Think Beyond the Data Center Insights
How we helpOur solutionsWhy HitachiResources

14 September 2026

Zero-trust architecture – how data center operators can bake in trust at the design stage
Marimuthu Muthusamy Global Delivery Leader at Hitachi

Data centers are often perceived as warehouses hosting the clusters of chips that deliver compute at scale – the engine room of the AI revolution. That’s accurate. But they are also huge repositories of data. Thanks to networks of servers and storage systems, information is stored and processed to deliver meaningful outcomes for users. Often, that information is sensitive, which makes access permissions an essential part of good governance.
Cybercriminals have been quick to catch on. In fact, The Uptime Institute’s 2025 Annual Report found that 5% of impactful data centre power outages are caused by information-security related incidents. And it’s not just sensitive data that’s attractive to cybercriminals. It’s also the volume and variety of data on offer. A modern hyperscale or large colocation data center can support hundreds to thousands of organizations, supporting infrastructure for a number of critical industries – from financial services to healthcare to education. Adding to this, outages for data center providers can be incredibly costly – where one minute of downtime can cost as much as $9,000. A recent IDC survey of senior technology and infrastructure leaders found that 52% of executives rank security as the second-most important factor in their data center strategy.
The Uptime Institute’s 2025 Annual Report found that 5% of impactful data centre power outages are caused by information security related incidents.
In the face of these threats, hyperscalers and colocation providers have no choice but to adopt a zero-trust operating model. Zero trust is built on the core principle that no user, device, or system is trusted by default; whether inside or outside the network perimeter. Every request must be verified before access to sensitive information is granted.
Let’s take a look at the key steps to implement zero-trust architecture, and how it can be continuously applied across data centers.
Zero-trust architecture must be underpinned by real-time visibility
You can’t control what you can’t see. Zero-trust architecture depends on operators gaining full visibility of what exists in their IT/OT environment, who uses it, and how it connects. Without a unified model to observe and manage data center assets, forgotten servers and dormant accounts are left unmapped and ungoverned – creating blind spots that hackers can easily exploit. This is particularly true of hyperscale environments, which are too sprawling to track manually, with engineering teams, contractors, and third-party providers constantly adding and modifying systems across different locations.
Where siloes create gaps, convergence removes the separation between digital systems (IT) and physical infrastructure (such as energy, cooling, building management systems) to ensure nothing slips through the cracks. Let’s look at how this works in practice. Imagine a hyperscale customer switches on a new AI workload, which causes a spike in compute demand. But then the centralized platform registers unusual activity. Servers running the workload are clustered in one part of the data center, connecting with databases they don’t normally interact with.
At the same time, the security monitoring system detects unusual login patterns and a sudden spike in power and temperature. In a traditional setup, those signals would be handled by different teams. Security would register the login anomalies, IT would register active workloads, and facilities would spot rising heat. But each team is left without the ‘full picture’.
A centralized approach with unified observability ensures that separate systems ‘speak’ to one another – and every team – from engineering to IT, works from the same live timeline of events and can work swiftly as a result with agentic as well as human in the loop workflows based on the identified issue. IT isolates the affected workload; security revokes the compromised credentials, and engineering redistributes load and cooling to stabilize the environment. Continuous, real-time signals support zero-trust architecture by ensuring every decision is based on evidence with context across the ecosystem.
Enforce the principle of least privilege
The principle of least privilege allows users the minimum access privileges required to complete a specific task and nothing more. We’ve moved far beyond traditional approaches to security, which focused on firewalls and web gateways to separate trusted users from untrusted users. In today’s threat landscape, it’s critical to protect against ‘trusted’ users too. Not because employees are less trustworthy, but because it’s becoming harder than ever to define clear boundaries between systems and data. This is particularly true now that reams of data are being moved into the cloud, so what used to operate via a single server now operates in hundreds of microservices. The introduction of AI agents has further amplified these threats, as many of these identities have privileges with limited observability. Securing the sprawl of NHIs (non-human identities) has become an increasingly critical part of securing an organizations’ data center assets.
Securing the sprawl of non-human identities has become an increasingly critical part of securing an organizations’ data center assets.
To operationalize the principle of least privilege, hyperscalers and colocators can work with industry partners to implement micro-segmentation across their data architecture. Micro-segmentation ensures that the data center environment is divided into tightly controlled zones, where each workload or service can only communicate with what it explicitly needs; as opposed to a flat network, where access is broadly inherited. Systems that store highly sensitive information, such as payment data, encryption keys, or security logs, are isolated in highly restricted segments. If a user, device, or workload is compromised, segmentation ensures the impact is contained within a small area, reducing the blast radius if a breach does occur. In addition, it is critical to address privileges of NHIs and ensuring observability of actions, clearly defining/managing scope of each NHI and governance.

Is your data centre resilient in the face of AI-driven threats?

Related article