hard hat and walk the building, plant, and/or facility.

What follows is not a complete inventory of what you will encounter. Equipment varies by facility age, design, cooling approach, redundancy model, geography, and customer requirements. Treat these seven stops as a route, not a checklist.

At each one, we ask three questions:

  • What is here?
  • Is it on a network?
  • Who gets called when it breaks?

That third question is the one that usually produces a pause. When nobody can name the owner in under ten seconds, you have found something worth writing down.

A few ground rules before you start. Bring a notebook or a phone and photograph nameplates, because model and firmware numbers are the difference between a useful inventory list and a list of nouns. Do not unplug anything, do not press buttons on a panel to see what happens, and do not point a network scanner at any of this. You are looking and asking, nothing else. And before the walk, ask the facilities team for the commissioning documents, the BMS points list, and the controls architecture drawing. Together they tell you what the system is supposed to read, write, and connect to. Understanding the gaps between those and your facility walkthrough is the meat of the exercise.

Stop One: Lobby and Loading Dock

Start where the building starts.

Badge readers, door controllers, mantrap interlocks, cage locks, cameras, and visitor management. In most facilities we walk, the door controllers sit on a dedicated security VLAN; the head end runs Lenel, C-CURE, Genetec, or something similar on a Windows server in a closet; and the cameras stream over ONVIF or RTSP to a recorder somewhere in the building.

The interesting part is rarely the controllers. It is the head-end server and who is responsible for it. Ask whether IT patches that operating system or whether the integrator owns the whole box under their maintenance agreement. In our experience, the answer is frequently “the integrator,” and the integrator’s definition of maintenance is keeping the access control application working, not keeping the underlying OS current.

Also worth pinning down: how the integrator reaches that server when they need to. A support laptop that plugs into the security VLAN on site is a very different risk conversation than a persistent remote session that has been open since installation.

Stop Two: The Electrical Room

Now look at everything that keeps power flowing.

UPS units, rack and floor PDUs, automatic transfer switches, switchgear, generator controllers, power meters, and battery monitoring. Rack PDUs are usually already in somebody’s inventory because IT bought them. The upstream equipment often is not.

Look for network management cards. Most UPS vendors ship them, most sites install them, and a large share of them are still answering SNMP with community strings that were set during commissioning. Power meters and breaker trip units frequently speak Modbus TCP on port 502, with no authentication in the protocol at all, because the protocol was never designed to have any. That is not a defect you are going to fix. It is a reason to care about who can reach the network segment those devices live on.

Questions we ask in this room:

  • Which devices have live network interfaces, and which ports are dark?
  • Are any credentials still at commissioning defaults?
  • Who reviews access when a facilities vendor changes staff or loses a contract?
  • Does anything in here report out to a vendor for warranty or service monitoring?

Stop Three: The Mechanical Yard

The yard is where the operationally important equipment lives, and it is where vendor remote access tends to hide.

You are looking at chillers, cooling towers, condenser water pumps, VFDs, and the control panels that tie them together. Chillers in particular are worth close attention, because service agreements from the major manufacturers often include remote performance monitoring. That connection has to arrive somehow. Sometimes it is a cellular modem bolted to the side of the unit. Sometimes it is a vendor appliance sitting on the building network with an outbound tunnel. Sometimes the controls contractor set up a VPN account in 2019 and the account still works.

None of that is automatically wrong. Remote support shortens outages and keeps warranties intact. The problem is when the security team cannot name the connections, cannot say who approved them, and has no way to tell whether the path is being used for anything other than pulling chiller performance data.

So the question is not “should this exist.” It is “where does it terminate, who authorized it, and when did we last look at it.”

Stop Four: The White Space

The data hall has its own layer of facility technology sitting right alongside the servers.

Computer Room Air Conditioner (CRAC) and Computer Room Air Handler (CRAH) units, in-row cooling, leak detection zones, environmental sensors, rack-level monitoring, and in liquid-cooled halls, coolant distribution units. Newer builds are adding equipment that did not exist the last time many of these inventories were updated, which is a good argument for walking the floor rather than trusting a spreadsheet.

The CRAC and CRAH distinction is worth keeping straight, because it changes what depends on what. CRAC units use direct expansion refrigeration and are largely self-contained. CRAH units rely on chilled water produced back at the plant you just walked past in the yard. If your cooling is CRAH, then your data hall availability has a dependency chain that runs through the chiller plant, the pumps, and the controllers managing all of it. That dependency belongs in your notes.

Protocols in this space are usually BACnet/IP on UDP 47808, Modbus TCP on 502, or a Tridium Niagara framework with JACE controllers using Fox. You will also find proprietary vendor protocols and gateways translating between them. Do not assume which one you have. Identify it, then find out what else can talk to it, because a “dedicated” building network with one route into it is not actually dedicated.

Stop Five: Fire and Life Safety

Interacting with safety systems can cause injury or worse. Look and ask, nothing else. Do not scan these devices, do not touch panels, and if a technician offers to demonstrate something, politely decline.

Aspirating smoke detection, pre-action sprinkler systems, clean agent suppression, fire alarm panels, and whatever interfaces tie them to the rest of the building. These systems are governed by fire code, the authority having jurisdiction, and vendor certification requirements. The questions we ask about here:

Does the fire system report into the BMS, and if so, through what?

  • Is there a gateway or protocol converter in the path, and where does it sit?
  • Are alarms forwarded to a central station over IP, cellular, or a POTS line?
  • Who maintains the integration, and is it documented anywhere you can get to?

Plenty of fire systems are genuinely isolated, and that is a fine answer. Others turn out to have a small gateway box in a closet that bridges the fire panel to the building network so operators can see alarms on a dashboard. Both are legitimate designs. You just need to know which one you have.

Stop Six: The Operations Office

The ops office is where everything you just walked past shows up on a screen.

Expect a Building Management System head end, a DCIM platform, one or more engineering workstations, vendor consoles, and an environmental monitoring dashboard. This is usually the highest-value stop of the walk, because these are the boundary machines. The BMS can see and often command a large portion of the facility. DCIM polls across both facility and IT territory. Engineering workstations hold vendor configuration software, project files, and saved credentials.

What we look for:

  • Workstations with two network connections, one to the building network and one to corporate
  • Whether operators can browse the web or read email from the same machine that programs controllers
  • Shared local accounts used by whoever is on shift
  • Where DCIM and BMS exchange data with corporate IT systems, and in which direction
  • Whether remote access to these consoles exists for after-hours support

None of this means the BMS is a problem. It means the BMS sits at a junction between facilities staff, vendors, operations, and IT, and junctions are where you want your visibility.

Stop Seven: Everything That Does Not Fit a Category

This is the stop that finds things.

Elevators. Generator fuel management and tank monitoring. Water treatment for the cooling towers. Battery monitoring. Lighting controls. Pump controls. Protocol converters and gateways in unlabeled boxes. Vendor appliances that arrived with a service contract. Engineering workstations installed at a specific piece of equipment. Anything a single customer asked to have installed for their workload.

There will be others. That is the whole point of this stop.

The way to work it is to ask several groups the same question separately: facilities, operators, electricians, the controls contractor, the mechanical techs, and your major vendors. Ask each of them what exists in this building that has a controller, a network connection, a remote interface, or software that manages it.

You will get different answers. The gaps between those answers are not an annoyance; they are the finding. When the mechanical contractor knows about a gateway that facilities has never heard of, you have learned something about how equipment gets added to this site.

What You Actually Do With the List

The goal is not to prove your facility is full of forgotten devices. Maybe it is. Maybe your asset program already covers ninety percent of what you wrote down. Either outcome is worth the time it took to walk the facility..

What the list gives you is a way to ask two questions about every system on it:

  • Who owns it?
  • How would we know if its behavior changed?

The first question is an organizational problem, and you can usually solve it with a conversation and a spreadsheet column. The second is harder, and it is where most teams get stuck.

Traditional vulnerability scanning is a poor fit for a lot of this equipment. Older controllers can fall over from ordinary scan traffic, and even when they survive it, “we scanned the fire panel” is a sentence you do not want to say out loud. Endpoint agents are not an option either, because most of these devices were never designed to run third-party software, and installing anything on them would void the support agreement holding your warranty together.

Passive network monitoring gives you a different path. Watching the traffic tells you what is actually communicating, with whom, and how that pattern changes, without asking the devices any questions at all. Valkyrie was built for exactly that kind of environment, so you can observe OT network activity without interrogating the equipment.

For sites where a permanent sensor deployment is not on the table yet, or where there is no cloud or internet connectivity to work with, Cygnet runs Valkyrie out of a portable kit. Our team uses it for on-site and air-gapped assessments, including the first pass on a facility where nobody is sure what is on the network yet. If you would rather not run the walkthrough or the assessment alone, that is what our OT services team does.

But the tooling comes second. Sensors placed from an inaccurate network diagram will give you confident, useless data.

Walk the building first. Talk to the people who run it, follow the connections, and find out who owns what. Your facility will have systems that are not on this list, and honestly, you should expect that. The asset inventory worth having is not the one somebody handed you when you started. It is the one you built from what is actually in the building.

Share:

Interested in building your OT Cyber Foundations? Take our free course here. 

More Posts