As AI workloads reshape the data center, operators are managing facilities that carry more critical infrastructure, more sensitive data, and greater financial value than ever before.

A security incident that might once have been considered a localized operational issue can now have significant financial, operational, and reputational consequences.

For Etienne Van Der Watt, vice president at Axis Communications, this changing landscape requires operators to rethink how they approach security:

"If we look a little bit deeper, the risks that we see today aren't entirely new. What’s really changed is the value of what’s being protected."

Expanding workloads, increasingly complex operations, and evolving threats are forcing operators to adopt a more agile mindset. As technology cycles continue to develop at pace, long-standing security strategies must upgrade in tandem.

In a recent DCD>Talks episode, Van Der Watt explores the evolving security landscape and shares his recipe for data center resilience.

GettyImages-2174551157 (1)
– Getty Images

Let's get physical

While cybersecurity often dominates discussions around data center protection, physical security remains equally critical.

According to Van Der Watt, operators must look beyond traditional concerns about perimeter breaches and recognize the growing complexity of both external and internal threats:

"Today, it's not just about forced entry anymore. Operators need to think about social engineering, contractor misuse, supply chain exposure, drone detection risks, and attempts to exploit weak operational processes."

The nature of physical attacks is changing. Rather than pursuing obvious points of entry, those that pose a threat are increasingly looking for weaknesses in procedures, vendors, devices, and day-to-day operations.

"Attackers are becoming more patient," says Van Der Watt. "They may look for process weaknesses over time rather than searching for an obvious breach. They're examining people, processes, vendors, devices, networks, and procedures to identify what can be exploited."

The result is a threat landscape that extends far beyond fences, gates, and cameras. Physical security now requires a broader operational view that considers how facilities are managed, who has access, and how security systems interact with the wider business.

Building resilience

For operators looking to strengthen security, Van Der Watt recommends starting with foundational design principles rather than individual technologies.

"The first approach is to make sure we have layered detection zones," he says.

This means moving beyond a single perimeter defense model. Fence lines, vehicle access points, operational areas, building entrances, and critical internal spaces should each form part of a structured security architecture with their own detection, protection, and response requirements.

The second principle is early detection and verification: "If we're going after early verification, we need to know what is happening in each zone and be able to respond quickly," says Van Der Watt.

Video analytics, radar systems, thermal detection, and other monitoring technologies must work together to provide accurate information while reducing false alarms. The goal is to ensure operators receive actionable intelligence, rather than an unmanageable volume of alerts.

The third principle involves planning beyond the perimeter. Many facilities continue to focus heavily on preventing an initial breach. But while perimeter protection remains important, Van Der Watt argues that modern security strategies should assume that attackers may eventually reach secondary layers:

"Sometimes, we should expect that the first layer will be breached. Your system becomes really smart on layers two, three, and four."

The final consideration is lifecycle management. Operators must understand how long devices should remain in service, when they should be upgraded, and how they will be maintained throughout their operational life.

AI as part of the solution

While AI is increasing the scale and value of many data center environments, driving up complexity, it’s also becoming an important security tool. One of the most immediate benefits lies in reducing pressure on security teams.

"AI is helping us limit false alarms," explains Van Der Watt. "Security teams no longer have to manage hundreds or thousands of alerts every day. It's helping them distinguish what’s a real threat and what requires action."

The technology is also accelerating investigations. AI-powered analytics can quickly identify relevant footage, reducing the time operators spend reviewing video footage after an incident and underpinning informed decisions based on accurate information.

"A good example is text search over video," continues Van Der Watt. "You can use metadata and search for somebody wearing a red hat, for instance, and the system can bring that person or incident up immediately."

Beyond badges and biometrics

Traditional access control technologies still have their place, but Van Der Watt argues they can no longer operate in isolation. Badges and biometric systems can confirm credentials, but they don't always provide the context needed to fully understand whether an individual should be in a particular location at a particular time.

"A badge tells you what credentials are presented," he says. "It doesn't always tell you who the person is, why they're there, whether they're in the right zone, or whether they're there at the right time."

This is where integrated security platforms become increasingly valuable. By combining access control systems with video surveillance, analytics, radar, and other technologies, operators gain a clearer picture of how individuals move throughout a facility.

"The movement of individuals within a space becomes really critical for us," says Van Der Watt. "It's an important layered approach that goes beyond simply looking at biometrics or cards."

Closing the access gap

With significant advances in security technology, many existing vulnerabilities stem from existing operational practices rather than technical limitations.

"I think most access gaps aren’t caused by a lack of technology," argues Van Der Watt. "They're really caused by weak processes and a lack of discipline."

Examples include sharing credentials, tailgating, delayed removal of contractor access privileges, and infrequent reviews of user permissions. In fast-growing environments, these minor issues can quickly accumulate into a much larger threat.

Security infrastructure itself can also introduce vulnerabilities. Default credentials, outdated firmware, unpatched devices, and poorly segmented networks are common concerns across access control systems, cameras, and intercoms.

For operators, regular audits of access rights and device security remain among the most effective ways to reduce exposure.

Balancing security and compliance

As surveillance technologies become more sophisticated, operators must also navigate an increasingly complex regulatory environment.

"Each market has different expectations when it comes to personal data, biometrics, video retention, and data movement," says Van Der Watt.

Rather than relying on a single global template, operators require security architectures that can adapt to local regulatory requirements while maintaining consistent governance standards.

To achieve this balance, Van Der Watt recommends three priorities: minimizing data collection, processing information at the Edge wherever possible, and building security into systems from the outset.

Security as operational intelligence

The role of security is expanding beyond protection alone. Modern platforms generate vast amounts of structured data that can support operational efficiency and critical decision-making at the same time.

"What we can do today is detect environmental risks, support compliance reporting, improve contractor visibility, and provide audit trails," says Van Der Watt.

Organizations can verify that documented procedures are being followed, gain greater visibility into site operations, and replicate successful practices across multiple facilities more quickly.

As data centers continue to grow in scale and strategic importance, security is becoming more proactive, intelligent, and more tightly integrated with operations.

For Van Der Watt, the central message is clear: operators must move beyond viewing security as a post-incident function. Resilience in the AI era will increasingly come down to a combination of strong processes, layered protection, and intelligent technologies to anticipate risks before they become incidents.

To hear more about building data center resilience, listen to the full DCD>Talks episode with Etienne Van Der Watt, here.