• Link to X
  • Link to LinkedIn
  • Link to Mail
  • ABOUT UI
    • Business Partners
    • Careers
    • Contact Us
    • News & Press
    • Our Team
    • Press Releases
    • Branding Guidelines
  • CONTACT
Uptime Institute Blog
  • Journal
    • Journal Home
    • Executive
    • Operations
    • Design
  • AI Services
    • AI Infrastructure Advisory
  • Tier Certification
    • Overview
    • Design
    • Construction
    • Operations
    • Tier Gap Analysis
    • Prefabricated/Modular
    • Tier Certifications List
  • Professional Services
    • Overview
    • Infrastructure Services
    • Management and Operations Services
    • Energy and Sustainability Services
    • Consulting Services
  • Education
    • Course Details
    • Course Calendar
    • Competency & Confidence Assessments
    • Private Education
    • Graduate Roster
  • Events
    • Industry Events
    • Leadership Events
    • Network Events
  • Network
    • Overview
    • Network Calendar
    • Network Roster
    • Request Corporate Access
    • Request Guest Access
    • Uptime Network Portal
  • Intelligence
  • Clients
    • Client Stories
  • Resources
    • Data Center Industry Surveys
    • Ebooks
    • Journal Blog
    • Product Datasheets
    • Research & Reports
    • Tier Specification Documents
    • Tools
    • Webinars
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Blog - Latest News
UI @ 2021

The insider threat: Social engineering is raising security risks

April 19, 2021/in Executive, Operations/by Rhonda Ascierto, Vice President, Research, Uptime Institute

Uptime Institute Members say one of their most vexing security concerns is the insider threat — authorized staff, vendors or visitors acting with malicious intent.

In extreme examples, trusted individuals could power down servers and other equipment, damage network equipment, cut fiber paths, or steal data from servers or wipe the associated storage. Unfortunately, data centers cannot simply screen for trusted individuals with bad intent.

Most data center operators conduct background checks. Most have policies for different levels of access. Some may insist that all visitors have security escorts, and many have policies that prevent tailgating (physically following an authorized person through a door to gain access). Many have policies to limit the use of portable memory devices in computer rooms to only authorized work; some destroy them once the work is complete, and some insist that only specific computers assigned to specific worktables can be used.

Yet vulnerabilities exist. The use of single-source authentication of identification (ID), for example, can lead to the sharing of access cards and other unintended consequences. While some ID cards and badges have measures, such as encryption, to prevent them being copied, they can be cloned using specialist devices. In some data centers, multifactor authentication is used to significantly harden ingress and egress access.

The COVID-19 pandemic increased the risk for many data centers, at least temporarily. Some of the usual on-site staff were replaced by others, and routines were changed. When this happens, security and vetting procedures can be more successfully evaded.

However, even before the pandemic, the risk of the insider threat has been growing — and it has changed. Trusted individuals are now more likely to unwittingly act in ways that lead to malicious outcomes (or fail to respond and prevent such outcomes). This is because human psychology tactics are increasingly being used to trick authorized people into providing sensitive information. Social engineering, using deception to obtain unauthorized data or access, is now prolific and becoming increasingly sophisticated.

Tactics can include a mix of digital and physical reconnaissance. The simplest approaches are often the most effective, such as manipulating people using phone or email, and using information available to the public (for example, on the internet).

Social engineering is a concern for all businesses but particularly those with mission-critical infrastructure. A growing number of data center operators use automated security systems to detect anomalies in communications, such as email phishing campaigns on staff and visitors.

However, even routine communication can be exploited by hackers. For example, the host names derived from the headers of an email may contain information about the internet protocol (IP) address of the computer that sent the email, such as its geographic location. Further information about, say, a data center employee can be obtained using online information (social media, typically), which can then be used for social manipulation — such as posing as a trusted source (spoofing caller IDs or creating unauthorized security certificates for a web domain, for example), tricking an employee into providing sensitive information. By surveilling employees, either physically or online, hackers can also obtain useful information at places they visit, such as credit card information used at a restaurant (by exploiting a vulnerability in the restaurant’s digital system, for example). Hackers often gain trust by combining information gleaned from chasing digital trails with social engineering tactics.

Reviews of policies and procedures, including separation of duties, are recommended. There are also numerous cybersecurity software and training tools to minimize the scope for social engineering and unauthorized access. Some data center operations use automated open-source intelligence (OSInt) software to scan social media and the internet for mentions of keywords, such as their organization’s name, associated with terror-related language. Some use automated cybersecurity tools to conduct open-source reconnaissance of exposed critical equipment and digital assets.

The insider threat is impossible to fully control — but it can be mitigated against by adding layers of security.


The full report Data center security: Reassessing physical, human and digital risks is available to members of Uptime Institute. Consider a guest membership here.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Email a link to a friend (Opens in new window) Email
Tags: digital Infrastructure, Infrastructure, security
https://journal.uptimeinstitute.com/wp-content/uploads/2021/04/Social-Eng-Security.jpg 935 2252 Rhonda Ascierto, Vice President, Research, Uptime Institute https://journal.uptimeinstitute.com/wp-content/uploads/2022/12/uptime-institute-logo-r_240x88_v2023-with-space.png Rhonda Ascierto, Vice President, Research, Uptime Institute2021-04-19 06:16:002021-03-31 09:34:29The insider threat: Social engineering is raising security risks
You might also like
Building trust: working with AI-based tools Building trust: working with AI-based tools
Neoclouds: a cost-effective AI infrastructure alternative Neoclouds: a cost-effective AI infrastructure alternative
Water cold plates lead in the small, but growing, world of DLC Water cold plates lead in the small, but growing, world of DLC
Cybersecurity and the cost of human error Cybersecurity and the cost of human error
AI power fluctuations strain both budgets and hardware AI power fluctuations strain both budgets and hardware
Managing server performance for power: a missed opportunity Managing server performance for power: a missed opportunity
Is this the data center metric for the 2030s? Is this the data center metric for the 2030s?
Equipment shortages may ease soon — but not for good reasons Equipment shortages may ease soon — but not for good reasons

Content Categories

  • Journal Home
  • Executive
  • Operations
  • Design

Subscribe to Journal via Email

Enter your email address to subscribe to Uptime Institute Journal and receive notifications of new articles by email.

  • Recent

Tags

Accredited Tier Designer (9) AI (21) artificial intelligence (16) ATD (10) Carbon Emissions (7) Climate Change (13) Cloud (22) Cloud Computing (17) Cloud Costs (15) Cloud Infrastructure (29) Cloud Migration (8) Colocation (6) cooling (9) Data Center (252) Data Center Availability (40) Data Center Cooling (13) Data Center Design (45) Data Center Disaster Recovery (7) Data Center Energy Efficiency (34) Data Center Facilities Management (43) Data Center Operations (66) data center power (8) Data Center Staffing (18) DCIM (9) digital Infrastructure (117) energy (8) Energy Efficiency (38) Environmental Sustainability (18) IT (7) IT Efficiency (16) IT Outages (10) M&O (6) outages (11) Public Cloud (7) PUE (10) Regulations (24) Resiliency (9) security (7) Sustainability (34) Sustainability Reporting (7) Tier Certification (26) Tier Certification Constructed Facility (16) Uptime Institute FORCSS (6) Uptime Institute Network (13) Uptime Institute Symposium (6)
© 2014-2025 Uptime Institute, LLC All rights reserved.
  • Link to X
  • Link to LinkedIn
  • Link to Mail
Link to: Data center insecurity: Online exposure threatens critical systems Link to: Data center insecurity: Online exposure threatens critical systems Data center insecurity: Online exposure threatens critical systemsData Center Security Link to: Renewable energy and data centers: Buyer, be aware Link to: Renewable energy and data centers: Buyer, be aware Renewable energy and data centers: Buyer, be aware
Scroll to top Scroll to top Scroll to top