In the first half of 2025 alone, over 3,000 cyber incidents were recorded in Ukraine.
How a distant campaign illuminates a local weak point
Those thousands of incidents are not an abstract statistic. The source material links them to a pattern of hostile operations that have targeted hospitals, energy and transport systems, government services and local authorities. That pattern helps explain recent sanctions imposed by Britain and the European Union after an attack by Russia’s Federal Security Service (FSB) in Poland that struck renewable energy facilities, a manufacturing firm and a plant supplying heat for nearly 500,000 people. The lesson drawn in the reporting is clear: the tactics and targets seen overseas map directly onto the systems that data centres depend on at home.
Operational technology inside data centres is exposed
Data centres require large amounts of power and water, and they rely on operational technology (OT) — the hardware and software used to monitor, control and automate physical devices and industrial processes — to keep those supplies flowing. The same story notes exploitable OT components inside data centres themselves: precision cooling systems, internet-exposed infrastructure management software, and physical devices such as sensors and cameras. A centre that is robust on its IT stack can still be vulnerable if an OT component is insecure.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildEnergy and water systems are shared attack surfaces
Data centres are not isolated islands. They depend on the energy grid and water systems they connect to, and those systems use OT such as network controllers and substation monitoring systems. The source cites repeated instances where these OT systems have been weaponised, and it warns that vulnerabilities in a water system connected to a data centre can put the data centre itself at risk — with downstream consequences for Australia’s increasingly digital economy.
Legal obligations and a missing cultural shift in Australia
Protecting data storage and processing is more than best practice: data storage and processing is a critical infrastructure sector under the Security of Critical Infrastructure Act 2018, so protecting these systems may be legally obligatory. Yet the reporting stresses a cultural problem in Australia: sentiment has focused on building more, faster, while cultural awareness about protecting the supporting OT has lagged. The Australian Signals Directorate (ASD) has repeatedly warned of persistent threats; in August the ASD warned that Chinese state-sponsored hackers were targeting networks globally, including Australia.
Where OT security routinely breaks down
The risk, the material emphasises, "lives in the gaps." OT security fails at handoffs — between the operator who runs the physical computers, the electricity company that supplies the energy, the vendor who remotely services the cooling systems and the landlord who owns the building. A facility can be immaculate on the IT side and still be exposed through an insecure building management system commissioned by a subcontractor. The ASD guidance cited describes OT environments as carrying old devices, outdated protocols and slow replacement cycles, and notes that operators are often locked into engineering contracts written long before cybersecurity was a consideration.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: Expect to find exploitable OT in cooling, infrastructure management software, sensors and cameras — and to face legacy devices, outdated protocols and long replacement cycles as practical constraints.
- Policymakers and regulators: The Security of Critical Infrastructure Act 2018 already places data storage and processing in the scope of critical infrastructure; the reporting suggests that legal obligations and cultural change must align to prioritise OT security alongside capacity-building for AI.
- Affected enterprises, landlords and vendors: The greatest operational risk is in contractual handoffs — between operators, utilities, vendors and owners — and protecting systems may be a legal as well as operational requirement.
AI and data-driven economies depend on physical systems as much as on models and chips. The reporting’s central insistence is that OT security — not an add-on but an operational imperative — must be folded into Australia’s AI ambitions and critical-infrastructure protections. If the systems that keep servers cool, powered and watered remain the weak link, the gains promised by increased computing capacity will be fragile.




