Risk Profile

Data Centre

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Risk profile for a data centre (colocation, enterprise or hyperscale server facility): the risk attributes typically assessed in underwriting and the resulting commercial insurance programme architecture.

Risk picture

Data centres combine very high concentrations of electronic equipment value with a business model where even short outages translate directly into severe financial and contractual consequences for the operator and its customers. Physical loss drivers centre on electrical faults, overheating of racks and cooling failure, gaseous or water-based fire suppression system discharge, and UPS/battery-related fire risk, while the cyber dimension covers unauthorised access to hosted systems, data breaches affecting customer data, and business interruption triggered by a cyber incident rather than a physical peril. Redundancy design (N, N+1, 2N power and cooling) and segmentation between operational technology and IT networks are central to both the physical and cyber risk picture.

Risk attributes to capture

The table below is generated from this profile’s linked risk attributes and grouped by category; see the individual attribute pages for underwriting logic, evidence requirements and mitigation measures.

Coverage architecture

Cyber cover is the anchor of the programme given the concentration of hosted data and systems and the contractual service-level obligations typically owed to customers, and employee accident cover is compulsory in Switzerland (UVG) wherever staff are employed. Property all risks and a dedicated electronic equipment (machinery/electronics) cover address the high-value server, power and cooling infrastructure, complemented by business interruption aligned to the facility’s actual recovery time objective rather than a generic indemnity period. General liability becomes relevant where the operator carries contractual or tortious exposure towards colocation customers or third parties for consequential loss.

Prevention

Loss prevention priorities are fire detection tailored to electronic equipment rooms (very early warning/aspirating smoke detection) combined with fire compartmentation between plant, battery and white-space areas, network segmentation between operational technology and IT/office systems, and a tested incident response plan covering both physical and cyber events. A documented, tested backup strategy with an offline or immutable copy, multi-factor authentication for privileged and remote access, and disciplined patch management round out the core measures.

Kind
Object

Risk attributes to capture

IT/Cyber

  • Backup Strategy and Offline Copy — Backup strategy and offline copy records how frequently an organisation backs up critical data and whether at least one copy is kept offline, air-gapped or immutable, a decisive control against ransomware queried in cyber proposal forms.
  • Multi-Factor Authentication — Multi-factor authentication records whether privileged, remote and email access to an organisation's systems requires more than one independent authentication factor, a baseline control queried in virtually every cyber insurance proposal form.
  • Incident Response Plan — Incident response plan records whether an organisation has a documented, tested procedure for detecting, containing and recovering from a cyber security incident, and how quickly it can be activated.
  • OT/IT Network Segmentation — OT/IT network segmentation records whether operational technology such as production and process control systems is logically and physically separated from the corporate IT network, limiting the ability of a cyber incident to cross into physical operations.
  • Patch Management — Patch management records how systematically an organisation identifies and applies security updates to operating systems, applications and network devices, and within what timeframe, a control central to limiting exploitable vulnerability exposure.

Fire protection

  • Fire Detection and Alarm System — Fire detection and alarm system records whether, and to what extent and design standard, a location is equipped with automatic fire detection, as queried in property insurance proposal forms.

Building

  • Fire Compartmentation — Fire compartmentation records how a building is subdivided into fire-resistant sections, and is queried in property proposal forms to assess how effectively a fire can be contained before it spreads.

Coverage architecture