Is the UK’s data centre resilience keeping pace with the threat?

Nick Haan
Nick Haan
Field CTO at Claroty

Nick Haan, Field CTO at Claroty, explains why data centre operators cannot afford to wait for regulation before strengthening cyber resilience, redundancy and remote access controls.

It’s been two years since the UK’s data centres were formally recognised as critical national infrastructure, the first new CNI designation in nearly a decade. Yet there are still no minimum cybersecurity or resilience requirements attached to that status, and the Cyber Security and Resilience Bill meant to close that gap is still working its way through Parliament.

Meanwhile, data centre infrastructure has become progressively more vital for the digital economy, making it an increasingly tempting target for cyber threat actors seeking to cause widespread disruption. With operators already balancing other challenges, including access to power grids, they cannot afford to overlook cyber risk while awaiting more official guidance.

Not every threat is an accident

With their unique combination of complex digital and physical systems, high energy demands and minimal tolerance for downtime, data centres are inherently vulnerable environments.

They are particularly exposed to dedicated hacktivist and state-backed groups seeking to cause disruption or deliver a message. Earlier this year, threat intelligence firm Vecert reported that the Russian hacktivist group Killnet had breached a French data centre and its backup power supplier, claiming access to 120,000 UPS units and exfiltrating energy and monitoring data.

The extensive disruption caused by data centre outages has also been seen multiple times this year, even without the added pressure of external threat actors. A fire at a data centre in Almere, Netherlands, in May disrupted Utrecht University, the Chamber of Commerce and IBM Cloud. A month later, a lithium battery fire in Delhi triggered an emergency shutdown that knocked out Google Cloud across three Indian metros for far longer than usual.

Accident or attack, the lesson is the same: data centres may be less resilient than operators assume.

This gap in risk assessment is becoming more significant as data centres grow more critical. In addition to the impact on their own customers, some of the newest campuses now draw power on a scale comparable to a small city, meaning a sudden, forced disconnection wouldn’t just take a single facility offline; it could also have implications for the wider grid.

If a data centre doesn’t fully understand something as fundamental as its own power resilience – its bread and butter – then cyber-physical monitoring and compliance, a much newer discipline, may be further behind still.

Data centres attract more advanced adversaries

Data centres typically boast a high level of physical security, even compared with other industrial sites, so threat actors will often look for ways to gain access through the cyber layer rather than through the site itself.

That raises the skill bar. These attackers can be patient and well-resourced, and may be financially motivated or backed by a state sponsor rather than opportunists running a port scan and hoping something’s open.

Alongside the usual tactics, such as targeted phishing attacks that are common across all industries, threat actors are vigilant for any opportunity to access the cyber-physical systems that keep sites running.

For example, standard corporate activity such as a job posting seeking specific vendor expertise or a partnership with a particular supplier could inadvertently tell an attacker exactly what’s running on site.

Why the cyber-physical layer stays exposed

Most sites contain blind spots that can be found without this level of advanced reconnaissance. Research conducted by Claroty across more than 174,000 data centre infrastructure devices found that only 0.4% were directly exposed to the internet, yet 18% sat just one hop away from a system that was, with power distribution units the riskiest single category at 41%.

Remote access remains one of the biggest issues, still often bolted together tool by tool as a site grows. You might find one system on an old GPRS link, another on its own VPN, and this ad hoc mixture can create gaps in visibility and control.

The infrastructure underneath, such as DNS servers and domain controllers, needs the same rigour built in from day one, not patched in later. Add in the third-party contractors every site relies on for remote maintenance, and there can be a significant number of potential access points to manage.

The rules are still catching up

While there is a high level of awareness that data centres are both critical and vulnerable, the sector is still waiting for more specific support and guidance. Europe’s NIS2 and the UK’s forthcoming Bill aren’t especially prescriptive yet on what good practice for something like remote access should actually look like.

However, operators don’t need to wait for that detail from the latest regulations, and much of the guidance already exists elsewhere. ISO 27002 and FIPS, for example, set out established approaches to areas such as individual accounts, logging and access control rather than reliance on shared credentials.

Customers are moving faster than regulators too. Large automotive corporations already require TISAX compliance from suppliers hosting their infrastructure, for example. And because data centres compete for customers in a way most utilities never have to, certification can increasingly become a commercial consideration as well as a compliance requirement. Either way, operators cannot afford to wait until a law is in force before considering how its requirements may affect them.

Building resilience that’s real

The key to real resilience starts with interrogating your own redundancy rather than assuming it holds. For example, both Almere and Delhi raise a similar question: whether sufficient independent redundancy exists to prevent a single failure in the power systems from affecting everything downstream.

Research has also found that backup systems can share the same exposures as the equipment they protect, meaning redundant hardware may be vulnerable to the same exploit that affects the primary system. This was also relevant to the Killnet incident, where the group targeted a backup power supplier rather than the primary site. Similarly, Claroty’s Team82 researchers discovered two critical vulnerabilities in Vertiv’s widely used Liebert UPS network cards, which are used in data centres to maintain operations during a power outage. The flaws could allow an attacker to bypass authentication and remotely issue an “output OFF” command, shutting down devices the UPS was intended to protect.

Understanding that dependency properly also changes what you tell your customers. Rather than assuming that two zones inside a single data centre give them the protection they think they do, genuinely critical applications may need to be spread across separate sites. Further, it’s essential to monitor those systems on an ongoing basis, rather than simply designing them and walking away, so resilience claims can be backed by evidence rather than assumption.

Alongside redundancy, simplification is another priority. When it comes to the large number of remote connections used by outside contractors, one or a small number of tightly controlled routes is preferable to numerous different ways into separate systems. That makes access easier to monitor and secure.

None of this requires new legislation to get started. Redundancy, segmentation and monitoring are achievable today, and operators that can demonstrate their resilience will be better placed to respond to growing expectations from both customers and regulators.

Related Articles

More Opinions

It takes just one minute to register for the leading twice weekly B2B newsletter for the data centre industry, and it's free.