S&P Global Ratings, a global provider of credit ratings, research and analysis, says cyber risks linked to data centres are increasing but remain underrecognised.
In a new report titled, Data Center Cyber Risk Is Increasing And Underrecognised, S&P examines how the growing integration of operational technology (OT) and IT systems, combined with the rapid expansion of AI infrastructure, could increase the potential impact of cyber incidents.
S&P said data centres have become increasingly important to cloud computing, AI, financial services, healthcare, telecommunications and government operations. As more critical workloads are concentrated within larger facilities and among fewer providers, the organisation said the consequences of a successful cyberattack could extend across multiple customers and sectors.
Cristina Polizu, an S&P analyst, commented: “A cyberattack at a data center, an operator, or in the sector’s complex supply chain could impact multiple tenants simultaneously, with potentially widespread financial and operational implications,” adding that “Mitigating data center cyber risks is often beyond the immediate focus of tenants’ cyber security operations, while defensive tools and systems continue to be developed.”
S&P said the expansion of AI is contributing to growing demand for computing capacity. It highlighted investment by Amazon, Microsoft, Alphabet, Oracle, Meta and SpaceX, whose combined capital expenditure is expected to exceed USD $1.3 trillion in 2027, compared with about USD 870 billion in 2026 and USD $470 billion in 2025. Much of this spending is expected to support data centre infrastructure.
The organisation said modern data centres depend on connected systems controlling functions such as cooling, electricity distribution, backup generation, fire suppression and environmental monitoring. Systems that were previously isolated are increasingly managed remotely and connected to wider IT networks, creating additional potential routes for cyberattacks.
S&P cited a 2025 SANS Institute survey showing that 58% of attacks on OT used an IT compromise as an entry point. It also noted that more than 2,400 industrial control system vulnerabilities were disclosed by 152 industrial technology vendors during 2025, according to Cyble Research & Intelligence Labs.
The risks are also extending into the wider data centre supply chain. S&P said operators rely on third-party suppliers for equipment, maintenance and remote monitoring, with vendors potentially introducing additional software, firmware, application programming interfaces and remote access points. Weak security controls or unpatched systems could provide attackers with routes into physical infrastructure.
S&P said responsibility for managing these risks depends partly on the data centre operating model. In managed hosting, the operator generally controls the facility and hosted equipment, while colocation customers typically retain responsibility for their own servers, storage and networking. In powered-shell arrangements, tenants generally take on greater responsibility for operating infrastructure, while enterprise data centres are owned and operated by the organisations using them.
These differences can affect the financial consequences of an incident. S&P said organisations managing their own infrastructure generally carry greater responsibility for resilience, while customers using managed services have greater reliance on their providers. An infrastructure outage in certain colocation or managed hosting arrangements could also trigger contractual provisions, including service-level agreements that affect tenant payments.
S&P identified compromised credentials, social engineering and weaknesses in access controls as key threats to tenant IT systems. For data centre OT, it highlighted exposed or poorly secured networks and insider activity, including accidental or deliberate misuse of authorised access.
The concentration of data centre infrastructure is another area of concern. S&P said larger facilities can house increasingly critical workloads, while operators with a limited number of major sites may have less diversification. It also highlighted the concentration of cloud services among Amazon Web Services, Microsoft Azure and Google Cloud, saying an incident affecting a significant part of one provider’s operations could have consequences for numerous customers.
Financial institutions are among those increasingly dependent on cloud infrastructure, with services such as payments, trading and online banking potentially affected by outages involving data centre operators or shared technology providers. S&P noted that banks and financial market infrastructures generally have established cyber risk management and recovery processes, but said these measures cannot entirely remove the risks associated with third-party and infrastructure concentration.
Public sector organisations face similar dependencies. S&P said local authorities and utilities use data centres for services including emergency communications, smart infrastructure, electricity-grid management and the storage of administrative and judicial records.
The potential financial impact also extends to project and structured finance. S&P said a cyber incident affecting data centre operations could reduce tenant utilisation or revenues, while reserve accounts and insurance may provide some protection against resulting cash-flow pressures.
For insurers, S&P noted that the rapid expansion of hyperscale data centres is creating new business opportunities alongside complex underwriting challenges. It estimated that hyperscale operations could generate around USD 10 billion in new premiums during 2026, with total insurable assets exceeding USD 2 trillion by 2027.
S&P also pointed to potential gaps between cyber and property insurance as digital and physical risks become increasingly interconnected. A single incident at a major facility could potentially result in property, cyber, business interruption, technology errors and omissions and liability claims involving multiple policyholders.
S&P said organisations can strengthen resilience through measures including network segmentation, multi-factor authentication, software patching, zero-trust security, monitoring systems, disaster recovery planning and staff training. It also emphasised the need for governance arrangements covering both IT and OT.
According to S&P, the growing dependence on data centres means cyber resilience is becoming a broader business continuity, financial and operational issue. As facilities become larger, more connected and more concentrated, the organisation said the effects of a cyber incident could extend beyond an individual operator or tenant to a wider group of businesses and infrastructure providers.
The post Data centre cyber risks growing and underrecognised: S&P appeared first on ReinsuranceNe.ws.