Sector
Data centres
Physical security here is not about deterrence. It is about evidence: a complete, retained, retrievable record of every person who came within reach of a rack. We design and maintain physical security for data centres and commercial data facilities in Mumbai, specified against what your clients' auditors ask for rather than what a standard specification contains.
A data centre sells trust, and it proves that trust through audits it does not control. Physical security here is not a protective measure, it is an evidence-producing system, and it is judged on whether the record stands up rather than on whether the door held.
What actually goes wrong
The building is secure. The record of it is incomplete.
| What fails | Why it fails | What it costs |
|---|---|---|
| Coverage stops at the hall door | The halls were specified; the route to them was somebody else's scope. | The audit asks for the journey from the entrance to the rack. You have the ends and not the middle. |
| Rack-level access is a key in a drawer | Cabinet locks were treated as furniture rather than as access control. | Hall access is logged to the second. The last metre is not logged at all. |
| Camera and access clocks disagree | Separate systems, never synchronised to one source. | Two records of the same visit, minutes apart. Neither will satisfy an auditor. |
| Contractor access issued permanently | Installation and maintenance vendors given standing credentials for convenience. | Live credentials belonging to firms whose contract ended two years ago. |
| Retention shorter than the audit window | Sized for storage cost, not for how far back a client can ask. | The client asks about a quarter. You hold six weeks. |
| Suppression tested once, at handover | Testing is disruptive and expensive, so it is certified and left. | The system most likely to cause damage if it misfires is the one nobody has exercised. |
Your client's audit is your audit
When your client is audited, you are audited. You just do not get told in advance.
A tenant fails a certification because their provider could not produce a physical access record for a named window. That is not their finding to carry. It becomes a conversation about you, in a room you are not in, with a renewal on the table.
The requirement is not complicated: who entered, when, which hall, which rack, verified by camera, with the two records agreeing on the time. It is complicated to produce if the system was specified for security rather than for evidence, and most are.
The difference does not appear at commissioning. It appears the first time somebody asks.
Check what my facility can actually produceWhat we carry here
- Access control
- Perimeter, building, hall, cage and rack as separate levels
- Every credential attributable to a person and to an authorising party
- Contractor access issued with an expiry, always
- Surveillance
- The complete journey: entrance, corridors, hall, aisle, rack face
- Timestamps synchronised with the access system to one source
- Retention set against your clients' audit windows, not against storage cost
- Fire & life safety
- Detection and suppression that protects equipment without destroying it
- A false discharge costs more than most fires, and the design should say so
- Tested and recorded rather than certified once
- Networking
- Physical security systems on their own segment, never on the operational network
- Logs retained, residency answered, access to them recorded
- Because the security system is itself an audit surface
Building management is usually already in place and specified separately. AV is not part of this.
The same six stages
Everything here is one long chain of custody.
- 01 Outside the gate Approach, standoff, vehicle control. The first link.
- 02 Entry Where an identity is established. Everything after this depends on getting it right.
- 03 Inside the building Corridor to hall to aisle. This is the part most often missing.
- 04 Who goes where Hall, cage, rack. Three levels, and most facilities log one.
- 05 Work areas Halls, plant, UPS and generator. Suppression throughout.
- 06 Control room Its measure is how fast it produces a named person's full journey for a named window.
Proof
The tender asked for an outdoor rack. The rack was going indoors.
A data centre, and the specification had been written at head office and issued without anybody visiting the site. It called for weatherproofing and earthing for a position that was inside a building.
Everybody who quoted it saw the mistake. Nobody said so, because the person who raises a question is the person who loses the tender. So the site got what was asked for.
Then the perimeter was bought separately, a year later, by somebody else, at a lower price, and it will not talk to the platform the rest of the building runs on. Two systems on one site that cannot see each other.
Nobody made a bad decision. Nobody made a decision at all.
Year seven
Access control here degrades the same way it does everywhere, and it matters more.
Every installation vendor, every maintenance visit, every client's own engineer needs access. Each one is issued a credential. Very few are ever revoked, because revoking is nobody's named job.
Nothing fails. The doors work, the logs record. The list of valid credentials simply grows every quarter, and the day somebody counts it against the list of people entitled to be there, the difference is the finding.
Find out what your facility can actually produce.
We test every camera, reader and door, verify that the access and camera records agree on time, and check what a full journey looks like for a named visit. A signed condition report, yours whatever you decide next.
The assessment is chargeable, quoted against the site, and adjusted in full against the first year if you take cover. Where cover is not taken, the fee covers our team’s time on site and the report we leave behind, and the report is yours either way.
Chargeable, and adjusted in full if you take cover.
Book an assessment