Skip to contentSkip to footer
returnToHomeBoon Edam logo
Contact

By Mike Fisher*, Managing Director, Boon Edam Australia

Canberra, our State capitals, and energy regulators have all weighed in on how to make them work best for Australia, while the Australian Treasury has warned that we risk missing out on the economic boom of artificial intelligence (AI) if we don’t correct a slow, shallow rate of adoption across local businesses. 

Fewer than one in 10 Australian businesses report significant adoption of AI, Treasury notes in a briefing to Treasurer Jim Chalmers, and we could miss out on the major economic benefits of AI unless domestic businesses move past superficial usage and deeply overhaul their operations. 

So, increasingly, governments understanding the risk of economic and technological isolation that would most likely occur if we fall behind in the digital and AI economy – thus losing strategic sovereignty by relying heavily on overseas infrastructure in areas such as national security, data control, and regional technology leadership.

The potential losses would cut deeply into the economy if we lacked the computing facilities needed to run modern AI and cloud services, placing Australian businesses and researchers at an operational disadvantage, reducing competitiveness, and starving tech startups and scientific research of the technology they need.

Our foremost scientific and technology organisation, the CSIRO, has reminded us that its forecast of $315 billion in benefits from digital technology over the next several years are tied to timely development of data centres and AI infrastructure, while warning of the significant energy and resource challenges they create. 

Recognising that the data centre discussion isn’t one-sided, and that high-performance computing creates heavy cooling demands, the CSIRO is researching advanced closed-loop and sustainable cooling solutions (such as carbon-dioxide systems) to minimise environmental footprints, according to the peak body representing the HVAC&R industry in Australia, AIRAH. The Clean Energy Finance Corporation, meanwhile, warns that data centres could consume up to 11% of Australia's electricity by 2035.

So, the rapid expansion of AI has sparked truly worthwhile and timely debate over the massive electricity and water demands of digital infrastructure, bringing home to designers, developers and operators of data centres the measures that need to be considered to maintain a social licence to operate.

Physical security – my particular area of business – is starting to be given the attention it thoroughly deserves, as hyperscale facilities increasingly concentrate the data and AI infrastructure upon which not only our businesses depend, but also our private and public infrastructure.

This collection and increasing concentration of critical infrastructure goes far beyond financial, telecommunications, and private and industrial IP, to span the spectrum of logistical infrastructure, including food supply and health services, through to public and personal records, defence, energy, water, and other critical areas where data centres are already subject to robust and expanding security obligations under the Security of Critical Infrastructure (SOCI) Act.

The tide of change is turning towards data centres and AI 

Prime Minister Anthony Albanese supports AI data centre development in Australia, but has called for strict national standards requiring operators to cover their own infrastructure and resource costs.

While supporting data centre expansion to capture economic benefits, the Government is proposing mandatory standards covering power, water, and community impact.

The latest Federal regulatory moves are mirrored by the Australian Energy Market Commission (AEMC), which has released a draft rule proposing new technical standards for large data centres and similar facilities connecting to the National Electricity Market. 

The proposed data centre energy and grid rules are currently the ministerial review stage, with formal National Electricity Rule (NER) changes scheduled for consideration in September.

AEMC notes that most data centres use inverter-based technology, similar to that used in many wind and solar farms, as well as batteries. When the grid experiences a credible disturbance such as a voltage dip, these facilities can suddenly disconnect – and if many disconnect simultaneously, it could increase the risk of cascading outages or instability. 

AEMC recalls that in July 2024, 60 data centres in the U.S. state of Virginia pulled 1,500 MW off the grid simultaneously during a single fault. This contributed to cascading failures and grid instability. Similar incidents in Ireland and Texas have prompted some jurisdictions to pause new data centre connections.

What the AEMC is proposing

The draft rules of interest to designers, developers, builders, and managers include three key changes:

First, a clearer framework for defining and classifying large inverter-based loads (including data centres), which would determine when and to which parties the technical connection standards apply, particularly for those parties connecting to the distribution network. The draft rule would raise the current threshold for large inverter-based loads from 5 MW to 30 MW and embed this definition directly in the National Electricity Rules, so stricter technical requirements apply only to those most likely to affect power system security.

Secondly, data centres would need to meet specific disturbance ride-through requirements, staying connected during certain voltage and frequency disturbances and recovering power within defined timeframes. These standards are based on actual plant capabilities and grid needs.

Third, alignment with global practice. By largely matching the standards proposed or used in the U.S. state of Texas, Ireland, and Finland, data centre operators could use the same equipment and feasibility studies used elsewhere. This standardised approach would mean faster deployment, lower costs, and better investment certainty.

So the discussion is no longer “If”, but “How”

AEMC Chair Anna Collyer says clear grid standards are essential to supporting Australia’s data centre growth without compromising system security.

Recent advice from the AEMC also recommends that data centres:

  • Bring new clean energy to offset their power use.
  • Prove their demand is backed by firm power capacity.
  • Register as active market participants instead of passive loads.

And how do we physically protect this major investment?

Just like the discussion about whether we should embrace AI is progressing rapidly, the discussion in my area, physical security, has also moved from “If” to “How”.

This need for protection of people, places, and vital facilities (ranging from server rooms through to essential HVAC, water, and energy controls) is expanding rapidlyc as hyperscale data facilities become critical components of our national infrastructure.

Data centres are quickly becoming too large and too important to our society to fail, so the cyber and physical security of data centres is now a matter of Government regulation and compliance. These statutory responsibilities to protect critical infrastructure and data fall under the Security of Critical Infrastructure Act (SOCI Act), which providers to the industry have a legal Duty of Care to understand and act upon.

Layered physical security of data centre hubs complements cybersecurity – each type of centre security is not complete without the other.

Layered physical security of data centre hubs complements cybersecurity – each type of centre security is not complete without the other. Mantrap portals (above) provide a high level of 24/7 protection against “piggybacking” and unauthorised access.

The Boon Edam Group, of which I am part, has particular expertise in the physical security priorities that must be addressed in compliance with such codes, nationally and internationally. 

Our experience has been built through providing security entrance systems to several of the world’s largest and most influential “Big Tech” companies, across different sectors of the digital economy. 

This experience in physical security – the other side of the coin from cybersecurity – addresses the protection of physical infrastructure and data within facilities ranging from in-house and dispersed networks, through to the needs of the very largest hyperscale facilities of the types arriving here. Physical security considerations include:

  • High-value targets, ranging from financial and commercial IP through to public and personal data. Because data centres are often highly centralised, physical damage – whether from sabotage, vandalism, or environmental factors – can disrupt services for thousands of clients with cascading risks to infrastructure.
     
  • Insider threats: Malicious insider threats to data centres may involve current or former employees, contractors, or business partners abusing their authorised access to compromise physical or digital infrastructure. “Accidental insider threats” may involve staff or suppliers who unintentionally cause security breaches through poor data protection practices, or falling for scammers’ access tricks such as fake technicians, auditors, deliveries, and “new” employees. These physical security requirements also extend to maintenance workers, cleaners, or external vendors who possess physical or remote access privileges but lack internal oversight.
     
  • Defence-in-depth: Security technologies are employed not just at the entrance, but layered throughout the facility, providing protection at appropriate levels covering everything from lobby and general areas access, through to critical server cabinets and power substations that support these energy-hungry facilities, as well as the large and essential HVAC plants that cool them.
     
  • Stringent access technologies: Government and high-risk data centres often employ biometric authentication and restrict devices with wireless functionality. Stronger access security enables selective entry for employees, contractors, and visitors with biometrics, two-factor authentication (2FA), and mobile credentials. Security systems can be validated through regular, rigorous penetration testing and audit procedures. Cyber-physical integration combines layered physical security measures with cybersecurity solutions to address both internal and external threats.
Layered physical access security (above) ensures that if one barrier fails, the next layer stops the threat.

Layered physical access security (above) ensures that if one barrier fails, the next layer stops the threat.

Layered physical security mitigates insider and external risks, combining multi-factor credentials, surveillance, and barriers. 

As practised by international leaders in the field, including clients of the Boon Edam Group, layered security is relied upon to meet expanding international and local statutory requirements as they evolve. 

It also aligns with rigorous compliance frameworks, including SOC 2, which requires appropriate controls and evidence to demonstrate the security of systems and data, as well as ISO/IEC 27001, the world's leading international standard for managing information security, providing a framework for an Information Security Management Systems.

Download Boon Edam’s white paper, “Best practices for data centre security and efficiency for more insights into data centre security. Contact the Author for personal attention to your needs.
 

About the Author

*Mike Fisher is Managing Director of Boon Edam Australia, which is part of the privately owned international Royal Boon Edam group, which provides architectural revolving door and layered security solutions to some of the world’s largest companies, Fortune 500 companies, and companies in Australia, New Zealand, and Papua New Guinea including financial, data and telecommunications, Federal and State Government, hospitality, health and age care, logistics, retail, and distribution facilities. Boon Edam Australia operates under Master security licence number: 000104487.