Hyperscale data shifts spotlight to security of operation-critical energy and water infrastructure
The security needs of huge data centres are in the headlines again, with the focus moving to the responsibility of designers, builders, owners, and operators to protect new technologies designed to reduce impacts on community energy and water resources.

By Michael Fisher, Managing Director, Boon Edam Australia
The security needs of huge data centres are in the headlines again, with the focus moving to the responsibility of designers, builders, owners, and operators to protect new technologies designed to reduce impacts on community energy and water resources.
The issue – of which data centre operators and investors are highly aware, and to which they are actively responding – has arisen as transformational investment in data centres pours into Australia. In the past year, for example, Microsoft has announced $A25b will go into Australian data centres and Amazon Web Services has committed another $A20b.
Commentators, including climate activist Independent Federal Senator David Pocock and business media commentator Alan Kohler, both argue that not only should Australians get a fair financial return from the artificial intelligence (AI) data centre boom, but note that these massive facilities could impact national resources by consuming large amounts of local water and electricity.
So what are the dangers?
The political equity debate is not the focus of this article.
We are focused, rather, on layered physical security for current and emerging solutions to data centre energy and water use issues as hyperscale data infrastructure becomes an integral component of our national infrastructure.
We explore how to make sure these solutions are access-protected and can continue to deliver the function for which they are designed: to protect against outages that could pose risks to their operational viability and social licence to operate.
The observations that follow are borne of our long-term experience as part of the Royal Boon Edam Group, based on real applications of layered security solutions for data facilities both in Australasia and globally. These applications range from smaller and in-house operations right through to some of the world’s very largest data centre operations (which we cannot name in this article, for security reasons – but we are happy to discuss the principles involved and the technologies to which they may apply, as follows).
Risk management – energy
With electricity, data centre operators understand that the first and most obvious danger is the need to prevent excessive energy draw where they operate on shared grids, so as to avoid driving up prices, or causing spikes in demand that could cause cascading outages through the grid.
Such safeguards are vital, when you consider that a single large data centre campus can use as much electricity (and water) as a mid-sized city. This creates a risk that large and concentrated demand could contribute to grid instability if safeguards fail.
Energy demand of data centres is a rapidly expanding issue, which the Australian Energy Market Operator is highlighting. Australia's data centres already consume about 3.9 TWh (terawatt-hours) of electricity, which is roughly 2% of grid-supplied power.
Driven by the boom in artificial intelligence and cloud computing, this demand is expected to triple by 2030 and could reach 34.5 TWh by 2050, according to economic advisory and forecasting firm Oxford Economics Australia.
This steep trajectory underscores the increasing importance of data centres as a structurally significant electricity load within Australia’s energy system. Of the projected 34.5 TWh, 33.8 TWh is forecast to be on the National Electricity Market, NEM, representing 12% of NEM grid-supplied consumption by FY50. This is highly significant, given that the NEM Step Change scenario is the primary roadmap used by the Australian Energy Market Operator (AEMO) to guide Australia's power grid transition, which in turn is fundamental to our national objective to be carbon neutral by 2050.
The long-term benefits will ultimately be assessed against outcomes such as support for local industry, sovereign technology capability, and returns on investment in Australia's electricity infrastructure.
But what happens, doubters ask, if a hyperscale data centre suddenly loses power or trips offline? This scenario looks to the power grid like a massive, instant drop in electrical demand. If a cluster of centres was to fail at the same time, it can cause an immediate power surge, with a supply-demand imbalance potentially triggering cascading blackouts across regions affecting communities and businesses.
Data centre operators and investors are well aware of these risks and generally support measures that strengthen grid stability.
New grid connection rules
The Australian Energy Market Commission (AEMC) is working to tighten technical standards for large users, including data centres with loads over 30 MW.
AEMC Chair Anna Collyer says clear grid standards are essential to supporting Australia’s data centre growth without compromising system security.
“Data centres aren’t passive loads anymore; they’re active grid participants. When they fail to ride through faults, it has the potential to trigger cascading failures and blackouts,” Ms Collyer said.
“We have seen this happen overseas, and it can cost consumers billions in lost electricity supply or emergency network upgrades.
“These proposed (AEMC) standards would help prevent that. They are designed to enable investment with certainty, not block it. Data centre operators would know exactly what’s required upfront, and network service providers would be able to apply technical connection standards consistently.”
The standards are currently (mid-year) being worked upon and may focus on aspects such as:
- Disturbance ride-through: Data centres must remain connected through minor grid faults and operate stably during voltage drops.
- Fast recovery: Facilities must quickly restore normal power demand once grid conditions stabilise.
- Strict Testing: Operators face expanded testing and compliance obligations before plugging into the grid.
Risk management – water
Not only is security to protect smooth continuity of energy vital, but also strong physical security must focus on facilities dedicated to restraining water use, particularly demand from cooling facilities.
Large data centres can consume up to 19 million litres a day, equivalent to the water use of a town of up to 50,000 people, according to the Environmental and Energy Study Institute, EESI (which was founded in the data centre capital of the world, the USA, by a bipartisan group of members of the US Congress to provide science-based educational resources to policymakers and the public).
As designers and builders of data facilities know, water use is driven in large measure by the fact that server hardware generates intense heat. Operators use water-cooled systems because water moves heat much more efficiently than air. But in dry areas such as Australia, heavy water usage could create competition with local communities and agriculture.
So smart operators of data centres understand the issue and are acting to overcome hurdles and issues it presents. Data Centres Australia (the industry association), for example, actively advocates for transparency, efficiency, and the use of non-drinking water. They highlight that data centres currently consume a tiny fraction (0.4 per cent) of national water supplies, but actively support sustainable practices to manage future growth. Governments also monitor these usage levels to ensure local drinking supplies are not harmed.
To help reduce water use, data centres can use many technologies, including closed-loop cooling, which recirculates the same water. Many also use recycled or reclaimed wastewater instead of fresh drinking water.
Direct-to-chip (D2C) data centre cooling is becoming a new industry standard. Because high-performance AI chips generate intense heat, with modern chips exceeding 700 watts, traditional air fans cannot remove heat fast enough.
Unlike total immersion cooling (where servers are submerged in liquid), D2C connects directly to the chips. This means operators can easily install D2C in older buildings without a massive rebuild.
D2C systems – including those engineered by Australian companies – solve this by pumping coolant through metal cold plates attached directly to CPUs and GPUs.
Massive energy efficiency gains can result, because liquid removes heat significantly more effectively than air, dropping server fan energy use by up to 80%.
Proponents of D2C cooling say it can also reduce a data centre’s cooling water usage by up to 100%. By circulating a sealed, closed-loop fluid directly to processors, these systems completely eliminate the need for evaporative cooling towers. This allows facilities to achieve a massive leap in water efficiency. So technology is responding to change, in these examples and in other ways (such as advocating that data centres use green energy, to actually help drive the energy transition to the national benefit).
The bottom line
But D2C data centre cooling and other water and energy-saving initiatives often come with high upfront costs, even as they lower long-term operating expenses and less risk of disruptions to surrounding communities.
And, because they are becoming so important, they must be physically protected, as closely as current security systems protect other operational and personnel areas of data centres.
Physical security is critical for safeguarding a data centre's energy and water-saving assets because unauthorised access, physical vandalism, or sabotage of equipment such as chillers, UPS systems, battery storage systems, and grid management infrastructure can cause major system failures. This in turn can result in massive operational downtime risks, environmental damage, and non-compliance with government sustainability and critical infrastructure regulations.
So protection of critical infrastructure should include:
- Grid and dedicated power facilities: Energy-saving assets (such as battery banks, microgrids, and high-efficiency transformers) are, because of their criticality, targets for sabotage. Physical breaches at these points compromise the continuous power supply required to maintain network stability.
- Cooling and water systems: Water filtration units, evaporative cooling towers, and new closed-loop chillers and D2C technology cores require security enclosures and strict access regulation. Interfering with or contaminating these systems can lead to burnout, hardware damage, and local environmental hazards.
- Besides internal or external sabotage, there is also accidental disruption to safeguard against: Strict access controls (such as biometrics and mantraps) ensure that only authorised, trained personnel have access to highly sensitive cooling and electrical zones. (Such selective physical barriers also help prevent accidental bumps, spills, or improper adjustments to valves and control cabinets by visitors or unvetted maintenance staff).
- Regulatory Compliance: Data centres are already subject to robust security obligations under the Security of Critical Infrastructure (SOCI) Act, which imposes mandatory reporting, risk management and compliance requirements on operators of critical data infrastructure. Many regions also mandate strict compliance requirements regarding energy efficiency and water usage, because physical failure or asset compromise can result in outages that can lead to substantial operational fines or revocation of operating licences.
With the huge investment now occurring in data centres – and also in the means to make them optimally efficient in resources use – the capital cost of repair or replacement of highly specialised sustainable infrastructure requires significant capital. Replacement of such infrastructure can also take months to source, leading to damaging business interruption costs.
So security of these resources is an important, complex, multi-layered issue, which typically begins with site-level perimeter safeguards and extends inward through 24/7 video surveillance of revolving entrances and speed gates, biometric authentication, and the ultimate strict mantrap-level controls to ensure total operational resilience of vital areas.
It requires a many-faceted response. One size or type of security does not fit all. Protecting people and community assets requires a “layered” physical security approach that companies such as our own Group practice worldwide.
If you are interested in how world leaders in data centre technology manage their risks, Download Boon Edam’s white paper, “Best practices for data centre security and efficiency” for more insights into data centre security.