

A proactive approach to keeping your people, information, and equipment safe
Physically securing data centers means protecting the people, information, and equipment they house in order to form a hierarchical strategy that’s paramount for operational integrity. This article delves into the importance of these three security pillars and how Stream Data Centers implements comprehensive strategies around them to maintain robust protection for its facilities.
Sure, security systems, policies, and technologies have evolved over time, but their core objective remains the same: to establish barriers between critical assets and unauthorized access. At Stream, we implement the industry-standard “concentric rings” methodology to achieve this goal effectively. This approach leverages multiple layers of protection at the perimeter, exterior, interior, restricted area, asset, and observation levels to deter, delay, and detect threats. For instance, a perimeter fence serves to deter intruders, biometric scanners delay entry to restricted areas, and surveillance cameras help detect the physical location of potential attackers. Between each physical ring lies an “intervention zone,” where observation, detection, and response occur. The idea is that a trigger at any one of these levels is integrated in such a way that it heightens security at the next level.
With this methodology in mind, we created and developed a Physical Security Basis of Design (PS-BOD) and a Construction Security Manual — both of which are instrumental in setting the stage for a secure facility.
The purpose of the PS-BOD is to establish and maintain consistent security design standards across all Stream Data Centers locations. The documents provide clear direction and maintain alignment between the owner, architect, and builder for Stream corporate security requirements. Maintaining the PS-BOD/CSM breeds a proactive approach to ensure our overall physical security posture is in a constant state of readiness.
But what does that really mean?
An effective security policy starts with an unbiased risk assessment — “unbiased” being the key word here. This essential step requires input from a diverse group of stakeholders — together, people from different backgrounds and experiences can identify various risks, some of which may initially seem trivial but could still be significant. After all, the first “computer bug” was, in fact, a moth that flew into the Harvard Mark II Aiken Relay Calculator — a minor issue that carried substantial impacts. That’s why a comprehensive risk matrix not only identifies all potential threats but also rates them based on likelihood and severity to determine the overall risk.
Once you know the risks, it’s time to construct clear policies and procedures to mitigate them. In a perfect world, that means avoiding them all entirely, but in reality, that’s impossible — think natural disasters, for instance. Therefore, a successful security strategy doesn’t guarantee risk-free data centers; it promises resilient ones, meaning there are systems in place to minimize the negative effects when an incident occurs. But testing systems and practicing procedures is vital, which means new threats will be identified and policies will have to be refined again, and again, and again.
Although some security measures are developed around people, information, and equipment separately, most policies provide a certain level of protection for each aspect simultaneously. Because of that, Stream combines these three security pillars into one holistic approach and uses the following guide to establish and maintain protection at each of the six concentric rings.
Observation
Protecting your people and property starts with security systems that monitor activity and access at all times — video surveillance and electronic access control systems fall into this category.
Perimeter
Electronic vehicle gates, anti-climb fences, crash-rated barriers, and lighting are common when it comes to perimeter security. But, some facilities may require more complex measures — especially those in areas prone to natural disasters and high crime rates.
Exterior
Everything from clearing walkways during a snowstorm and installing door locks to putting up signage and designing for crime prevention fits in this ring.
Interior
It’s imperative that interior operations are aligned with security protocols, which means training must be an ongoing process. Periodic policy reviews and emergency drills strengthen your security strategy and provide an opportunity to observe unusual employee demeanor. Any signs of threatening behavior should be addressed immediately.
Restricted access
Access control systems can effectively implement the principle of least privilege, ensuring users are granted only the access necessary to perform their specific tasks with no additional permissions. But, as we move closer to the center of our rings, our protective measures intensify. Heightened security at the restricted access level might require dual-factor authentication, biometric scans, patrol guards, visitor logs, bag searches, etc. This layered approach not only restricts access to critical resources but also fortifies the overall security framework by scaling up defenses in accordance with the sensitivity of the information or systems being protected.
Assets
A lot goes into keeping data center assets safe. Internal operations procedures and access control systems help to mitigate malicious threats, but that barely scratches the surface. IT equipment, HVAC systems, and power supplies are all subject to mechanical or electrical failures that can result in anything from minimal damage to catastrophic loss — not only to the equipment but to the information and the people as well. So, protecting them means complying with local life safety codes, performing regular maintenance, using AI technologies to detect issues early on, addressing building deficiencies, maintaining a safe and clean work environment, hiring employees that exhibit low-risk behaviors, and so much more.
This high-level overview allows us to custom tailor policies and procedures to fit the unique needs of each facility. But, that’s just the start.
The challenge with security is that it isn’t a set-it-and-forget it program you can implement once — the persistence of new threats results in a never-ending cycle of assessment, adaptation, and advancement in protective systems and practices.
To maintain a strong physical security posture, our team of experts undergoes rigorous training. Security officers are required to pass an annual exam in our Global Security Operation Procedures and maintain satisfactory scores on our Security Officer Qualification Cards. Qualification card testing is administered orally between security officers and site supervisors or field training officers. Additionally, we have security operational awareness training, workplace violence prevention, and several LMS courses specified through the contract guard-force provider.
We also validate our security measures by conducting an annual in-house Threat Vulnerability Risk Assessment (TVRA). During the TVRA, we review physical threats, such as crime, collateral damage, weather, wildlife, and site history, and identify opportunities for remediation. Additionally, a third-party vendor performs annual physical penetration tests at our facilities to exploit security vulnerabilities and evaluate our detection and response protocols. These tests include social engineering tactics, false identification, and boundary breaches, all of which are designed to measure the effectiveness of our security policies and our staff’s ability to carry them out.
We don’t simply achieve physical security at Stream — we cultivate a protective environment that continues to evolve and grow with us. That means we’re constantly reviewing our policies to ensure they’re based on an unbiased risk assessment and accompanied by clearly defined and tested procedures that our employees adhere to.
Security challenges aren’t anomalies; they’re normal, everyday occurrences. So, the question isn’t if one will happen, it’s are you ready for it when it does?
