Physical security protects a data centre's equipment, and its customers' data, from unauthorised access. Standards are highest in facilities that host Australian Government data, where certification under the Hosting Certification Framework and agency security requirements apply. CDC, for example, lists 24/7 on-site security operations at its Canberra campuses.
This page covers physical security. Cyber security is a separate discipline and is not covered here.
The Role of Security in Data Centres
Data centre security is layered, with each layer adding an independent control:
- Site perimeter: fencing, vehicle barriers, anti-ram protection, lighting and intrusion detection
- Site entry: gatehouses, vehicle inspection, visitor registration
- Building entry: access control, turnstiles, mantraps (interlocking doors that admit one person at a time)
- Data hall entry: additional authentication, often biometric
- Cage and rack level: customer-specific locks and access logging
- Monitoring: CCTV coverage, a security operations room, alarms and audit trails
Key Infrastructure Requirements
Perimeter security
Hardened fencing, crash-rated barriers where required, perimeter intrusion detection and lighting designed with the CCTV system.
Access control
Card or credential systems integrated with visitor management and HR processes, with anti-passback and time-based permissions.
CCTV
Coverage of perimeters, entries, corridors and data halls, with retention periods set by customer contracts and government requirements.
Biometrics
Fingerprint, iris or facial recognition at high-security entry points, usually combined with a card and PIN.
Visitor and contractor management
Pre-registration, identity checks, escorts, induction and tool and equipment controls. This affects every contractor working on an operating campus.
Government facilities
Facilities hosting classified government data have additional physical security requirements, cleared personnel and separation of government customers. See Canberra data centres for the Hosting Certification Framework and related frameworks.
Critical infrastructure obligations
The Security of Critical Infrastructure Act 2018 covers data storage and processing assets, adding risk management obligations that include physical security.
Australian Security Suppliers
Directory listings for this category are being verified before they are published. Supply to data centre projects? Add your company to be considered.
| Type | Typical scope |
|---|---|
| Security consultants | Threat and risk assessment, security design |
| Electronic security integrators | Access control, CCTV, intrusion detection, integration |
| Perimeter and physical barrier suppliers | Fencing, bollards, barriers |
| Guarding and security operations | Manned security, control room operations |
Selecting a Supplier
- Relevant state security licences for installation and guarding
- Security-cleared personnel where government facilities require them
- Integration experience across access control, CCTV, BMS and visitor management
- Ability to work in live, operating facilities under strict change control
- Maintenance and response SLAs
Current Project Demand
- New campuses need complete perimeter-to-rack security systems: Marsden Park, Laverton, Maddington, Beard and SYD01 Artarmon, then S7, MEL2, M4 and the Mamre Road campus
- Government-focused capacity (CDC Beard, ADC Fyshwick's capital works, CDC Perth's defence and sovereign focus) raises demand for cleared personnel
- Operating campuses need ongoing guarding and security operations
Relevant Data Centre Projects
List Your Company
Grow Your Data Centre Pipeline
AISB helps security integrators, consultants and guarding providers build visibility with operators and head contractors, including in government-focused facilities.
See something that needs updating? Submit a correction.

























