AI Infrastructure

Do Data Centers Need Physical Hardening, or Just Cybersecurity?

Most outages still start in power, cooling and connectivity. The physical dependency chain around the servers is where a determined attacker, and most failures, find the facility.

data centersphysical dependenciessubstation security
Do Data Centers Need Physical Hardening, or Just Cybersecurity?

By Authentic Intelligence Research · Published

Both, and the physical side is the one most often left to default. A data center is only as available as its power feed, cooling plant, fiber paths and access routes, and none of those are protected by a firewall.

Discussions of AI infrastructure risk tend to start at the network: identity, segmentation, model access, supply-chain code. Those controls matter. But a data center is a building full of physical dependencies, and the evidence on what actually takes facilities offline points outside the server hall.

What takes facilities down

Uptime Institute's 2026 outage analysis found that power problems caused 45 percent of impactful outages in 2025. That was down from 54 percent the year before, but power remains the leading cause, and the same report notes fiber and connectivity failures are a growing share. Fifty-seven percent of operators said their most recent major outage cost more than $100,000.

None of those numbers describe an attack. They describe how dependent the facility is on things that sit at its edge: the utility interconnection, transformers, switchgear, generators and fuel, chillers and cooling towers, and the conduits that carry fiber off site. Accidental failure and deliberate attack use the same paths. A design that has not mapped them for one has not mapped them for the other.

The grid has already shown the attack pattern

On December 3, 2022, two Duke Energy substations in Moore County, North Carolina, were damaged by gunfire. About 45,000 customers lost power at the peak, and restoration took until the following Wednesday. Nine years earlier, on April 16, 2013, attackers at PG&E's Metcalf substation cut underground telephone cables and then fired more than 100 rounds into the yard, disabling 17 transformers. There was no blackout, because operators rerouted power, but repairs took 27 days and damage exceeded $15 million.

Both attacks were cheap, fast and aimed at equipment that sat in the open. Neither required any network access. NERC reported to FERC in 2023 that physical security incidents causing measurable outages had increased 71 percent since 2021, while noting that 97 percent of all reported incidents caused no disruption to service. The pattern is low frequency and high consequence, which is exactly the profile that gets under-designed.

Regulation is moving toward the fence line

The electric sector's physical security standard, NERC CIP-014, is being tightened. FERC approved CIP-014-4 on September 10, 2026, with implementation effective October 1, 2028. The revision requires a documented risk-assessment methodology, a single 36-month reassessment cycle, identification of other transmission stations and substations within 1,500 feet of a covered site regardless of owner, and unaffiliated third-party verification of both the risk assessment and the physical security plan. CISA's guidance on substation physical security uses a layered model that includes deter, detect, delay and respond, and recommends considering shielding or obscuring the line of sight to critical components at the most critical substations.

Large data centers are not CIP-014 entities. But they increasingly sit next to, or build, the substations that are. A campus with its own high-voltage yard inherits the substation's exposure whether or not a standard names it.

What owners should map before they specify

Field implication

Cybersecurity protects what the facility computes. Physical design protects whether it computes at all. An AI facility risk plan that starts at the server rack has already skipped the gate, the transformer and the fiber vault.

Sources

  1. Uptime Institute, Annual Outage Analysis 2026
  2. FBI, Shooting of Electrical Substations (Moore County, NC)
  3. Duke Energy, Restoration to all customers in Moore County (Dec. 8, 2022)
  4. NPR, Sniper attack on California power station raises terrorism fears (Feb. 5, 2014)
  5. ASIS Security Management, Utility Attacks (Nov. 2014)
  6. NERC, Report on CIP-014-3 to FERC (2023)
  7. Federal Register, Order Approving Reliability Standard CIP-014-4 (Sept. 15, 2026)
  8. CISA, Sector Spotlight: Electricity Substation Physical Security

Cite this article: Authentic Intelligence Research, “Do Data Centers Need Physical Hardening, or Just Cybersecurity?” Authentic Intelligence, September 30, 2026, https://authenticint.com/articles/data-centers-need-hardened-infrastructure-not-just-cybersecurity.html.

Continue reading

What Does Access Delay Actually Buy a Facility? · How Should Energy and Data Facilities Screen the People With Access?

Return to research library