Our work in action On sites, across sectors

Blended Threat in Data Centres: Why Cyber and Physical Security Can’t Stay Separate

Data centre security is still too often treated as two separate disciplines: cyber security on one side, physical security on the other.

That model is no longer enough.

The most serious risks increasingly sit where the two overlap. A compromised account can become a physical access issue. A physical breach can become a cyber incident. In a blended threat scenario, attackers don’t need to choose one route. They can combine digital and physical methods to increase impact, avoid detection and exploit gaps between teams, systems and response plans.

The blind spot

Many data centre operators still think about access control, CCTV and perimeter security separately from identity management, network segmentation, remote access and operational technology.

In reality, those layers are connected through the same operational environment.

Badge systems, visitor management platforms, environmental controls, cameras, alarms and building management tools all interact with the wider data centre estate. If one part is weakened, it can create an attack path into another.

That’s what makes blended threats difficult to manage through a siloed security model. The weakness isn’t always the absence of a control, but often the gap between controls.

Why data centres are exposed

Data centres are high-value environments with very low tolerance for disruption. They concentrate critical systems, depend on constant availability and rely on a complex mix of permanent staff, contractors, suppliers, visitors and third-party specialists.

They also increasingly depend on connected facility systems and operational technology. Cooling, power, monitoring, fire, security and building management systems are now part of the wider security picture, not separate from it.

That creates more opportunity for an attacker to move between digital, physical and operational systems if controls are not properly aligned.

What blended threat looks like

Blended threat isn’t a theoretical risk. In a data centre environment, it can include scenarios such as:

  • A stolen credential being used to support unauthorised physical access.
  • A rogue insider or contractor enabling access for another party.
  • A cyber attack disabling cameras, alarms or access logs to support physical intrusion.
  • Tampering with power, cooling or environmental systems to trigger outage or damage.
  • Coordinated activity that distracts one team while another part of the operation is targeted.
  • Misuse of remote access or building systems to weaken physical protection.

The key issue isn’t just the initial breach, but how one compromise can make the next one easier.

Why the old model falls short

Traditional security structures often split cyber and physical risk across different teams, systems and escalation routes.

That may work for isolated incidents, but it becomes a weakness when an incident crosses disciplines.

If a cyber team identifies suspicious activity but the physical security team isn’t looped in quickly, an unauthorised person may still be able to access the site. If the physical team detects unusual access activity but the cyber team isn’t informed, related systems, accounts or networks may remain exposed.

Put simply, more than a lack of controls, the issue is a lack of convergence.

What good practice looks like

A stronger approach is to treat cyber and physical security as one connected risk domain.

That starts with joint risk assessments, shared incident response plans and common escalation routes. It also means testing how systems interact in practice, not just assuming they are secure because each individual layer has been specified correctly.

Operators should be asking questions such as:

Can access logs, CCTV, alarm data and identity systems still support an investigation if one layer is compromised?

Are physical and cyber events correlated quickly enough to identify a blended incident?

Do emergency procedures still work if communications, building systems or remote management tools fail?

Are contractor access, privileged credentials and site permissions reviewed together?

Does incident response include facilities, security, IT, operations and senior management?

These are the questions that matter in a blended threat scenario.

ISO 27001 also supports this way of thinking. Annex A 7.1 on physical security perimeters makes clear that physical protection forms part of protecting information and associated assets. In other words, physical security isn’t separate from information security, but an integral part of it.

A more resilient model

The practical shift is from siloed protection to converged resilience.

That means designing security so that cyber, physical and operational controls reinforce each other, rather than operating independently.

For data centre operators, the key considerations usually include:

  • Shared visibility across facilities, security, IT and operational teams.
  • Tight control of privileged access for staff, contractors and suppliers.
  • Regular reviews of building, identity and security system integrations.
  • Incident exercises that include both physical and cyber response. Recovery planning that assumes one control layer may be unavailable.
  • Clear ownership of risk where systems, people and processes overlap.

That’s where blended threat becomes more than a security buzzword. It’s a practical reminder that the data centre is one environment, not two.

As attackers become more willing to combine methods, the safest operators will be the ones that stop separating cyber and physical risk in their thinking.

In a data centre, resilience now depends on seeing the whole system: not just the network, not just the building, but the connection between them.

If this raises questions about a data centre project you’re planning, delivering or reviewing, our specialist team would be happy to discuss it with you.

Meet with our experts

Tell us about your project: we'll deliver a solution that gets the job done.