Behind the Rack / Physical security

Physical security

BEHIND THE RACK

3 min read · 667 words

A facility that stores other people's websites and customer data is serious about who can get in. Typical measures include perimeter fencing, staffed reception, badge access, biometric or PIN readers at inner doors, cameras with retained footage, mantraps (two-door entry vestibules) and visitor logs. Within the building, cages and locked cabinets limit who can touch which equipment.

Operators of reputable facilities undergo external audits, for example against ISO 27001 or SOC 2, and will usually summarise their certifications on their website. These do not guarantee anything on their own, but their absence in a provider that handles sensitive data is a reason to ask questions.

Security in layers

No single lock is trusted. The design idea is depth: an intruder, or a careless visitor, must pass several independent checks, and each layer is watched. The outermost layer is the site boundary, with fencing, vehicle barriers and lighting. Next comes the building shell, with few doors, no ground-floor windows into the hall and a staffed reception. Then the data hall itself, behind a mantrap. Finally the cage or cabinet, and, for the most sensitive kit, locks on individual racks.

1. Site perimeter: fence, barriers, lighting, cameras2. Building: reception, badge, visitor log3. Data hall: mantrap, PIN or biometric reader4. Cage: fenced area, separate lock5. Locked cabinetyour servers
Each ring has its own control, so getting past one does not open the next.

Doors that make people stop

The mantrap earns its place because it defeats tailgating, the habit of walking in behind someone who has opened a door. In a mantrap, the inner door stays locked until the outer door has closed, and some sets use weight sensors or a camera to confirm only one person entered per badge. Add a PIN or a fingerprint reader and a stolen badge is no longer enough on its own.

The weak points are rarely the doors themselves. They are the habits around them: propping a door during a delivery, lending a badge to a colleague, letting a contractor wander without an escort. Good facilities train staff to challenge strangers and log every visitor with a name, a purpose and the time in and out.

Cameras, logs and escorts

Cameras are only as useful as the footage retained and the people who review it. A reasonable operator keeps recordings for weeks or months, covers every entry point and every aisle, and ties door events to badge logs so that "who was in row C at 03:10" has an answer. Visitors are escorted, and visits to cages are booked in advance with the customer's approval.

ControlWhat it stopsWhere it fails
Fence and barriersCasual approach, vehiclesDetermined intruders; it only buys time
Badge readerUnregistered visitorsLent or stolen badges
MantrapTailgatingStaff overriding it for convenience
CameraDeters, and records afterwardsNobody watching or footage overwritten
Cage or cabinet lockOther tenantsShared keys, weak locks

What the audits mean

ISO 27001 certifies that an organisation runs an information security management system and that an independent body has checked it against the standard. SOC 2 is an attestation report in which an auditor describes controls and tests them over a period. They answer different questions, and neither says "this building cannot be broken into".

Read the scope. A certificate may cover the head office but not the data centre you are in, or one product line but not another. Many facilities also rely on a landlord's building, so the audit may cover only the operator's own procedures.

Outer door opensbadge acceptedOuter door locksperson alone insideSecond checkPIN or fingerprintInner dooropens to hallThe inner door never opens while the outer door is open
A mantrap forces entry one person at a time, with a second check before the hall.

Loose ends

Can anyone from the data centre see my files?

Physical access is not the same as logical access, but a technician with the right permissions can reach a disk. Encryption at rest, and a provider that logs staff access, limit the exposure.

Is a certificate a guarantee?

No. It shows a process was checked at a point in time. It is a good sign, not a promise.

Do I need my own cage?

Only for specific compliance rules or very large setups. A locked cabinet in a well-run hall covers most cases.

PreviousStorageNextWhy redundancy still fails

More from Behind the Rack

Behind the Rack

Energy, water and the footprint of hosting

Data centres use roughly one to two percent of the world's electricity, and the figure is growing as more...

Behind the Rack

Storage

Hard drives fail. That is a statistical certainty, not a rare accident, and storage design starts from that...

Behind the Rack

Disaster recovery sites

A disaster recovery site is a second location able to take over if the first is lost. It can be a hot...