At a data centre, a drone-in-a-box belongs to the outermost security layer. It patrols the fence, gates, generator and fuel yards, and the routes where power and fibre cables enter the campus. It also flies out to check perimeter alarms. It does not replace access control, intrusion detection or guards. It adds a moving camera that can reach any part of the perimeter quickly, and records every flight in an audit log kept on site.
- Data centre service providers are listed as digital infrastructure in Annex I of the NIS2 Directive.
- NIS2 says cybersecurity risk management should also address the physical and environmental security of systems.
- EN 50600-2-5 grades protection against unauthorised access and intrusion into protection classes.
- An offline-first drone keeps security video on the campus by default.
- Nestua's software runs in development builds. The drone and base station are still being built.
What physical security is expected of data centres in Europe?
The NIS2 Directive (EU) 2022/2555 lists data centre service providers in Annex I under digital infrastructure. Recital 35 defines the service broadly: structures dedicated to IT and network equipment, together with their power distribution and environmental control. It excludes in-house corporate data centres run for the owner's own purposes. Recital 79 says cybersecurity measures should also address the physical and environmental security of systems, including protection against malicious acts. Recital 31 explains that for digital infrastructure entities, NIS2 rather than the CER Directive covers that physical security.
The European standard series EN 50600 covers data centre facilities and infrastructures. Part 2-5 (security systems) deals with protection against unauthorised access, intrusion, fire and environmental events. It uses protection classes applied space by space, from publicly accessible areas up to areas restricted to designated staff. The outdoor perimeter is the lowest-class layer, but it is where any physical attack begins.
Why do static cameras and guard patrols leave gaps?
- Large outdoor areas. Modern campuses have long fence lines, generator compounds, fuel storage and substations, with views blocked by buildings and plant.
- Guards stay inside. Security staff are usually tied to reception, the control room and escorting visitors. Leaving to check a far corner of the fence weakens the inside.
- Verification time. A fence alarm at night needs eyes on the scene. A fixed camera may not face the right way, and a guard on foot takes minutes to get there.
How would a drone-in-a-box patrol a data centre?
A drone-in-a-box unit consists of the drone, a weatherproof base station and an edge node that controls that one drone. In Nestua's design:
- Scheduled patrols. The mission editor in the browser defines routes on a satellite map along the fence, gates, generator yard and cable entry points. Missions are uploaded, started and stopped from the browser, and each action is audited.
- Geofences. Polygon geofences keep the drone off roofs and away from cooling plant, and outside the campus boundary over neighbouring property and public roads. Circle geofences protect masts and stacks. A breach either blocks the command or triggers return-to-launch.
- Alarm-triggered checks. When a perimeter sensor fires, the operator sends the drone to the location. A command only counts as successful after the drone's MAVLink acknowledgement, with retries and timeouts.
- Person and vehicle detection. A YOLO model on the NPU of an NXP i.MX 8M Plus edge computer detects people and vehicles. AI rules can notify, start recording, hover or return the drone to launch, always within the safety policy and geofences. The system does not identify individuals.
- Control room view. Operators see WebRTC video and a live map with the drone's trail. More than one video source can be shown, using a selector. Local recording goes to a ring buffer, and clips can be exported.
- Governance. Admin, operator and viewer roles, typed confirmation for critical commands, time windows and an exportable event journal support the documentation an auditor will expect.
Why does offline-first matter at a data centre?
A data centre has good connectivity, so the issue is not coverage. It is where security data goes and who can reach the drone. Aerial footage of a campus shows its layout and protective measures. In an offline-first design, the control plane runs on site and uploading recordings off-site is disabled by default. Remote access is also off by default. If it is enabled, the optional cloud connects over a WireGuard tunnel with per-node signed commands, MFA and optional SSO. Policy modes such as local-only, remote-view, confirm-local and emergency-only limit what a remote user can do. Separately, the drone's radio link uses per-packet authenticated encryption and hard mutual pairing.
Regulatory and privacy notes
- NIS2. Scope, supervision and penalties depend on national transposition. A drone can help an operator meet its physical-security expectations, but it is not a compliance certificate.
- Drone rules. Many data centres sit near cities and airports. Member States can restrict UAS operations through geographical zones under Article 15 of Regulation (EU) 2019/947. Automated patrols from a box are normally a "specific" category operation that needs authorisation. See our EU drone regulations guide.
- Privacy. Staff, contractors and neighbours may be filmed. Apply GDPR and the EDPB Guidelines 3/2019 on video devices, limit routes to the campus and set retention periods.
This page is general information, not legal advice.
What to evaluate for a data centre
- Does the system run fully on site, and can off-site upload and remote control be disabled and audited?
- How are roles, re-authentication and remote-command approval handled?
- Can perimeter alarms from your existing systems trigger a verification flight? Ask about the integration effort.
- Is the airspace over and around the campus in a geographical zone, and what authorisation is needed?
- How is the drone's radio link secured against interception and spoofing?
- What are the camera's night performance and the drone's weather limits? Ask vendors for tested figures.
- Can the event journal be exported for your NIS2 and ISO/IEC 27001 evidence?
Sources
- Directive (EU) 2022/2555 (NIS2), Recitals 31, 35 and 79 and Annex I: eur-lex.europa.eu/eli/dir/2022/2555/oj
- Directive (EU) 2022/2557 (CER): eur-lex.europa.eu/eli/dir/2022/2557/oj
- EN 50600-2-5:2021, Data centre facilities and infrastructures, Part 2-5: Security systems (CENELEC; catalogue entry): standards.iteh.ai
- Commission Implementing Regulation (EU) 2019/947, Article 15: eur-lex.europa.eu/eli/reg_impl/2019/947/oj
- EDPB Guidelines 3/2019 on processing of personal data through video devices: edpb.europa.eu