Data center business continuity planning (BCP) has traditionally been developed around IT disaster recovery activities. However, given that infrastructure components such as power distribution and management, building management systems, and environmental monitoring platforms are increasingly interconnected and often remotely managed, BCP must expand to include these cyber-physical systems (CPS).
CPS assets ensure overall data center operational resilience and system uptime. Because they’re increasingly considered digital assets that rely on software, firmware, and operational technology (OT), they must be accounted for as part of a facility’s attack surface. This is driving a fundamental switch for BCP; the objective CISOs, CIOs, and COOs must account for must move beyond server and networking recovery to also ensuring that the physical infrastructure supporting computing, storage, and networking remains operational throughout a cyber incident.
This blog will explain:
The link between business continuity and operational resilience
What must be included in data center business continuity planning
The physical response plans that make up data center BCP
Business continuity planning is a facility framework that spells out how organizations would continue to deliver services, meet contractual obligations in the event of disruptive events, including cyberattacks targeting not just IT assets but also, now, CPS.
CPS disruptions could have consequential physical impacts on a data center facility. A heating, ventilation, and air conditioning (HVAC) failure could result in key digital systems overheating and failing. Power distribution and monitoring systems that fail could miss power surges that could physically damage equipment, or prevent safe shutdowns. Manipulated environmental sensors can prevent operators from recognizing dangerous operating conditions until it is too late.
BCP is the governing framework for operational resilience, ensuring ongoing service availability, in addition to spelling out recovery in the event of catastrophic failures.
An effective business continuity plan begins with understanding which cyber-physical assets are mission critical. This requires complete, accurate, up-to-date asset inventories of operational infrastructure, technology that’s often very different from traditionally understood IT assets.
Deep CPS asset visibility brings contextual device information down to the firmware version, information that lessens the potential impact of a risky exposure. It also helps illuminate exposures such as assets containing known exploited vulnerabilities (KEVs), weak configurations, legacy protocols, and insecure access controls. Moreover, deep visibility can also provide the business-critical context of an asset within the broader CPS environment, a key factor in enabling security teams to effectively assess risks and prioritize remediation efforts.
A comprehensive data center business continuity plan should account for CPS assets, including: power distribution, uninterruptible power supplies, backup generators, cooling and HVAC, BMS, data center infrastructure management platforms, environmental monitoring, OT assets such as controllers, sensors, and other field devices, and secure access controls.
These assets contain some of the riskiest exposures putting data centers at risk, according to Claroty Team82’s recent State of CPS Security: Data Center Exposures report. For example, our research looked at more than 750,000 CPS assets and core infrastructure running in data centers, uncovering that power distribution units (41%) and HVAC/cooling systems (32%) have the highest percentage of assets one hop away from a risky connection to the public internet or directly exposed online. BMS, meanwhile, contain some of the riskiest exposures, with 88% communicating over insecure protocols and 40% containing outdated firmware
Each asset should be evaluated for its operational importance, exposures, recovery requirements, and dependencies, all of which surface points of failure before attackers can exploit them.
Dependency mapping is equally important for data center facilities. For example, cooling systems depend upon power. Building automation systems depend upon network connectivity. Environmental monitoring platforms rely on sensors, controllers, and communications infrastructure. A business continuity plan should document these dependencies to inform incident responders and understand how failures may cascade throughout the facility.
BCP is not just a framework, it’s people. BCP demands coordination across multiple business units, and it's incumbent upon CISOs to sketch out incident response teams in BCPs that extend well beyond traditional security operations. Stakeholders should include data center operations, facilities engineering, OT engineers, physical security, and network engineering in addition to executives, risk management, legal, communications, and some third parties. This saves valuable time coordinating responsibilities while outages continue to grow.
Data center business continuity planning must also account for CPS’ impact on physical processes. This is why respective engineering teams are key stakeholders and must be included in BCP. Disconnecting a compromised building management controller without understanding its operational function may disable environmental controls protecting entire server rooms.
Similarly, taking industrial controllers offline during an investigation could interrupt generator synchronization or power monitoring. Response plans must take into account whether systems can operate in a manual mode and which processes can proceed without automation in the event of an incident. Test whether backup operational procedures can be validated. BCP must also include who among the stakeholders may approve any shutdowns or isolation of affected systems, and which vendors should be connected. These procedures allow organizations to contain cyber threats while maintaining operational resilience, safety, and availability.
Business continuity plans quickly become outdated if they are never tested, therefore, regular tabletop exercises should be scheduled and include attack scenarios against CPS rather than just concentrating on attacks impacting the IT network and infrastructure. Test responses to BMS and DCIM failures, or illicit access to environmental monitoring platforms where malicious changes to cooling or power management may be made.
Tabletop exercises also expose communication gaps, undocumented dependencies, and decision-making bottlenecks long before a real incident occurs.
Data center CISOs should understand they’ll be measured against not only how their policies and procedures prevent compromise, but also by how effectively the organization continues operating when compromise inevitably occurs. CPS is a key fixture in data center BCP since they are the foundational piers of any modern facility and make continuous operations possible. The strongest business continuity strategy is one that treats cybersecurity and operational resilience as inseparable.
How Claroty Claire™ Brings AI-Powered Cybersecurity to Cyber-Physical Systems
How Governance of CPS Security Drives Operational Resilience
How CPS Resilience Enables Data Center Sustainability
Interested in learning about Claroty's Cybersecurity Solutions?
Life, uninterrupted
We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.