Physical security in data centers or how to protect the digital environment beyond the internet

Jane Anderson
Jane Anderson
Un hombre dentro de un centro de datos

Data centers, such as those spaces that store the servers that host the internet infrastructure, have acquired a critical role in the digital economy and their relevance is only growing, because global demand for their capacity may triple by 2030. But as demand for these assets increases, the risks and, therefore, the need to protect them also multiply.

The expansion of data centers has one of its main levers in the development of artificial intelligence, which could make global spending on data centers reach $7 trillion by 2030, according to McKinsey projections. However, it finds other driving factors in the improvement of connectivity or the progress of the edge computing.

All this growing digitalization of life and the construction of increasingly complex infrastructures supported by a greater diversity of technologies force us to stop seeing security as a sum of independent tools and systems. The current context requires working on resilience by jointly addressing physical, digital, operational and environmental threats.

The complexity of the context requires jointly addressing physical, digital, operational and environmental threats.

For a long time the market has tended to pay more attention to cybersecurity due to fear of the unknown and the risks associated with digital information, but the truth is that if the physical issue is not well shielded, it would be useless to have the best firewall of the world because everything would be exposed.

And regarding physical security, the conversation has focused on issues such as energy consumption, cooling or connectivity. But as the market enters a new and more demanding era the focus is shifting towards holistic resilience and therefore the ability to anticipate, resist, adapt and recover quickly after any disruption or incident, whether digital or physical.

Furthermore, protection and security are now also issues of mandatory compliance, imposed by international regulations. For example, the NIS2 (Network and Information Security) Directive requires, among other things, stricter cybersecurity risk management measures, robust incident reporting protocols and reinforced security throughout the supply chain.
supply.

For its part, the CER Directive (Critical Entity Resilience) requires
critical entities, which includes data centers, to strengthen their resilience against all types of threats, from natural disasters, terrorist attacks, cyber sabotage or public health emergencies. The objective is to prevent any interruption that could lead to significant downtime and, consequently, affect critical services or business operations causing financial losses.

Data center risks and how to mitigate them

When it comes to data center security, and as is also the case in other areas, overconfidence is usually the most common mistake. Thinking that nothing is going to happen because good systems have already been installed is a trap. According to the hosting and domain company Dinahosting, all measures and solutions, no matter how good they are, must be subject to continuous audits and stress tests.

“A fairly typical failure is to focus only on shielding the interior rooms”

“If you don’t put them to the test, it doesn’t take long for blind spots to appear on the cameras, unauthorized access that no one had thought of, or poorly defined protocols, such as what happens to access controls when a real emergency breaks out.“explains Miguel Alayón, Head of Dinahosting’s Data Centers, in statements to reason.Why “Another fairly typical failure is to focus only on shielding the interior rooms and leaving the exterior perimeter security a little aside, an oversight that is often caused by the lack of sufficient personnel to monitor accesses and patrols.”.

Data centers can be exposed to a wide variety of risks:

  • Physical security risks, such as fire, water damage, intrusions or intentional damage, electrical short circuits, lithium battery failures, etc.
  • Cybersecurity risks, which include all those acts that threaten the confidentiality, integrity and availability of large volumes of information, such as terrorist attacks
  • Occupational health and safety risks, which involve, on the one hand, human errors, and on the other, possible risks for facility professionals, such as electrical, fire and noise hazards, ergonomic problems, exposure to chemicals, slips and falls, etc.
  • Environmental risks, including natural disasters, extreme temperatures and humidity, water damage, poor air quality, wildlife,
    vegetation or the inclemencies derived from climate change

A holistic approach to physical security

The increasing diversity of elements that can affect the integrity of data centers requires the adoption of a holistic approach that integrates people, processes and technology and is supported by a proactive strategy. In this way, physical security can become an asset and a competitive advantage with positive ramifications for both the brand and the business.

Experts recommend, first of all, supporting systems with official and recognized certifications and standards, such as the National Security Scheme (ENS), Tier, ISO 27001 or regulations such as NIS2, since they require data centers to undergo strict periodic reviews and give companies the certainty that their infrastructures comply with the best practices in the sector.

Permissions and access are one of the biggest security risks

Secondly, they suggest paying special attention to accesses. In addition to preventing the entry of intruders, the focus must be on proper management of permits, which often pose the greatest risks. At Dinahosting they aim to apply a strict policy of least privilege, that is, each employee or technician has access exclusively to what they need for their work and nothing else. Along these same lines, they highlight the importance of neatness in internal processes so that there are no errors or delays, for example, when collecting cards, keys and permits when a worker is fired, changes position or is on leave.

On the other hand, Axis Communications, a company specialized in security for companies, proposes a multi-layer approach in its report “Rethinking physical security in the era of data centers; That is, addressing security measures taking into account the risks that each part and elements that make up a data center may experience. Thus, they divide the interventions into the following layers:

Perimeter and external areas

In this area, the perimeter, access to buildings, traffic areas or parking lots could be affected.

  • Risks: intrusions or unauthorized access, vulnerabilities in loading and delivery docks, vehicle theft, monitoring of employee routines, visual surveillance, attacks based on physical mail, infrastructure mapping, etc.
  • Solutions: video cameras and thermal cameras, radars to detect movement and classify objects, access control solutions for authorized personnel and vehicles or direct communication lines with drivers can be implemented

Facilities

In this area, power generators, air conditioning or refrigeration systems could be affected.

  • Risks: sabotage, vandalism, theft of fuel or components, manipulation through unauthorized access, deliberately contaminated fuel, cyber attacks, blockages of air flows, manipulation of controllers, etc.
  • Solutions: measures such as access control for authorized personnel, thermal cameras, periodic inspection of components and quality controls, or intercoms apply in this area.

Buildings

Entrances, rooftops, reception and offices, security rooms or air conditioners can be the target of attacks or threats

  • Risks: employee tracking (tailgating), forced entry, theft or cloning of credentials, human errors, damage to components, theft or sabotage of documents, manipulation of software or hardware, access to data and information, etc.
  • Solutions: the measures that can be implemented are surveillance and security solutions, both human and material; access controls, both physical and electronic; or monitoring systems for digital devices and tools.

server rooms

At this level what could be affected are the server rooms and network rooms.

  • Risks: unauthorized access, failures in electrical air conditioning, fire prevention or energy supply, overheating, water damage, or theft and sabotage of components, etc.
  • Solutions: again, access controls, intrusion alert systems, video surveillance, alternative and redundant systems for power supply and data prevention, installation of firewalls, network segmentation or data encryption, etc. can be implemented.

Mitigating risks guarantees the reliability, safety and efficiency of the activity and ultimately protects services and businesses. And it also boosts the brand. ““Physical security has become a brutal competitive advantage”says Miguel Alayón (Dinahosting). “The image and reputation of a data center skyrockets the more security it demonstrates, because today companies are not only looking for power or connectivity, they are looking for complete peace of mind that their data is under lock and key.”.