The weak point is not the internet-facing device itself. It is the trusted internal host one network step away, because that path can carry an attacker into cooling, power, fire, and backup systems even when the control gear is not directly exposed online.
Claroty analyzed more than 750,000 data center assets and found that about 32,000 infrastructure CPS devices, or 18%, sit one hop from internet-exposed systems. The set includes HVAC, power distribution, fire management, and UPS gear; Claroty also found insecure protocols in 88% of building management systems, outdated firmware in 40%, and thousands of devices with known exploited flaws, including 11,000 OT control systems.