The last two years of industry incidents share a pattern: the network held, and the building didn't. Tailgating, shared white-space and unlogged vendor visits keep showing up in post-mortems. Physical security is the perimeter — here's how we treat it.
Layered entry, logged everything
Every Ferrowatt hall runs five gates between the parking lot and a rack face: perimeter fence, lobby mantrap, biometric corridor, caged white-space and locked rack. Each gate logs badge, biometrics and video — and every log is available to clients on request.
Zero-trust doesn't stop at the cage door
Fabric segmentation extends the same logic inside: management networks isolated from tenant traffic, per-cage ACLs by default, and console access that requires phishing-resistant MFA even on site.
- Visitor access expires automatically; nobody holds a standing badge except staff.
- Vendor work inside cages is escorted and video-logged.
- Firmware and BMC updates ship with signed images and rollback plans.
A breach report that says "unauthorized physical access" is a design failure, not bad luck. Build the gates before you need them.
Ask for the evidence
Whatever provider you choose, ask for SOC 2 Type II reports, penetration-test summaries and a walkthrough of the entry layers. We hand ours over before the quote — start here and we'll show you the gates in person.