Blended Threat in Data Centres: Why Cyber and Physical Security Can’t Stay Separate

Data centre security is still too often treated as two separate disciplines: cyber security on one side, physical security on the other.

That model is no longer enough.

The most serious risks increasingly sit where the two overlap. A compromised account can become a physical access issue. A physical breach can become a cyber incident. In a blended threat scenario, attackers don’t need to choose one route. They can combine digital and physical methods to increase impact, avoid detection and exploit gaps between teams, systems and response plans.

The blind spot

Many data centre operators still think about access control, CCTV and perimeter security separately from identity management, network segmentation, remote access and operational technology.

In reality, those layers are connected through the same operational environment.

Badge systems, visitor management platforms, environmental controls, cameras, alarms and building management tools all interact with the wider data centre estate. If one part is weakened, it can create an attack path into another.

That’s what makes blended threats difficult to manage through a siloed security model. The weakness isn’t always the absence of a control, but often the gap between controls.

Why data centres are exposed

Data centres are high-value environments with very low tolerance for disruption. They concentrate critical systems, depend on constant availability and rely on a complex mix of permanent staff, contractors, suppliers, visitors and third-party specialists.

They also increasingly depend on connected facility systems and operational technology. Cooling, power, monitoring, fire, security and building management systems are now part of the wider security picture, not separate from it.

That creates more opportunity for an attacker to move between digital, physical and operational systems if controls are not properly aligned.

What blended threat looks like

Blended threat isn’t a theoretical risk. In a data centre environment, it can include scenarios such as:

  • A stolen credential being used to support unauthorised physical access.
  • A rogue insider or contractor enabling access for another party.
  • A cyber attack disabling cameras, alarms or access logs to support physical intrusion.
  • Tampering with power, cooling or environmental systems to trigger outage or damage.
  • Coordinated activity that distracts one team while another part of the operation is targeted.
  • Misuse of remote access or building systems to weaken physical protection.

The key issue isn’t just the initial breach, but how one compromise can make the next one easier.

Why the old model falls short

Traditional security structures often split cyber and physical risk across different teams, systems and escalation routes.

That may work for isolated incidents, but it becomes a weakness when an incident crosses disciplines.

If a cyber team identifies suspicious activity but the physical security team isn’t looped in quickly, an unauthorised person may still be able to access the site. If the physical team detects unusual access activity but the cyber team isn’t informed, related systems, accounts or networks may remain exposed.

Put simply, more than a lack of controls, the issue is a lack of convergence.

What good practice looks like

A stronger approach is to treat cyber and physical security as one connected risk domain.

That starts with joint risk assessments, shared incident response plans and common escalation routes. It also means testing how systems interact in practice, not just assuming they are secure because each individual layer has been specified correctly.

Operators should be asking questions such as:

Can access logs, CCTV, alarm data and identity systems still support an investigation if one layer is compromised?

Are physical and cyber events correlated quickly enough to identify a blended incident?

Do emergency procedures still work if communications, building systems or remote management tools fail?

Are contractor access, privileged credentials and site permissions reviewed together?

Does incident response include facilities, security, IT, operations and senior management?

These are the questions that matter in a blended threat scenario.

ISO 27001 also supports this way of thinking. Annex A 7.1 on physical security perimeters makes clear that physical protection forms part of protecting information and associated assets. In other words, physical security isn’t separate from information security, but an integral part of it.

A more resilient model

The practical shift is from siloed protection to converged resilience.

That means designing security so that cyber, physical and operational controls reinforce each other, rather than operating independently.

For data centre operators, the key considerations usually include:

  • Shared visibility across facilities, security, IT and operational teams.
  • Tight control of privileged access for staff, contractors and suppliers.
  • Regular reviews of building, identity and security system integrations.
  • Incident exercises that include both physical and cyber response. Recovery planning that assumes one control layer may be unavailable.
  • Clear ownership of risk where systems, people and processes overlap.

That’s where blended threat becomes more than a security buzzword. It’s a practical reminder that the data centre is one environment, not two.

As attackers become more willing to combine methods, the safest operators will be the ones that stop separating cyber and physical risk in their thinking.

In a data centre, resilience now depends on seeing the whole system: not just the network, not just the building, but the connection between them.

If this raises questions about a data centre project you’re planning, delivering or reviewing, our specialist team would be happy to discuss it with you.

Where Data Centre Specs Underestimate Insider Threat

Most data centre specifications still treat insider threat as an access control problem. Tighten permissions, add a stronger credential, add another biometric layer, deepen the audit trail.

That’s too narrow.

Data centre resilience is usually designed around continuity: keeping the facility running while maintenance, upgrades and operational work take place. Physical security often gets specified to a lower bar than that resilience logic, and insider threat is where the gap shows. In a live data centre, insider risk sits in the relationship between people, movement and operational necessity, not in the door on its own. NPSA’s insider risk guidance treats it as a people and process issue, and its data centre material reflects the reality of a mixed-site population: operators, client engineers, security teams, cleaners and maintenance contractors all moving through the same space.

Harmful access rarely starts with a failed credential check. More often it starts with a design assumption. A zone model that’s too broad. A service route that’s too permissive. A maintenance path too close to a critical space. A quiet shift that changes the risk while the access model stays put. 

So the real point is this: insider threat in a data centre is usually a zone design problem, a shift pattern problem or a maintenance access problem before it’s a reader problem.

Access hierarchy only works if the zone model is right

The market isn’t short of access control: layered permissions by role, location and time, biometrics, anti-tailgating, full audit visibility. All of it useful. None of it rescues a weak zone structure.

Put a strong hierarchy on top of lazy zoning and the system just enforces a bad decision more efficiently. We still see facilities split into broad buckets, perimeter, plant, white space, admin, with credentials left to do the rest. Tidy on paper. Less tidy once operators start moving through it.

Insider opportunity lives in the seams between zones. Service corridor to riser. Riser to plant. Plant to support area. Support to cabinet row. If those transitions aren’t designed around real task needs, supervision and dwell time, the hierarchy becomes permissive exactly where it matters. The more useful question isn’t “what readers go here?” It’s “what movements should never become routine?”

Shift pattern is a security control

This is where a lot of specs go quiet. They add layers at key thresholds but say little about how those controls behave on a night shift, a weekend maintenance window or a reduced-staffing period.

A zone that’s well controlled at 11:00 on a Tuesday can be weak at 02:30 on a Sunday. Fewer witnesses. More reliance on remote monitoring. More pressure to get the job done. Activity that would stand out in core hours looks normal out of hours.

So a spec benefits from defining more than access rights. Access conditions: by time, by supervision model, by operational state. Different rules for low-occupancy periods, dual authorisation for selected tasks, temporary rights that expire on task completion rather than end of day. Most platforms already support this. Specs often just don’t ask for it clearly enough.

Maintenance access is where good intent becomes broad exposure

This is the one most often underestimated. Everyone accepts maintenance access is necessary. Fewer specs treat it as its own insider risk.

In practice it creates pressure for convenience. Engineers need to move fast. Faults don’t respect zone boundaries. Temporary works create temporary routes. Escorts get stretched. Access groups widen because uptime matters.

That’s exactly why it needs its own logic, not a line in the O&M pack. Maintenance-only paths that avoid higher-sensitivity zones where possible. Temporary rights tied to the work order. A clear line between accompanied and unaccompanied access. Review triggered by actual use, not an annual policy cycle. That’s a stronger posture than another reader outside the white space.

What we’d do differently

In resilient data centre environments, insider threat needs to be treated as a design condition, not a hardware schedule. The threat assessment must account for route logic, zone segmentation needs to reflect task pathways, and the access model should recognise that maintenance activity, shift state and supervision can all change the risk condition.

Biometrics matter. Audit matters. Hierarchy matters. None of it works properly unless the zone model reflects how the building is actually used, and unless physical security is held to the same resilience logic as the rest of the data centre design.

That’s the shift. Insider threat isn’t something the access control package solves later. It’s better placed in the spatial and operational logic while the zones are still being drawn, where the risk actually reduces and the spec becomes more useful to the operator who has to live with it.

If that’s a conversation worth having on a project you’re working on, talk to our data centre team.