Supply Chain Trust

Why Vet Vendors Before Data Center Construction Starts?

A facility is most exposed while it is being built. Drawings, schedules, rooms and equipment pass through dozens of third parties before the first server arrives.

vendor vettingcontractor accesssupply chain risk
Why Vet Vendors Before Data Center Construction Starts?

By Authentic Intelligence Research · Published

Because construction exposes the facility first. Design documents, schedules and unfinished rooms pass through many hands before the site goes live, so vetting the people and firms involved is a security control, not procurement paperwork.

Owners tend to think of security as something a building gets when it opens. By then, much of the sensitive information about it has already circulated. Structural and electrical drawings, equipment schedules, the location of the network core and the fiber entries, the generator and fuel layout, and the access-control design are all shared with architects, engineers, general contractors, subcontractors, suppliers and inspectors. Rooms that will later be locked are open for months.

The best-known case started with a refrigeration contractor

The Senate Commerce Committee's 2014 "kill chain" analysis of the 2013 Target breach found that attackers first stole the network credentials of Fazio Mechanical Services, a Pennsylvania refrigeration contractor, through malware-infected email. From that foothold they reached the payment system. The breach exposed 40 million card accounts and personal information for up to 70 million customers. The report also found that Target failed to act on multiple automated warnings and likely had not fully isolated sensitive systems from vendor access.

The lesson owners took from it was about network segmentation. The broader lesson is that a building-services contractor was a trusted party with access that nobody had sized to its risk. Data centers depend on exactly those contractors for power, cooling, fire protection and controls.

Frameworks already exist

NIST SP 800-161 Rev. 1 sets out a multilevel approach to cybersecurity supply chain risk, built into an organization's existing risk management. It addresses products that contain malicious functionality, are counterfeit, or are vulnerable because of poor manufacturing and development practice. CISA's ICT Supply Chain Risk Management Task Force, formed in 2018, publishes practical tools on the same problem.

For physical access, the Interagency Security Committee's best practice on facility access control, written for federal facilities, is a useful model for private ones. Where a facility decides visitors need an escort, it sets escort levels by risk, with the highest requiring continuous monitoring within ten feet and briefings before and after. It also covers checking identity documents for fraud or tampering. The electric sector's CIP-004 standard requires that contractor and vendor personnel meet the same screening requirements as employees before they get unescorted access.

What to put in the contract

Field implication

A facility's trust chain starts with the first vendor who sees the drawings. Vetting at that stage costs little; discovering the gap after opening costs a redesign.

Sources

  1. U.S. Senate Committee on Commerce, Science, and Transportation, A "Kill Chain" Analysis of the 2013 Target Data Breach (Mar. 26, 2014)
  2. NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices
  3. CISA, ICT Supply Chain Risk Management Task Force
  4. Interagency Security Committee, Facility Access Control: An ISC Best Practice (2020)
  5. CISA, Defining Insider Threats (third-party threats)
  6. NERC, CIP-004-7 Cyber Security: Personnel & Training

Cite this article: Authentic Intelligence Research, “Why Vet Vendors Before Data Center Construction Starts?” Authentic Intelligence, September 30, 2026, https://authenticint.com/articles/vendor-vetting-for-data-center-construction.html.

Continue reading

How Should Energy and Data Facilities Screen the People With Access? · What Happens When a Building Becomes an Evidence System?

Return to research library