Data Centre Physical Access Control: What It Is. Where It Usually Fails.
Data centre network defences usually focus on (or at least give a lot of attention to) firewalls, encryption and monitoring for cyber threats trying to steal data over a virtual network. The idea that no one can walk in and put their hands on a server is almost a given.
But not much attention is given to it in a lot of cases outside of a security desk and card access.
Physical access control might not get the same attention or mentions as cyber security systems, but it’s just as important and if anything needs extra thought because of the potential complexity. You need to know where it’s working and where it’s not.
What Data Centre Physical Access Control Covers
Physical access control is the measures that decide who can get into your facility (including which rooms once they’re through the main security barrier), verifying they are who they claim to be and having a clear recording of every entry and exit for every door.
Effective physical security measures work around four things:
- Credentials
- Permissions
- Zoning
- Logging
The misconception is often that physical security is a barrier to entry. We don’t think that’s completely true. Yes, fences, doors, turnstiles and locks are all barriers. But access control is the human element behind it and the experienced officers who decide when things open and keep access clear for the people who are allowed to be there.
You can run the same hardware as another data centre, but without the right SIA-licensed officers or the right data centre security provider behind it all, the risks are very different.
Four Zones Of A Secure Data Facility
Access control systems aren’t a single solution. It’s a layer of controls that sit inside one another, each adding a layer of security on top of the previous and each needing increasingly higher clearance to get past.
A cleaner who can get past a perimeter security fence shouldn’t then just be able to walk into a server room with the same ease.
Perimeter Boundary
The outer layer of your physical security measures controls who can get on your site at all. Security fencing, gates, CCTV cameras (ANPR and AI CCTV included) and perimeter sensors that can detect unusual activity. This is all part of it.
Behind it are the people who can judge activity, note suspicious activity – like a vehicle that keeps driving past the security fencing – and raise an alarm or escalate an incident to the emergency services when needed.
Building Entry
Getting into your facility should always start with asking does the person who’s showed up have a genuine reason for being there. Whether they work there, or are a contractor from a verified supplier who’s passed all the necessary vetting.
Multi factor authentication, biometric authentication, visitor management, staffed gatehouse points and, for higher risk facilities, mantraps or turnstiles at reception. Everything at this stage relies on the fact that you have one accepted credential per person.
Data Halls & Cages
Inside your facility we recommend you start thinking about role-based permission, which limit access to area to only authorised personnel.
This is the point where a contractor with legitimate access to a loading bay should be constricted to that area, and where guards should be looking out for anti-tailgaiting measures.
This is also where permission management comes down to managing credentials. We recommend timely reviews of any credentials being handed out so you know they should still work and they’re not being used by someone who should no longer be able to get into your data centre.
Cabinets & Server Racks
We highly recommend this is the area where you start to look at electronic locks and biometric readers to access individual enclosures. Entry and exit logs should be recorded by a security desk and ID verification needs to be managed by a person, ensuring the person trying to access is the person with the authority.
For every layer of security, we’d argue that the security and value in your access control comes from the people running the audits and managing entry, rather than just the hardware.
Credentials Your Access Control Systems Rely On
Access control credentials for data centres typically fit into one of the three buckets:
- Something you hold like a card, RFID fob or mobile credential
- Personal credential and biometric authentication (fingerprints and facial recognition)
- Something you know, like a PIN or passcode
Like wider data centre physical security, credentials run in layers and it’s recommended you use multi-factor authentication for more reliable security.
You should never be in a situation where someone is waved through to server rooms because they’ve tapped an RFID badge unchallenged.
Obviously, the rigour and requirements someone needs should be designed around the area they’re trying to get to.
A single credential to get through a car park barrier is fine. But the same credential shouldn’t then work at the entrance to a data hall.
On a quick side note. At ProFM Group, we deliver Paxton Gold, accredited access control systems alongside intruder alarms built to the same quality standard.
Across all your credential options, badges and fobs are usually the weak point. They’re easily lost – or stolen. People will often lend a card or fob to get into an area and then not give it back. And they can be cloned.
Biometrics can’t. So that’s why, as you get further into your data centre, the access requirements need to be matched more specifically to only authorised personnel.
Why Physical Security Needs The Same Focus As Cyber Security
Someone with direct access to hardware in a data centre can do just as much damage, arguably more, than someone breaking through a digital network. So doors are as much a network control issue as wires. And should be budgeted for the same level of security.
Someone standing in front of a rack can easily remove a drive and walk out. Or attach a device to a network segment that’s already past your firewall. They could even just pull the power and take your whole facility offline in a second.
None of it needs a credential from IT. Just someone who can engineer access to a room.
This isn’t to say physical security is more important than data security. By far the biggest threat to dats centres still comes from hacks. But cyber and physical security are ultimately protecting the same critical assets, the physical side us often just underinvested in.
ISO 27001, SOC 2, PCI DSS and the NIST frameworks all lay out the physical security requirements to protect data centres. We’ve already written about the physical security standards for data centres and the NPSA and NCSC recommendations.
Where Data Centre Access Control Often Fails
Access control systems tell you a door was opened and who was genuinely credentialed to open it. But it doesn’t always tell you who really walked into a room, what they did, or whether they ever left.
Security professionals usually work on the basis that their job is to:
- Deter
- Detect
- Delay
- Deny
- Defend
A physical access control system can deny someone entry and is pretty good at deterring efforts to enter your building without authorisation and delay any attempts to gain unauthorised access or cause damage if someone gets in.
Where it needs additional layers of security is the detection – which requires video surveillance and SIA licensed guards who know what to look for – and defending against attacks, which means structuring access control effectively in the beginning.
The Challenge of Granting Access And Verifying Presence
Authentication is step one of access control in data centres.
Is the person trying to get access the person who is allowed it? After that, you need security features that monitor what someone does once they’re inside your facility.
In our experience, this is the number flaw we see with physical security in data centres. Managers see credentials as the security measure and detailed access logs are treated as the final point of control. No-one is working on the assumption that something could go wrong.
Video surveillance is one answer provided you have the experienced security staff monitoring it. That’s why our CCTV monitoring runs through our manned National Operations Centre, with guards overseeing all feeds and raising alarms or responding to incidents by deploying a guard as required.
Tailgating And Anti-Passback
Tailgating happens when an unauthorised person follows an authorised person through a controlled opening. If you’ve ever been on the Tube in London we guarantee you’ve seen this happening with people trying to follow directly behind someone to avoid paying for entry at the barrier.
Only physical security can reliably stop this from happening.
Barriers and card readers work, but you need the security guards who’ll challenge someone who shouldn’t be on site.
Dealing With Contractors, Visitors And Mismanaged Permissions
Temporary access is the biggest hole in data centre security from a physical standpoint.
At any given time engineers, auditors or vendor technicians will have genuine reason to access your facility, but only ever for a short window of time. But you run into problems when badges are issued and permissions carry on working after jobs have been done.
Your visitor management should run like a concierge security operation. Visitor management should need pre-registration, photo ID capture, permissions that are time-limited, physical escorts around the facility and an officialy signed out exit.
Once someone has left the site, cards or access fobs should be disabled.
This is where you need a professional security company running your physical security systems, especially if you’re managing multiple visitors and contractors at once or dealing with colocation data centres.
We review permission lists are part of every data centre contract so we start each deployment knowing exactly who has permission to be on your site.
What Happens When Physical Security At Your Data Centre Fails?
Downtime is the biggest problem with a physical security breach. A physical incident means you have to take hardware out of action in a way a remote attack usually wouldn’t need.
One IBM research report found 70% of data centres that were breached physically experienced significant or very significant business disruption in the immediate aftermath while access control systems were reconfigured or improved.
Theft and tampering are where much of the longer time damage come from. If someone removes hardware from your location, you’ll see a problem pretty quickly. Your bigger risk comes from someone who inteferes with hardware, and your security never caught it.
In theory, this tampering could go unnoticed for months – even years – and you’d never know it. In IBM’s research, it claimed the average time to find and contain a breach involving compromised credentials was 292 days. And that’s not even getting into your audit exposure. If your access records can’t say who was in a data hall at a given time on a given day because a credential was compromised and you had no CCTV in place, your audit will fail and you run the risk of losing contracts if it’s shown you don’t have the required security features in place.
Insurance premiums can become a problem for a similar reason. Policies are offered on the assumption you have steps in place to prevent unauthorised access or security breaches, but also you have steps in place to clearly see what happened and who was responsible in the event something does happen.
If you don’t have the right data centre security management in place, you can expect to pay more for insurance or risk becoming uninsurable.
Physical Access Control For Data Centres With ProFM Group
Access control systems are a combination of hardware that helps decide who gets entry, and people who make sure systems are working and can react quickly to anything that comes next.
We’d recommend running your manned, monitored and electronic security through a single provider.
This is where ProFM Group excel. We’ve worked with three major data companies, including TATA Communications, protecting around 34,000 square metres of active server space and completing 550 hours of manned data centre security a week.
Our security guards are SIA-licensed, BS 7858 vetted and DBS checked as a minimum alongside right-to-work checks. CCTV packages are accredited to NSI Gold standards with Paxton Gold accreditations for access control systems and intrusion detection systems.
Everything is monitored 24/7 from our manned National Operations Centre, which coordinates and oversees every deployment.