Resilience at the Edge: Rethinking Data Centre Security
Wed 17 Jun 2026
Data centre security is often discussed through a cyber lens, where networks, firewalls and system resilience define the boundaries of the problem. In conversation with Michael Paule, DVP Vertical Business Owner Data Centres at dormakaba, that framing begins to turn outward, toward the physical environment and the conditions in which access is created, managed, and recovered.
“It’s about high availability… it’s about redundancy… but it’s also about disaster recovery”
The inclusion of recovery changes the frame. Security is no longer only about preventing failure, but about how systems behave once failure occurs, and how quickly operations can be restored when disruption moves beyond the digital layer.
That distinction becomes more pronounced when the discussion moves from systems into buildings. Digital infrastructure can often be restored through replication and connectivity, but physical environments operate under different constraints, where access, structure and sequencing determine how recovery unfolds. The point is not that physical systems are weaker, but that they respond differently and require a different kind of planning.
Where Access Actually Begins
The boundary of the system does not sit at the server or the network. It begins at the perimeter, where movement is initiated and where decisions are made before any interaction with technology takes place.
“At the perimeter… it’s the start of a people flow process”
This reframes entry as a sequence rather than a checkpoint. Access is not granted in a single moment, but constructed over time, through interactions that accumulate as individuals move deeper into the facility. Early assumptions carry forward, and by the time a system is reached, the conditions that determine risk may already have been established.
Distance from critical infrastructure does not necessarily reduce exposure. A weakness introduced at the edge can persist through the system, even when it remains physically far from the assets it ultimately affects.
The Fragility of Trust
One of the more difficult aspects of physical security is that it operates within social environments as well as technical ones. Procedures exist, but they are interpreted through human judgement, and that judgement changes depending on context.
Familiarity is one of the most persistent variables. When individuals recognise each other, or believe they do, processes begin to adapt. Steps are shortened, checks are relaxed, and interactions are shaped by assumption rather than verification.
“You need to really do everything, every time, the same”
Consistency becomes less about enforcement and more about stability. Systems hold when behaviour remains predictable, particularly in environments where small deviations can accumulate into larger vulnerabilities over time.
Complexity as a Condition
As movement continues through the facility, the environment becomes progressively more complex. Different roles, permissions and access paths intersect, creating layers that must be coordinated rather than simply controlled.
This is not a failure of design, but a consequence of how data centres operate. Complexity is inherent to the system, and resilience depends on whether that complexity remains visible and structured.
The challenge is not only to define access, but to maintain clarity as the number of interactions increases. Without that structure, complexity becomes a source of exposure rather than a feature of capability.
From Physical Control to System Awareness
Security, in this context, extends beyond the act of granting or denying access. It becomes a question of how each interaction is recorded, understood and connected to a broader system of accountability.
“Robust security ensures every access event is managed, monitored and tied to a verified identity”
The change is subtle but significant. Prevention remains important, but it is no longer sufficient on its own. Control depends on continuity, where actions can be traced and understood over time, rather than simply blocked at the point of entry.
The Human Variable
Even within structured systems, one element remains inherently variable: behaviour.
Human interaction introduces both flexibility and unpredictability. Decisions are made in real time, often under incomplete information, and influenced by factors that sit outside formal processes.
This does not represent a failure of individuals but a limitation of systems that depend on human interpretation. Security models can define structure, but they cannot eliminate variability.
Design and Constraint
Many of the conditions that shape resilience are established early, often before systems are fully deployed. Design choices determine how much flexibility exists later, and how easily systems can adapt when requirements change.
“If you think about design… you can really build everything… standardised… modular”
Once those systems are in place, the space for change narrows. Retrofitting introduces constraint, and adaptation becomes incremental rather than structural.
A System That Evolves
Data centres do not remain static. They evolve continuously, as workloads change, technologies shift and new risks emerge.
Security follows that movement, requiring ongoing adjustment rather than fixed solutions. What appears stable at one moment may become insufficient at the next, particularly as the environment around the system changes.
Familiarity introduces its own risk in this context. Over time, organisations adapt to known conditions, and that adaptation can obscure emerging threats.
External perspective becomes a way of restoring visibility, not only by identifying gaps, but by challenging assumptions that have become embedded in day-to-day operations.
