S&P Global Identified Rising Data Center Cyber Risks

Increased integration of IT and operational systems has created new vulnerabilities for critical infrastructure.

Updated on Sept. 25, 2026 in Data Centers

S&P Global Identified Rising Data Center Cyber Risks

Live Poll

Does increased reliance on large data centers make our essential services less secure?

A recent S&P Global Ratings report highlights growing, underrecognized cyber risks facing data centers as they consolidate critical infrastructure for AI and cloud services. The findings analyze how systemic dependencies leave hyperscale operations increasingly exposed to security breaches.

Why it matters

The expansion of AI is accelerating the concentration of workloads into fewer, massive facilities, which increases the potential for systemic failures. As these sites manage essential functions like power and cooling via connected networks, their security profile has shifted from isolated to highly interconnected.

Data centers now face risks stemming from 2,400+ industrial control system vulnerabilities disclosed in 2025. With total insurable assets expected to exceed $2 trillion by 2027, the industry is seeing a surge in insurance premiums, estimated at $10 billion for hyperscale operations.

The players

S&P Global Ratings

A financial services company that provides credit ratings, benchmarks, and analytics for global capital and commodity markets.

The details

Modern data centers increasingly rely on integrated digital architectures where IT networks manage essential physical facilities, including cooling, electricity distribution, and fire suppression. Operational technology — the hardware and software that detects or causes a change through the direct monitoring and control of physical devices — has become fully networked to support remote monitoring. This integration means that vulnerabilities in third-party equipment or connected IT systems can provide unauthorized access to critical physical infrastructure controls.

Timeline

  1. 2025: 152 industrial technology vendors disclosed over 2,400 vulnerabilities.

  2. 2025: 58% of operational technology attacks utilized IT entry points.

  3. 2025: Major tech firm capital expenditure reached $470 billion.

  4. 2026: Major tech firm capital expenditure reached $870 billion.

  5. 2027: Tech firm capital expenditure is expected to exceed $1.3 trillion.

The Tech Race

The transition to massive, consolidated data centers follows a clear trend of prioritizing scale for AI and cloud demands. This report updates the risk model relative to that trajectory, indicating that facility security has not kept pace with the scale of capital deployment.

As data centers underpin essential services like financial trading and healthcare, systemic security lapses could cause cascading disruptions to these daily operations. Organizations relying on these facilities should prepare for rising insurance costs and increased oversight of third-party vendors.

The takeaway

The rapid convergence of physical facility controls and digital networks has created a security profile that requires immediate re-evaluation by operators. Stakeholders should monitor 2027 capital expenditure figures and the $2 trillion in insurable assets as key metrics for industry risk management.

Further reading

For broader context on infrastructure security, explore the latest analysis in Data Centers.

Source note: This article includes information reported by ReinsuranceNe.

Live Poll

Does increased reliance on large data centers make our essential services less secure?

S&P Global Identified Rising Data Center Cyber Risks