The Internal Data Center Paradox: Why Enterprise Facilities Are Vulnerable from the Cooling Up
- RubyComm Team

- Jul 2
- 4 min read
When chief information security officers (CISOs) at major banks, insurance companies, or healthcare networks evaluate their cyber risk, their focus naturally gravitates toward the obvious: cloud configuration, database encryption, endpoint protection, and API security. There is a comforting assumption that if you own the building, control the badge access, and run a private, internal data center, your core infrastructure is securely insulated from the chaotic realities of the public internet.
New research published in June 2026 by Claroty's Team82 threat research group challenges this assumption. The team uncovered severe vulnerabilities in two products widely deployed in data center facilities worldwide: the Trane Tracer SC+ HVAC controller and Vertiv's Liebert IS-UNITY-DP network cards, which provide the network interface for Vertiv uninterruptible power supply (UPS) devices. The flaws include authentication bypass, unauthenticated remote code execution, and hardcoded credentials. Two of the Vertiv vulnerabilities scored 9.8 out of 10 on the CVSSv3 severity scale. According to Claroty, successful exploitation could give an attacker complete control over critical building management equipment from the outside, disrupting cooling and power management with the potential for thermal shutdowns, hardware damage, and millions of dollars in losses.
The research was conducted on data center equipment, and both Trane and Vertiv have since released patches. But in our view, the most exposed organizations are not the hyperscale data center providers. Rather, they are the enterprises that operate their own internal, private data centers (where risks are sometimes underestimated).
The IT and OT Security Ownership Gap in Enterprise Facilities
Pure-play data center providers sell uptime as their primary product. Because their entire business model hinges on power and cooling reliability, they typically maintain clear ownership of facilities infrastructure: dedicated teams responsible for power distribution units (PDUs), chillers, and backup generators, with established processes for tracking vendor advisories and applying firmware updates. When a vendor like Trane or Vertiv publishes a patch, someone's job is to know about it and schedule it.
In contrast, an enterprise running an internal data center (like an insurance provider processing claims, a manufacturer managing supply chain data, or a regional bank hosting transaction ledgers) often has no equivalent function. In many of the enterprise environments we visit, a dangerous ownership gap exists between the IT teams protecting the servers and the facilities teams managing the physical building. HVAC systems and UPS units are viewed through the lens of facility maintenance rather than cybersecurity, and they are routinely connected to corporate networks without proper OT security controls, creating an unmonitored digital backdoor. A patch can exist for years without anyone in the organization being responsible for applying it.
From Compromised Controller to Forced Thermal Shutdown
The technical reality of the Claroty findings demonstrates just how dangerous this IT/OT convergence blind spot can be. The research shows that attackers don't need to breach a heavily defended, firewalled database to take a company offline. They can instead compromise an exposed UPS network card or HVAC controller directly, using flaws like authentication bypass and remote code execution to take control of the equipment itself.
In a data center environment, an HVAC failure is not a matter of employee discomfort. Modern high-density server racks generate immense heat; without continuous cooling, ambient temperatures skyrocket within minutes.
To prevent physical fires and permanent hardware destruction, servers are engineered to trigger immediate, emergency thermal shutdowns. For an enterprise, an unexpected, sudden thermal shutdown of internal data centers means an instantaneous halt to operations that can lead to:
Transactional databases fracture and experience data corruption.
Internal communication networks and active directories go dark.
Customer-facing applications and digital portals freeze.
The result can potentially create millions of dollars in operational losses, corrupted data, and severe reputational damage, all achieved without the hacker ever interacting with a traditional IT asset.
The Operational Reality of Legacy OT Patch Management
Both vendors in the Claroty research responded responsibly and made fixes available. So why are we still worried? Because in OT environments, the existence of a patch and the application of a patch are two very different things.
When a critical vulnerability is announced in an enterprise software suite, IT teams can roll out automated patches across thousands of endpoints overnight. Operational technology runs on an entirely different lifecycle. Patching a physical HVAC controller or a legacy UPS network card requires specialized expertise. It often involves manual firmware flashes, coordination with third-party automation vendors, and worst of all, planned operational downtime. Because enterprise facility teams prioritize continuous availability above all else, critical OT security patches are frequently deferred, leaving the backdoor open for months or even years after a fix is published.
Enterprise security leaders must face a hard truth: trying to manage IT-style patch cycles for hundreds of fragmented, legacy facility components is a losing battle. A new defensive boundary is required.
Insulating Critical Building Management Systems with Rubyk-OT
This is precisely the challenge we set out to solve with Rubyk-OT.
Instead of forcing enterprise IT teams to rewrite their entire network architecture or compelling facilities teams to constantly chase firmware updates on legacy equipment, Rubyk-OT introduces a compact, hardware-based security layer that connects directly in-line with physical assets.
By enforcing strict, granular micro-segmentation and protocol-aware threat prevention, Rubyk-OT acts as a digital shield around building management systems, HVAC units, and UPS controllers. It intercepts incoming traffic, ensuring that only verified, legitimate operational commands reach the hardware, while blocking unauthorized remote access attempts.
This approach allows enterprises to achieve robust protection for both brand-new and aging legacy equipment without disrupting the critical uptime of internal data centers, and without waiting on the next patch cycle. Securing the physical backbone of an enterprise shouldn't require an army of specialized network engineers or endless firmware anxiety. With Rubyk-OT, the strongest defense is an efficient hardware enforced boundary.
About RubyComm
RubyComm delivers tailored operational technology cybersecurity solutions designed specifically for the unique challenges of industrial and critical-infrastructure environments faced by organizations of all sizes. Unlike one-size-fits-all security products, RubyComm addresses the operational constraints, legacy system realities, and integration complexities that conventional off-the-shelf solutions often cannot adequately handle. Our approach maintains operational efficiency and business continuity while providing robust protection against sophisticated OT-specific threats.


