Data Centres: the convergence of the physical and digital environments

Data Center

00:03. A door opens. A technician enters a critical room. He attempts to access a sensitive rack. The system must not only know who he is: it must know whether he is authorised to be there, why, for how long, and what other events are triggered if something is amiss. Nothing in data centres can be left to chance; a single security breach can compromise the availability of essential services, the integrity of information, and disrupt critical banking, industrial, healthcare, energy, logistics and corporate operations. 

 

Data Centres in the Spotlight

Such is their importance that the new NIS2 regulation already classifies digital infrastructure as a critical sector, imposing new technical requirements to ensure service continuity. Although infrastructure has improved, the complexity of modern architectures and the evolution of both internal and external threats continue to generate new risks that must be actively managed.

It is common to think of the vital importance of protecting the data housed in these facilities; however, it is worth remembering that protecting the infrastructure is critical to achieving this. One of the challenges facing this sector is the multitude of people who must pass through the facility: from internal staff to specialist technicians, including operators, suppliers, private security, cleaning staff and accredited visitors. 

To ensure that only authorised personnel gain access to designated areas, DORLET offers specific solutions, such as two-factor authentication, which requires two valid forms of identification—be it a card, a digital badge (DMA) and/or biometric data (fingerprint, facial recognition, iris scan, etc.)—to be presented before access is granted. In the event of forced access under threat, DORLET offers a coercion feature, which allows access via card or code but sends an alert to the control post so that appropriate action can be taken. 

As is evident, there are areas with a high level of sensitivity; we are referring to technical rooms, rack rooms, power or air-conditioning areas that require specific measures to prevent anyone, except those authorised to do so, from gaining access to them. 

To achieve this, it is not only necessary to configure profiles, schedules, authorised areas and reasons for access; it is also highly recommended to deploy anti-reverse locks, room control systems that alert the control centre if the permitted time is exceeded, or the escort function, which only validates access if two authorised persons present their credentials.

Clearly, it is not enough simply to know who is entering, where they are entering and for what purpose; it is also necessary to review these permissions on a regular basis, detect any deviations, manage temporary access for suppliers or visitors, and generate auditable evidence in the event of any incident.

 

Integration, traceability and continuous auditing

In addition to the need for traceability, data centres require a comprehensive approach that encompasses system integration. Access control must communicate with VMS, intrusion detection, fire systems, visitor management, accreditation, perimeter alarms… Only in this way is it possible to build a complete picture of the risk and respond in a coordinated manner to emergency situations. 

But this is only the most visible part. To protect critical infrastructure, it is not enough to control who physically accesses it. It is also essential to ensure that the access control solution itself is cyber-secure.

 

Convergence between physical security and cybersecurity

This is where DORLET offers distinctive value with SHeld, a cyber-secure access control solution featuring fully protected and encrypted end-to-end communications between the various components of the system. This means that each component encrypts the information it sends, ensuring that any attempt to steal data would have to target one of the encrypted communications, thereby preventing sabotage even in the face of highly sophisticated cyberattacks.

It is worth noting that SHeld is the first and only cyber-secure access control solution included in the ICT Products and Services Catalogue (CPSTIC), a tool promoted by the National Cryptology Centre (CCN) that provides usage recommendations for public administrations.

 

DORLET at DCD>Connect Madrid

With the aim of showcasing this solution to data centres, DORLET has been exhibiting at DCD>Connect Southern Europe, a key event for the digital infrastructure ecosystem which took place on 6 and 7 May at IFEMA-MADRID.

The fact is that DORLET’s solutions go beyond the paper: they are implemented in flagship projects such as Merlin-Edged (Madrid, Barcelona and Bilbao), the Barcelona Supercomputer and DAMAC Riyadh (Saudi Arabia), amongst many others. Please do not hesitate to contact us if you would like to know more about our most recent projects. 

Do you think we can help you? Send an email to online@dorlet.com!