The rapid expansion of artificial intelligence infrastructure is increasing cyber risks across data centres, with the growing integration of information technology (IT) and operational technology (OT) systems creating additional vulnerabilities, S&P Global Ratings has warned.
S&P raised the concern in a new report titled Data Center Cyber Risk Is Increasing And Underrecognised, sighted by Reinsurance News, which examined how the growing importance of data centres to cloud computing, AI and other digital services could amplify the consequences of cyber incidents.
According to the ratings agency, data centres have become critical infrastructure for financial services, technology companies, healthcare providers, telecommunications operators and government institutions. As more workloads are concentrated in larger facilities and among fewer providers, a successful cyberattack could affect multiple customers and sectors at the same time.
Cristina Polizu, an S&P analyst, said a cyberattack targeting a data centre, its operator or a supplier could affect several tenants simultaneously, creating wider financial and operational consequences.
S&P noted that mitigating these risks can fall outside the immediate cybersecurity operations of individual tenants, while the technologies and controls needed to protect increasingly connected data-centre environments continue to evolve.
The agency said the expansion of AI is accelerating demand for computing capacity and driving major investments in data-centre infrastructure. It estimates that the combined capital expenditure of Amazon, Microsoft, Alphabet, Oracle, Meta and SpaceX will exceed $1.3 trillion in 2027, compared with about $870 billion in 2026 and $470 billion in 2025.
Much of the investment is expected to support the expansion of computing infrastructure needed for AI and other digital services.
S&P said the cyber exposure is increasing as modern data centres become more dependent on connected systems that control physical operations, including cooling, electricity distribution, backup power, fire suppression and environmental monitoring.
Systems that were previously isolated are increasingly being managed remotely and connected to broader IT networks, creating additional pathways through which attackers could potentially gain access to critical infrastructure.
The report cited a 2025 survey by the SANS Institute, which found that 58 percent of attacks against operational technology used an IT compromise as an entry point. S&P also referenced data from Cyble Research & Intelligence Labs showing that more than 2,400 industrial control system vulnerabilities were disclosed by 152 industrial technology vendors during 2025.
The exposure extends beyond the data-centre operators themselves to the wider supply chain, according to S&P.
Data-centre operators depend on third-party providers for equipment, maintenance and remote monitoring, with suppliers potentially introducing software, firmware, application programming interfaces and remote-access systems into the infrastructure.
S&P said weaknesses in these systems, including poor security controls and unpatched software, could provide attackers with additional routes into data-centre environments.
The level of responsibility for managing cyber risks also varies according to how a data centre is operated. In managed hosting arrangements, operators generally control the facility and hosted equipment, while customers using colocation facilities typically retain responsibility for their own servers, storage and networking systems.
In powered-shell arrangements, tenants generally assume greater responsibility for operating the infrastructure, while enterprise data centres are owned and operated by the organisations using them.
S&P said these differences can affect the consequences of a cyber incident, particularly where an outage disrupts tenant operations or triggers contractual obligations such as service-level agreements.
The agency identified compromised credentials, social engineering and weaknesses in access controls among the key threats to tenant IT environments. For data-centre OT systems, it highlighted exposed or poorly secured networks and insider activity, including the accidental or deliberate misuse of authorised access.
The concentration of data-centre infrastructure is another concern. S&P said larger facilities are increasingly housing critical workloads, while operators with relatively few major sites may have limited diversification if one facility experiences an outage or cyber incident.
It also pointed to the concentration of cloud services among Amazon Web Services, Microsoft Azure and Google Cloud, noting that an incident affecting a significant portion of one provider’s operations could have consequences for numerous customers.
The risks are particularly relevant to sectors that increasingly depend on cloud infrastructure. S&P noted that financial institutions use cloud and shared technology infrastructure to support services including payments, trading and online banking, while public-sector organisations depend on data centres for emergency communications, smart infrastructure, electricity-grid management and the storage of administrative and judicial records.
Nigeria’s growing digital infrastructure
The concerns are also relevant to Nigeria as the country expands its data-centre and cloud infrastructure to support a growing digital economy.
Nigeria’s Federal Government unveiled a National Digital Cloud Policy earlier in the year, with a framework aimed at encouraging investment in cloud computing and data-centre infrastructure, expanding local hosting capacity and strengthening safeguards around government and regulated data. The government said the policy is intended to position Nigeria as a regional digital services and hosting hub.
Industry estimates put the number of data-centre facilities in Nigeria at about 26, including commercial facilities serving banks, fintechs, cloud providers and other businesses. The country’s expanding digital financial services, telecommunications and enterprise technology markets are also increasing demand for computing, storage and cloud infrastructure.
For Nigerian businesses, the expansion means that more critical digital workloads are increasingly dependent on the resilience and security of the infrastructure supporting them. This makes issues such as network segmentation, multi-factor authentication, software patching, access controls, continuous monitoring and disaster recovery increasingly important as data-centre capacity expands.
S&P recommended measures including network segmentation, multi-factor authentication, software patching, zero-trust security, monitoring systems, disaster recovery planning and staff training to strengthen resilience.
It also stressed the importance of governance frameworks that cover both IT and OT systems, as the distinction between digital systems and the physical infrastructure supporting them becomes less clear.
The ratings agency said the growing dependence on data centres means cyber resilience is increasingly a business continuity and operational issue rather than a concern limited to cybersecurity teams.
As AI adoption drives further investment in computing infrastructure, S&P warned that larger, more connected and increasingly concentrated data-centre environments could make the consequences of a cyber incident extend beyond a single operator to multiple businesses and infrastructure providers.







