Perimeter to rack, one architecture

Physical Security Architecture for European Data Centres

Data centres carry more risk per square metre than almost any other facility type. Hardware theft, insider access to high-value systems, cross-tenant exposure in colocation cages, tailgating through secured zones, and perimeter reconnaissance are daily operational realities, not edge cases. Primion secures your facility across six security layers, from the outer perimeter to the individual rack, with one converged security architecture built specifically for data centres.

lynn Qn7dUULTZhs unsplash scaled

4.5

million is the average cost of a data breach

60%

of incidents involve an insider component

Complete physical security architecture engineered for data centres

Physical security in a data centre only works as an interlocking system. Primion brings access control, video, intrusion detection, visitor management, environmental monitoring, and event management together into a single integrated security system. Every event is recorded, every audit trail remains complete, and the system keeps working even when the connection to the core network isn’t.

Perimeter and approach detection

Security starts before anyone reaches the building. Zone 1 combines radar, LiDAR, and acoustic sensors to detect fence interference, with thermal imaging. Drone detection radar and RF scanning identify unmanned aircraft, while optical tracking follows activity across the full perimeter.

Every detection event is triaged automatically by priority, with video verification and continuous audit logging from first detection through to resolution.

Vehicle access and gate control

Zone 2 controls every vehicle at site entry. Licence plate recognition identifies approaching vehicles, induction loops confirm presence in the gate lane, and underbody scanning and video intercom verification run before any barrier opens. Anti-ram barriers and motorised gates stop forced entry.

Access decisions are made locally at the gate, so operations continue even if the connection to the core system drops. Detect, identify, control, log: one fixed sequence, with no step skipped.

Building access and the security lobby

Zone 3 is where access control becomes physical. Mantraps enforce two-door separation so only one person passes per cycle, making tailgating physically impossible rather than just policy-prohibited. Speed gates with tailgating detection handle higher-traffic entrances, and secure readers support RFID, mobile credentials, PIN, and biometrics.

High-security doors fail-secure. Every escape route fails safe, without exception, because protecting life always takes priority over access control.

White space and technical areas

Zone 4 covers server halls and technical rooms, where access runs on role-based rights, time slots, and presence logic enforced locally at the door. A technician authorised for one hall isn’t automatically authorised for another.

Access control, intrusion detection, and video operate as three independent layers that correlate the audit trail, so every event in the white space is traceable from first alarm through to resolution.

Colocation cages and client separation

In a colocation environment, Zone 5 turns security into a contractual obligation as much as a physical one. Each tenant gets a physically isolated cage with no spatial overlap, separated camera views, and access rights and audit logs configured independently per client. No tenant sees another tenant’s data.

An optional four-eyes principle adds a second approval step for critical cage access, and SLA evidence reports generate automatically, ready for compliance audits and customer due diligence.

Rack-level access and chain of custody

Zone 6 is the point of maximum control. Every rack access runs through an eligibility and time-window check, an optional four-eyes release, controlled lock opening, event logging, automatic video linkage, and a closing report. Offline rack locks keep a full local audit record and synchronise the moment connectivity returns.

Break-glass access for emergencies is time-limited and fully logged. No unlogged access is possible at rack level, and every access carries a complete chain of custody from request to close.

Designed for how data centre operators actually work

The same threats look different depending on whether you run a single enterprise facility, a multi-tenant colocation campus, a hyperscale estate across several countries, or a site under KRITIS regulation. Primion runs all of these on one converged system.

Colocation operators

Your security architecture is also part of your commercial proposition. Tenants choosing your facility want proof that their cage is physically isolated, their access logs are private, and your security posture supports their own compliance obligations. You get per-tenant access configuration, physically separated zones, client-specific reports and camera views, and automatic SLA evidence, so your security documentation becomes part of what you sell, not just an internal control.

Enterprise data centre operators

Single-site and campus facilities need tight control over contractor and visitor access without building a large internal security team to manage it. Contractor lifecycle runs automatically from pre-registration through to deactivation, with zone-specific, time-limited rights that expire without manual intervention. Visitor workflows cover sponsor approval, ID verification, and escort rules per zone, with quarterly access recertification running on its own. No lingering credentials, full traceability on every visit.

Hyperscale and multi-site operators

At hyperscale, the architecture has to work identically across every site without separate configurations. You run the same APIs, the same operational procedures, and the same audit structure whether you’re managing 100 rack locks or 10,000. Each site continues to operate independently during network interruptions, with events buffered locally and synchronised on reconnect, while multi-site visibility is consolidated centrally so your operations team maintains oversight across the estate without site-by-site reconciliation.

Operators under NIS2, KRITIS, and EN 50600

European data centre operators face a regulatory stack that global vendors rarely map with precision. NIS2 requires technical protective measures and incident reporting for essential entities. KRITIS in Germany adds physical access and BSI verification requirements. ISO 27001 requires documented access control and risk treatment. EN 50600 defines zone, redundancy, and security classes for data centre design and operation. Primion supports all of it within one system, generating compliance documentation directly from daily operations, so evidence is always current.

Customer cases

fraport

Fraport AG, Frankfurt

csm Hauptgebaude UKE fq UKE 70833bc3dc

Hamburg-Eppendorf University Hospital

Capabilities built for the demands of data centre security

A physical security that protects every layer, from the site boundary to the individual rack.

  • Six-zone architecture, perimeter to rack: Access control, detection, and video configured for six distinct zones, each with its own logic and audit trail. Control density and verification requirements increase with criticality.
  • Edge-resilient access control: Local controllers hold full decision logic during network outages. Every door and rack lock keeps working without a central connection, with events buffered locally and synchronised on reconnect.
  • Colocation multi-tenancy by design: Physical isolation per tenant, independent access rights, separate camera views, client-specific audit logs, and automatic SLA evidence. Structural separation, not policy alone.
  • Rack-level traceability: Full chain of custody down to the individual rack: eligibility check, time window, optional four-eyes release, event logging, video linkage, and closing report. Fail-secure by default.
  • Visitor and contractor lifecycle management: Pre-registration, sponsor approval, ID verification, temporary zone-limited access, and automatic deactivation on expiry. Blacklist checks and tenant separation built in.
  • Drone detection and documentation: Radar, RF scanning, acoustic sensors, and thermal imaging detect and classify unmanned aircraft and locate their operators. Findings log with a full chain of custody for authority handover. Countermeasures stay with the authorities; Primion detects, documents, and escalates.
  • NIS2, KRITIS, ISO 27001, and EN 50600 compliance: Compliance documentation generates directly from operations, with tamper-resistant audit trails, event logs, and approval records available on demand, not assembled before an audit.
  • Scalable from enterprise to hyperscale: From 100 to 10,000-plus rack locks, across enterprise, colocation, and hyperscale tiers. Same platform, same APIs, same operations at every scale.
  • Integration-first deployment: Connects with existing video, alarm, key cabinet, and intercom systems, and with SIEM and SOC tools through documented APIs. Existing investment stays protected, with compliance and audit capability added on top.

Frequently Asked Questions

How does Primion’s Data Centre Solution support NIS2 and KRITIS compliance?

NIS2, KRITIS, ISO 27001, EN 50600, and GDPR are mapped into the architecture itself, not retrofitted later. That mapping covers documented processes, least-privilege access models, audit-proof logging, traceable visitor and incident workflows, and structured reports. When an auditor asks for evidence of physical access controls, operators export it from one source rather than reconstructing it across separate PACS, video, alarm, and visitor systems.

How long does it take to produce a NIS2 or KRITIS audit report?

Access, visitor, and incident events are logged continuously to tamper-proof, NTP-synchronised, immutable records. Standardised exports are filterable by person, zone, and time period, with hash checksums for chain of custody that authorities and courts accept as evidence. A specific query such as “who was in Cage 7 between 14:00 and 18:00 on 14 March” returns a verified answer in under 60 seconds. Audit preparation shifts from days or weeks of manual reconstruction across separate systems to an on-demand export from a single evidence source.

Does this lock us into a single vendor for data centre physical security?

No. The architecture uses standardised interfaces, including OSDP for access hardware, ONVIF for video, MQTT for sensor and IoT events, and REST APIs for identity and system integration. Where standard interfaces exist, integration with existing systems is supported. What stays consolidated is responsibility: one accountable owner for the security outcome, not one proprietary protocol stack. Lock-in comes from systems that cannot exchange data, not from a converged architecture that can. 

How does Primion prevent tailgating in a data centre environment?

Zone 3 building access uses mantrap and personnel lock systems that enforce two-door separation, allowing only one person per cycle. This makes tailgating physically impossible at the primary entry point. Speed gates with bidirectional tailgating detection sensors are used at higher-throughput entry points. Anti-passback logic in prime WebAccess prevents credential reuse. CCTV in the lobby provides real-time alarm verification and forensic documentation of every entry event.

With Primions solution can we keep our existing PACS? 

Yes, in brownfield environments. With Primion existing physical access control systems can be connected where standard interfaces are available, and the rollout works alongside what is already deployed. For new builds, a converged architecture reduces complexity and audit effort from day one. The right path depends on the site profile rather than a forced migration.

What happens to our existing PSIM or control room?

Existing PSIM platforms and control rooms continue to operate. The architecture provides structured events and status information for correlation and escalation, so there is no requirement to replace a working PSIM. Where operators prefer to consolidate the control room, that path is also supported. Either way, the access control layer remains authoritative for who is allowed where, and the PSIM layer remains the operational picture.

How does physical access control integrate with corporate IAM, SIEM and FAS?

Physical access events flow as a first-class data source into corporate identity and security operations. Integrations remain authoritative for the user lifecycle, with provisioning and revocation flowing into PACS through documented APIs. Structured event streams in syslog. Network architecture uses standard TCP/IP, with no proprietary overlays required.
Building Management Systems remain separate. Where useful, physical access events can be exposed to BMS through documented APIs, but the architecture does not take over building automation logic, and Phase 1 typically goes live without disrupting an existing FAS estate.

How does access control stay operational during a network outage? 

Access decisions remain locally functional at the controller level when the central server or LAN/WAN link is unavailable. Fail-safe and fail-secure logic is defined per zone: escape routes always fail-safe for life safety, racks, cages, and high-security zones fail-secure to stay locked on failure. Edge controllers buffer events locally and synchronise with the central platform on reconnect, which is essential for KRITIS-grade operations where access cannot depend on a remote network link.

Let’s talk possibilities!

Data centre security has its own requirements: zone architecture, multi-tenant separation, regulatory compliance, and edge resilience. Tell us what you’re working on, and we’ll help you plan the right approach.