Data center security spending overwhelmingly targets what happens on screens: phishing defenses, credential monitoring, endpoint detection. That focus makes sense. IBM’s 2025 Cost of a Data Breach Report puts the global average cost of a breach at $4.44 million, with cybercriminals using AI in 16% of breaches, often in phishing and deepfake attacks.
In the United States, average breach costs have surged past $10 million, driven by steeper regulatory penalties and rising detection and escalation expenses. Malicious insider attacks remain the most expensive initial threat vector, at $4.92 million, just ahead of third-party vendor and supply chain compromises at $4.91 million.
IBM notes that “data can be vulnerable wherever it’s stored,” with most breaches involving information distributed across public cloud, private cloud and on‑premises environments.
All that data, whether compromised through a phishing email, abused credentials or insider malfeasance, still must move through the physical network. As it travels over fiber optic links, it is not immune to tampering, interception or sabotage, making cybersecurity at the physical layer as critical as any control in the logical stack.
As Wesco Data Center Solutions’ Andy Jimenez wrote in Data Center Knowledge in March 2026, campus-scale AI data centers must protect their operational integrity and high-value assets from a growing mix of connected devices, external bad actors, insider threats and human errors, using layered physical security that extends all the way down to cabling and data cabinets.
Fiber Isn’t as Untouchable as It Looks
Fiber optic networks have long carried a reputation for being resistant to eavesdropping, since they transmit light rather than electrical signals that radiate detectable interference. That reputation is only partly deserved. Fiber connections remain vulnerable to tapping through techniques such as fiber bending, optical splitting and evanescent coupling, where an attacker gently bends an exposed fiber until a fraction of the light signal leaks out and can be captured by a detector attached to the outside of the cable. Commercially available clip-on tapping devices can introduce a signal loss below 1 dB, small enough to escape standard network monitoring.
Newer research pushes that risk even further. At the Network and Distributed System Security Symposium in April 2026, researchers from Hong Kong Polytechnic University and partner institutions demonstratedthat standard telecom fiber can be turned into a passive listening device. By attaching a distributed acoustic sensing system to one end of a fiber run, they found that sound vibrations hitting the cable subtly alter the phase of light traveling through it, allowing speech in a room to be reconstructed from more than 50 meters away. In their strongest test case, the technique produced a near-complete transcript with a 9% word error rate. Because the method relies on light rather than radio signals, it evades standard bug sweeps and even defeats ultrasonic jammers designed to block conventional listening devices.
That kind of research is aimed at conference rooms and government facilities more than server racks, but it underlies a point that matters for any hyperscale operator: fiber is not a passive, risk-free medium. It is physical infrastructure and it needs to be secured like it.
Layered Security for Campus-Scale Facilities
As data centers scale into campus-sized AI infrastructure, with some facilities spanning hundreds of acres, the physical security model has to scale alongside them. Layered security itself isn’t new: it traces back to defense-in-depth, a military concept using multiple barriers to delay an attacker and buy time for a response, later adapted by Crime Prevention Through Environmental Design principles that apply the same layered logic to building and site design.
For today’s hyperscale campuses, Jimenez outlines four key layers of physical protection:
-
Outer layer: The site perimeter, protected by fencing, video surveillance and increasingly by drone-detection technology and IoT-enabled perimeter sensors that provide real-time alerts.
-
Middle layer: Building entry points, where single points of access, badge and biometric checks and AI-powered video analytics help flag anomalies like a badge used at an unusual hour.
-
Inner layer: The gray space (mechanical, electrical and cooling systems) and white space (critical IT load), monitored increasingly through AI-assisted threat detection rather than relying on security staff watching video feeds.
-
Asset layer: Individual data cabinets, where access-control systems combined with biometrics restrict entry to authorized individuals and log exactly who accessed which assets and when.
The logic behind the model is straightforward: if one layer fails, it should not create a catastrophic vulnerability across the entire system. A breach at the perimeter still has to defeat building entry controls, gray and white space protections and cabinet‑level authentication before it reaches the equipment itself.
Securing the Fiber Layer Specifically
Within that layered framework, the fiber plant needs targeted protections rather than being treated as a passive utility. Cable pathways should run through locked, tamper‑evident conduit wherever possible, especially in shared or multi‑tenant spaces where outside contractors have routine access.
Excess fiber slack should be minimized and secured, since loose cable near desks, walls or other resonant surfaces is exactly what makes acoustic eavesdropping techniques more effective. Distributed fiber sensing and OTDR‑based monitoring can flag the characteristic signal loss or change in backscatter profile associated with an unauthorized tap in near real time, turning the fiber itself into an intrusion‑detection surface rather than just a target.
Network architects should also design physical route diversity into critical paths, so a single cut, tap or damaged run cannot silently remove both redundancy and primary service in one incident.
An Integrated Approach
Security teams too often operate in silos, with IT, facilities and physical security functioning as separate concerns. As Jimenez notes, aligning those teams under a single strategy and looping in architectural and construction partners early so building plans reflect security goals from the start, is what allows physical security controls to keep pace with data center growth rather than trail behind it.
As hyperscale campuses scale to meet AI‑driven demand, the instinct is to pour security investment into the digital layer: firewalls, access management and AI‑driven threat detection. All of that matters. But none of it matters if the physical medium carrying the data can be tapped, tampered with or simply walked past. Protecting a data center means protecting every layer it is built on, right down to the glass the light travels through.
Physical security and network infrastructure are inseparable. Hexatronic partners with data center operators to design fiber networks built with that reality in mind, embedding route diversity, secure pathways and monitoring capabilities directly into the physical architecture from day one.