Free shipping over S$500 - Technical support available on purchases

Data Center Cybersecurity

Ramping Up Digital
Security to Prevent
Physical Threats

The rapid adoption of generative AI has fueled the rise of larger and more sophisticated data centers running on unified IT/OT infrastructure. As connectivity increases, protecting critical facility systems has become a foundational requirement for maintaining uptime and resilience.

Data Center Cybersecurity

This level of integration has been a boon for malicious actors, who are increasingly exploiting vulnerabilities in less secure OT protocols to target critical systems in the facility. A renewed focus on cybersecurity has led operators to consider robust network protection as a foundational requirement for survival.

Deploying secure-by-design hardware and incorporating zero-trust architecture into the power chain and cooling loops is the cornerstone of a robust cybersecurity framework for AI data center networks. Every power meter, gateway, and switch should be treated as a potential entry point that requires hardware-level defense.

Every connected device in the data center — from sensors and power meters to gateways and industrial switches — should be treated as a potential security entry point.

Navigating a New Threat Landscape

In the past, facilities operated as a collection of isolated systems, which provided sufficient network protection against most threats. In today’s AI facilities, the demand for real-time telemetry has introduced an array of legacy assets into the network to optimize cooling and power efficiency.

This interconnectivity of IT and OT systems exposes legacy industrial protocols like Modbus and BACnet to a whole new generation of AI-enhanced malware.

The behavior and execution of these autonomous threats have also evolved from simply crashing a system to slowly weakening defenses and enabling targeted sabotage.

For example, by subtly altering the setpoints of a liquid cooling distribution unit (CDU) or spoofing the telemetry of a backup generator, an attacker can trigger a compute crash during a critical AI training run.

The challenge for operators is clear: how do you secure infrastructure filled with legacy devices that were never designed with modern cybersecurity in mind?

Enforcing Zero Trust in the Power Chain

With the rise of more sophisticated threats, zero trust has become a leading security principle. No device is trustworthy by default, and all access must be authorized.

Applying zero trust to the facility’s power chain means that every communication between a PDU and the DCIM, or a UPS and the EPMS, must be encrypted and authenticated. However, putting this into practice poses major challenges when dealing with serial-based legacy hardware.

Secure-by-design hardware eliminates this hurdle by layering built-in security measures on top of its intended function. Secure terminal servers allow operators to safely incorporate legacy assets into a zero-trust framework by encrypting vulnerable serial data streams with secure protocols such as TLS 1.2.

Enforcing strict access control at the serial port level adds another layer of protection, ensuring that only authorized management systems can issue commands to critical power infrastructure.

Hardening Security at the Edge

Locally tailored security measures are no longer enough to handle the complex threats aimed at modern data centers. The industry is instead gravitating towards internationally recognized security standards.

Specifically, the IEC 62443 framework provides an important cybersecurity foundation for industrial automation and control systems.

For data center operators, selecting hardware designed around IEC 62443 security requirements can help establish stronger protection at the network edge.

Secure Boot

Helps ensure that only authorized firmware is allowed to run on the device.

User Authentication

Strengthens device access through robust password management and authentication controls.

Network Access Control

Allows unused ports and services to be disabled, helping minimize the device's overall attack surface.

With IEC 62443-aligned security controls, operators can establish a standardized security environment that can be further segmented into individual defense zones.

This segmented architecture helps prevent a breach in one part of the network from affecting mission-critical subsystems such as cooling and power systems.

Secure Edge Telemetry for a Data-Driven Defense

While AI is being used to design more sophisticated attacks, it can also become a powerful tool for defense. However, an AI-driven security platform is only as effective as the data it receives from the edge.

To effectively detect and respond to an attack, the security system needs access to high-fidelity and accurate telemetry in real time.

Deploying an elaborate connectivity fabric serves as the neural network of the facility, connecting sensors at the edge and sending aggregated telemetry data to the defense platform.

To ensure the integrity of collected data, telemetry from edge devices should be encrypted so that response mechanisms are always acting on authentic information.

If a sensor reports a temperature spike, the system needs confidence that the data is genuine and has not been spoofed to conceal an attack elsewhere in the facility.

Resilience Through Security

In the generative AI era, a data center’s value is measured by its uptime. As threats against AI infrastructure increasingly target interconnected physical components, defense strategies must evolve accordingly. Building a resilient DCI backbone requires protecting every system, from the smallest sensor to the largest switchgear, through secure-by-design hardware, network segmentation, encryption, and robust authentication mechanisms.

Schedule a Discussion with TNS