A nighttime data center with server racks, linked to a citywide cloud network and marked by a cybersecurity warning shield.
S&P Global Ratings published a report in late September 2026 warning that cyber risk at data centres is rising and underrecognised. It says three things are driving that: IT networks are merging with the operational technology (OT) that runs power and cooling, AI infrastructure is growing fast, and workloads are concentrating among a few providers. For enterprise tenants, one attack on a facility or its suppliers could hit many customers at the same time. The report, detailed by Reinsurance News, does not describe a new vulnerability or a specific attack. It is a credit-rating agency arguing that an organisation can harden its own servers and identities and still be exposed through building systems, vendors and contracts that it does not control. For anyone running workloads in colocation, managed hosting or a hyperscale cloud such as Microsoft Azure, the report is a useful prompt to check who is responsible for each layer of the stack.

S&P Global Ratings says data centre cyber risk is increasing and underrecognised​

The report is titled Data Center Cyber Risk Is Increasing And Underrecognized. According to Reinsurance News, it examines how the growing integration of operational technology (OT) and IT systems, combined with the rapid expansion of AI infrastructure, could increase the potential impact of cyber incidents. S&P treats data centres as shared infrastructure for cloud computing, AI, financial services, healthcare, telecommunications and government operations. Its central point is about scale: as more critical workloads are concentrated within larger facilities and among fewer providers, the organisation said the consequences of a successful cyberattack could extend across multiple customers and sectors.

S&P analyst Cristina Polizu made the tenant-level point directly. She warned that "A cyberattack at a data center, an operator, or in the sector's complex supply chain could impact multiple tenants simultaneously". She also said that mitigating these risks "is often beyond the immediate focus of tenants' cyber security operations". That second remark describes the blind spot. A typical enterprise security programme watches endpoints, identities, email and its own network. The chillers, power distribution units and generator controllers in someone else's building are rarely part of that picture.

This topic fits S&P's recent work. S&P Global Ratings has published separate research on data centres as an insurable risk pool and on what data centre growth means for US utilities and local governments. Its broader cyber-risk research warns that as IT systems become more complex, increased integration and external connectivity could expand the attack surface. The new report applies that reasoning to the buildings where cloud and AI workloads physically run. At the time of writing, Reinsurance News is the only outlet to have reported the new report's contents. The report-specific figures below are S&P's estimates as relayed there.

S&P's case for why the stakes are rising rests on spending. The report highlighted investment by Amazon, Microsoft, Alphabet, Oracle, Meta and SpaceX, whose combined capital expenditure is expected to exceed USD $1.3 trillion in 2027, compared with about USD 870 billion in 2026 and USD $470 billion in 2025. These are forward-looking estimates, not reported spending. They do show the direction of travel: the combined figure would nearly triple between 2025 and 2027, and much of this spending is expected to support data centre infrastructure.

Cooling, power and fire suppression systems are now reachable from IT networks​

The technical core of the argument is the building management layer. S&P says modern data centres depend on connected systems controlling functions such as cooling, electricity distribution, backup generation, fire suppression and environmental monitoring. For many years, the working assumption was that these systems sat on their own isolated networks. S&P says that assumption no longer holds: systems that were previously isolated are increasingly managed remotely and connected to wider IT networks, creating additional potential routes for cyberattacks.

The report cites two industry statistics. S&P cited a 2025 SANS Institute survey showing that 58% of attacks on OT used an IT compromise as an entry point. It also noted that more than 2,400 industrial control system vulnerabilities were disclosed by 152 industrial technology vendors during 2025, according to Cyble Research & Intelligence Labs. Both numbers cover OT and industrial control systems across all sectors. They are not counts of attacks on data centres or vulnerabilities in data centre equipment. They support S&P's main mechanism instead: attackers usually reach OT by first compromising the IT network, and there is a large, growing pool of disclosed flaws in industrial control products.

For Windows administrators, the mechanism is familiar even though the targets are not. Attackers routinely obtain initial access through phished credentials, an exposed remote-access service or an unpatched server. Once a facility's building management system can be reached from the corporate IT network, that same foothold can lead to cooling or power controls. S&P splits the threats along this line. For tenant IT systems, it names compromised credentials, social engineering and weaknesses in access controls. For data centre OT, it highlighted exposed or poorly secured networks and insider activity, including accidental or deliberate misuse of authorised access.

S&P also flags the supply chain. It said operators rely on third-party suppliers for equipment, maintenance and remote monitoring, with vendors potentially introducing additional software, firmware, application programming interfaces and remote access points. Every remote-monitoring agent, vendor VPN or maintenance API is a connection someone has to govern. S&P warns that weak security controls or unpatched systems could provide attackers with routes into physical infrastructure. The report, as described, does not name an exploited vendor or a particular incident. It describes a structural exposure, not a campaign in progress.

Colocation, managed hosting and powered shell contracts decide who owns the risk​

The most practically useful part of the report explains how responsibility changes with the hosting model. S&P said responsibility for managing these risks depends partly on the data centre operating model. The division it describes is summarised below.

Operating modelWho generally controls what, per S&P
Managed hostingThe operator generally controls the facility and the hosted equipment.
ColocationCustomers typically keep responsibility for their own servers, storage and networking.
Powered shellTenants generally take on more responsibility for operating the infrastructure.
Enterprise data centreOwned and operated by the organisation that uses it.

The financial consequences follow from that division. S&P said organisations managing their own infrastructure generally carry greater responsibility for resilience, while customers using managed services have greater reliance on their providers. Contract terms also matter: an infrastructure outage in certain colocation or managed hosting arrangements could also trigger contractual provisions, including service-level agreements that affect tenant payments. The word "certain" is S&P's, and it carries weight. What an SLA actually pays out, and when, depends entirely on the individual contract. Nothing in the report suggests every outage leads to the same remedy.

In practice, a colocation customer running Windows Server hosts in a rented cage owns patching, identity and network security for that hardware. It still depends on the operator's cooling, power and physical access controls, and on the operator's own vendors. A managed-hosting customer hands over more of the stack and therefore takes on more dependency on the provider. S&P's point is that neither arrangement removes the risk. Each one moves it to a different place, and tenants often fail to map where it ended up.

Concentration in Microsoft Azure, AWS and Google Cloud means one incident can hit many customers​

S&P treats concentration as a risk in its own right. It said larger facilities can house increasingly critical workloads, while operators with a limited number of major sites may have less diversification. The report names the three largest public clouds. It highlighted the concentration of cloud services among Amazon Web Services, Microsoft Azure and Google Cloud, saying an incident affecting a significant part of one provider's operations could have consequences for numerous customers.

This is an argument about structure. It does not claim that Azure, AWS or Google Cloud have been compromised, and nothing in the report as described alleges that. It also focuses on cyber incidents in particular, though loss of availability can have other causes. The consequence for Microsoft-centric organisations is simple. Many run Entra ID, Microsoft 365, Azure-hosted line-of-business apps and backups all on one hyperscaler. That makes them a clear example of the dependency S&P describes, whatever security controls the provider itself has in place.

S&P traces these effects into specific sectors. Financial institutions are among those increasingly dependent on cloud infrastructure, with services such as payments, trading and online banking potentially affected by outages involving data centre operators or shared technology providers. The agency credits banks with mature controls, but adds that these measures cannot entirely remove the risks associated with third-party and infrastructure concentration. The public sector has similar exposure. S&P said local authorities and utilities use data centres for services including emergency communications, smart infrastructure, electricity-grid management and the storage of administrative and judicial records.

The report also covers how data centres are financed. S&P said a cyber incident affecting data centre operations could reduce tenant utilisation or revenues, while reserve accounts and insurance may provide some protection against resulting cash-flow pressures. A rating agency makes this link because many new facilities are funded through project and structured finance, where lower tenant revenue feeds directly into credit analysis.


Insurers see a $10 billion data centre market with gaps between cyber and property cover​

S&P's estimates about insurance are the ones most readers will quote. It estimated that hyperscale operations could generate around USD 10 billion in new premiums during 2026, with total insurable assets exceeding USD 2 trillion by 2027. The premium figure is consistent with S&P's earlier work. In April 2026, Insurance Business reported an S&P analysis that said rising demand for data centre insurance could generate around US$10 billion in new premiums in 2026, roughly twice the size of the global aviation insurance market. The timing of the asset figure differs, though. That earlier analysis said there are about 11,000 operating data centres globally, with a combined insurable asset base of more than US$2 trillion, which describes the current asset base. The new report, as relayed by Reinsurance News, puts the $2 trillion mark in 2027. The underlying scale is the same either way. The difference may come from how the report was summarised or from a change in definition, and the public reporting does not settle which.

The underwriting problem matters more to IT and risk teams than the headline totals. S&P pointed to potential gaps between cyber and property insurance as digital and physical risks become increasingly interconnected. Consider an attacker who uses a compromised IT account to reach cooling controls and causes equipment damage and downtime. That single event is both a cyber incident and a physical loss, and the two are typically covered by different policies with different exclusions. S&P warns that a single incident at a major facility could potentially result in property, cyber, business interruption, technology errors and omissions and liability claims involving multiple policyholders.

The earlier S&P analysis also expects insurers to grow their data centre portfolios cautiously, given limited long‑term loss data and the evolving nature of the risk, and says technology and cyber policies are expected to adjust as new operational and cyber incident scenarios emerge. Tenants should expect policy wording on data centre dependencies to change. Where a loss falls between cyber and property cover is currently decided policy by policy.

What this means for Windows and Azure administrators​

The decision in front of IT teams is whether their resilience planning reaches past their own estate. For organisations with workloads in third-party facilities, S&P's analysis says it should. The mitigations S&P lists are standard practice: network segmentation, multi-factor authentication, software patching, zero-trust security, monitoring systems, disaster recovery planning and staff training. The less common item is governance: S&P emphasised the need for governance arrangements covering both IT and OT. The report, as described, gives no configurations, timelines or checklist. The steps below are our inferences from the risks it lays out, not S&P's instructions.

Colocation and managed-hosting customers gain the most from acting now. The contract determines which layers they are responsible for and which they merely depend on. Organisations that run their own enterprise data centres already own the OT problem outright, so for them S&P's IT-to-OT statistics amount to a request to audit the paths between corporate networks and building management systems. Pure SaaS consumers have little direct control over facility security. Their decisions come down to concentration and recovery: how much depends on one provider, and what still works if that provider has a bad week.

  • Map, layer by layer, who owns security and recovery for facility controls, tenant hardware, network links, vendor remote access, identity and backups. Do not assume "the provider" or "the customer" covers all of it.
  • Review colocation and managed-hosting contracts to see which outage scenarios actually trigger SLA provisions and what those provisions pay, because S&P says only certain arrangements do.
  • Treat any route from corporate IT into facility OT as a high-value attack path, given S&P's citation that 58% of OT attacks in the SANS survey began with an IT compromise.
  • Include vendor remote-access tools, monitoring agents and APIs in patching and access reviews, since S&P names these third-party connections as routes into physical infrastructure.
  • Test disaster recovery for scenarios where a whole facility or a large part of one cloud provider is unavailable, including the case where Entra ID, Microsoft 365 and Azure workloads are all affected together.
  • Ask insurance and risk colleagues how a single event causing both cyber and physical damage would be handled across cyber, property and business interruption policies, because S&P flags gaps between those lines.

S&P's report makes data centre security a shared problem across tenants, operators, vendors and insurers. The companies behind S&P's capex estimates are forecast to spend about $870 billion in 2026 and more than $1.3 trillion in 2027, so the concentration S&P describes is likely to increase. Insurers are adjusting their cover now, and a rating agency is building these risks into credit analysis. Tenants who have not yet documented how their own contracts split responsibility for data centre facilities will be making those decisions with incomplete information.