Field Note • Critical Power Defense
Data Center Power Infrastructure as an Overlooked OT Attack Surface
In hyperscale and enterprise colocation data centers, hundreds of millions of dollars are invested in zero-trust network architectures, micro-segmentation, and endpoint detection. Yet beneath the server floor lies an interconnected web of industrial microcontrollers, electrical monitoring meters, and lithium-ion battery management systems that are virtually invisible to the enterprise CISO.
The Five Nines Fallacy
Data center reliability is traditionally measured in uptime percentages: 99.999% availability ("five nines"). Facilities engineering teams design extensive redundancy into the electrical topology: 2N or N+1 power paths, dual utility feeds, rotary or static uninterruptible power supplies (UPS), and banks of emergency diesel generators coordinated by automatic transfer switches (ATS).
However, traditional redundancy models are predicated on random hardware failure or utility grid transients. They assume failure events are independent: if Utility Feed A fails, Utility Feed B or Generator Set A carries the load.
A cyber attack fundamentally invalidates the assumption of independent failure. If an adversary gains access to the common Electrical Power Monitoring System (EPMS) or discovers a shared vulnerability in the firmware of identical UPS controllers across both the A and B sides of the power train, they can trigger simultaneous failure across redundant paths, taking down the entire facility in milliseconds.
Anatomy of the Data Center Power Train Attack Surface
1. The Lithium-Ion UPS Transition
Over the past five years, data center operators have aggressively replaced legacy Valve-Regulated Lead-Acid (VRLA) batteries with high-density lithium-ion chemistries. While lithium offers smaller footprints, longer lifespans, and lower total cost of ownership, it introduces a major cyber-physical transformation:
- VRLA batteries are passive chemical cells requiring minimal active digital intervention.
- Lithium-ion cells require active, continuous microprocessor-driven monitoring (BMS) to regulate cell voltages, manage thermal profiles, and control contactor disconnects.
This shift transforms the emergency backup power supply from a purely electrical/chemical asset into a networked, software-defined computer system running exposed embedded operating systems directly connected to facility networks.
2. Electrical Power Monitoring Systems (EPMS) & BAS Cross-Talk
EPMS networks aggregate real-time telemetry from thousands of smart circuit breakers, power distribution units (PDUs), branch circuit monitors, and power quality meters. To facilitate facility-wide energy management, EPMS networks are frequently bridged with Building Automation Systems (BAS) and Computer Room Air Conditioning (CRAC/CRAH) chillers.
These networks almost universally run unauthenticated protocols: Modbus TCP, BACnet/IP, and SNMPv1/v2c. Anyone with network access can forge sensor readings, spoof power metrics, or send trip commands to motorized circuit breakers.
3. Contractor & OEM Maintenance Portals
Data center electrical infrastructure is rarely maintained by in-house IT personnel. It is serviced under contract by UPS manufacturers, generator specialists, and mechanical engineering firms.
To perform predictive diagnostics and emergency support, these vendors often insist on external connectivity. Our field audits routinely discover:
- Unmanaged 4G/5G cellular modems installed inside generator enclosures and chiller control cabinets.
- Technician laptops plugged directly into switchgear maintenance ports during quarterly testing without endpoint health verification.
- Shared, default vendor credentials on critical power meters and UPS network interface cards (NICs).
Bridging the CISO and Facilities Engineering Gap
Defending critical power infrastructure requires breaking down the organizational wall between enterprise information security and physical plant engineering:
- Passive Power-Train Asset Discovery: Inventorying every IP address, MAC address, PLC, power meter, and BMS controller on the facility network without sending disruptive active network probes.
- Zero-Standing-Access for Electrical Vendors: Mandating that all electrical contractors and OEMs authenticate through an ephemeral, Just-In-Time access gateway with protocol-aware command inspection and full session recording.
- Physical Consequence Risk Scoring: Mapping network vulnerabilities directly to their physical impact on PDU feeds, busway feeds, and server uptime.
Conclusion
Cyber threats do not care about internal organizational boundaries. If an attacker cannot breach cloud-hosted server applications, they will target the lithium battery banks and switchgear that supply those servers with electricity. Securing modern data centers requires protecting the entire chain of availability—from the cloud edge down to the high-voltage electrical busbar.
Evaluate your critical power cyber exposure
Battery Cyber conducts non-intrusive electrical power network audits for data center operators and mission-critical facilities.
Discuss an environment