Skip to main content
Logo print

Cybersecurity Starts at the Rack: Defending Data Centers | Legrand United Kingdom

Cybersecurity Starts at the Rack: Defending Data Centers

Blog 25/04/2025

Cybersecurity threats have evolved significantly since the first computer virus, Creeper, spread across a handful of machines in the 1970s. What started as an experimental self-replicating program has since evolved into a global threat landscape capable of crippling infrastructure, disrupting essential services, and costing businesses millions in downtime and data loss.

Today, the stakes are exponentially higher. Data centers serve not just as passive infrastructure but as the digital nerve centers of healthcare, finance, communications, and national security. As attacks grow more targeted and sophisticated, so must our defenses.

From Perimeter to Precision: The New Era of Attacks

In the early 2000s, threats like the Blaster Worm exploited basic network vulnerabilities, often spreading through open ports or unpatched systems. By 2010, Stuxnet changed the game as a highly sophisticated cyberweapon designed to sabotage physical infrastructure, even in isolated "air-gapped" environments. It was the first virus confirmed to cause physical destruction of a device; it managed to blow up centrifuges by forcing a continuous malfunction.

And it didn't stop there. One of the most alarming examples was the 2015 cyberattack on Ukraine’s power grid, which temporarily disrupted electricity for approximately 225,000 customers. According to the Cybersecurity and Infrastructure Security Agency (CISA), attackers used spear-phishing emails containing malicious Microsoft Office documents to deploy BlackEnergy3 malware. Once inside, they remotely operated circuit breakers via SCADA systems, leading to coordinated outages across multiple regions.

Modern attackers don't just aim to infiltrate systems; they seek to manipulate, disable, and control critical infrastructure, much of which lives inside our data centers.

cyber war

 

Cybersecurity = Uptime: The Real Cost of a Breach

It's no longer just about stolen data. A cyberattack that compromises a single device—such as an uninterruptible power supply (UPS) or power distribution unit (PDU)—can cascade into full-scale operational disruption.

And the cost? According to the Uptime Institute, over 50% of downtime incidents now exceed $100,000, with 16% costing over $1 million. Meanwhile, IBM’s latest report puts the average cost of a data center breach at $4.88 million in 2024.

In fact, according to Cybersecurity Ventures, the total global cost of data breaches in 2025 is expected to reach $10.5 trillion, a 15% annual increase.

Downtime isn't just inconvenient; it's catastrophic—and increasingly caused by targeted attacks on infrastructure devices that were never traditionally considered vulnerable.

cyber attacks

 

Welcome to the IoT-Connected Data Center: New Risks, New Rules

As more data center devices—from PDUs to smart locks—connect to the network, the risk landscape expands dramatically. A once-simple device like a Rack PDU is now an intelligent, connected component with an OS, firmware stack, and remote management capabilities.

As a result, any connected device could become a potential attack vector. Yet, many legacy PDUs and infrastructure components still lack basic cybersecurity protections.

This is where Legrand comes in.

Built for Defense: How Legrand is Securing the Future of Rack-Level Infrastructure

Recognizing the need for zero-trust security at the rack level, Legrand has embedded advanced cybersecurity features across its intelligent infrastructure portfolio—especially in Rack PDUs powered by the Xerus™ firmware platform.

Why Xerus™ Stands Out: Security by Design

  • Secure Boot: Ensures only verified firmware runs on your PDU, preventing tampering or malicious code execution.
  • Vulnerability Testing (VAPT): Our firmware undergoes rigorous internal and third-party testing.
  • Secure Element: Protects your network connection from Man-in-the-Middle attacks.
  • Encrypted Communications: Devices use AES 128b/256b encryption, firewall support, and strong password policies.
  • SB 327 & NISTIR 8259 Compliance: Meets or exceeds leading security regulations for IoT devices.
  • Stringent Internal Standards: All products align with LNCA’s security policies for IoT devices.
  • Frequent Firmware Updates: Typically two major and six minor updates annually, with urgent patches promptly delivered.
  • Customizable Alerts: SmartLock™ and webcam triggers provide real-time visual alerts for unauthorized access events.

Xerus™ runs on over 5,000 Legrand products and is developed by a dedicated team with over 150 man-years of cybersecurity expertise.

Legrand Xerux Platform - VAPT Testing

 

A Culture of Security-First Design

Legrand isn't just building PDUs—it’s designing and building trusted infrastructure informed by evolving threats and shaped by the realities of operating in a hyperconnected world.

With ISO/IEC 27001:2013-certified R&D Centers, a global cybersecurity team, and third-party validation from partners like Pivot Point Security, Legrand is setting a new standard for infrastructure protection within the data center.

Looking Ahead: Resilience Starts at the Rack

Cybersecurity must extend beyond the network perimeter; it needs to exist within the data center—within the firmware, the hardware, and every connected component.

Legrand’s intelligent rack PDUs, like the Raritan PX4 and Server Technology PRO4X, are not merely power distribution units but secure, software-driven devices designed to detect, protect, and adapt to today’s evolving threats.

As cyberattacks become more advanced and interconnected systems more vulnerable, the future of cybersecurity must start at the foundation—with trusted, tested, and intelligent infrastructure.


Want to secure your data center infrastructure?

Contact our team here to learn how Legrand's intelligent PDUs and firmware solutions can strengthen your data center from the inside out.