The 700-Acre Blind Spot: Why Manned Security Alone Can’t Protect a Data Center Campus
Written by: Matt DeSarno, Rob Chadwick, AJ Montgomery
Walk a 1-gigawatt data center campus sometime. The perimeter alone covers miles. Inside the fence, buildings the size of aircraft hangars run continuously, housing billions of dollars in equipment that governments, banks, and technology companies cannot afford to lose. For years, protecting these sites meant rural locations, guards, cameras, and access badges. That baseline is not keeping up with what is being built, nor with the rising threat levels these sites now face.
This paper argues for a different approach: pairing the workforce intelligence and access control capabilities that anchor ground-level security with persistent aerial awareness that covers what guards physically cannot see. The threat data is becoming more well-known, risk and loss events are amassing, and solutions to prevent incidents are still dispersed and only just entering the private sector. A proven approach from proven operators, reaching beyond traditional security, is needed now more than ever.
1. The Scale Problem
Security professionals who came up protecting 10- and 20-acre commercial facilities are now being asked to secure campuses ten times that size, and the instinct is to scale the familiar model: more guards, more cameras, more fencing. That instinct is understandable. It also does not work.
Perimeter length on a 1-gigawatt campus can run four to six miles. A guard completing a full perimeter circuit on foot covers that distance in roughly 90 minutes under good conditions. In practice, patrols are shorter, posts are fixed, and the gap between any guard’s last pass at a given point and the next one regularly exceeds 20 minutes. Doubling guard headcount narrows the window but does not close it, and the economics of staffing at that scale make the approach unsustainable.
Cameras help, but only at fixed points. A dense camera grid on a large campus still leaves blind spots, and cameras do not respond to what they see. They record it.
Construction phases are worse. Before a facility goes live, the perimeter is still being established. Fencing relocates as building phases progress. Contractor populations run into the thousands and turn over constantly. Equipment worth hundreds of millions of dollars sits on site, staged for installation on a schedule that subcontractors, suppliers, and anyone who has read a project update can forecast for use and downtime vulnerability alike. Security programs designed for an operational facility are not built for this continuously changing environment.
2. The Threat Has Already Evolved
In February 2025, Gen. Gregory Guillot, the commander of U.S. Northern Command, sat before the Senate Armed Services Committee and reported that roughly 350 drones had been detected over more than 100 U.S. military installations during the previous year. Some of those incursions, he said, may have been conducting surveillance of sensitive capabilities on the ground.
He was also direct about what the count missed: "I have no doubt that there are significantly more incursions that we don’t see, either with a system or with our own eyes."
Those are hardened federal installations, many with dedicated counter-UAS systems and standing response protocols. Many commercial data center campuses lack comparable counter-UAS detection and standing response protocols. A consumer-grade drone capable of perimeter reconnaissance or equipment mapping costs under $1,000 and can be operated by someone with no technical training and no need to set foot on the property.
In March 2026, the conversation intensified. Drone strikes damaged three AWS data centers in the United Arab Emirates and Bahrain. AWS confirmed that two facilities in the UAE were directly struck and a third in Bahrain was damaged by a nearby blast, with fires, power disruption, and water damage that the company described as requiring prolonged recovery. Iran’s Islamic Revolutionary Guard Corps claimed responsibility, framing the cloud facilities as legitimate military targets based on their role in supporting intelligence operations. It was the first time a major U.S. technology company’s cloud infrastructure had been physically disrupted by hostile military action.
The strikes accelerated calls to treat commercial data centers as critical national infrastructure, a designation previously reserved for power plants and oil fields. The policy conversation had been moving in that direction for years. The strikes naturally accelerated it.
The Gulf scenario involved state-level adversaries operating in an active conflict zone. The domestic threat picture is less dramatic and no less real. Competitive intelligence gathering, construction-phase theft, and perimeter reconnaissance for later operations don’t require military assets. A drone, an operator, and an airspace that no one is watching is enough.
3. Construction Is When the Site Is Most Exposed
Most security planning for a major data center focuses on the live, operational phase: badging protocols for permanent staff, camera coverage of server halls, perimeter controls around a finished fence line. That planning is critical, but by the time it kicks in, the highest-risk phase of construction is already over.
During construction, a hyperscale campus runs at peak workforce density, often several thousand workers drawn from dozens of subcontractors operating on overlapping schedules. Physical access controls are being installed rather than enforced. Perimeter configurations shift week to week as construction phases turn over. High-value equipment, including transformers, switchgear, and high-capacity cabling, arrives on documented schedules and sits staged before installation.
Worker identity management during this phase is genuinely hard. People arrive from multiple firms with varying credentialing standards. Badging systems may not yet talk to each other. Site supervisors rotate. The practical conditions that keep a job site moving are largely the same ones that make it difficult to maintain tight access discipline.
Industry estimates put annual theft losses from U.S. construction sites above $1 billion. For hyperscale projects, the losses aren’t just materials. Delays caused by equipment theft or damage on a project running hundreds of millions of dollars per month in carrying costs have consequences that dwarf the replacement value of whatever was taken.
The argument for building workforce intelligence capability from the start of a project rather than retrofitting it once the facility is live is straightforward: the foundation of any security program is knowing who is on site and whether they should be. Everything built on top of that, cameras, aerial systems, guard response protocols, works better when the workforce layer is solid. Owners who defer it are accepting a period of genuine exposure during the months when the asset is at its most valuable and its most accessible.
4. Detect, Verify, Respond
Three words cover the operational logic: detect, verify, respond. Identify something before it becomes an incident. Confirm what it is before deploying response resources. Then act with enough information to be effective. The effect of doing all three well is deterrence: a site with visible aerial presence, verified workforce credentials, and a demonstrated response capability is a harder target, and threat actors know it.
Ground-based security does parts of this reasonably well. Guards at access points verify identity, exercise judgment, and respond when something happens nearby. In a threat event, however, that response is typically reactive and limited to calling the police. Camera systems capture activity at fixed locations. Access control platforms create records and enforce permissions at defined entry points. None of this goes away in an upgraded security model. What it cannot do, at any staffing or camera density, is cover the full perimeter of a large campus continuously or observe the airspace above it. Nor can it replicate what an aerial platform delivers through zoom optics, thermal imaging, and AI-assisted threat detection.
A drone operating at 200 feet can scan in 90 seconds what a guard takes 20 minutes to walk. It can be in the air within moments of an alarm triggering, sending live video to an operator before any guard has been dispatched. When a guard does respond, they are moving toward confirmed information rather than a report that something might be happening somewhere on the north fence line. That difference, between acting on verified information and acting on an alert of unknown reliability, affects both response speed and safety.
Unauthorized-drone detection and deterrence capability has become a baseline requirement for any serious critical infrastructure security program. Detection and location of unauthorized unmanned aircraft, combined with deterrence measures and coordination with on-site security and state and local law enforcement, closes the airspace gap without running into the legal and regulatory limits on private counter-UAS operations. The key distinction is that detection and deterrence are available to private operators, while kinetic or electronic defeat require federal authorization. Building a program around the former, with clear escalation protocols to the latter through law enforcement coordination, is both operationally sound and legally defensible.
5. One Program, One Picture
Security programs built from separate vendor relationships have a structural problem that shows up most clearly when something goes wrong. The guard company and the drone operator are on different contracts, with different reporting lines and different operating pictures. When an incident happens, the question of who should have seen it, and who is accountable for the gap, is genuinely complicated. More often, the failure is in the seam between programs rather than in any single one.
Integrating ground-level workforce and access control with aerial surveillance and guarding under a single program eliminates that problem by design. There is one operational picture. Alerts from the access control platform are visible to aerial operators. Video from aerial systems feeds into the same interface that security supervisors use for workforce tracking. When a guard responds to a detected threat, they already know what the drone operator knows. That kind of operational coherence is difficult to achieve across separate vendor relationships, and it matters most during the high-stakes moments when it is hardest to improvise.
There is also a practical argument around program evolution. A large construction project runs for years. The security program that fits groundbreaking is not the same one that fits outfitting, which is not the same one that fits early operations. A single integrated program can be tuned by phase without renegotiating contracts or onboarding new vendors. Aerial patrol intensity during a major equipment delivery week looks different from a quiet period, and a program built to adjust in real time is simply more useful than one that isn’t.
The proof case is operational. A joint deployment of this model at a landmark U.S. data center project, one of the largest active infrastructure builds in the country, has provided workforce compliance, access control, and aerial surveillance across a large, high-security environment. A major event at the site, attended by senior officials, concluded with zero security incidents.
Conclusion
The infrastructure buildout underway across the United States is unlike anything the country has seen in decades. Hundreds of billions of dollars are flowing into facilities that will carry AI workloads, financial systems, cloud services, and national security applications. Protecting those assets, from the first day of construction through years of continuous operation, requires a security model built for that scale.
The manned model was built for a different era. Geometry limits it. Budget constraints cap it. And the threat environment has changed in ways that make the airspace above a campus just as important to monitor as the fence line around it. Adding more guards to a 700-acre campus does not solve the problem. Building a program that multiplies what those guards can see, verify, and respond to does — and that deters threats before they ever require a response.
Owners and developers who are asking the right security questions during the design and construction phase of a major project are ahead. Those waiting until the site is live and operational are making a high-risk choice in today’s environment. The partnership between Odin and DXD exists to deliver a proven, integrated solution for critical sites, enabling modern defenses against modern risks that carry cascading consequences for the project, the business, and society at large.
ABOUT THE AUTHORS
Odin Labs, Inc. is the end-to-end workforce and physical security platform built for large-scale construction and critical infrastructure. Odin delivers worker onboarding and credentialing, workforce visibility, access control, and jobsite surveillance integration. Led by veterans of the U.S. Marine Corps, U.S. Army, the FBI, and Texas law enforcement. www.useodin.com
Deus X Defense, LLC is a modernized physical security company that combines manned guards, drones, and counter-drone systems into a single service. Instead of managing multiple vendors, clients get one operator accountable for the security result. The company’s leaders built the largest public-safety tactical drone program in the United States and helped shape the national standards for tactical drone operations, drawing on careers across the FBI, the U.S. military, and public-safety technology. Deus X Defense protects critical open-air environments, events, and industrial sites nationwide. Phoenix, AZ. www.deusxdefense.com
REFERENCES
Gen. Gregory Guillot, Senate Armed Services Committee Budget Hearing, February 2025. Reported by Fox News (February 14, 2025) and DefenseScoop (February 13, 2025).
Breaking Defense: "Hundreds of drone incursions reported at military installations over past few years: NORTHCOM" (September 2024); updated figures reported October 2025.
Reuters: "Amazon cloud unit’s data centers in UAE, Bahrain damaged in drone strikes" (March 2, 2026).
Data Centre Magazine: "How War is Damaging the Middle East’s Data Centre Ambitions" (March 2026).
TechPolicy.Press: "The Legal and Policy Fallout from Data Center Strikes in the Middle East War" (March 2026).
Silicon Canals: "Drone strikes on Gulf data centers reveal a $5 trillion infrastructure vulnerability" (April 2026).
McKinsey & Company: Global data center capital expenditure projections through 2030.
Copyright 2026 Odin Labs, Inc. and Deus X Defense, LLC. All rights reserved.