What Security Measures Does A Data Centre Need?
Data centres now sit alongside energy and water as critical national infrastructure, so the security expectations have increased as well. Working out which data centre security measures your facility needs means taking a layered approach that considers both manned guarding and the latest security technology.
A Layered Approach To Data Centre Security Measures
Any security measure installed at a data centre either detects an intruder (CCTV monitoring) or delays them (gatehouse security).
Both the National Protective Security Authority (NPSA) and National Cyber Security Centre (NCSC) recommend that a physical presence is a strong line of defence for any UK data centre, making the argument that showing as a difficult target can be enough on its own to deter any attempts to attack your facility.
For less overt attacks their Barriers, Access, Detect (BAD) philosophy again leans on the idea that data centres take a layered approach to their security to prevent any unauthorised access, with further access control and monitoring the further you get to the critical infrastructure inside your facility.
The data centre industry itself has now started to recognise the position it holds in terms of the value of what is stored in facilities, and the need for more robust security.
Writing in Data Center Knowledge, Michael Giannou, global general manager for data centers at Honeywell, argued that the sector’s security future lies in “unifying physical, digital and operational intelligence into one cohesive system.”
His argument is that access control, surveillance and intrusion detection need to be treated as one security system so can monitor and manage risk from one place (or working with a trusted data centre security provider who can monitor it for you).
For us, data centre security measures fall into four areas:
- Perimeter security
- Vehicle entry and gatehouse security
- Entrance
- Secure internal zones
Site Perimeter
Your data centre perimeter serves two purposes. First is a physical deterrence (trying to get past a perimeter fence will be enough to put low level criminals or opportunistic criminals off).
Second is a point of detection, giving your security operatives time to assess an incident and decide on the best course of action. The detection side of perimeter security is sometimes overlooked, because a fence is seen just as a physical barrier. But a detection system is just as important.
At ProFM Group, this is where our ProEyez AI detection system comes in. It uses AI image analysis to assess movement in real-time, it can identify the nuances of human movements and separate actual suspicious behaviour from animals or nearby traffic that can often trigger alerts on cameras.
It offers a 35 metre detection zone and a 500 metre connection range, is IP68-rated against water and dust and has been stress-tested to temperatures ranging from -40C to 60C.
It’s also solar panel compatible and protected against tampering (useful for larger sites that are isolated from your guards or lacking a fixed power supply).
All this is overseen 24/7 by our National Operations Centre, where our SIA licensed guards assess footage in real-time.
Where you still want a manned presence, mobile patrol officers can conduct planned and ad hoc patrols at agreed times to provide a physical presence (either on foot or in a marked security vehicle).
Vehicle Entry & Gatehouse Security
Your gatehouse is the first place a trained security guard can make a decision about who gets access through your perimeter.
The NPSA recognise the importance of this security layer, suggesting you ask any operator what assurances they can give that anyone who gets past the gatehouse has a genuine reason.
This can be managed with a pass-wearing policy, a visitor management system and biometric checks.
We’d recommend treating your gatehouse security as a “screening” function rather than just a barrier.
Officers should check credentials against who is expected to turn up on a given day, controlling a single point of entry and having the ability to turn people away when they’re not authorised to be there.
Entrance Desk & Security Control Room
Entrance desks aren’t just a reception with a uniform on. And it needs to be a lot more than somewhere visitors sign in and out.
It can be easy to see the role as that and officers will reasonably deal with concierge work like taking calls or accepting any authorised deliveries. But the substance of the role is still security, so it needs to be factored in.
- Monitoring on-site CCTV
- Welcoming visitors and doing the necessary checks or searches
- Patrolling accessible areas either on a schedule or ad hoc
- Issuing and controlling access based on clearance levels
- Dealing with alarms and emergency situations
The NPSA’s recommendation is to treat the entrance as a specific layer of your data centre security, encouraging you to ask any potential provider how many security staff should be used, what the roles should be and how they’d manage your entrance and control room.
This is where any argument that security should be tech only runs into trouble.
Rick Nee, CRO at Alcatraz AI, has argued facilities need to take an approach that “combines advanced technology with robust protocols and procedures”, reducing unnecessary friction.
His argument is that people need to be involved to make sure protocols and procedures are followed, along with the right security technology to help them.
Officers who work on a site daily notice things out of the ordinary that a camera wouldn’t. It could be blind spots in coverage or that activity has picked up around a particular part of your perimeter.
Any judgement only makes a difference if the people making it are experienced. Our officers are fully SIA-licensed, vetted in line with BS7858 and DBS-checked as standard.
Anyone we place at a data centre also completes CPD-certified training relevant to the contract and has site specific knowledge.
Data Halls, Meet Me Rooms & Secure Zones
These are the areas where vulnerabilities carry the highest risks.
Anyone in these parts of your data centre are close to servers and customer data. NPSA guidance reflects this, with recommendations for Biometric Automatic Access Control Systems (BAACS) stating biometrics are more secure than a PIN or fob (which can be duplicated or stolen).
We’d advise tiering security rather than applying it in a blanket approach.
Biometrics suit areas where unauthorised access has the most serious consequences.
PIN codes and ID fobs are often a better fit where permissions can be granted or changed frequently just because they’re easier to reissue (you just need to have proper management to revoke permissions once they’re no longer needed).
One data centre area that’s often under-protected is Meet Me Rooms (MMR).
The NPSA are clear in their guidance that MMR is part of your data centre perimeter, because it’s part of the infrastructure that separates people from your critical data.
It’s just in practice it sits within the physical building, so often isn’t treated with the same strict controls as other perimeter areas.
Complete Data Centre Security Measures From ProFM Group
We’ve been the partner of choice for major UK data facilities, including TATA Communications’ Stratford facility and the NTT Data Centre at Hemel Hempstead.
Our officers are SIA-licensed, BS7858-vetted and DBS-checked. And our systems carry NSI Gold accreditation for CCTV alongside Paxton Gold for access controls and intruder alarms.
Everything we monitor runs through our own ISO27001-compliant National Operations Centre, staffed 24/7/365.
And it all starts with a conversation with our experts. Get in touch with our in-house team on 0808 196 7709, or drop us an email at [email protected], and we’d be more than happy to discuss our physical security services for your data centre.