Designing Data Center Security: Why the Industry Needs a Common Starting Point

The data center industry is experiencing one of the fastest infrastructure expansions in its history. Artificial intelligence, cloud computing, sovereign data requirements, edge computing, and the continued digitization of nearly every sector of the economy are driving enormous investment in new facilities. At the same time, the security environment surrounding those facilities is becoming more complicated. Data centers are no longer simply buildings containing servers. They are cyber-physical infrastructure dependent upon power, telecommunications, water, cooling, operational technology, people, suppliers, and increasingly complex regional infrastructure. That makes the timing particularly good for the Security Industry Association’s work on a new book focused specifically on designing data center security.

Security Industry Association has long occupied an important position between security manufacturers, integrators, practitioners, consultants, and the broader technology community. A book devoted to data center security design has the opportunity to bring many of those perspectives together around a fundamental question: What should good security design actually look like for a modern data center? That sounds straightforward, but anyone who has worked on these projects knows there is no single answer. A hyperscale campus, colocation facility, enterprise data center, edge location, AI factory, and government facility may share basic security principles while presenting very different threat profiles, operational requirements, regulatory environments, and consequences of failure.

That is why I believe the value of this project extends beyond cameras, access control, intrusion detection, or perimeter systems. Those technologies are obviously important, but designing data center security begins much earlier. It starts with understanding the mission of the facility, identifying critical assets and dependencies, evaluating threats, and determining how the site itself can support or undermine security. Site selection, adjacent land use, topography, standoff, vehicle approaches, utility routing, fiber pathways, loading areas, roof access, substations, generator yards, fuel systems, water infrastructure, and the location of critical equipment all influence the eventual security posture. By the time a security integrator arrives to install equipment, many of the most important security decisions have already been made.

This is also where the Architecture, Consulting, and Engineering community becomes essential. Architects, security consultants, civil engineers, electrical engineers, mechanical engineers, network designers, commissioning professionals, and owners collectively shape the environment that the security system must eventually protect. Major mission-critical design organizations such as Jacobs, HDR, Burns & McDonnell, AECOM, Corgan and many specialized data center consultants are helping design an unprecedented generation of digital infrastructure. Security professionals need to be working alongside these disciplines while the facility is still lines on a drawing, not trying to correct vulnerabilities after concrete, conduit, utilities, and buildings are already in place.

This becomes even more important as AI changes the physical characteristics of the data center. Power densities are increasing, liquid cooling is becoming more prominent, electrical infrastructure is expanding, and operators are considering microgrids, battery energy storage, fuel cells, onsite generation, and other behind-the-meter solutions. The traditional data center campus is gradually becoming something closer to a combination of computing facility, utility plant, telecommunications hub, and industrial operation. Every additional system creates another dependency, and every dependency creates something that must be understood from a risk and security perspective.

This is the same systems-based approach I explore in my own book, Data Center Security: The Blueprint for Resilient Infrastructure. One of the central ideas behind that work is that security cannot be separated from resilience. A sophisticated access control system provides little comfort if a vulnerable substation can remove power from the entire campus. Multiple fiber carriers provide limited resilience if their cables eventually converge into the same physical pathway. Two supposedly independent systems are not truly redundant if they share a common controller, utility source, fuel supply, network connection, or physical location. The security professional therefore needs to follow the mission dependencies beyond the traditional perimeter, a concept I describe as looking at security from grid to rack.

A SIA design-focused book can complement that conversation by helping establish practical guidance for translating risk into architecture. What should the layers of a data center security program look like? How should perimeter protection relate to the site’s threat assessment? Where should vehicle screening occur? How should pedestrian and contractor flows be separated? What deserves two-factor physical authentication? How should loading docks, shipping and receiving, maintenance areas, mechanical spaces, electrical rooms, meet-me rooms, network spaces, and data halls be segmented? Where should video analytics supplement physical barriers? How should access events correlate with video? How should visitor management connect with identity governance? These are design questions rather than simply product questions.

Operational technology deserves particular attention. Modern facilities depend on building management systems, electrical power monitoring systems, UPS controls, generators, cooling systems, pumps, environmental monitoring, battery management, and industrial controllers. The distinction between cybersecurity and physical security becomes increasingly artificial when a cyber compromise can manipulate a physical process or physical access can provide an adversary with access to an OT controller. CISA continues to emphasize the cyber-physical consequences associated with industrial control system compromise, reinforcing why OT needs to be incorporated into critical infrastructure protection rather than treated solely as a facilities responsibility.

People remain another critical part of the design. Data centers depend upon employees, contractors, construction workers, service providers, manufacturers, integrators, delivery personnel, utility representatives, and temporary labor. During construction, thousands of individuals may cycle through a hyperscale campus before it ever becomes operational. Security design therefore has to address identity lifecycle management, credentialing, contractor access, escort requirements, background screening, temporary access, privileged areas, anti-passback, access anomalies, and credential revocation. The insider threat is not solved by putting another reader on a door; it requires governance connecting identity, behavior, access, video, policy, and operational awareness.

Commissioning should also be part of the security conversation. We routinely commission electrical, mechanical, fire-life-safety, and other critical building systems, yet electronic security is still too often treated as a collection of devices that need to demonstrate basic functionality. A camera displaying an image does not prove that the security architecture works. A card reader unlocking a door does not prove that identity workflows, alarms, video associations, emergency procedures, network dependencies, and failover conditions operate correctly. Data center security needs integrated testing that asks what happens when systems fail together and whether operators can recognize, respond to, and recover from those failures.

There is another reason the SIA project is timely. Security manufacturers themselves need a stronger understanding of how the ACE community works. A manufacturer cannot effectively participate in data center design simply by presenting a product catalog. Architects and consultants need specifications, drawings, BIM/Revit content, cybersecurity documentation, integration information, network architecture, power requirements, environmental limitations, lifecycle information, and credible technical support. They also need manufacturers that understand the consultant’s role and can discuss risk and design intent without turning every interaction into a sales pitch. That relationship between manufacturers and the ACE community is something I explored extensively in The ACE Alliance: Navigating the Art of Selling to Architects, Consultants, and Engineers, and it becomes even more important in highly technical mission-critical projects.

The best outcome for a publication like this would not be to prescribe one security architecture for every data center. The industry is far too diverse for that. Its greater value would be establishing a framework that helps designers ask the right questions at the right point in the project. A security professional should be able to look at a concept drawing and begin identifying risk. An architect should understand why security is requesting certain site conditions. An electrical engineer should recognize when the placement of critical infrastructure creates a protection problem. A manufacturer should understand how its technology fits into the larger design. An owner should be able to understand what risk is being accepted when a security requirement disappears during value engineering.

Ultimately, designing data center security is about protecting the mission rather than protecting individual devices or even individual buildings. The modern data center exists within a much larger ecosystem of electricity, communications, cooling, water, transportation, people, suppliers, software, and communities. A disruption anywhere in that ecosystem can eventually affect availability inside the white space. That means our security architecture has to follow those dependencies wherever they lead.

The SIA book on designing data center security provides an opportunity to bring together practitioners, architects, consultants, engineers, manufacturers, integrators, operators, and other subject-matter experts around that broader view of the problem. If we do it correctly, the conversation will not begin with “Which security technology should we specify?” It will begin with “What are we protecting, what does it depend upon, how can it fail, and how do we design resilience into the facility before it is built?”
That is the conversation the data center security community needs to be having now.

Author

  • Christopher Hills is a career security professional specializing at the intersection of physical security, cybersecurity, and critical infrastructure. With decades of experience spanning hyperscale data centers, global security operations centers, and complex infrastructure projects, he has served as a security consultant, technology executive, and trusted advisor to architects, engineers, consultants, and enterprise organizations worldwide. He is the author of Data Center Security: The Blueprint for Resilient Infrastructure, a comprehensive guide to securing modern data center environments. See what Security Leaders are saying about my latest book >>