While critical infrastructure has traditionally been built to last, the rise of data centers has accelerated a different set of priorities: capacity, efficiency and speed to market. Both approaches create the same challenge for any facility’s resilience. The buildings underpinning our cities, work and essential services are often no longer aligned with today’s evolving risk landscape.

From hospital wings and schools to substations and data centers, our whole economy – and many of society’s critical functions – quietly depend on physical infrastructure. Most people never think about it until something goes wrong. When a school or office is attacked or a major utility compromised, attention immediately turns to the consequences and containment. The headlines focus on the threat, people affected or communities whose power is disrupted or taps have run dry.

For asset owners and operators, these events should prompt a different question. Long lifecycles and increasing demands complicate resilience, but the challenge remains the same: when something goes wrong, what stands between continuity and consequence —a plan, a design or luck?

Built for capacity, not for consequence

Demands on critical infrastructure have increased dramatically over the past decade, increasing society’s dependence on these assets and the consequences when they fail. At the same time, threats have become more complex, ranging from physical intrusion and insider risk to cyber-attacks that can disrupt operations far beyond a single site.

For data centers, resilience often competes with commercial and operational pressures during design and construction. The rush to deliver capacity and meet demand often outstrips the typical 5% of construction budget allocated for physical security. As attack surfaces expand and scrutiny increases, intrusion detection, monitoring and visibility must extend far beyond traditional fence-line assumptions. This shouldn’t just be viewed as a technology issue. It is a design and operating gap that widened as the threat landscape moved far beyond the original risk assessment.

Other critical infrastructure faces issues around age and legacy, at a much greater scale. Power, water, telecommunications, and transport assets were frequently designed decades ago, under threat assumptions that predate the convergence of physical and cyber risk. While most facilities continue to perform their core mission reliably, infrastructure designed for yesterday’s threat environment must withstand today’s disruptions. As incidents make headlines, questions inevitably follow about whether similar vulnerabilities exist elsewhere. What was once a back-burner plan to replace aging systems now requires urgent reassessment of process, program and planning.

The same pattern can be found across civic and commercial institutions. Hospitals designed to feel less restrictive must re-examine security as violence against staff climbs. Schools built around openness and glass must consider active-threat scenarios. Offices laid out for collaboration offer little delay or protection during an incident. Data centers and critical infrastructure make this challenge most visible because the consequences are immediate and measurable, but the underlying problem is universal: the assumptions that shaped a facility’s design no longer reflect the risks it faces today.

From assessment to engineered delivery

A Security Vulnerability Risk Assessment identifies where this gap is widest. It starts with what has changed since the asset was designed: who depends on it, what threats it faces, and whether existing controls were built for those threats. Leaders should ask which assets now rest on outdated assumptions, and whether they would rather discover shortcomings, which bring disruption and drive up costs, during an incident rather than before one.

For a data center, that means examining perimeter design, access sequencing and layered zones. For critical infrastructure, it may involve reviewing legacy detection and monitoring against today’s convergence risks. For a hospital, it means testing access to high-risk units and ensuring staff can quickly call for help. While the risks differ, the objective remains the same: understanding if the asset can withstand the threats and operational pressure it faces today.

The assessment is only the starting point. Findings only matter once converted into engineered, buildable solutions: hardened perimeters, layered zoning, integrated detection and procedures that hold under pressure, all delivered without taking the facility offline. Risk consulting and security design engineering must operate as one discipline. An assessment that cannot become a phased, continuity-safe plan is not actionable. Equally, an engineered solution not grounded in evidenced risk is not defensible to a board, insurer or regulator.

Retrofit as the price of dependence

Facilities are designed with specific challenges in mind, whether that’s supporting growth, enabling openness or maximizing uptime. The problem is that the demands on these assets, and the threats they face, have changed faster than the buildings or utilities have.

As regulations and expectations rise, retrofit is shifting from discretionary upgrade to a standing board risk agenda item. The imperative is straightforward:

  • assess the portfolio now,
  • prioritize the widest design-risk gaps, and
  • insist that retrofit programs strengthen resilience without compromising the continuity they exist to provide.

Infrastructure should be invisible to the people who rely on it. When it becomes visible, something has already gone wrong. The organizations best positioned to withstand disruption are those that recognize a simple reality: resilience is not defined by how long an asset lasts, but by how well it adapts as the world around it changes.

For more insights around Built Infrastructure and Risk Management Services, sign up for our quarterly newsletter.


Article written by: Brent Mahoney and Chris Smaldone

Get in touch

Can our experts help you?