What Are The Physical Security Standards For Data Centres?


With the value of data now exceeding gold and oil, protecting personal information has never been more crucial. And while cloud computing and network safety are integral, there’s no denying the importance of physical security for data centres, especially as new facilities (like Google’s Waltham Forest premises) open across the UK.

 

Why Is Physical Security Important For Data Centres?

 

Data centres have the same safety concerns as many other properties, including trespassing, criminal damage, theft, and deliberate arson attacks. That’s emphasised by the large quantity of highly valuable (and lucrative, in the eyes of a thief or cybercriminal) data that’s stored, processed and transmitted across the site.

In essence, a data centre functions similar to a bonded warehouse, but the “items” stored aren’t physical assets – they’re multiple millions of points of data tied to users across the UK and worldwide. Imagining it like that helps us see what the threats are.

It’s also important to recognise that a data centre isn’t just a single facility that houses servers. The infrastructure that surrounds data centres is vast and often complex in the tech it uses, meaning there’s opportunity for criminals to target what could be upwards of a million pounds in equipment.

That includes areas like:

  • The data halls themselves, which house servers, transmission equipment and other tech
  • Meet Me Rooms (MMRs)
  • Power rooms
  • Mechanical or engineering rooms, including any BMS infrastructure
  • Fire suppression systems, including sprinklers and foam-based systems

All these present targets for thieves and trespassers, and disruptions to any of those facilities can be incredibly costly and disruptive, especially for larger-scale, enterprise facilities or colocation premises where multiple businesses could be affected by any prolonged outages.

We’d also point towards the very real threat of terror acts involving data.

With Large Language Models (LLMs) like ChatGPT estimated to process over 2.5 billion prompts per day, and Google handling over 13 billion searches daily, it’s a matter of time before terror cells and threat actors use data networks and physical data facilities as part of their intentions.

Getting ahead of the curve with physical data centre security is essential, and as we’ll discuss, guidance from the UK government is already well-established.

 

What Is The Law Around Data Centre Security Measures?

 

While there are no specific laws or legislation governing physical data centre security just yet, we (and many other security service providers) follow the official guidance laid out by the National Protective Security Authority (NPSA), in conjunction with the National Cyber Security Centre (NCSC).

As part of their Data centre security guidance, they stress the importance of “individual risk management strategies”, and how a “layered security model” is the methodology that should be followed to keep the centre secure and free of interruption. Under their guidance, that’s broken down into seven key areas:

  • Geography and site ownership security
  • Physical perimeters and buildings (the focus of our security measures)
  • The data hall
  • Meet-me room
  • People security considerations
  • Supply chain considerations
  • Cyber security

What’s important to note here is the inclusion of cyber security.

There are laws that govern the integrity and robustness of cyber security (such as the UK GDPR law, the Data Protection Act 2018, and the Network and Information Systems (NIS) Regulations 2018), but these do not directly apply to physical security at data centres.

Instead, the takeaway from the NPSA’s is that a layered approach to physical security for data centres is crucial in building a tailored security solution.

 

A Layered Model: The Key Stages Of Physical Data Centre Security

 

Under that recommended layered approach, you need to plan to secure multiple aspects of your premises, including the perimeter, internal walls, tiered access controls, and your more sensitive data processing and storage areas.

Here are four areas we’ve identified as key priorities in accordance with NPSA’s guidance on data centre security, and how we’d advise securing those to ensure maximum compliance.

 

Your Site’s Perimeter

Your first line of defence and your visitors’ first point of contact with your facility.

It stands to reason you’d need to invest in physical security measures for your data centre’s perimeter. There are multiple reasons why.

Chief among these is it’s thought that over 80% of all crime – even serious crime – is done because there’s opportunity to do so. It’s not premeditated in most circumstances. So having a strong, reinforced site perimeter ensures any opportunistic criminals aren’t given an unnecessary opening.

A sufficiently strengthened perimeter also means another hurdle for those who are more determined. Vehicle-based attacks are a concerningly big trend, with brazen criminals using cars and even JCBs to steal cashpoints and conduct “ram raids”.

Crash-proof barriers – ideally certified to PAS 68, which checks barriers against a medium-sized truck – are often recommended here, alongside high-rise steel fencing and meshing, to ensure that large-scale data centres (especially enterprise or collocational facilities) are kept secure.

Smaller data centres often find that fencing is sufficient, but we would still advise taking a tailored approach to ensure that all areas of your facility’s perimeter are covered.

That’s just the more tangible, visible aspects of perimeter security for data centres.

Tech plays a crucial role – especially in filtering out false alarms – and a perimeter detection system can be an ideal accompaniment to those more “concrete” measures. At ProFM Group, that niche is filled by our cutting-edge ProEyez system.

This equipment creates a digital “forcefield” around your site, using wireless infrared detection and integrated AI enhancements to detect and analyse movement, instantly determine its threat level, and automatically trigger an alarm when a human is detected.

It works using wireless connections between strategically placed cameras, effectively creating that invisible perimeter line.

 

Building Exterior & Entrances

While your perimeter is often the first point of passage for visitors to your premises, the real challenges for physical security at data centres often come at the actual outer walls of your building.

This is where many focus their efforts in the initial instance, and for good reason. It’s the face of your business, and arguably of the AI revolution that’s shaping Britain’s business landscape.

It’s also, unfortunately, the area most at risk from some of the UK’s more common criminal issues, like vandalism, arson or graffiti. It’s equally true that AI can be divisive in its applications, and protests (especially given the sector’s well-publicised energy and water consumption statistics) could become a major thorn in the side of data centres and companies.

It’s from there that the need for external data centre security arises, and what we’d always advise here is that this should be where your layering of security measures begins. That starts with proper, segmented access controls, especially if there are staff entrances that lead to maintenance or servicing areas.

For an enterprise facility that accepts authorised visitors, it may be that there’s a main entrance that relies on a more manual response (i.e., from security personnel on a reception desk) that can check credentials before admitting guests. This adds to that “layered” approach, and further segments security into a package that prioritises protection where it’s needed most.

The outside of your building should also be the first area where you invest in your CCTV solutions. Here, modern AI detection solutions – likely already familiar, given the importance of data centres in the wider implementation of artificial intelligence – play a crucial role, recognising faces and behaviours to issue immediate alerts where they’re needed.

A strategically positioned camera can also help identify and admit authorised visitors and service personnel, meaning there’s a more streamlined process for access, and a relief of any bottlenecks that might’ve been caused by delayed access.

 

Entrance Desk & Facility Monitoring

While the temptation is to refer to a security hub as an entrance or reception area, it’s significantly more than that. Although you can reasonably expect your personnel to conduct concierge duties (like accepting telephone calls or taking authorised deliveries), they’re ultimately there to function as a comprehensive security solution.

Security officers should form a nucleus for your site’s security solutions, and from there control multiple key functions across the full remit of your data centre’s physical security, including:

  • Monitoring all on-site CCTV cameras through integrated screens
  • Accepting visitors and performing any necessary checks or searches
  • Conducting patrols of accessible areas
  • Controlling and issuing access based on clearance levels and necessary coverage
  • Responding to any alarm activations or emergency scenarios

While your officers will predominantly be based at those desks and function as the “face” of your data centre outside of any employees or staff, it’s important to remember that they are trained protective professionals and will have completed extensive licensing and training to be able to deliver that service.

Officers stationed at a central desk or as part of a Security Control Room can also make incisive decisions on the measures you have in place, recommending upgrades for the future.

That could be something simple, like covering blind spots not covered by CCTV cameras, or insights on where there needs to be increased access controls (such as an upgraded data hall or new Meet Me room).

 

Data Halls & Sensitive Areas

This is where security is at its most crucial, and where it pays dividends to invest substantially in a layered system of access controls and intruder alarm systems, all of which centrally connect to the manned presence we discussed in our previous section. In fact, that’s not just our recommendation. It’s a key feature of the NPSA’s guidance on data centre security.

Under their recommendations for Automatic Access Control Systems, BAACS (or Biometric Automatic Access Control Systems) are an integral part of keeping sensitive spaces and data processing hubs (server rooms, Meet Me rooms, etc.) separately authenticated from other places at your data centre.

The NPSA say it best themselves, viewing biometrics as “more secure” than a PIN or other form of access control, as it’s “harder (though not impossible) to lose biometric information”. This offers a robust and adaptable option for controlling access across the premises, and one that can be easily scaled to suit differing demands and changing permissions or job roles.

Access controls can also be assigned to a range of systems.

Biometrics can suit those that are most mission-critical, but PIN code access or ID badges could be an alternative for access to areas that need more “fluid” control, like necessary maintenance or repairs in staff facilities.

 

Robust Physical Security For Data Centres From ProFM Group

 

Perhaps the key takeaway from the guidance and documentation around physical security for data centres is that everything you implement – whether that’s tech-focused or manned solutions – should be interlinked.

It’s possible to get these from multiple suppliers, of course, but it’s far more beneficial to partner with a provider that’s able to keep those solutions under one roof and one standard of expert service.

That’s where ProFM Group excel.

Our track record is one thing – we’ve been the partner of choice for multiple major data facilities across the UK, including TATA Communications’ major Stratford facility and the NTT Data Centre at Hemel Hempstead, and proven time and again that we’re up-to-date and compliant with the latest recommendations from the NPSA and NCSC.

We’ve coupled that with stellar, industry-leading service. Our officers are fully SIA-licensed, vetted and checked in line with the rigorous BS7858 standards, and, where needed, have passed the notoriously strict SC clearance (often reserved for governmental or critical infrastructure sites).

That translates to equally groundbreaking tech, too.

We’re NSI Gold accredited and Paxton Gold-certified, two of the highest possible standards for CCTV, access controls and intruder alarms respectively. It’s proof of not just our commitment to the very best for physical security at data centres, but to pushing the envelope of what you can expect from your security provider.

And it all starts with a conversation with our experts. Get in touch with our in-house team on 0808 196 7709, or drop us an email at [email protected], and we’d be more than happy to discuss our solutions for tailored, layered protection.

Emily Macaulay, Director of Sales

Emily

Shared Services Director

Emily’s extensive expertise in the field spans over 10 years, and positions her as a thought leader and pioneer for our sector. She discusses key security advice, crucial steps for securing the future, and how our industry is evolving at a breakneck pace.

MORE POSTS FROM EMILY