For data centre owners, operators and customers, the most serious security exposure may sit beyond the visible perimeter, in shared interconnection spaces, underground infrastructure, building systems and third-party supply chains. Effective protection starts by identifying every point where control, access or responsibility changes hands.
Ask most people to describe data centre security, and they picture the same thing: the fence line, the barrier, the cameras, the badge reader on the door.
That’s not the wrong place to start. Perimeter and building security are still the foundation of any good spec. It’s just not where the boundary ends.
Security isn’t one line; it’s seven areas
The National Protective Security Authority (NPSA), the UK’s national technical authority for protective security, and the National Cyber Security Centre treat the data centre boundary as a network of connected risks rather than a single fence line. Their joint guidance identifies seven areas that must be considered together: geography and ownership; the physical perimeter and buildings; the data hall; meet-me rooms; people; the supply chain; and cybersecurity.
Fences, gates and access control address only one part of that model. The remaining risks run through shared rooms, buried infrastructure, operational technology, people and suppliers, many of them outside the operator’s direct control and absent from the first security conversation.
The interconnect point nobody outside can see
Meet-me rooms are the points at which a facility’s networks physically interconnect with external carriers and the wider internet. NPSA guidance treats these rooms as part of the customer’s security boundary because they connect directly to customer racks, even when the customer does not control the room itself. Where encryption across that connection is absent or unverified, the interconnection becomes a material exposure that should be tested during design and procurement.
Most customers will never set foot in one. That’s precisely why the questions asked of an operator at tender stage matter more than the ones asked of the fence.
What’s underground, and what’s in the walls?
Cable access and draw pit chambers, the covers sometimes called manhole or maintenance covers, carry connectivity between buildings and out to the street. NPSA treats them as an important piece of infrastructure that’s easy to walk straight past without a second look. A cover that isn’t positioned out of the way, locked and monitored, is a route past every camera and turnstile above ground.
Ducting raises a similar question from the opposite direction. Cooling systems need ventilation and drainage routes wide enough to move real volumes of air, which in places means wide enough to move a person. NPSA’s guidance specifically calls for grilles and cages on venting and ducting, and recommends mesh even over smaller runs, since these could otherwise be used to pass items between secure and non-secure areas and sidestep whatever screening sits at the front door.
Then there’s the system running quietly underneath all of it: the building management system, controlling power, cooling, fire and ventilation across the site. A BMS is usually operated by the facility rather than the tenant, but a fault or compromise in it can trigger an outage that reaches every customer on the floor. NPSA’s questions for owners are pointed: is it connected to client networks, is it run from a secure area rather than reception, and has it actually had a cyber-vulnerability assessment?
The hall itself, and everyone who supplies it
Even the data hall, the room every customer assumes is safely “inside”, has its own boundary questions. In a shared facility, people unfamiliar to one tenant may still have proximity to another tenant’s racks. NPSA’s guidance for operators covers grilles on HVAC access points, keeping building services equipment outside the hall where practical, and controlling what devices, particularly phones and cameras, get carried in.
The supply chain extends the boundary further still. Every vendor supplying hardware, firmware or managed services into a facility inherits a share of its risk. NPSA has been consistent on this point: threat actors have both the appetite and the know-how to go after weak links in a supply chain, and that has to be treated as a physical, personnel and cyber question together, not a procurement checkbox.
Why this matters more than it used to
The stakes have risen. UK data infrastructure was designated Critical National Infrastructure in September 2024, putting it in the same category as energy and water. Legislation now moving through Parliament is set to bring data centre operators into scope as operators of essential services in their own right. A spec that stops at the fence line increasingly falls short of what regulators, insurers and customers now expect.
The perimeter is best understood as every point where control, access or responsibility changes hands. For each room, chamber, duct, system and supplier at that boundary, the test is the same: who owns the risk, who can gain access, how is activity monitored, and what happens when a control fails?
If you are planning, designing or reviewing a data centre project, our data centre team can help assess the full security boundary, from perimeter protection and internal spaces to operational technology, interconnections and supply-chain assurance.