Chapter 11.2
In this chapter · 7 sections
Physical Security: Siting, Zones & Kinetic/Drone Threats
Physical security is fixed by siting years before the first attack: standoff, aerial approach paths (drone incursions became a live threat in 2026) and exposed utility ties can bypass a ground-intrusion perimeter, so assess their actual reach and outage consequence before treating detection as protection.
What you'll decide here
- Where on the threat spectrum your facility actually sits — opportunistic theft and vandalism, organized sabotage of single-points-of-failure, or nation-state kinetic/aerial attack — and therefore which zones and counter-measures are justified versus wasted.
- The concentric-zone model you commission to: how many layers, where the access-control and biometric chokepoints fall, and which assets (weights storage, OT cores, the utility tie) sit in the innermost zone.
- Choose the counter-drone action the actual jurisdiction authorizes: passive optical/acoustic detection, RF interception and emitting radar have different legal tests. In the US, map FAA/FCC conditions and the specific agency’s statutory authority before specifying mitigation; a private facility’s ownership alone grants no interception or kinetic authority.
- Trace the substation, gas tie, fiber and water paths an attacker can reach; losing a utility interface can disable a hall without breaching its white space.
- That access control, cameras, and the building-management/EPMS plane are now treated as operational technology (OT) on a segmented network — because the physical-security system is itself a cyber attack surface into the facility.
Treating physical security for an AI data center as a checklist item reduces it to a fence, a guard, a badge reader, some cameras, and a SOC 2 line item that says controlled access. That framing misses the asset and consequence being protected. The reason is partly value-density — a single hall now concentrates billions of dollars of accelerators and, more importantly, model weights whose theft is a strategic, not a financial, event (the asset taxonomy and adversary tiers are set in Chapter 11.1). But the sharper reason is that the threat became kinetic. In March 2026, during the escalation following Operation Epic Fury, Iranian one-way attack drones struck commercial cloud infrastructure in the Gulf — two AWS facilities in the UAE took direct hits and a Bahrain site took blast damage, with AWS reporting structural damage, disrupted power delivery, and fire-suppression water damage (DefenseScoop, Mar 2026). The event illustrates aerial exposure; it does not supply a universal attack probability for another site. For site selection, civilian compute now sits at the intersection of economic and political pressure, which makes it a target.
The chapter moves outward-to-inward and then up into the air. Siting comes first — the most irreversible physical-security decision, made before any zone exists — then the concentric-zone model, with access control, biometrics, and surveillance placed inside it. Two threats the perimeter model handles badly close it out: aerial (drones) and kinetic/sabotage against the single-points-of-failure outside the fence, along with the physical-cyber convergence that turns the security system itself into an OT attack surface.
Siting as a physical-security decision
The earliest physical-security choice is where the slab goes, and it is made for power and latency reasons (the reordered siting hierarchy is in Chapter 3.1) long before a security engineer is in the room. That is the problem: by the time security is consulted, the standoff distance, the airspace overhead, the proximity to a hostile border, and the routing of the utility tie are already fixed in concrete. Standoff — the distance from the public road or fence line to the critical building — is the cheapest blast and small-arms mitigation that exists, and it is free at scoping time and ruinously expensive to retrofit. The available standoff and required controlled perimeter are site-specific; assess them against the threat model, construction, assets and land constraints — down to details as concrete as whether the loading dock opens onto a public street.
Siting also sets the threat tier you must design against, and this is where the global, vendor-neutral view matters. A facility in a politically stable interior region defends mostly against opportunistic theft, insider misuse, and protest activity. A facility within drone or missile range of an active or latent conflict — the Gulf, parts of Eastern Europe, contested maritime regions — must design against a kinetic adversary, which changes everything from glazing to dispersal architecture. The 2026 Gulf strikes are the proof: the same hyperscaler's facility is a fence-and-badge problem in one region and a war-infrastructure problem in another. The siting decision pre-selects which of those two buildings you are operating, and you cannot move a slab.
The concentric-zone model
The organizing pattern for everything inside the fence is concentric zones — nested rings, each crossing requiring stronger authentication and granting access to higher-value assets, provided credential scope, emergency exits, service routes and shared administration do not bypass the next boundary. This is defense-in-depth expressed physically. The number of zones is the design variable: derive it from the protected assets, credible access paths and response time, using the RAND framework in Chapter 11.1 for the weight-theft threat. A higher target can justify dual control and stronger inner access without prescribing a ring count. The principle is that asset, adversary, safety and access-path analysis set the boundaries — you push the highest-value assets (weights storage, the OT/control core, the key-management hardware) to the center and make the path to them long, observed, and authenticated at every step.
| Zone | Boundary | Primary controls | Assets protected | What a thin layer costs you |
|---|---|---|---|---|
| 0 — Approach | Public road to fence line | Standoff, berms, vehicle barriers, lighting, ANPR cameras | Standoff distance itself | Vehicle-borne blast reaches the building; no warning time |
| 1 — Perimeter | Fence / wall line | Anti-climb fence, intrusion detection (PIDS), CCTV with analytics, patrols | The campus envelope | Cut-and-climb intrusion undetected; trespass to inner zones |
| 2 — Site / yard | Inside the fence | Gatehouse, badge + vehicle inspection, mantrap at building face | Substation, generators, fuel, fiber vaults | Sabotage of un-fenced single-points-of-failure (see below) |
| 3 — Building | Building shell | Badge + biometric, anti-tailgating, visitor escort, no public lobby | Office, NOC, staging, loading dock | Tailgating and social-engineering reach the white space |
| 4 — Data hall | White space door | Two-factor (badge + biometric) mantrap, anti-passback, escorted vendors | Racks, cages, network core | An insider or escorted vendor reaches racks unobserved |
| 5 — Cage / core | Cage, weights store, OT room | Two-person rule, dedicated biometric, tamper-evident cabinets, full audit | Model weights, HSM/KMS, OT/EPMS controllers | Theft of weights or OT compromise — a strategic loss |
Read the table as a depth budget. Every ring you add buys detection time and forces the adversary to defeat another distinct control type — which is why the value is in heterogeneity, not just count: a badge reader on every door is one control defeated five times; a badge plus biometric plus a two-person rule plus tamper-evident hardware is four different defeats. The economics are direct: zones are cheap to specify at design time and expensive to retrofit, so the depth budget is a density-ramp decision — a hall scoped today for three zones cannot easily grow a weights-bearing fifth zone later without re-planning circulation, doors, and the OT room. If there is any chance the facility hosts frontier weights, reserve the innermost-zone footprint now, the same way you reserve floor loading and water for a cooling ramp.
Access control, biometrics, and surveillance
The zone model is only as good as the chokepoints that enforce it. Three control families do the work, and each carries a decision with a downstream cost. Access control — badges, PINs, and increasingly mobile credentials — is the backbone, but its failure modes are tailgating and credential sharing, which is why the meaningful controls are anti-tailgating mantraps, anti-passback (you cannot badge in twice without badging out), and turnstiles rather than swing doors at the high-value boundaries. Biometrics — fingerprint, facial, iris, vein — raise the bar from something you have (a clonable badge) to something you are, and biometrics is the fastest-growing segment of the physical-security spend precisely because credential theft is the cheap attack. But biometrics imports its own decisions: a privacy/data-residency obligation on the biometric template (which is personal data under GDPR and equivalents — data governance in Chapter 10.10, residency and sector overlays in Chapter 11.11), a false-reject rate that throttles legitimate throughput, and a spoofing surface that demands liveness detection.
Surveillance is the third leg, and 2026 changed its economics: AI video analytics turn cameras from a forensic record (useful only after the fact) into a real-time detector — loitering, line-crossing, abandoned-object, and crowd analytics that alert before the breach completes. The fork here is record-and-review versus detect-and-respond. A passive CCTV estate is cheap and exonerates you in the post-mortem; an analytics-driven estate is more expensive, generates false positives that must be staffed, but compresses the detection-to-response time that is the whole point of the concentric model. For a high-value facility the answer is detect-and-respond, because the depth budget you bought in the zone model is wasted if nobody is watching the rings in real time.
Scope & caveats
Load loss as seen by the grid. NERC's incident review ('Load Details') found the affected data centers transferred their loads to backup power — static UPS, decentralized rack UPS, or DRUPS — in response to the disturbance. The figure is a loss of demand at the interconnection, not evidence that IT power was interrupted or that training jobs restarted.
The approximately 1,500 MW is the total customer-side load reduction coincident with the six-fault sequence; NERC reports approximately 1,260 MW as the sustained drop at the third voltage depression. The NERC-investigated canonical case. A second, larger occurrence followed on 2026-07-22: ~3.8 GW dropped on a single normally-cleared Ashburn 230 kV fault (see companion key number). Two vintages of the same failure mode, not a replacement figure.
Aerial threats and counter-UAS
The perimeter model assumes the threat arrives along the ground. Drones break that assumption: they ignore standoff, fence, and mantrap entirely and arrive over the top, on the one axis the concentric zones do not cover. The 2026 Gulf strikes are the proof-of-concept at the nation-state end of the spectrum, but the more pervasive risk is cheaper — a commercial FPV quadcopter or a fixed-wing one-way drone costing a few hundred dollars can carry a small charge to a rooftop chiller, a transformer yard, or a CDU plant, or simply hover with a camera over a yard the fence was supposed to protect. The asymmetry is decisive: a sub-$1,000 airframe against a facility worth hundreds of millions, attacking exactly the un-hardened single-points-of-failure (cooling, power tie, fuel) that the ground perimeter leaves exposed.
Here the decision is sharply constrained by law, and not along the line most operators assume: mitigation is closed to a private operator, and detection is not a single legal category. The DOJ/FAA/DHS/FCC interagency advisory is explicit that the analysis does not turn on active-versus-passive or detection-versus-mitigation; it turns on what a given sensor actually collects and transmits. Passive acoustic and optical sensing is the clean case. A system that captures or uses the radio link between a drone and its controller can implicate the Pen/Trap Statute and the Wiretap Act, and any emitting system — radar included — needs FCC authorization (UAS-detection radar requires a Radiolocation Service license) as well as FAA clearance. Assess each sensor's collection and transmission functions, your own authority, and the available exceptions before the purchase order, not after. Defeating a UAS — jamming, spoofing, capturing, or downing it — collides with federal statutes (the Wiretap Act, 18 U.S.C. §32 on aircraft sabotage, and FAA airspace rules), and the authority to do so has historically been reserved to a narrow set of federal agencies. The FY2026 NDAA opened the first crack in that wall, creating a statutory path for certified state, local, and tribal law enforcement to deploy counter-UAS after DOJ training — but a private data center operator still has no legal authority to take a drone down. The consequence is decisive for design: your counter-UAS program is a detect-classify-alert-and-coordinate program, not a kinetic one. You build airspace awareness and a fast line to the agencies who can act; you do not build a jammer you are not allowed to switch on.
| Capability | Function | Legal status for a private US operator (2026) | Design implication |
|---|---|---|---|
| Passive acoustic / optical detection | Detect & track an approaching UAS without emitting or intercepting | Generally permitted — no interception, no emission | Build airspace awareness into the SOC; integrate with CCTV |
| RF interception / active radar | Detect via the drone's control link, or by emitting and receiving | Fact-specific: RF capture can implicate the Pen/Trap Statute and Wiretap Act; radar needs an FCC Radiolocation license | Counsel and FCC/FAA authorization before procurement, not after |
| Optical / EO-IR classification | Identify payload, intent, model | Permitted | Cue response and evidence; feed law-enforcement handoff |
| RF jamming / spoofing | Sever the control link, force land | Prohibited — federal authority only (NDAA opened narrow LE path) | Cannot deploy; rely on coordinated LE / federal response |
| Kinetic / capture / net | Physically down or capture | Prohibited for private operators | Out of scope; harden the targets instead |
| Hardening & dispersal | Reduce consequence of a hit | Fully permitted | The operator's real lever: rooftop hardening, geo-dispersal, redundancy |
Because mitigation is mostly off the table for the operator, the engineering response shifts from stopping the drone to surviving the hit — a resilience decision rather than a security-guard one. Two levers dominate. Hardening the exposed single-points-of-failure: protective screens or cages over rooftop chillers and CDUs, blast-resistant transformer enclosures, and structural separation so a rooftop strike does not propagate into the white space. Dispersal and redundancy: the West Point analysis of the 2026 strikes argued the durable defense is architectural — spread critical capacity across multiple sites and power/cooling trains so no single drone-deliverable charge takes down the workload. This is the same logic the reliability chapters apply to random failures (goodput-over-availability in Chapter 12.2), now applied to a deliberate adversary: the cheapest way to beat a $500 drone is to make sure hitting any one target does not matter.
Kinetic and sabotage resilience: the targets outside the fence
The most under-defended attack surface is not the data hall — it is the cluster of overlooked single-points-of-failure that sit outside the building and often outside the fence: the substation and the utility tie, the on-site generators and their fuel, the behind-the-meter gas connection, the fiber entrance vaults, and the make-up water supply. A saboteur does not need to reach a rack to take the facility down; an angle grinder on a substation, a rifle round through a transformer radiator, or a few minutes with the fiber vault strands the entire load. The grid data makes the prize concrete: a 2024 Virginia transmission-line fault sequence — a lightning-arrestor failure on a 230 kV line, whose staggered auto-reclosing produced six faults in 82 seconds — dropped roughly 1,500 MW of exclusively data-center load customer-side, with about 1,260 MW staying off the system for hours (NERC). That is the consequence of a successful hit on the tie — and because a damaged utility tie or large substation transformer may require new equipment, repair, study and service on a path whose duration must be established for that asset (Chapter 4.3), the substation is a single-point-of-failure that cannot be restored on the timescale of a rack swap.
The decision fork is how far to extend the concentric-zone model and the hardening budget to these external assets. The cheap, often-skipped controls are: pulling the substation and fuel inside the fenced and monitored Zone 2 rather than leaving them on a public easement; ballistic-rated or screened transformer enclosures; diverse, physically-separated fiber entrances (so cutting one vault does not isolate the site); and intrusion detection on the yard, not just the building. The consequence of skipping them is that you have built five concentric zones around the racks and left the thing that powers them sitting on the roadside. The physics of these failure modes — the synchronized load step, the thermal runaway from a disabled CDU — are dual-use: the same events appear as random faults in the reliability chapters and as deliberate weapons in the OT-attack chapter. Transient physics is in Chapter 4.5; the destructive-attack treatment of OT systems is in Chapter 11.10.
Deep dive: cage and rack controls — the last meter, and the insider problem
Inside the data hall, the concentric model gets granular, and the threat profile shifts from outsider to insider and escorted-vendor — which is the dominant unaddressed vector treated fully in Chapter 11.9. At the cage and rack level the controls are: lockable cages and cabinets with electronic access logging (who opened which cabinet, when, mapped to a ticket); tamper-evident seals on the cabinets holding weights-bearing storage and the HSM/KMS hardware; a two-person rule on the innermost cabinets so no single credential — even a privileged one — opens the crown jewels alone; and full audit of every cage entry, retained and reviewed, not just recorded. The point of cage controls is that the perimeter and zone model assume the adversary is outside; cage controls assume the adversary already has legitimate access to the hall and is trying to reach a specific cabinet.
The decision here is granularity-versus-friction. Per-cabinet electronic locks and two-person rules slow legitimate maintenance and add cost, so a low-value colo cage runs a simple lock and a camera. A weights-bearing cage at a high Weights Security Level runs per-cabinet logging, tamper-evidence, and a two-person rule, accepting the operational friction because the asset is a strategic one whose theft cannot be undone. This is where physical security and the weight-protection discipline meet: the at-rest protection of weights in Chapter 11.8 assumes the physical cabinet they live in is itself a controlled, audited, tamper-evident boundary — the cage control is the physical floor under the cryptographic ceiling.
Physical-cyber convergence: the security system as OT
The final decision is the one most likely to be missed, because it inverts the chapter: the physical-security system is itself a cyber attack surface. Access-control panels, biometric readers, the CCTV/VMS estate, and — most dangerously — the building-management system (BMS) and electrical-power-management system (EPMS) that the security team often co-owns are all networked devices running embedded firmware, frequently on flat networks with default credentials and vendor remote-access tunnels. They are operational technology, and they must be treated as OT: segmented off the corporate and production networks, patched, monitored, and access-controlled the same way any other control plane is. The convergence cuts both ways. An attacker who compromises the access-control system can unlock the doors the concentric model relies on; an attacker who reaches the BMS/EPMS can manipulate cooling and power directly — turning a cyber intrusion into a physical, destructive event (the forced load step, the disabled CDU, the BESS runaway).
The fork is organizational as much as technical: who owns the security/BMS network, and is it on the OT-segmentation program or orphaned as facilities IT? The 2026 best practice — and the convergence that the industry guidance now emphasizes — is a single converged security function where physical and cyber are not separate fiefdoms, the cameras and door controllers live behind the same microsegmentation as any other OT, and the BMS/EPMS sits inside the OT zones of the Purdue model rather than on a flat facilities VLAN. The downstream cost of the un-converged organization is the seam: a physical team that owns the cameras but not their network security, and a cyber team that does not know the door controllers exist, leaves exactly the gap a converged adversary walks through. Network segmentation and the zero-trust treatment of these planes is in Chapter 11.7; the destructive OT-attack physics and the safety-instrumented-system independence that a compromised control plane cannot override are in Chapter 11.10; the cooling-controls plane specifically in Chapter 5.12.
Deep dive: cameras and door controllers are OT, not appliances
It is tempting to treat IP cameras, NVRs, and badge panels as plug-and-play appliances — they ship working, they are bought by facilities, and they are rarely on the CISO's asset inventory. That is precisely why they are a favored foothold. They run embedded Linux or RTOS firmware that is patched late or never; they ship with documented default credentials; many phone home to vendor clouds over outbound tunnels that bypass perimeter controls; and they are often dual-homed between the security VLAN and something more sensitive. A compromised camera is a quiet pivot point inside the building network; a compromised door controller can unlock the mantrap that the entire concentric-zone model depends on; a compromised VMS can blind the SOC during a physical intrusion.
The control set is ordinary OT hygiene applied to gear nobody thought of as OT: inventory every device and put it on the asset register; segment the physical-security and BMS/EPMS networks away from corporate and production (microsegmentation per Chapter 11.7); kill default credentials and disable or proxy vendor remote-access tunnels; patch firmware on a managed cadence with provenance checks (the firmware-integrity discipline of Chapter 11.4 applies to a door controller as much as to a BMC); and monitor east-west traffic so a camera that suddenly talks to a domain controller raises an alarm. The unifying idea: the device that enforces your physical security is also a host on your network, and an adversary who owns it owns both planes at once.
Anti-patterns
The same physical-security mistakes recur, each from reasoning about one layer in isolation:
- Hardening the core, ignoring the tie. A flawless five-zone interior wrapped around a substation, fuel farm, and fiber vault sitting un-fenced on a public easement. The adversary strands hundreds of megawatts without ever touching a rack — and the restoration path still needs a compatible transformer, transport, permits, installation and energization.
- Buying a counter-UAS weapon you cannot legally fire. Procuring jammers or kinetic interceptors that a private US operator has no authority to deploy, instead of investing the budget in detection, law-enforcement coordination, rooftop hardening, and dispersal — options whose local authority, permitted use and site effectiveness still need confirmation.
- Orphaning the security network. Treating cameras, door controllers, and the BMS/EPMS as facilities appliances outside the OT-segmentation program, leaving default credentials and vendor tunnels as the seam between the physical and cyber teams that a converged adversary walks through.
- Designing zones for the wrong asset class. Scoping the access boundaries for an enterprise inference hall contractually barred from frontier weights, then admitting frontier inference without reassessing access paths, response time and credential scope for its weights and adversary class — the physical-security equivalent of the density-ramp trap, where the irreversible substrate (circulation, doors, OT room) was never reserved.
Fund barriers, response and alternate-service capacity against the chosen adversary’s access paths, including substation, fuel and fiber outside the hall. Additional zones consume space and slow service; omitted paths can defeat every interior door. Reserve irreversible circulation and protection provisions before admitting an asset class that needs them.
Cite this chapter
Fehn, J. (2026). Physical Security: Siting, Zones & Kinetic/Drone Threats (Chapter 11.2). The Definitive Guide to AI Data Centers. https://aidatacenterguide.com/part-11-security/11-2-physical-security-siting-zones-and-kinetic-drone-threats (accessed 2026-09-29).
@misc{aidc-11-2,
author = {Fehn, Jacob},
title = {Physical Security: Siting, Zones & Kinetic/Drone Threats (Chapter 11.2)},
howpublished = {The Definitive Guide to AI Data Centers},
year = {2026},
url = {https://aidatacenterguide.com/part-11-security/11-2-physical-security-siting-zones-and-kinetic-drone-threats},
note = {Accessed 2026-09-29}
}