// Practitioner Reference Framework - v1.2 - 2026 // Updated: Google GDC Air-Gap Integration

AI Weight Data Center
Physical Security Framework

The core premise: physical and cyber security for data centers should be tiered and scaled the same way IDCA has built infrastructure resiliency - with defined security levels that match the criticality of the workload and the environment it operates in. Just as a Tier IV facility is engineered to a higher resiliency standard than a Tier I, the security posture protecting it must escalate accordingly. This framework applies that principle across physical controls, cyber-physical integration, and AI-weight environments using a defined Security Level (SL) model. Cross-referenced against RAND SL1–SL5 and the Escalating Cyber-Physical Defenses Maturity Model - authored by Paul M. Jankowski. Technology preferences reflect current practitioner evaluation - not exhaustive market coverage or vendor endorsement.

Research & Framework: Paul M. Jankowski - CoreBastion Security Consulting
Why this framework exists: This document was developed to inform, educate, and help security practitioners, data center operators, and infrastructure owners understand what a rigorous, layered physical security posture looks like for AI-weight and critical data center environments. It is shared freely as a contribution to the industry. It is not a product. It is not a sales tool. It is a practitioner's attempt to raise the floor - because the consequences of getting physical security wrong at this class of facility are no longer limited to one organization.

01 Threat Model - Why Physical IS the Attack Surface

// You don't need to break into a data center to take it offline. You just need to hit the unprotected infrastructure feeding it.

The Sidewalk Problem

Data centers are some of the most hardened facilities on earth. The substation 300 yards away has a padlock and a paper logbook. The fiber vault at the curb has a standard utility lid. An adversary targeting a frontier AI training cluster doesn't need to defeat biometrics, mantrap portals, and guard forces. They need bolt cutters, a shovel, and 20 minutes. This is not a theoretical concern - utilities reported over 2,800 physical security threats in 2023 alone, a jump of more than 1,000 from the prior year.

Theft / vandalism
Casual trespass
Social engineering
Cybercrime syndicates
Malicious insider
Hardware implant (4/5 RAND feasibility)
USB exfiltration
Coordinated substation strike
Fiber cut campaign
Drone surveillance / IED (TN 2024)
Supply chain compromise
Model weight exfiltration
Blended cyber-physical ops
Long-term infrastructure degradation
Insider recruitment

RAND rates direct physical access to sensitive systems at 3/5 feasibility (40–60% success probability) for OC3 actors against average security. Malicious portable device placement rates 4/5 (60–80%) for the same adversary tier. Physical security is the prerequisite for every cyber control deployed. A TEE cannot survive a side-channel attack if the room it sits in is not secured first.

02 The Onion - Defense in Depth Layer Model

// Seven concentric rings. Each ring must delay, detect, and report before an adversary reaches the next. Compression of layers equals compression of response time.

UPSTREAM
INFRA
EXTENDED
PERIM.
CAMPUS
PERIM.
FACILITY
ENVELOPE
INTERIOR
ZONES
DATA
HALL
ENCLAVE
L7 - UPSTREAM INFRASTRUCTURESubstations, fiber vaults, water and cooling supply. Off-site, utility-owned, but your operational dependency. Most neglected ring in the industry.
L6 - EXTENDED PERIMETER1–3 mile stand-off zone. Drone ground control station detection range. Adjacent roads, parking, elevated terrain. Counter-UAS starts here, not at the fence.
L5 - CAMPUS PERIMETERFence line, anti-climb, anti-ram barriers, CPTED design, perimeter IDS, patrol zones. JIATF-401 HOP framework (Harden, Obscure, Perimeter) applies.
L4 - FACILITY ENVELOPEBuilding exterior, loading docks, utility ingress, mantrap portals, visitor control. Construction security baseline from Day 1 - not at go-live.
L3 - INTERIOR ZONESCorridors, staging areas, NOC/SOC, support spaces. Role-based access, escort policy, interior AI analytics, segmented access levels per zone.
L2 - DATA HALLThe compute floor. MFA + biometric at threshold, rack-level monitoring, AI camera analytics, two-person rule for sensitive zones. No mobile devices.
L1 - MODEL WEIGHT ENCLAVEFrontier AI model weight protection. SCIF-derived architecture, TEE hardware, air-gapped OOB management, 2N power, armed response protocol. RAND SL3–SL5.

03 The Sidewalk Problem - Upstream Infrastructure

// Only ~3% of U.S. substations are classified High Impact under NERC CIP-014. The other 97% have no mandatory adversarial physical security controls. They are powering your data center.

High-voltage transformers have 2–5 year procurement lead times. Gas turbines up to 7 years. A coordinated physical attack on substation infrastructure feeding a frontier AI campus does not need to defeat any building security at all. The SECURE Grid Act (H.R. 7257, 2026) begins to address distribution-level infrastructure - but it is a starting point, not a solution. Data center operators cannot wait for regulatory mandates.

AssetMinimum ControlsEnhanced Controls (L2–L3)Elite (L4+)
Dedicated Substation Anti-climb fence, camera coverage, motion IDS, access control on equipment enclosures AI video analytics (Ambient.ai or ZeroEyes), fiber perimeter IDS, lighting, guard patrol integration, utility liaison MOU Hardened enclosures, overhead netting (JIATF HOP), thermal imaging, armed rapid response SLA, DBT assessment
Shared Substation (utility-owned) Named utility security liaison, outage notification SLA <1hr, basic camera awareness Joint security working group (quarterly), voltage/frequency monitoring into your SIEM, joint tabletop exercise annually Embedded analyst model, classified threat briefings, coordinated DBT, FERC/CISA coordination
Fiber Vault / Manhole Hardened locked vault lid (not standard utility grade), periodic inspection logging Fiber Intrusion Detection System (FIDS) - OFS, AFL, Bandweaver. Armored conduit on final approach. Camera on vault access point. Dual diverse fiber paths via physically separate routes. Continuous FIDS into SOC. Cut-through alarm triggers response within 4 minutes.
Water / Cooling Supply Access controls at pump houses, basic monitoring IDS on supply lines, monitoring integrated into FOC/SOC dashboard Redundant supply routes, sensor fusion, tamper detection feeding SOC
Drone / Aerial Threat JIATF-401 HOP: overhead netting on generators and critical outdoor equipment, obscuration of sensitive infrastructure, extended perimeter patrol trained on GCS behavioral indicators RF detection (Dedrone, D-Fend Solutions), personnel trained on ground control station recognition, defined drone detection SOP and response protocol Full C-UAS: RF + radar + EO/IR detection, mitigation authorities per FY26 NDAA / EO Airspace Sovereignty (June 2025), coordinated with CISA and FBI
Upstream and perimeter detection - practitioner preferences: Dedrone (RF drone detection and classification - passive, no airspace interference). D-Fend Solutions (GPS spoofing and RF-based C-UAS mitigation). Bandweaver / AFL (fiber perimeter IDS using distributed acoustic sensing - standard sites, low-wind environments). Senstar OmniTrax (buried cable IDS - preferred for high-wind, coastal, or environmentally exposed sites). Evolv Technology (frictionless weapons screening at entry nodes). ZeroEyes (multi-threat AI detection with human-verified escalation, DHS SAFETY Act certified).

04 Recommended Systems by Onion Layer

// Systems listed are practitioner-recommended based on deployment experience and operational performance in data center and CNI environments. Preferences reflect real-world fitness, not vendor relationships. CPTED principles are applied first at every layer - design out risk before deploying electronics.

A note on vendor preferences: The platforms named in this section represent the author's current preferences based on market evaluation, direct deployment experience, and demonstrated operational performance in critical infrastructure environments. The security technology market is evolving rapidly - this is not an exhaustive survey of every capable platform, and it is not an endorsement. Other capable solutions exist in each category. These are the systems that have earned a place on a practitioner's shortlist today, for the specific use cases described. Selections will be updated as the market evolves. No vendor relationship or sponsorship influences these recommendations.
L5 - CAMPUS PERIMETER
Physical Perimeter + CPTED + Drone Detection
JIATF-401 HOP Framework // RAND SL1+ // CPTED-First Design
CPTED first - before you spec a single camera: Site layout, terrain, and landscaping are the cheapest security controls you will ever deploy. Natural access control through berms, dense plantings, grade changes, and restricted sight lines from public right-of-way reduce both opportunistic threat and your electronic sensor count. A well-designed campus that is difficult to approach, observe, and navigate reduces IOC before the first post order is written. Maximize CPTED dividends at the design stage - you cannot retrofit natural surveillance or territorial reinforcement.

Physical Barrier System - Fencing, Bollards & Vehicle Control

Physical barrier selection must match the facility type, threat profile, site environment, and the security level the operator is building to. Not every data center build warrants the same perimeter specification - a single-tenant hyperscale campus at SL3 has a different requirement than a colocation facility at SL1, an edge node in an urban environment, or a nontraditional build in a hardened location. The fence type, barrier approach, IDS selection, and vehicle restraint specification must all be driven by a site-specific threat model, the build type, and the target security level - not a one-size standard applied uniformly.

Gibraltar Perimeter Fencing - PREFERRED
Anti-climb, anti-cut, anti-dig fence systems purpose-built for high-security perimeters. Rigid mesh panels resist climbing aids and defeat common cutting tools. Preferred for data center campuses where perimeter integrity must survive persistent physical attack. Specify outrigger arms with deterrent wire (not barbed wire - anti-climb weld mesh topping) at top of fence line. Anti-dig foot rail at grade for burial-level hardening.
Crash-Rated Bollards - Vehicle Entry Points
ASTM F2656 / IWA 14-1 rated bollards at all campus entry points, loading dock approach, and any location where a vehicle can approach within ramming distance of a structure. Fixed bollards for permanent barriers. Retractable/removable for controlled access lanes. Do not substitute decorative landscaping elements for rated barriers at data center campuses - the threat is real and documented.
Vehicle Restraints & Campus Entry Gates
Crash-rated sliding or swing gates with integrated vehicle restraint systems at all campus access roads. Shallow-foundation surface-mounted vehicle barriers (Delta Scientific, Perimeter Products, or equivalent) where deep-foundation installation is not feasible. Mantrap vehicle portals (sally ports) for L3+ campuses - one gate does not open until the first closes. Guard booth positioned to cover the entire sally port kill zone.

Perimeter Intrusion Detection - Site Conditions Drive Technology

The environment the facility sits in must drive sensor technology selection. A solution appropriate for a calm suburban campus may perform poorly in a coastal, high-wind, or seismically active site. Do not let a vendor's standard spec sheet override local conditions knowledge.

High-wind and exposed environments: Above-fence taut-wire and vibration sensors generate chronic false alarms in sustained wind environments. For coastal sites, open plains, elevated terrain, or any site with frequent winds above 25 mph, buried ground sensor technology is the correct baseline. Senstar OmniTrax (buried cable detection) eliminates weather-driven nuisance alarms and provides sub-meter resolution regardless of surface conditions. Where a dual-fence configuration is appropriate for the build and security level, Senstar cable buried in the clear zone between fences performs reliably in conditions where above-fence sensors would saturate the alarm stream.
Senstar OmniTrax - PREFERRED (High-Wind / Exposed Sites)
Buried ported coaxial cable IDS. Electromagnetic field detection - immune to wind, weather, and above-grade environmental noise. Ideal deployment: buried in the clear zone between dual fence lines. Provides detection coverage in the most attack-relevant corridor - after the adversary has breached the outer fence but before they reach the inner. Sub-meter location accuracy. Pairs with Senstar LM100 fence-mounted sensors for combined above/below-grade detection on standard sites.
Dual-Fence Perimeter Configuration - SL3+ / High-Threat Sites
Where the build type, threat environment, and target security level warrant it: outer fence (Gibraltar anti-climb, anti-cut, anti-dig), clear detection zone between fences (3–5 meters minimum), Senstar buried cable or fiber IDS in clear zone, inner fence (Gibraltar equivalent with PIDS sensor layer). This configuration forces an adversary to defeat two independent physical barriers and a detection corridor. Appropriate for hyperscale campuses, AI weight facilities, CNI-adjacent builds, and any site where the threat model identifies a persistent, capable adversary. Not required for all builds - SL1/SL2 colocation, edge, and standard commercial facilities typically achieve the correct posture with a single hardened fence line and well-placed IDS.
Bandweaver / AFL - Fiber PIDS (Standard Sites)
Distributed acoustic sensing along fence line. Sub-meter resolution. Strong performance in low-wind, temperate environments. Preferred for fiber vault and perimeter applications where above-grade installation is practical and wind load is not a primary concern.
Axis Communications - Perimeter Cameras
NDAA-compliant. ACAP edge analytics ecosystem. LPR, thermal integration, PTZ pursuit. Open architecture integrates with Genetec, Milestone, and AI video analytics layers. Specify thermal for fence line coverage - thermal outperforms visible light in fog, darkness, and glare conditions common on perimeter duty.
i-PRO (formerly Panasonic)
Open architecture, NDAA-compliant alternative to Axis. Strong privacy compliance posture. On-camera AI analytics. Solid enterprise support. Appropriate where procurement policy requires dual-sourcing of camera hardware.
Dedrone - RF Drone Detection
Passive RF drone detection and classification. No airspace interference. Integrates into Genetec and SOC alerting workflows. Perimeter-layer deployment - detection zone begins well outside the fence line, not at the building wall.
ZeroEyes
AI threat detection (firearms, drones, vehicles, intruders) with human-verified escalation. DHS SAFETY Act certified. Overlays on existing camera infrastructure - no hardware replacement required.
Evolv Technology
Frictionless concealed weapons screening at vehicle and pedestrian entry points. High-throughput - no stopping, no pockets empty. Best deployed at campus entry portals and guard booths.

Baseline physical requirements scale with security level and build type. At any production data center: CPTED site design, anti-climb fencing appropriate to the threat environment, crash-rated vehicle barriers at approach vectors, perimeter lighting with no dark pockets, and perimeter alarm streams federated into a unified SOC queue. At SL2+: hardened anti-cut, anti-dig fencing (Gibraltar or equivalent, 8ft minimum with outrigger arms), perimeter IDS layer matched to site conditions. At SL3+ on high-threat or hyperscale builds: dual-fence with detection corridor where the threat model and site environment warrant it. At all levels: the specification must be driven by the actual build type, operational environment, and target security level - not applied uniformly across dissimilar facilities.

L4 - FACILITY ENVELOPE
Building Entry / Access Control / Visitor Control
Mantrap portals // Anti-tailgate // Visitor screening
Genetec Synergis - SUPPORTING PLATFORM
Access control infrastructure. Native module within Genetec Security Center. Open API, Mercury hardware support, NDAA-compliant. Functions as the credentialing and door control layer - Ambient.ai sits on top as the intelligence engine that interprets and acts on access events in context.
Gallagher - HIGH SECURITY ALTERNATIVE
Purpose-built for tiered zone-within-zone access control. Strong alarm integration, trusted in government, nuclear, and CNI environments globally. Best choice for the model weight enclave zone.
HID Global
Credentials - mobile (Apple/Google Wallet), multi-technology readers, FIDO2, biometric options. BlueDiamond platform for smartphone-as-badge. Platform-agnostic.
Ambient.ai (Pulsar VLM)
Tailgate and piggyback detection at mantrap entries. Door forced open correlated with live camera feed. 150+ threat signatures. Integrates with Genetec natively.
Evolv Technology
Weapons screening at facility entry. Frictionless throughput for authorized workforce. Detects concealed weapons on contractors and visitors without stopping the line.
Identiv / Allegion
Mantrap and portal hardware. Interlock controllers, anti-tailgate portals, weight and occupancy detection integrated with the access control platform.
Construction Phase Principle: Security is built in, not turned on at go-live. Access control panels, cameras, and a staffed guard post must be operational from the first day of site preparation. Construction workers are insider risk by definition - treat construction access with the same rigor as steady-state operations.
L3 - INTERIOR ZONES
Interior Analytics + Behavioral Detection + SOC Integration
AI video layer // Alarm management // Escort policy enforcement
Ambient.ai (Pulsar VLM) - AI VIDEO ANALYTICS PREFERENCE
Behavioral threat detection platform. Vision language model (VLM) approach reasons about activity in context rather than relying on object classification alone. Agentic video wall, semantic search, and 150+ threat signatures. Demonstrated performance in hyperscale data center environments. The operator interface through which everything else is contextualized. Practitioner preference based on operational fit - not the only capable platform in the category.
Genetec Security Center + Omnicast - VIDEO INFRASTRUCTURE
VMS platform for camera ingestion, recording, storage, and multi-site federation. Certified integration with Ambient.ai and most major AI analytics platforms. Access control events, door alarms, and video streams in a unified interface. Strong multi-site federation capability. Open architecture - supports Axis, i-PRO, and other NDAA-compliant hardware. Practitioner preference for enterprise data center deployments.
Milestone XProtect
Alternative VMS. Largest open ecosystem - 10,000+ compatible camera models. Best choice when maximum hardware flexibility is required. Certified Ambient.ai integration.
BriefCam (Canon)
Forensic video intelligence. VIDEO SYNOPSIS technology condenses hours of footage to minutes for post-incident investigation. Law enforcement grade chain of custody for evidence export.
Actuate
Pure-play AI layer - firearm, intruder, and loitering detection. Certified Genetec integration. 95%+ false alarm reduction. SaaS - no on-prem appliance required.
Hakimo (AI Operator)
Autonomous multi-site monitoring agent. AI triages and handles routine alarm response, escalates to human only on confirmed threats. 40–60% guard force cost reduction documented at multi-site commercial deployments.
L2 - DATA HALL
Compute Floor - Biometric Access + Rack Security + Environmental
MFA mandatory // Rack-level audit // No mobile devices
Genetec Synergis / Gallagher
Data hall threshold: card + biometric minimum. Mantrap or airlock entry. All access logged with video correlation. Remote lockdown capability from GSOC.
Suprema / Idemia
Biometric readers - fingerprint, iris, face recognition. Enterprise-grade, high throughput, anti-spoofing detection. Integrate via OSDP with Genetec or Gallagher.
Panduit / Rack Solutions RSD
Rack Security Devices - individual electronic rack-level locks with access logging and tamper detection. Full audit trail per rack door open event.
Ambient.ai + Axis cameras
Floor-level AI surveillance. Aisle behavior monitoring. Unauthorized crouching and access detection. USB device insertion behavioral signature detection.
Nlyte / Sunbird DCIM
Data center infrastructure management - asset tracking, environmental sensors (temp, humidity, power). Integrates physical security events with operational data for holistic SOC view.

Floor controls required: Escort policy for all non-credentialed visitors. No personal devices on floor without documented exception. All work orders correlated with camera coverage. Two-person integrity rule for any rack work on AI weight hardware at L4+. Environmental sensors (temperature excursion = security alert as well as facilities alert).

L1 - MODEL WEIGHT ENCLAVE
Frontier AI Weight Protection - SCIF-Derived Architecture
RAND SL3–SL5 // Air-gapped OOB // Armed rapid response
The prerequisite problem: RAND and Anthropic's Confidential Inference paper both identify TEE-based confidential computing (AMD SEV-SNP, Intel TDX, NVIDIA H100/Blackwell Confidential Mode) as the priority cyber control for AI model weight protection at SL4/SL5. But TEEs are defeatable through physical side-channel attacks - electromagnetic emanation analysis, power consumption monitoring, cache timing attacks - if the physical environment is not secured first. Physical security is the prerequisite for confidential computing to function as intended.
SCIF-Derived Zone Design
Hardened walls (8"+ reinforced concrete or equivalent), EMI shielding, no windows, RF-hardened if required, separate power circuit, independent HVAC zone, no shared IT infrastructure with production systems.
NVIDIA H100 / Blackwell - Confidential Computing
GPU-level TEE. Protected PCIe encryption. Hardware trust boundary for model weight protection. Requires physically secured hardware environment - side-channel exploitation is possible without it.
AMD SEV-SNP / Intel TDX
CPU-level Trusted Execution Environments. Encrypt compute operations in-flight. Physical side-channel resilience requires EMI/RF shielded enclave to be fully effective.
Gallagher (Enclave Zone Control)
Dual-authentication mandatory. Two-person integrity for all access. All entry events trigger SOC notification. No remote unlock - physical key required as fallback. No exceptions.
Out-of-Band Management Network
Console-only admin access. Physically separate from production and corporate networks. Air-gapped OOB for SL5. Hardened jump hosts as sole ingress. No internet connectivity for management systems.
Google Distributed Cloud (GDC) Air-Gapped Appliance - Commercial Enterprise Reference Architecture
Isolated AI compute is not new - classified cloud environments (AWS C2S, Microsoft Azure Government Top Secret) have operated on air-gap principles for years, and Microsoft deployed GPT-4 in an air-gapped DoD cloud in May 2024. What the Google GDC appliance via Cirrascale (April 2026) adds is the first commercially packaged, enterprise-deployable version of this architecture outside a classified government contract. Gemini runs on a single Dell-built, Google-certified appliance with eight NVIDIA GPUs inside a customer facility - fully disconnected from the internet and Google's cloud. The model resides in volatile memory: power off and it is gone. Session caches clear on session end. Physical tamper detection renders the machine inoperable on confidential compute violation. For maximum assurance, the server is physically swapped rather than reconnected for model updates. This is the production commercial reference for the enclave architecture this framework specifies at L4+. The physical controls at this tier are the envelope that makes such a deployment operationally defensible.
Armed Rapid Response Protocol
Dedicated trained responders on-site or SLA under 4 minutes. Federal counterforce escalation path at L4+. Two-person rule for all enclave access. All anomalies treated as intrusion until cleared.

05 Secure Network Architecture for Physical Security Systems

// Physical security systems must operate as an independent resilience domain - not a dependent service of enterprise IT. They require OT architecture: dedicated segments, deny-by-default policies, local decision-making capability, and survivability during upstream failure. This is not simply "air-gapping" - it is control-plane isolation with restricted, one-way integration back to CorpNet where operationally required.

The T-Mobile lesson: Inadequate network segmentation allowed lateral movement from compromised IT systems into physical access control infrastructure - 37 million records compromised and $500M in fines and settlements. Physical security systems on flat or shared production networks are a liability, not a security control.
Precision on terminology - isolation spectrum: "Air-gapped" is often used loosely. This framework uses a defined spectrum. At the baseline (L2+), the requirement is a dedicated Security Network (SecNet) with its own switching and routing, independent identity plane, and restricted one-way integrations to CorpNet via data diode or hardened API gateway. No physical security systems operate on CorpNet. At L3, control-plane isolation is required - no inbound control from CorpNet, data egress only via controlled gateways, physically separate OOB management. At L4+, the architecture approaches true air-gap characteristics: no external routing, data moves only via controlled transfer mechanisms, management is console-only with physical separation. A true air gap - zero external connectivity, no inbound or outbound routing - is appropriate for frontier AI weight enclaves and classified workloads, but is operationally too restrictive for most physical security system networks, which require controlled integration paths for monitoring and response. The goal at all levels is the same: security systems must not be a dependent service of enterprise IT.

Three-Tier OT Network Model (Purdue-Adapted for Physical Security)

No physical security systems operate here. SOC reporting dashboards only, via one-way data diode or hardened API gateway.

Corporate LAN
IT systems
Guest WiFi
SIEM reporting feed (one-way only)
▼ DENY-BY-DEFAULT FIREWALL - explicitly permitted flows only ▼

Genetec / VMS servers, access control head-ends, analytics platforms. Dedicated VLAN/routing domain. MFA required. Hardened. Role-based access only.

Genetec Security Center servers
Ambient.ai appliance
Access control head-end
SOC workstations
NVR / storage
Physical security SIEM
Hardened jump hosts (admin only)
▼ MICRO-SEGMENTED - each device class on separate sub-segment ▼

Cameras, door controllers, sensors. Each device type on a separate VLAN. No lateral movement between device segments. Deny-by-default.

Camera VLAN (isolated)
Access control panel VLAN (isolated)
Sensor / IDS VLAN (isolated)
Intercom / audio (isolated)
Fiber IDS feed
Drone detection (isolated)
▼ OUT-OF-BAND MANAGEMENT (L4+: physical separation or air-gap) ▼

Physically separate management network. Console-only access for critical systems. No connectivity to production IT. Sole ingress via hardened jump host. For L4+: air-gapped with physical KVM only.

Console server / KVM
OOB management switch
Dedicated fiber (separate physical path)
Vendor remote access gateway (monitored, time-limited)

Network Hardware Recommendations

Palo Alto Networks
Next-gen firewall for security network segmentation. Strata platform for Zero Trust enforcement between management plane and device layer. App-ID for granular permit rules per device class.
Cisco Catalyst / Meraki
Core switching for security VLANs. Meraki for cloud-managed multi-site with centralized policy. Catalyst for on-prem with full IOS feature set. Both NDAA-compliant.
Aruba CX / HPE
Dynamic segmentation for PoE security device infrastructure. ClearPass NAC - enforces policy before any camera or controller gains network access. Strong for large campus deployments.
Fortinet FortiGate
Alternative NGFW with strong OT/ICS segmentation. FortiNAC for automated device discovery - new cameras and panels are quarantined until policy-approved. Good value at scale.
Opengear / Vertiv
Out-of-band console servers. Cellular failback for OOB when primary network is down or compromised. Critical for maintaining security system management during active incidents.
Claroty / Dragos
OT security monitoring for the physical security device network itself. Passive asset discovery, anomaly detection, and vulnerability assessment on access control panels and camera firmware.
Power resiliency requirement: Security systems shall be powered from facility (house) power - not data hall IT load. UPS minimum 15-minute ride-through at full load, aligned with generator start and stabilization time. Dedicated security electrical panels on separate branch circuits. Generator restoration priority assigned to security loads as part of COOP planning. If the site is operational, security must be operational.
Industry Validation - April 2026: The air-gap architecture enters commercial production

The concept of isolated AI compute is not new. AWS GovCloud and C2S established physically and logically isolated cloud regions for the intelligence community over a decade ago. Microsoft deployed GPT-4 in an air-gapped Azure Government Top Secret cloud for the Department of Defense in May 2024, followed by GPT-4o accreditation for classified use in January 2025. SCIF environments and ICS/OT networks have operated on air-gap or near-air-gap principles for decades. The architecture pattern is well-established in classified and industrial environments.

What changed in April 2026 is the delivery model. Google's Distributed Cloud air-gapped appliance, deployed commercially via Cirrascale Cloud Services, makes a frontier proprietary AI model available as an enterprise-deployable, on-premises appliance - outside of a classified government cloud contract, accessible to any regulated commercial enterprise. The model lives in volatile memory. Power off and it is gone. Physical tamper detection destroys the confidential compute boundary on violation. This is the first time that combination - frontier model, commercial availability, customer-controlled facility, fully disconnected operation - has been packaged as a production product. The three-tier OT architecture in this section is the physical security network equivalent of that design philosophy. The argument is the same: systems protecting critical assets cannot depend on a shared, less secure network.

06 Security Architecture by Facility Type

// Threat surface, maturity requirements, and budget allocation differ significantly across deployment types. One size does not fit all.

Hyperscale / AI Campus
Colocation
Edge DC
Hybrid Enterprise

Hyperscale / AI-Optimized Campus (200MW+ / Multi-Building)

This is the frontier AI model weight environment. OpenAI, Anthropic, Google DeepMind. Multi-billion dollar asset concentration. Nation-state adversary capability assumed at the weight enclave level. RAND SL3–SL5 applies.

DomainRequirementPrimary Systems
Maturity LevelL3 baseline / L4 for AI weight zones / L4+ for frontier training clustersRAND SL3–SL5 crosswalk (see Section 08)
PerimeterFull campus perimeter with anti-drone netting on critical outdoor equipment. FIDS on fence line. Extended drone detection (1–2 mile radius). Vehicle barriers at all entry points. Overhead netting on generators and cooling equipment.Axis cameras, Bandweaver FIDS, Dedrone C-UAS, Evolv at personnel entry
Access ControlGenetec Synergis or Gallagher. Zone-within-zone: campus → building → data hall → row → weight enclave. Each transition requires MFA. Biometric mandatory at data hall threshold and all inner zones.Genetec + Mercury hardware, HID credentials, Suprema biometric readers
AI VideoAmbient.ai Pulsar VLM across all zones. Agentic video wall in GSOC. Semantic search for forensic investigation. Automated dispatch workflow for confirmed anomalies.Ambient.ai + Genetec, ZeroEyes on outer perimeter, BriefCam for forensics
Model EnclaveSCIF-derived construction, EMI shielding, air-gapped OOB management, 2N UPS, separate HVAC, two-person integrity rule, armed rapid response SLA under 4 minutes, no mobile devices permitted.Gallagher, NVIDIA H100/Blackwell CC mode, AMD SEV-SNP, Opengear OOB
NetworkFull 3-tier OT architecture. Separate routing domains per device class. OOB with physical separation. Palo Alto NGFW enforcing Zero Trust between tiers. Claroty monitoring OT device layer.Palo Alto, Cisco Catalyst, Aruba NAC, Opengear OOB, Claroty
UpstreamDedicated substation with full camera, analytics, and IDS coverage. FIDS on all fiber ingress. Utility liaison MOU, joint tabletop exercises, real-time telemetry integration into SOC.Axis cameras + ZeroEyes on substation, Bandweaver FIDS, DBT assessment
Guard ForceOperational Intelligence Officers trained on AI systems, not just observation. Two-person rule for high-security zone access. Armed response element on-campus at L4. Federal coordination protocol at L4+.Specialized DC security staffing model, AI system operator certification program

Colocation Facility (Multi-Tenant / Shared Infrastructure)

Colo adds complexity: your posture must account for dozens of tenants with different risk profiles sharing infrastructure. The shared model means perimeter and facility controls protect everyone - but cage and data hall controls must be tenant-specific. One tenant's insider compromising another is a real and documented risk vector.

DomainColo-Specific RequirementSystems
Maturity LevelL2 Enhanced baseline. Tenants with AI weight workloads should contractually negotiate L3+ cage-level controls and explicit audit rights.RAND SL2 baseline
Tenant IsolationSeparate access credentials per tenant. No cross-tenant visibility in VMS. Cage-level rack security with tenant-managed credentials. Audit logs exported to tenant SIEM independently.Genetec multi-tenant federation, Panduit RSD, HID multi-tenant credential management
Shared PerimeterColo operator owns perimeter, building envelope, data hall threshold. Tenant owns cage and above. Contract must specify response time SLAs, alarm management obligations, and incident notification windows.Colo: Axis/Ambient.ai/Genetec. Tenant-managed: cage locks, rack security devices
Visitor / EscortNo unescorted third-party access to data hall. All visitors logged with camera correlation. Two-person rule for remote hands in AI weight cages. Visitor credentials time-limited and auto-expired.Genetec visitor management, camera coverage on all remote hands activity
Audit TrailImmutable access logs exported to tenant SIEM. Camera recordings retained per SLA (minimum 90 days for AI weight zones). Incident notification SLA to tenant within 1 hour of detection.Genetec audit export API, BriefCam forensic review, SOC-to-tenant notification workflow

Edge Data Center (Micro-DC / Distributed / Unstaffed or Lightly Staffed)

Edge DCs are the hardest to secure well. Small footprint, often unstaffed, distributed across many locations, high physical accessibility. The security model here is less about depth and more about remote visibility and autonomous response. AI does the monitoring - humans respond to verified events.

DomainEdge-Specific ApproachSystems
Maturity LevelL1–L2. Physical controls must compensate for absence of on-site personnel. Cloud-managed everything.RAND SL1–SL2
Remote MonitoringAll alarms fed to centralized GSOC. Hakimo AI Operator handles routine events autonomously. Human operators receive only escalated, verified threats. Target: human intervention for true positives only.Hakimo AI Operator, Rhombus (cloud-native VMS), Ambient.ai where site scale justifies the appliance
Physical HardeningReinforced enclosure. Tamper-evident seals on equipment racks. No windows. Single controlled entry. Bollards if vehicle intrusion risk exists. Overhead netting if drone threat is relevant.Prefab secure enclosures (Crenlo, Rittal, Vertiv), Panduit rack security devices
Access ControlCloud-managed with local credential caching (fail-secure on loss of connectivity). Mobile credentials. Every access event generates GSOC alert. Two-factor minimum. Remote lockdown from GSOC available.Avigilon Alta, Brivo, or Kisi - all cloud-native with local caching and GSOC integration
CamerasCloud-managed cameras with on-camera AI analytics. Person detection and motion feeds GSOC in real time. Evidence-grade recording retained minimum 90 days.Axis cloud-connected, Rhombus, Avigilon Alta - cloud-managed, no on-prem server required
NetworkDedicated 4G/5G OOB cellular backup for security systems. If primary connectivity fails, security systems maintain cloud connectivity and local access control decisions continue via cached credentials.Cradlepoint cellular gateway for OOB redundancy, cloud-managed security systems
ResponseArea patrol contract: verified response within 15 minutes minimum. Pre-defined law enforcement escalation for confirmed breach. GSOC coordinates dispatch - no on-site guard reliance.Local patrol contract, TrackTik dispatch integration from GSOC

Hybrid Enterprise Data Center (On-Prem + Colo + Cloud Mix)

Enterprise DCs running a combination of on-prem infrastructure, managed colo cages, and cloud workloads. Security posture must span all three without creating blind spots at handoff boundaries. The most common failure mode: security is architected only for the on-prem piece.

DomainHybrid-Specific ApproachSystems
Maturity LevelL2 on-prem baseline. Colo portions governed by operator SLA with contractual audit rights. Cloud physical security is provider-managed - audit their controls and contractualize notification timelines.RAND SL2
On-PremFull onion model for on-prem data hall. Genetec Security Center unifying VMS and access control. Ambient.ai for AI analytics. Dedicated security OT network per Section 05 architecture.Genetec + Ambient.ai + Axis + Gallagher/Synergis
Colo / Co-managedContractual SLA for access logs, incident notification, escort policy, camera retention, and audit rights. Tenant-managed cage security. Unified into on-prem SIEM for single visibility pane.Rack security devices, cloud access control, Genetec federation
Unified VisibilitySingle GSOC view across on-prem, colo, and edge. Genetec Federation or Milestone Federated Architecture for multi-site video. SIEM aggregating physical security events from all locations into one dashboard.Genetec Federation, Splunk or Microsoft Sentinel for physical event correlation
Vendor AccessRemote vendor access via secured, monitored gateway only. No direct remote access to security OT network. All sessions recorded, time-limited, and provisioned through PAM solution. Zero standing access.CyberArk or BeyondTrust PAM for all vendor remote access to security systems

07 SOC / GSOC Architecture - Scalable from Single-Site to Global

// SOC architecture should be built around verified, AI-pre-triaged events - not raw alarm queues. AI video analytics handle volume; human operators handle decision-making. The platform stack below reflects practitioner preferences based on data center operational experience.

Tier 1 - Site-Level SOC (Single Facility)
1–5 operators // 1 site // L2–L3

Single-site SOC at L2–L3 maturity. AI video analytics handle alarm pre-triage - operators respond to verified escalations, not raw sensor events. Genetec Security Center provides the video and access control infrastructure. Ambient.ai (preferred AI analytics layer) surfaces relevant feeds and pre-triages events before they reach an operator, reducing alarm volume 60–70% in documented deployments. Mission Control automates SOP-driven workflow. TrackTik or Guardtek manages guard force operations and patrol verification.

Ambient.ai - PREFERRED AI ANALYTICS
Agentic video wall surfaces relevant feeds automatically. Pre-triages alarms before they reach a human operator. Semantic search for incident investigation. 150+ behavioral threat signatures. Practitioner preference for data center SOC environments.
Genetec Security Center + Omnicast
VMS infrastructure. Camera ingestion, recording, retention, and Synergis access control events in one platform. Certified integration with Ambient.ai and other AI analytics platforms. Federation-capable for multi-site growth.
Genetec Mission Control
Incident workflow engine. SOP automation, role-based task assignment, audit trail for all operator actions. Triggered by AI-verified escalated events.
TrackTik / Guardtek
Guard force management - patrol scheduling, post orders, mobile officer app, incident reporting. Dispatch triggered by AI-verified alarm escalations.
Tier 2 - Regional GSOC (Multi-Site Portfolio)
5–15 operators // 5–20 sites // L2–L3

Centralizes monitoring for a regional portfolio. AI analytics (Ambient.ai preferred) handle the majority of alarm triage autonomously across all sites. Hakimo supplements for routine after-hours autonomous response. Genetec Federation provides the unified video and access infrastructure across all locations. Human operators focus on verified, escalated events only - not raw alarm queues.

Ambient.ai - PREFERRED REGIONAL INTELLIGENCE
Regional threat detection and behavioral analysis across all sites. Semantic search for cross-site forensic investigation. Agentic video wall at the GSOC console. Practitioner preference for multi-site data center portfolio operations.
Genetec Federation
Federated video and access control infrastructure. Single GSOC view across all sites. Each site continues operating independently if GSOC connectivity is lost. Foundation layer for multi-site portfolio visibility.
Hakimo AI Operator
Autonomous 24/7 routine alarm handling across the portfolio. Handles low-priority events independently, escalates confirmed threats to the analytics layer or directly to human operators per defined protocol.
Splunk / Microsoft Sentinel
SIEM aggregating physical security events with cyber events. Correlated alerts - AI-detected physical anomaly combined with a network event elevates response priority automatically.
TrackTik
Guard force management across all sites. Dispatch triggered by AI-verified escalations. Patrol verification, KPI dashboards for SLA compliance reporting.
Tier 3 - Global GSOC (Hyperscale / Multinational Portfolio)
15–40+ operators // Global // Follow-the-sun model // L3–L4+

Operates 24/7/365 with follow-the-sun nodes. AI analytics are the primary operator interface at every GSOC node globally. AI handles 95%+ of alarm volume autonomously at this scale. Human operators function as Operational Intelligence Officers: interpreting what the AI surfaces, making escalation decisions, coordinating with law enforcement and federal agencies, and managing the armed response element. Genetec Federation runs underneath as the global video and access control infrastructure. This is not a monitoring center. It is a command center built around AI-enabled human decision-making.

Ambient.ai - PREFERRED GLOBAL ANALYTICS PLATFORM
Primary operator interface at every GSOC node. Consistent AI detection posture and threat signature library across all facilities globally. Agentic video wall. Semantic search for cross-site investigation. Practitioner preference for hyperscale global portfolio command operations.
Genetec Security Center + Federation
Global video and access control infrastructure. Each site operates independently if GSOC connectivity fails. Centralized policy, distributed execution. Single audit trail across the global portfolio. Foundation layer.
Palantir Foundry / Hexagon AB
Decision layer above AI analytics for nation-state threat environments. Cross-site pattern analysis, predictive threat intelligence, command-and-control for CNI scenarios. Converts security data into executive-level operational intelligence.
Splunk Enterprise Security
Global SIEM. AI-detected physical events correlated with cyber events. Threat hunting, compliance reporting, federal incident reporting workflow automation.
ServiceNow SecOps
Incident management at global scale. Automated ticket creation and escalation routing triggered by AI-verified events. SLA tracking and post-incident review workflow.
The Operational Intelligence Officer model: These are not guards watching screens. They are trained practitioners who understand AI system outputs, interpret behavioral threat signatures, make rapid decisions under pressure, and interface with law enforcement and federal agencies. The role is a new profession that the industry needs formal educational infrastructure to support - as argued in the Escalating Cyber-Physical Defenses paper.

08 RAND SL Crosswalk - Physical Controls by Security Level

// Physical security maturity aligned to RAND's SL1–SL5 cyber framework. Physical controls escalate autonomously with workload criticality and adversary capability - independent of, yet aligned with, cyber maturity.

LEVEL RAND SL PHYSICAL CONTROLS REQUIRED KEY SYSTEMS
L0 SL0 Basic safety compliance only. No adversarial design. Not appropriate for any production data center - do not accept this as a baseline. N/A
L1 SL1 CPTED site design baseline. Anti-climb perimeter fencing (Gibraltar or equivalent - anti-cut, anti-dig, anti-climb). Crash-rated bollards at vehicle entry. Camera coverage, contracted guard force presence, card-only access control, basic VLAN segmentation, UPS on security head-end. Gibraltar fencing, Axis / i-PRO cameras, Genetec or Avigilon Alta (entry), crash-rated bollards, contracted guard force
L2 SL2 Hardened access (card + PIN or biometric), AI video analytics, perimeter IDS (Bandweaver fiber or Senstar buried cable per site conditions), dedicated security routing domain, FIDS on critical fiber ingress, monitored substation, utility liaison MOU, generator-backed security systems, drone detection awareness and HOP physical measures. Genetec + Ambient.ai + Axis, Senstar OmniTrax or Bandweaver (site-condition driven), Dedrone, dedicated security panel + generator
L3 SL3 SCIF-derived data hall zones, dual-path telecom, trained on-site responders, TEE mandatory for AI compute hardware, OOB management network (physical separation), armed rapid response SLA, joint utility tabletop exercises, C-UAS RF detection layer, construction-phase security from Day 1. Dual-fence perimeter with Senstar buried IDS in detection corridor where build type and threat environment warrant it. Gibraltar hardened fencing (dual-fence where warranted by build/threat), Senstar OmniTrax, Gallagher + Genetec, Ambient.ai full deployment, NVIDIA CC mode, Dedrone full stack, Opengear OOB, Palo Alto NGFW, Claroty OT
L4 SL4 Multiple hardening layers (physical, electronic, human), air-gapped weight enclave, 2N UPS for security enclave, utility separation strategy, armed response force on-site, C-UAS electronic detection and mitigation, DBT assessment per IAEA/NERC CIP-014 methodology, federal coordination (CISA, FBI, DOE CESER), joint SOC operations with serving utility. AI inference hardware operating inside customer facility on fully isolated network with volatile-memory-only model storage - consistent with Google GDC air-gapped appliance architecture (April 2026). Gallagher, Ambient.ai + Palantir/Hexagon, full C-UAS stack, Splunk, federal liaison protocols, NVIDIA H100 CC + AMD SEV-SNP, Google GDC air-gapped appliance (AI inference at L4)
L4+ SL5 Multi-site SCIF architecture, post-quantum cryptography (NIST Kyber / Dilithium) for harvest-now-decrypt-later threat, federal counterforce integration, classified threat briefings, embedded analyst model with serving utility, air-gapped OOB with console-only admin, extraordinary measures per RAND - requires national security community support. RAND estimates 5+ years to achieve with NSC support. Federal coordination, classified systems, NVIDIA Blackwell CC, PQC implementation, CISA/NSA alignment, multi-facility resilient topology
The gap RAND did not close: RAND's SL framework is cyber-centric and assumes physical security as an unstated baseline without specifying what that baseline is. This framework fills that gap. Physical security is not a derivative of cybersecurity - it is the foundational prerequisite. Confidential computing TEEs are defeated by physical side-channel attacks if the enclosure is not secured. SL4 cyber controls deployed inside an L1 physical environment deliver L1 actual protection. The two must escalate together.
April 2026 - Commercial deployment validates the SL4 architecture: Isolated AI compute is not a new concept. Classified environments have operated on air-gap and near-air-gap principles for decades, and Microsoft deployed GPT-4 in an air-gapped Azure Government Top Secret cloud for DoD in 2024. What changed in April 2026 is that Google's Distributed Cloud air-gapped appliance, via Cirrascale Cloud Services, made this architecture commercially available outside classified government contracts - a frontier proprietary model running on a customer-controlled, fully disconnected appliance in any regulated enterprise facility. Volatile memory storage means the model is gone when power is removed. Physical tamper detection destroys the confidential compute boundary on violation. This is the production-deployed, commercially available reference point for the SL4/L4 architecture this framework specifies. The hardware is only as secure as the room it sits in - and that room requires the physical controls at this tier to make the deployment defensible.