You Think Your Data Center Is Resilient. But Do You Actually Know?

Data centers are some of the most critical facilities operating today.

They support financial transactions, healthcare, government services, communications, cloud platforms, AI infrastructure, and virtually every other part of our increasingly digital world.

We spend enormous amounts of money protecting them: fences, cameras, guards, access-control systems, biometrics, mantraps, backup generators, fire suppression, environmental monitoring, redundant power, and detailed policies and procedures.

All of these things are important. But there is a question I think organizations need to ask more often:

You think your data center is resilient. But do you actually know?

There is an important difference between having security and resilience controls and having independently validated that those controls will work when you need them.

I have spent much of my career assessing preparedness and putting organizations through exercises designed to expose weaknesses before a real crisis does. One lesson has remained consistent throughout that work: documentation and technology can provide confidence, but not necessarily assurance.

The same principle applies to data centers.

Resilience Is About More Than the Front Door

When people think about data-center physical security, access control is often one of the first things that comes to mind, and understandably so. Unauthorized physical access to critical systems can potentially bypass layers of cybersecurity investment.

But data-center resilience extends much further. A comprehensive assessment should consider the entire protective and operational environment, including:

  • Site, environmental and external threats
  • Perimeter and building security
  • Access control, identity management and insider threats
  • Security operations, CCTV, detection and monitoring
  • Power, cooling, telecommunications and other critical infrastructure
  • Fire, environmental and utility protection
  • Governance, procedures and personnel
  • Incident response, crisis management and recovery

None of these capabilities operates independently.

A data center could have excellent access control but poor protection around critical electrical infrastructure. It could have extensive CCTV coverage but weak procedures for responding to alarms. It could have multiple backup generators but discover during an emergency that its procedures, people, or dependencies haven’t been adequately tested.

This is why an assessment has to look beyond whether a control exists. It needs to establish whether the control works, whether people understand their responsibilities, and whether the wider system remains resilient when something goes wrong.

Real Assessments Have Found Real Problems

Here are a few useful examples of why independent assessment matters.

In 2022, the U.S. Department of Veterans Affairs Office of Inspector General reported on an information-security inspection at the St. Cloud VA Medical Center in Minnesota. Identified weaknesses included missing logs and visitor-access records and nonworking video surveillance in the data center. Inspectors also identified an untested emergency power shutoff associated with contingency planning.

These weren’t theoretical vulnerabilities identified during a hypothetical scenario. They were weaknesses uncovered through independent inspection.

An audit of the Industry Canada Data Centre provides another example. The facility had multiple security measures in place, including a 24/7 guard force, CCTV and proximity-card readers. On paper, those are exactly the types of controls we would expect to see.

However, auditors found that procedures weren’t always being followed. Their review also identified access rights assigned to three individuals who had left the department, with two of their cards still active at the time of the audit.

This illustrates an important principle: a security control is only as effective as the process supporting it.

You can install sophisticated access-control technology, but if access privileges aren’t reviewed, removed, and tested effectively, the technology alone doesn’t solve the problem.

The Tennessee Valley Authority Office of Inspector General similarly examined physical and environmental controls at two TVA data centers. It concluded that physical-access controls at both facilities needed improvement, while environmental controls at one facility also needed improvement. Management agreed with the findings and initiated or planned corrective actions.

Related: Beyond Cyber Awareness Month: What Leaders Must Do Year-Round to Prepare for the Next Cyber Crisis

Sometimes the Weakness Is Surprisingly Simple

One of the more interesting examples involves the VA’s Hines Information Technology Center in Illinois.

On May 4, 2023, the facility experienced a power outage lasting approximately 22 hours. More than 10,000 VA employees nationwide were affected and couldn’t access critical systems supporting areas including compensation, pension, and education benefits.

The subsequent VA Office of Inspector General evaluation found that the center’s physical-access controls were generally adequate. But another problem remained: the facility lacked an effective physical control preventing activation of the circuit breaker involved in the inadvertent outage.

Think about the implications of that finding. A facility can have strong overall physical-access controls and still have a vulnerability around one critical component that can cause significant operational disruption.

This is why a good resilience assessment shouldn’t stop at asking whether an unauthorized person can enter the data center. It should look at what could happen once someone is inside, as well as what could happen through human error, equipment failure, or the loss of a critical dependency.

Questions I want answered include: What equipment could be accessed or inadvertently affected? Where are the single points of vulnerability? What happens when a control fails? Who receives the alarm and takes ownership? How quickly can the organization contain the impact and recover?

Those questions move the conversation from physical security to operational resilience.

Standards Give Us the Foundation

Fortunately, organizations don’t need to develop their approach from scratch. Several established standards and frameworks provide a strong foundation for assessing data-center security and resilience.

ISO/IEC 22237 provides requirements and recommendations for data-center facilities and infrastructure. ANSI/TIA-942 provides another important data-center-specific framework covering architecture, electrical and mechanical infrastructure, telecommunications, fire protection, safety, monitoring, and physical security.

NIST SP 800-53 provides extensive security and privacy controls, including Physical and Environmental Protection controls, while NIST SP 800-53A provides methodologies for assessing whether controls operate as intended. ISO/IEC 27001 and 27002 add further requirements and guidance around information-security management, physical security, personnel, access, and governance.

These frameworks provide valuable benchmarks, but meeting a framework’s requirements shouldn’t be the end of the conversation. It should be the beginning of assurance.

From Assessment to Assurance

I believe there are several stages organizations need to work through to understand whether their data center is genuinely resilient:

  1. Establish what should be in place. Determine the required security, infrastructure, resilience, and response controls based on risk and recognized standards.
  2. Assess what is actually in place. Examine documentation, systems, facilities, processes and responsibilities rather than relying solely on policy statements.
  3. Look for evidence. Determine whether controls are consistently implemented, maintained, monitored and reviewed.
  4. Identify and remediate weaknesses. Prioritize vulnerabilities based on their potential operational impact rather than treating every finding equally.
  5. Validate the capability. Test whether people, processes, and technology work together under realistic conditions.

That final stage is where exercises become extremely valuable.

Imagine an assessment identifies strong documented procedures for an attempted physical intrusion. Rather than stopping there, put the team through the situation.

An unauthorized individual breaches the outer perimeter and triggers an alarm. Security responds, but the individual reaches a restricted area and interferes with critical equipment. Part of the facility subsequently loses power.

Now the organization has to make decisions.

Who takes command? How do security, facilities, IT, and cybersecurity coordinate? When does this become a crisis-management issue? When is executive leadership notified? When should customers be informed? What happens if CCTV or communications are unavailable? What if claims about the incident are already appearing on social media?

Suddenly, we’re no longer reviewing a document. We’re evaluating capability.

The Difference Between Compliance and Readiness

A traditional assessment might establish that an organization has a crisis-management plan, emergency procedures, access-control systems, CCTV coverage, backup power, and other required controls.

That’s valuable, but it doesn’t necessarily tell leadership whether those capabilities will work together during a serious incident.

Independent assessment should therefore go beyond identifying gaps. It should establish maturity and provide leadership with a clear picture of where the organization stands today and where it needs to improve.

One approach is to measure maturity through six stages:

Not Established → Initial → Developing → Defined → Managed → Assured

Reaching Assured should require more than good documentation. It should require evidence that critical controls are implemented, monitored, tested, and continuously improved.

That might mean examining records, interviewing personnel, and physically inspecting the facility. It could involve testing alarms, access controls and escalation procedures. And for the most important capabilities, it should include realistic tabletop, simulation, or functional exercises.

So, Do You Actually Know?

The rapid growth of AI, cloud services, and our dependence on digital infrastructure means data centers will only become more critical. At the same time, organizations must consider a wide range of threats and disruptions: physical intrusion, insider threats, sabotage, utility disruption, extreme weather, fire, cyber-physical attacks, equipment failure, and human error.

Organizations will continue investing heavily in technology to manage those risks, and they should. But technology alone doesn’t provide assurance. Neither does a policy, a completed checklist, or a one-time assessment.

Independent assessment, continuous improvement, and realistic testing provide something much more valuable: evidence that your organization can actually perform when it matters.

So perhaps the question data-center owners and operators should be asking isn’t simply, “Are we compliant?”

It is:

“Can we demonstrate that we’re resilient?”

At PreparedEx, that’s where we believe assessment should ultimately lead: understanding the controls that exist, identifying vulnerabilities, prioritizing remediation, and then validating critical capabilities through realistic exercises.

Because the first time you discover that a critical security or resilience control doesn’t work shouldn’t be during the crisis.

Similar Posts

Add your first comment to this post