Skip to content
Airspace. Send an enquiry

Data centres

Data centres are driven by customer audit obligations rather than statute, their exposed assets are on the roof rather than behind the fence, and unlike most infrastructure someone is always there to receive an alert.

Key facts

  • The assets most exposed to aerial observation at a data centre are outside the building shell: rooftop cooling plant, generators, fuel storage and utility entry points.
  • There is no statutory requirement for data centres to detect drones; the driver is customer security requirements, audit regimes and tenant agreements.
  • Continuous staffing means a detection alert has a recipient able to act, which materially changes the value of detection compared with unstaffed infrastructure.
  • Not all overflight is hostile. Data centre developments attract local opposition and media interest, and the response to a journalist differs from the response to reconnaissance.
  • Detection is lawful for a data centre operator to deploy. Mitigation is not available to a private operator under United States law.

What makes this facility type different

The threat model

The exposed assets sit on the roof and in the yard rather than inside the hardened shell: chillers, cooling plant, generators, fuel storage and utility entries. Overflight maps the single points whose loss interrupts service, and the operator also faces a second, more common vector in activist or journalistic overflight, since data centre developments are increasingly contested locally over power, water and noise.

The regulatory position

There is no statutory drone mandate for data centres. The obligations are contractual, arriving through customer security requirements, audit regimes and tenant agreements, which means a physical security gap is raised by an auditor or a prospective tenant rather than by a regulator. The driver is therefore commercial rather than regulatory, and the relevant standard is what a customer will accept.

What constrains the response

A data centre is continuously staffed with an operations floor already monitoring alarms, so unlike a substation or a pipeline there is somebody present to receive a detection alert and act within minutes. The constraint is the opposite one: the site is dense with sensitive electronic equipment and radio systems, so anything transmitting has to be assessed for interaction with existing infrastructure before it is installed.

The exposure is on the roof

A data centre is built around a hardened core, and it works. What keeps the core running is not inside it.

Cooling plant, chillers, generators, fuel storage and utility entry points sit on the roof and in the yard, because they have to. They are visible from above, they are the single points whose loss interrupts service, and they are what aerial observation actually maps.

Most descriptions of data centre security concentrate on access control at the entrance, which is usually well covered. Aerial observation raises a different question, about the supporting infrastructure that sits outside the building.

The driver is a customer, not a regulator

Almost every other facility type on this site has a statutory hook: a Part 139 response plan, an NRC reporting duty, a NERC standard. Data centres have none.

What they have instead is contractual. Customer security requirements, audit regimes and tenant agreements are where physical security obligations are set, and the party who raises a gap is an auditor or a prospective tenant rather than an inspector.

That changes how the work is commissioned. There is rarely a deadline, and there is frequently a specific question from a specific customer that has to be answered in writing. The useful output is often the documented assessment rather than the equipment, because the assessment is what gets sent back.

Somebody is actually there

This is the operational advantage data centres have over almost every other site in this field, and it is easy to overlook.

A substation is unstaffed. A pipeline corridor is unstaffed. A data centre has a continuously staffed operations floor already monitoring alarms, with defined escalation and people who respond to conditions for a living.

So a detection alert here has a recipient, immediately, at three in the morning. That materially raises what detection is worth, because the alert connects to an existing response capability rather than needing one built around it. It also means the integration question is concrete: the alert should arrive in the system that floor already watches, not in a separate console nobody is looking at.

Not every drone is a threat

Data centre developments are contested in a growing number of communities over power consumption, water use and noise. The consequence is that a real share of overflight is lawful: residents documenting construction, campaigners gathering footage, local media.

Deciding in advance how those are handled is worth more than the sensor is. A response posture that treats every detection as a security incident produces confrontations with people who are entitled to be filming from public land, and those confrontations become the coverage. Distinguishing the two, and having separate responses ready, is part of the plan rather than an afterthought.

FAQ

Is there any regulation requiring drone detection at a data centre?

No. Unlike airports, nuclear plants or transmission utilities, there is no statutory obligation. What drives the requirement is contractual: customer security questionnaires, audit regimes and tenant agreements. That changes how the case is made internally, because the trigger is usually a customer asking a question rather than a compliance deadline.

What is actually at risk if the building itself is hardened?

The plant that keeps it running. Cooling, generators and fuel are outside the shell by necessity, and they are the single points whose loss interrupts service. Aerial observation maps exactly those, along with utility entries and the access routes to them. The shell is not the attack surface; the support infrastructure is.

How should we treat overflight that turns out to be a protester or a journalist?

Differently, and deciding that in advance is worth more than the sensor. Data centre developments are contested in many communities, so a meaningful proportion of overflight will be lawful filming rather than reconnaissance. A response plan that treats every detection as a security incident generates confrontations that end up as the story.

Will detection equipment interfere with our systems?

It has to be assessed, and this is a stronger consideration here than at most sites given the density of electronic and radio equipment. Passive sensors raise fewer questions than transmitting ones. Whatever is proposed should be checked against existing systems before installation, not commissioned and then investigated.

Tell us what you are dealing with

We reply by email. If the answer is that this is not work we should be doing, we will say so.

We use what you send to answer your enquiry and nothing else. Please do not send security-sensitive detail about a site in this form. See our privacy notice.