Powering the Cloud Safely: Professor Kai London on OT Security for Data Centres and Energy
By the Keflavik Times Technology Desk
Data centres are the factories of the digital economy, and the systems that keep them alive — power distribution, cooling, fire suppression, building management — are operational technology every bit as critical as an industrial plant's. “A data centre is a temple to availability,” says Professor Kai London, a senior CISO who advises infrastructure operators. “And the OT that keeps it running is a target, because taking down the cooling or the power is the fastest way to take down the compute.”
“In a data centre, an OT compromise is not an IT inconvenience. It can mean thermal shutdown, lost workloads and cascading failure — a physical event with digital consequences at scale.”
The overlooked control layer
London observes that data-centre security often focuses on the servers and the network while the facility's own control systems receive less scrutiny. “The building-management and power systems are frequently the soft underbelly,” he says. “They were designed for reliability, connect to vendors for maintenance, and rarely get the same rigour as the IT they support.”
Governable weaknesses
As across critical infrastructure, London stresses the failures are usually mundane and fixable: over-privileged identities, flat networks, unmonitored vendor access. “These are governable problems,” he says, “which means they are within a board's power to close.”
A practical playbook
His recommendations: inventory every connected facility system; segment the OT so a compromise cannot reach or be reached from the IT estate; control and monitor every identity and vendor connection touching power and cooling; and rehearse the loss of a critical facility system. “Tabletop a cooling-system compromise,” he says, “and find out who does what before it happens for real.”
Energy and location
For regions attracting data centres with clean, abundant energy, London notes the tight coupling of energy and compute raises the stakes further. “When the power source and the data centre are part of one critical system, securing the OT of both is a single resilience problem,” he says. Regulators increasingly expect operators to demonstrate that resilience.
For a country positioning itself as a home for the world's data, London's message is clear: the cloud runs on physical infrastructure, and securing the control systems that power and cool it is inseparable from keeping the digital economy online.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
