After Entitlement, the Constraint Moves
Written by: Rob Chadwick, AJ Montgomery
Security planning should reset when a data center project shifts from permission to execution.
Before entitlement, the central question is whether a project can proceed. Land use, approvals, utilities, community requirements and design decisions determine whether the project has permission to move forward. After entitlement, uncertainty changes shape. The project now has to move people, materials, information and decisions through a site that changes every week. The economic problem becomes execution.
The constraint moves, and the security plan should move with it.
That shift is important because data center construction security is often planned around the finished facility rather than the changing conditions of the build. The future perimeter is treated like the current perimeter. Permanent access assumptions are applied to a temporary workforce. Cameras, guards and response procedures are designed around site geometry that may still be months away.
Across our team’s work in public safety and private-sector security, we have seen how quickly a great plan can age. On one project during early construction, sightlines, camera placement and patrol routes had been mapped carefully against the site at groundbreaking. Months later, earthwork had reshaped the terrain. Berms and staged dirt piles had become visual obstructions, leaving portions of the perimeter outside the visibility the original plan assumed.
The original plan had done its job. The site had moved on. Grading, staging and logistics decisions are made every day for reasons unrelated to security, and each can quietly erode an assumption the plan depends on. Sightlines need to be re-walked on a regular cadence, with the plan updated against the site as it physically changes.
Data Center Construction Security Should Protect Flow
The threats are familiar. Copper, cable, tools and staged equipment attract theft. High-value equipment creates exposure in transit and during delivery. A changing subcontractor population creates access and credential complexity. Temporary fencing, new work zones and changing site geometry create gaps in visibility.
Verisk has identified high-value organized theft as an emerging exposure on data center construction projects, particularly around building materials, tools, equipment and enterprise hardware. In August, authorities in Loudoun County, Virginia, arrested three suspects following the theft of approximately $100,000 in copper wire from a data center construction site.
The project executive’s concern is larger than the value of what disappears. A credential exception can slow access to a work zone. A disputed delivery can force re-sequencing. A blind spot can matter more when high-value equipment arrives. A slow verification process can turn an ambiguous event into unnecessary escalation.
Security protects flow when it helps the project identify a change quickly, verify what is happening and give the right person enough information to act.
The execution environment is already tight. JLL’s 2026 Global Data Center Outlook found that 57% of data center projects experienced construction delays of three months or more in 2025.
Critical equipment compounds that exposure. A 2024 report from the President’s National Infrastructure Advisory Council cited Wood Mackenzie data showing average large power transformer lead times rising from roughly 50 weeks in 2021 to 120 weeks in 2024, with some substation power and generator step-up transformers ranging from 80 to 210 weeks.
For a project working against critical-path delivery windows, timelines like those leave little room to absorb preventable disruption. If a critical component is damaged and must be replaced, its replacement clock may be longer than the schedule remaining on the build.
That is part of the economic case for security during construction. Protecting the asset matters. Protecting the project’s ability to keep moving matters more.
The posture changes with the phase
A construction site does not present one security problem from groundbreaking through commissioning. The dominant exposure changes with the work.
Mobilization: The perimeter, access points and site geometry are still forming. The question is whether the plan on paper still matches the ground.
Vertical construction: Headcount and subcontractor complexity increase quickly. The question becomes whether the project can reliably know who is on site, where they are authorized to be and where exceptions exist.
Fit-out and critical deliveries: High-value systems arrive while work remains tightly sequenced. The question becomes where theft, damage, delayed verification or a disputed delivery could create schedule exposure.
Commissioning: Sensitive systems begin coming online while construction crews, engineers and early operations staff overlap. Access rules tighten, temporary and permanent security systems coexist, and responsibility begins to transfer.
That progression is why a security plan should have defined reset points rather than a single design that survives untouched from groundbreaking to turnover.
The reset after entitlement
The transition into active construction is a useful moment to ask five questions:
What has to keep flowing for the project to stay on schedule?
Where could weak visibility, delayed verification or unclear ownership interrupt that flow?
What security capacity is actually needed in the current phase, and what can wait?
What information has to move across the owner, GC, subcontractors, security team and eventual operator?
Which project milestone should trigger the next security review?
Those questions keep security at the level where owners and project executives already manage the rest of the build. They focus the program on capabilities selected at the right time, for a clear operating purpose.
One of the most important security decisions after entitlement may therefore be the decision to keep deciding. Establish ownership, define what information must be available, set the review cadence, agree on the triggers that change the plan, and preserve options until the project knows enough to make permanent choices.
Entitlement gets the project permission to move. The operating plan determines whether it can keep moving.
Is your security plan keeping pace with your build?
A complimentary DXD Build Security Readiness Review is a 30-minute working session that compares your current visibility, response and access posture to the phase your project is entering.
We follow the session with a short gap summary identifying where the plan and the project may have drifted, along with the smallest credible next step to address it.
Request a Build Security Readiness Review.