Technology

The $100 Billion Target: How Unsecured IT is Jeopardizing Texas’s AI Data Center Boom

By Charles Swihart, Founder and CEO of Preactive IT Solutions 

The construction industry is under siege. In August 2025, a wave of major cyber attacks—including devastating ransomware incidents—rocked operations, underscoring the field’s critical vulnerability.

This follows reports of a staggering 800% increase in data breaches targeting construction firms over recent years. 

These incidents are a massive threat right when Texas is experiencing an unprecedented boom in AI data center construction.

Just this month (November 14, 2025), Google announced a $40 billion investment in three new data centers in West Texas and the Panhandle, aimed at expanding AI infrastructure.

Hyperscalers like Microsoft, Amazon, and Oracle are pouring billions into the state to capitalize on energy resources, business policies, and strategic location. 

As the founder of Preactive IT Solutions, an MIT Services provider supporting construction and engineering firms in Texas for over two decades, I’ve seen firsthand how these massive projects amplify cyber risks.

Data centers are not just buildings; they are hubs of sensitive intellectual property (IP), real-time operational data, and interconnected systems. A compromise can lead to multimillion-dollar delays, regulatory fines, and permanent reputational damage. 

This article dives into the specific cyber threats facing AI data center builds, drawing from recent incidents and industry data to provide actionable, proactive strategies for mitigation. 

1. The Texas AI Boom: Scale, Speed, and Risk

Texas has become a global leader in AI data center development, thanks to low energy costs, vast renewable resources, and enticing tax abatements. By 2025, data center capacity projections have soared, with investments topping $100 billion in ongoing and planned projects. 

Why Data Center Construction is a High-Value Target:

  • Hyperscale Complexity: Projects span millions of square feet and require intricate integration of high-voltage electrical, mechanical, and digital systems.
  • Aggressive Timelines: Construction often runs on aggressive 12-24 month schedules, forcing rapid integration of IT systems.
  • AI-Fuelled Demand: Global demand for AI processing is driving a 50% projected increase in U.S. data center power consumption by 2030, putting immense pressure on Texas’s grid and construction teams.
  • Digital Reliance: The build relies heavily on digital tools like Building Information Modeling (BIM) software, IoT sensors for site monitoring, and cloud platforms (Procore, Autodesk Revit). These systems house blueprints, material specs, and compliance data—all prime targets.

A single cyber incident can halt progress. Supply chain disruptions from attacks on vendors can delay critical components and inflate costs by 10-20%

2. Unpacking Cyber Risks: Supply Chains, Field Data, & OT

AI data center construction faces unique risks due to its hybrid nature, blending physical builds with vast digital ecosystems. This creates multiple, easily exploitable entry points for attackers. 

Key Attack Vectors Targeting AI Data Center Builds:

Supply Chain Vulnerabilities:

  • Construction relies on a complex web of suppliers for materials and technology.
  • Attacks exploiting unpatched software in vendor systems can cascade.
  • The Threat: Compromised firmware in cooling units or networking gear, potentially leading to operational sabotage.
  • Data Point: In 2025, 73% of reported operational technology (OT) attacks targeted industrial control systems, up from 49% the prior year.

Field-to-Office Connectivity Gaps:

  • Unsecured Wi-Fi or Virtual Private Networks (VPNs) used by site personnel, mobile devices, and IoT sensors can be easily intercepted.
  • The Threat: Leaking proprietary AI layouts and blueprints, enabling IP theft by competitors or nation-state actors.
  • Data Point: Phishing remains a top threat; over one-third of construction firms reported increased phishing in 2025.

Human Factors and IoT Insecurity:

  • On-site teams, often subcontractors, may lack specialized cybersecurity training.
  • The Threat: Social engineering and common IoT devices (cameras, trackers) with default passwords acting as backdoors into the core network. A breach can allow lateral movement to access core AI systems.

Critical Infrastructure Threats:

  • AI-driven centers consume up to 100 MW of power. Attacks on connected energy systems could trigger blackouts or safety hazards, escalating cyber risk to physical risk.
  • Financial Impact: Data breaches in this sector lead to financial losses averaging $4.5 million per incident, before legal and compliance fines (e.g., Texas’s data privacy laws).

3. Implementing Proactive IT Strategies: The Prevention Focus

To counter these sophisticated risks, construction firms must integrate security into the project from the planning phase—a shift from reactive fixes to resilient system building. 

Actionable IT Measures for Protection:

1. Comprehensive Risk Assessments:

  • Conduct regular vulnerability scans (Nessus, OpenVAS) to identify weaknesses in networks and devices.
  • Map all endpoints—from BIM servers to site IoT—and prioritize based on impact.
  • Preactive IT recommends quarterly audits focusing on supply chain due diligence (e.g., vetting vendors for SOC 2 compliance).

2. Zero-Trust and Segmentation:

  • Implement end-to-end encryption (TLS 1.3) for data transfers.
  • Segment networks to isolate site operations from corporate systems and critical OT environments.
  • Enforce Zero-Trust architectures, where access is continuously verified, not assumed.

3. Mandatory Training and Hygiene:

  • Tailor cybersecurity training (e.g., KnowBe4) to construction scenarios, simulating phishing emails that mimic supplier invoices.
  • Incorporate just-in-time training for on-site teams covering IoT setup and password hygiene.
  • Note: The human element accounts for 74% of breaches.

4. AI-Assisted Monitoring and Response:

  • Leverage AI-assisted monitoring tools (CrowdStrike, Splunk) for real-time analysis of logs and anomaly detection.
  • Automate patch management—critical for avoiding exploits in software like AutoCAD and Revit.

5. Robust Disaster Recovery & Continuity:

  • Develop and regularly test incident response plans with clear roles.
  • Use immutable storage for critical project files to prevent ransomware alterations.
  • Utilize hybrid cloud backups to ensure continuity, especially in areas prone to natural disasters.

Conclusion: Securing the Foundation of AI Infrastructure

The Texas AI data center boom offers immense opportunity, but it also creates the highest-value targets the construction sector has ever faced. Without addressing the cyber risks embedded in these complex, time-sensitive projects, firms are inviting catastrophe. 

By understanding the threats—from supply chain compromise to IoT backdoors—and deploying these proactive strategies, construction leaders can successfully protect their multi-billion dollar investments. 

This challenge often exceeds the capacity of in-house IT.

Specialized providers like Preactive IT Solutions, with a track record since 2003, deliver the enterprise-level support that SMBs in construction need to secure these high-stakes data center projects through 24/7 helpdesk, AI-driven threat monitoring, and customized cybersecurity protocols. 

About the Author

Charles Swihart is the Founder and CEO of Preactive IT Solutions, a Managed IT Services provider that has supported construction, engineering, and architectural firms in Texas for over two decades.

He is a recognized expert in small business cybersecurity, and the author of the Amazon best-seller, “On Thin Ice: A Practical Guide to Cybersecurity for Small Businesses.” 

Sweta Bose

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago