UII UPDATE 519 | AUGUST 2026

Intelligence Update

Drones over data centers: security risks and mitigation

5 min read

Drones are a recent addition to the arsenal of security threats facing data centers. They can be used to spy on or attack facilities, but aviation law severely limits the ways in which owners and operators can respond.

Drones, or unmanned aerial vehicles (UAVs), are cheap and ubiquitous. Data center operators can use them for visual mapping, security patrols, temperature monitoring and deliveries; but attackers will use them for surveillance, cyber hacking or even direct attacks. Very few drone incidents at data centers have been publicly reported (compared with the levels of disruption drones have caused in the aviation industry), but Uptime Institute network members have registered some concerns:

  • A financial services company has been asked to conduct a drone risk analysis and risk assessment to meet compliance requirements.
  • A global colocation company has considered testing how much damage a deliberate or accidental drone collision could cause to external equipment and infrastructure.
  • Drones surveilled a UK wholesale colocation construction project in plain sight. Staff confronted the drone operators but had no legal authority to stop them.
  • Another colocation company reported suspected covert reconnaissance. During drone delivery trials, an unidentified UAV lingered over the operator's site for 15 minutes, mimicking delivery operations before disappearing into a nearby building.
  • Drones have been used by journalists to document data center activity and could also be deployed by protesters.

Emerging risks

Reconnaissance

Drone surveillance can identify physical security systems, staffing levels and shift patterns, and expose vulnerabilities such as open doors — a technique penetration testers report using successfully. Drone enthusiasts are sharing and monetizing footage online, exposing construction partners and facility design features.

Operational disruption

Drone activity can trigger investigations and incident responses, creating unnecessary costs and operational distraction.

Drone failures, whether caused by mechanical faults, software errors or loss of control, can cause injury to staff and damage to facilities or infrastructure.

Physical damage

Modified delivery drones can carry (or serve as) improvised payloads designed to damage or disable exposed equipment (such as chillers and generator sets). Unprotected, fragile heat exchanger fins are likely targets for attacks, which could cause fire incidents.

Mobile wireless hacking

Drones operating within range of Wi-Fi-enabled devices, such as CCTV cameras, can be used as mobile hacking platforms, enabling cyberattacks on less secure networks.

Radio-silent drones

Some drones are immune to wireless detection and interference. Fiber optic drones are controlled via an ultra-thin optical fiber cable that can spool out behind the drone for up to 20 km (12.4 miles). Fully autonomous drones capable of operating in radio silence without a fiber are also available.

Legal limits

Drones are legally classified as aircraft, making them subject to aviation law. As a result, data center operators are prohibited from intervening against unwanted drone activity. Malicious drone operators, on the other hand, may disregard legal restrictions on drone activity.

  • Data center operators do not own the airspace above their facilities and cannot legally prevent any aircraft from flying over their data center.
  • The use of drones is legal in most jurisdictions worldwide. Only a small number of countries, including Cuba, Egypt, Iran, Nicaragua, North Korea and Syria, prohibit them entirely.
  • Localized no-fly zones exist at sites such as airports, military bases, prisons or city centers. Pilots can apply for exemptions - or operate illegally. Authorities can disable and seize unauthorized drones within no-fly zones.
  • Legal civilian drones are "geofenced": preconfigured to avoid no-fly zones. Geofencing generally imposes soft restrictions. DJI, a leading manufacturer of drones headquartered in China, supplies 90% of the world's drones; its units alert pilots to proceed at their own risk.
  • Drones are private property and intentionally damaging one constitutes a criminal offence and may risk public safety.
  • Drone pilots are legally required to remain within visual line of sight (140 jurisdictions stipulate this distance to be around 500 meters). Criminal operators can ignore this requirement and use first-person view systems to control drones beyond visual line of sight.
  • All consumer drones, apart from toy or specialist models, include a failsafe "return to base" mode, triggered by loss of signal or power. Third-party interference with this function is illegal under aviation and property law.
  • In regulated countries, drones are legally required to transmit a remote ID signature or "digital license plate", which includes the pilot's location, using Wi-Fi or Bluetooth.
  • Tethered fiber optic drones are subject to stricter regulations; autonomous drones are illegal unless a special license has been obtained.

Precautions

Assessment and design

Operators should monitor routine drone activity around their facility and commission a drone flight to identify assets vulnerable to attack or observation. Before construction, facilities can be designed with protective fences and enclosures, and passive measures such as privacy screens, cages and netting can be deployed to obstruct drone operations.

Drone detection systems

Drone detection systems combine radar, cameras and radio sensors, to identify drone models and eliminate false positives (e.g., birds) with image recognition. Some drone detection systems include signal jammers and hot-line communication channels to authorities that can authorize their use. Radio-silent drones can only be detected by radar and visual sensors.

Logging, reporting, confrontation

The first legal recourse for a drone incursion is to log the flight and notify both the police and the local aviation authority (e.g., the US Federal Aviation Administration). If the pilot is visible, a courteous conversation may dissuade them — or reveal a more serious security risk.

Staff training is vital. Pilots may be "trolling" for a confrontational or legally uninformed response that can be monetized online or used to discredit the data center operator (sometimes referred to as a First Amendment audit).

Geofencing and signage

Data centers may qualify for inclusion in geofencing databases (especially if they are classified as critical national infrastructure), but this is unlikely to deter deliberate incursions and may draw attention to the facility's location. Similarly, signs prohibiting drones have no legal protection, outside designated no-fly zones.

About the Author

Peter Judge

Peter Judge

Peter is a Senior Research Analyst at Uptime Intelligence. His expertise includes sustainability, energy efficiency, power and cooling in data centers. He has been a technology journalist for 30 years and has specialized in data centers for the past 10 years.

Posting comments is not available for Network Guests