Data Center Security

Data Centre Design 101: Architecture, Layout and Security Principles for Resilient Facilities

Published
Aerial view of modern data center facility exterior, with solar panels on the roof and green space around it. The building is large in size, featuring sleek grey metal cladding and glass windows that showcase its interior tech equipment. In front of the structure stands an empty parking lot surrounded by trees, while the background shows other buildings and the city skyline under clear blue skies during golden hour. --ar 3:2 --quality 2 --v 6.1 Job ID: dcb08744-a35a-47be-bf95-20bc2b7a7922
Data Centre Design 101: Architecture, Layout and Security Principles for Resilient Facilities

What Is Data Centre Design?

A data centre's most consequential security decisions are made before a single server, camera or badge reader goes into place: at the design table, not on the day the facility opens its doors.

In short: data centre design is the discipline of planning a facility's layout, power and cooling systems, network architecture and physical security before construction begins. Get it right at the blueprint stage, and a facility runs efficiently and securely for its entire operating life; get it wrong, and those gaps are expensive and disruptive to fix later.

Data centre design is the process of planning a facility's physical layout, infrastructure systems and protective measures before construction begins: where equipment goes, how power and cooling are distributed, how the network is built and who can access which zones. Data centre architecture is often used interchangeably with design, but it is more precise to think of architecture as the technical blueprint (the specific systems and standards chosen), while design is the broader planning discipline that produces that blueprint.

The distinction matters because of what is at stake. Decisions made at this stage (the aisle layout, the cooling approach and the security zones) are not easy or cheap to unwind once a facility is operating. They shape uptime, operating cost and risk exposure for the life of the building. In this article, we will walk through the core components of data centre architecture, the security principles that belong in the blueprint stage and the standards and best practices that keep a facility resilient throughout its life.

To see how this plays out in practice, explore Securitas Technology's approach to data centre security.

Why Data Centre Design Decisions Matter

Three forces are reshaping what ‘good’ data centre design looks like today.

  1. AI workloads are driving power and cooling densities that many existing facility designs were not built for. Racks built to support conventional server loads often cannot support the density of GPU-heavy AI infrastructure, which means higher-capacity power distribution and cooling systems need to be considered at the design stage rather than retrofitted later.
  2. Sustainability pressure is pushing operators to treat energy efficiency and water usage as core design criteria, not afterthoughts: from free cooling and liquid cooling approaches to how a facility's location and layout affect its overall footprint.
  3. Compliance obligations are expanding. A growing share of data centres, particularly those supporting critical infrastructure, now fall under formal cybersecurity and resilience requirements that touch on physical design, not just IT policy. This means design teams need to account for regulatory obligations before ground is broken, not after a facility is already live.

Together, these forces mean data centre design is no longer just an engineering exercise: it is a discipline that has to account for capacity, sustainability and compliance at the same time. That is exactly why we treat security as belonging at the design table from day one, not as a system added afterwards. For a closer look at what is driving these shifts, see Securitas Technology's data centre trends page.

The Core Components of Data Centre Architecture

Every data centre design has to answer the same core questions, regardless of size or industry: how space is organised, how power and cooling are delivered and how the network moves data reliably. Here is what each of those components involves.

Physical Layout and Floor Plan

The floor plan determines how efficiently a facility can operate and how easily it can grow. Most modern data centres use hot-aisle/cold-aisle containment (arranging server racks in alternating rows so cold-air intakes face each other and hot exhaust air is contained and channelled away) to control cooling costs and keep equipment within safe operating temperatures.

Beyond containment, a floor plan needs to account for:

  • Space planning that separates equipment zones, staging areas and support infrastructure such as electrical rooms and network operations space
  • Expansion flexibility, so added racks or new equipment types do not require a full redesign
  • Clear circulation paths that support both day-to-day operations and emergency response

Power and Cooling Infrastructure

Power and cooling design centres on redundancy: how much backup capacity a facility builds in so a single failure does not cause an outage. Two configurations come up most often: N+1 redundancy, which adds one extra unit of capacity beyond what is needed so a single component can fail or go down for maintenance without affecting operations; and 2N redundancy, a fully duplicated, independent system in which an entire path can go offline without any loss of capacity.

Cooling design follows similar logic, with approaches including air-based systems (traditional CRAC/CRAH units), liquid cooling (increasingly common for high-density AI racks) and free cooling, which uses outside air or water sources to reduce mechanical cooling load where the climate allows. Efficiency here is often measured by PUE (Power Usage Effectiveness): the ratio of a facility's total energy use to the energy used by its IT equipment alone. A PUE closer to 1.0 means less energy is lost to overheads such as cooling and lighting.

Data Centre Network Design

Network design determines how reliably data moves in and out of the facility and how well the network can scale as bandwidth demand grows. Key decisions include topology choices (spine-leaf architectures are common in modern data centres), redundant connections and carrier paths so no single link is a point of failure, and sufficient scalability headroom to support future growth without requiring a network overhaul.

Security Principles: Designing Protection in from Day One

Security is too often treated as a checklist applied after a data centre's layout, power and network design are already finalised: cameras and badge readers added to a floor plan that was never built with them in mind. Physical security, cyber-physical convergence and regulatory readiness work better as architectural decisions, planned alongside everything else, rather than as an add-on.

Physical Security as a Design Input, Not an Add-On

Access control, video surveillance and perimeter design each work best when they are planned alongside the floor plan rather than retrofitted onto it. Zone-based access control (restricting who can reach the server floor, the network operations centre or the loading dock) is far easier to build into a facility's layout from the outset than to impose on a finished building. The same is true of camera placement and perimeter design: sightlines, lighting and physical barriers are architectural decisions that are far more effective, and typically less costly, when they are part of the original design.

Cyber-Physical Convergence

Physical security systems today run on the same network infrastructure as everything else in the facility, which means network design and security design cannot be planned in isolation. This overlap is often called cyber-physical convergence: the point where physical security systems and IT infrastructure depend on each other closely enough that they have to be designed together. As Mike Beattie, Global CIO & SVP Information Technology at Securitas Technology, puts it:

“Physical security relies on a modern, technical network foundation. In a connected ecosystem, good cyber hygiene is no longer optional; it's the essential discipline that keeps today's security platforms resilient and trustworthy.”1

That convergence is also why integration matters as a selection criterion, not just as a feature. The ability to integrate systems is now one of the top three factors organisations consider when choosing an electronic security technology provider, across organisations of all sizes and geographies.2 Security systems that cannot communicate with the rest of a facility's technology stack therefore create risk, not just inconvenience. Read more about how data centre physical security intersects with cybersecurity.

The stakes are real: 92% of organisations are extremely or moderately concerned about security device hacking, and 91% are concerned that dated equipment creates cybersecurity vulnerabilities.3 Equipment choices made at the design stage — what gets installed, how it is networked and how it is maintained — create years of exposure if security and network teams do not plan together from the start.

Layered Design and Regulatory Readiness

No single control should carry the full weight of a facility's security. A layered, defence-in-depth approach (combining perimeter measures, access control, surveillance and network segmentation) means that if one layer is compromised, others still hold. Securitas Technology's multi-layered approach to de-risking data centres breaks this down in more detail.

Regulatory pressure reinforces the case for building security in early. A growing share of data centres now fall under formal cybersecurity and critical-infrastructure obligations that directly affect design decisions, rather than simply creating a compliance checklist to work through after a facility opens. The ‘Data Centre Design Guidelines and Standards to Know’ section below explains what this looks like in practice in the EU.

AI-assisted monitoring can also help security teams identify anomalies across a facility's physical and network environment. In the EU, however, each use case should be assessed before deployment under the GDPR and, where applicable, the EU AI Act. Video analytics, facial recognition, remote biometric identification and systems that infer sensitive characteristics can carry additional restrictions or high-risk obligations. Design teams should define the purpose, lawful basis, data flows, retention periods, human oversight and technical safeguards before selecting or integrating these capabilities. Our guide on how to improve data centre security with AI covers this in more depth.

Cameras, access-control records, visitor logs and biometric credentials may contain personal data. An EU-ready design should therefore apply data protection by design and by default: use only the data necessary for a defined purpose, provide appropriate transparency, restrict access, set proportionate retention periods, protect data in transit and at rest, and assess whether a data protection impact assessment is required. Biometric data used to identify a person is subject to additional safeguards under the GDPR and may also be regulated under the EU AI Act.

See how we approach data centre security as part of the design process, not as an afterthought. View our data centre security solutions.

Data Centre Design Guidelines and Standards to Know

European data centre projects may draw on several design standards and certification schemes. They serve different purposes and are generally voluntary unless legislation, permits, procurement requirements, contracts or client commitments make them binding. The right combination should be selected through a business-impact and risk assessment, then checked against applicable EU and national requirements.

EN 50600 and ISO/IEC 22237

For European projects, EN 50600 is a central reference for data centre facilities and infrastructure. Its multi-part framework covers building construction, power distribution, environmental control, telecommunications cabling, security systems and operational management, with classifications for availability, protection and energy efficiency. ISO/IEC 22237 is the closely aligned international series. These standards provide a holistic basis for translating business risk into technical design requirements, but they do not replace applicable EU, national or local law.

Uptime Institute Tier Ratings

The Uptime Institute's Tier system rates data centres by redundancy and the resulting uptime, not by size or cost. Here is what each tier means in practice:

Tier

What It Means

Annual Uptime

Tier IBasic capacity, single distribution path, no built-in redundancy

99.671% (up to 28.8 hours downtime/year)

Tier IIAdds redundant capacity components (power, cooling) but still one distribution path

99.741% (up to 22 hours downtime/year)

Tier IIIConcurrently maintainable: multiple distribution paths with N+1 redundancy, so maintenance does not require downtime

99.982% (up to 1.6 hours downtime/year)

Tier IVFault tolerant: fully duplicated (2N) infrastructure that tolerates planned and unplanned failures

99.995% (about 26 minutes downtime/year)

 

Higher tiers cost more to build and operate, so the right tier for a given facility depends on how much downtime the business can realistically tolerate, not on defaulting to the highest rating available.

ANSI/TIA-942

ANSI/TIA-942 is a widely recognised data centre infrastructure standard covering telecommunications cabling, architecture, redundancy and security. It may be specified on European projects, particularly by multinational clients, but should be positioned as a complementary reference rather than a substitute for EN 50600, applicable European standards or national requirements.

Where EU Compliance Meets Design Standards

In the EU, the NIS2 Directive establishes cybersecurity risk-management and incident-reporting obligations for covered entities, including data centre service providers. NIS2 entered into force in January 2023, and 17 October 2024 was the deadline for Member States to transpose it into national law. Commission Implementing Regulation (EU) 2024/2690 adds detailed technical and methodological requirements for covered data centre service providers. Because national implementation and supervision can vary, project teams should confirm the rules that apply in each Member State and translate the risk assessment into proportionate controls for access management, network segmentation, supply-chain security, vulnerability handling, business continuity, logging, monitoring and incident response.

EU requirements also extend beyond cybersecurity. Under the Energy Efficiency Directive and Commission Delegated Regulation (EU) 2024/1364, data centres with significant energy consumption are subject to monitoring and reporting of energy-performance and water-footprint indicators; the EU reporting threshold generally covers facilities with installed IT power demand of at least 500 kW, while Member States may introduce additional requirements. The Critical Entities Resilience Directive adds an all-hazards resilience framework for entities designated as critical under national law, including risks such as natural hazards, sabotage, insider threats and public-health emergencies. GDPR requirements apply where video surveillance, access-control records, visitor logs or biometric systems process personal data. Together, these rules make compliance an early design input rather than a post-construction exercise.

If you are scoping an active data centre project, three strategies for your data centre project explains how to plan for both the engineering and compliance aspects at once.

 

Data Centre Design Best Practices: A Practical Checklist

Bring these considerations into your next data centre planning conversation, whether you are designing a new facility or reassessing an existing one.

Layout and Infrastructure

  • Plan hot-aisle/cold-aisle containment and equipment zoning before finalising the floor plan, not after equipment is installed.
  • Build in expansion flexibility so growing power, cooling and rack-density needs do not require a full redesign.
  • Match redundancy level (N+1 vs. 2N) to what the business can realistically tolerate in downtime, not to the highest tier available.

Network and Security

  • Treat access-control zoning as part of the floor plan, not as a system layered on afterwards.
  • Plan camera placement, lighting and perimeter design alongside the building's architecture, not around it.
  • Involve network and security teams in the same planning conversations: cyber-physical convergence means these can no longer be designed in isolation.
  • Choose systems built for integration, not just for their standalone function, so the facility's security stack can operate as one system.
  • Apply hardening practices to every device on the network, from cameras to access-control panels, to reduce exposure from outdated or unpatched equipment. See six considerations for hardening your physical security systems.

Standards and Compliance

  • Use EN 50600 and, where appropriate, ISO/IEC 22237 as primary design references for European facilities; add Uptime Tier or ANSI/TIA-942 where the business case, client specification or contract requires them.
  • Document which standards are design references, which certifications are being pursued and which requirements are legally or contractually binding.
  • Confirm early whether NIS2 and Commission Implementing Regulation (EU) 2024/2690 apply to the operator or service provider, then check the relevant national implementing law and supervisory guidance.
  • Assess whether the facility is subject to EU and national energy-performance, sustainability, reporting, permitting, waste-heat or water-use requirements.
  • Apply GDPR data protection by design to surveillance, access-control, visitor-management and biometric systems, including purpose limitation, transparency, retention, security and any required data protection impact assessment.
  • Evaluate AI-enabled video analytics and biometric functions under both the GDPR and the EU AI Act before deployment.
  • Check whether the operator has been designated as a critical entity under national implementation of the Critical Entities Resilience Directive and build all-hazards resilience measures into the design where applicable.
  • Validate national and local building, fire-safety, environmental, employment and data-protection requirements before final design approval.

Frequently Asked Questions About Data Centre Design

What is the difference between data centre design and data centre architecture?

Data centre design is the overall planning process: deciding on layout, infrastructure and security before construction. Data centre architecture usually refers to the specific technical blueprint that comes out of that process: the chosen systems, standards and configurations. In practice, the terms are often used interchangeably, but design is the broader discipline and architecture is its output.

What is a data centre floor plan, and why does it matter?

A data centre floor plan is the physical layout of a facility: where server racks, cooling equipment, staging areas and support infrastructure are positioned. It matters because it determines cooling efficiency through hot-aisle/cold-aisle containment, how easily the facility can expand and how effectively security zones can be enforced.

How does data centre cooling design affect uptime?

Cooling failures are one of the most common causes of data centre outages, as overheating equipment can shut down or fail outright. Redundant cooling design, whether through additional capacity (N+1) or fully duplicated systems (2N), keeps a facility operating even if one cooling unit fails or needs maintenance.

What security features should be part of data centre design, rather than added later?

Access-control zoning, camera placement, perimeter design and network segmentation should all be planned alongside the floor plan and network architecture, not retrofitted afterwards. Because physical security systems now run on the same network infrastructure as the rest of the facility (known as cyber-physical convergence), security and network teams need to plan together from day one, not as separate workstreams. Building these in from the start is more effective, and typically less costly, than adding them to a finished facility.

How do compliance requirements such as NIS2 affect data centre design?

For covered data centre service providers, NIS2 requires proportionate cybersecurity risk-management measures and incident reporting. Commission Implementing Regulation (EU) 2024/2690 provides more detailed requirements, while national law determines supervision and enforcement in each Member State. In practice, project teams should use the risk assessment to inform access management, network segmentation, supply-chain security, logging, monitoring, business continuity, incident handling and recovery. NIS2 does not prescribe one universal camera layout, redundancy tier or access-control architecture, so controls should be appropriate to the facility's risks, services and national context.

Designing for What Comes Next

Data centre design is not a box to tick before opening day: it is an ongoing discipline that has to keep pace with rising density, tightening regulation and a threat landscape that increasingly spans both physical and digital risk. The facilities built to last are those where security was designed in from the start, planned alongside power, cooling and network architecture rather than retrofitted once the building is already live.

We bring that perspective to data centre security specifically: more than 10,000 of our officers are being trained specifically for data centre security operations,6 reflecting a level of specialisation built for facilities where the margin for error is narrow.

Planning a new facility or reassessing an existing one? 

Talk to a Securitas Technology data centre security specialist.

References

1  Mike Beattie, CIO & SVP Global Information Technology, Securitas Technology. (Global Technology Outlook Report, 2027, p. 131.)

2  The ability to integrate systems is one of the top three criteria for selecting an electronic security technology provider, across organisations of all sizes and geographies. (Securitas Technology, 2027, p. 51.)

3  92% of organisations are extremely or moderately concerned about security device hacking; 91% are concerned about dated equipment creating cybersecurity vulnerabilities. (Securitas Technology, 2027, pp. 117, 121.)

4  EU compliance references for this article: Directive (EU) 2022/2555 (NIS2); Commission Implementing Regulation (EU) 2024/2690; Directive (EU) 2022/2557 on the resilience of critical entities; Directive (EU) 2023/1791 on energy efficiency; Commission Delegated Regulation (EU) 2024/1364; Regulation (EU) 2016/679 (GDPR); and Regulation (EU) 2024/1689 (EU AI Act). Requirements should be confirmed against applicable national implementation and current regulatory guidance.

5  European design references discussed in this article include the EN 50600 series and the aligned ISO/IEC 22237 series for data centre facilities and infrastructures. Uptime Tier ratings and ANSI/TIA-942 may also be used where specified by the project, contract or client.

6  More than 10,000 Securitas officers are being trained specifically for data centre security operations. (Securitas Technology, 2026, p. 69.)