HDI Global Risk Consulting published findings this month on natural hazard and climate exposure across Asia-Pacific data centres. Four factors are identified as shaping loss exposure: micro-location risk assessment, resource availability, construction standards, and operational preparedness. The construction finding is blunt. Data centres across the region are frequently designed as standard commercial buildings despite carrying a critical infrastructure risk profile.
For anyone who has walked these sites, that will not be a surprise. What is worth setting out is exactly where the divergence occurs, because in lightning terms it is specific and it is identifiable at design stage.
The building is not the exposure
A commercial property assessment for lightning implicitly weights toward physical damage. Fire, mechanical destruction, structural consequence. That is the correct emphasis for a warehouse or an office block, and the protection measures follow accordingly: air termination, down conductors, earth termination network, all sized to conduct and dissipate a direct strike safely.
The distinction matters more once you look at where the energy arrives from. The standard separates four sources: S1, flashes to the structure; S2, flashes near the structure; S3, flashes to a service connected to the structure; and S4, flashes near a connected service. A conventional structural assessment concentrates on S1. The data centre loss more often originates at S3 and S4, arriving along the incoming utility feed, the fibre entries, the metallic services, and the control cabling running out to plant.
Design attention that stops at the roof line is aimed at the wrong source.
What gets missed
In practice the recurring gaps on these sites are consistent.
Rooftop cooling plant. Air-cooled chillers, condensers and dry coolers sit in the most exposed position on the building and carry control electronics, variable speed drives and BMS connections. They are frequently outside the effective protected volume, and their control circuits are frequently outside the surge protection scheme. Cooling failure in a facility at design load is measured in minutes before thermal shutdown, not hours.
Generator and transfer control circuits. The standby system is the thing relied upon when supply is lost, so its control and signalling paths deserve the same protection standard as the load they serve. They often do not receive it, because they are treated as ancillary services rather than as part of the critical path.
Communications and signalling entries. Fibre is not a conductive path, but its associated metallic strength members, the copper on the customer side of the demarcation, and the earthing arrangement at the entry point all are. Multiple service entries at different points on the structure create potential differences across the internal bonding network during a nearby strike.
Bonding network design. Meshed bonding and equipotential bonding at every zone boundary is what limits the potential difference that D3 failures depend on. A compliant earth electrode resistance measurement says very little about the impedance the transient actually sees, and a single figure recorded at commissioning says nothing about the network's condition three years later. We have written before about why data centre uptime depends on earthing you cannot see.
Zone discipline. IEC 62305-4 sets out lightning protection zones with coordinated surge protection at each boundary. Where a building has been specified as commercial property, the SPD schedule is often a main incomer device and little else. Coordination between the incomer, distribution boards and terminal equipment is what actually limits the let-through voltage at the load.
Redundancy is not protection
The strongest argument for treating this as a design problem rather than a resilience problem is common mode.
N+1 and 2N architectures address component and path failure. They assume the failure is independent. A lightning transient arriving on a shared incoming service, or a potential rise across a bonding network serving both paths, is not independent. It presents at both paths at the same instant. Redundancy that shares an entry point, an earthing system, or a control network shares the transient too.
This is why lightning protection for a data centre is properly a design input rather than a mitigation added afterward. Entry point separation, zone boundaries and bonding topology are decisions made early or not at all. The same reasoning applies wherever continuity of service is the product, as we set out for critical infrastructure operators.
Assessment at the site, not the region
IEC 62305-2:2024 Edition 3 requires the assessed risk R for the structure to be compared against the tolerable risk RT for each loss type under consideration. For a data centre that will typically mean loss of service to the public where the facility supports essential services, alongside economic loss evaluated on a cost-benefit basis.
The input that drives the whole calculation is ground strike-point density, NSG, in Edition 3 notation. It is worth being precise about what that is, because the wrong figure is in wide circulation. NSG counts strike points to earth in the vicinity of the structure. It is not total flash density, which is a satellite-derived count including intracloud discharges that never reach the ground. The two are different quantities and substituting one for the other does not produce a conservative result. It produces a result with no defined relationship to the exposure.
This is where HDI's micro-location finding and the lightning question converge. Ground strike-point density varies meaningfully across a metropolitan area. A regional average applied to a specific site is an assumption, not a measurement, and every collection area and protection decision downstream inherits it.
We run risk assessments in LRAplus®, a deterministic Edition 3 calculation engine, precisely so that the inputs, the assumptions and the resulting protection level are auditable line by line. When a facility is later reviewed by an insurer, a regulator or an incoming owner, a defensible assessment is worth considerably more than a compliant one.
Operational preparedness
HDI's fourth factor is operational preparedness, and it is the one most often left as a paper procedure.
For sites with rooftop work, external plant maintenance, generator testing, fuel transfer or construction activity on a live campus, thunderstorm warning against IEC 62793 turns a lightning policy into an operational control. It sets defined alert thresholds, defined suspension and resumption criteria, and a defined all-clear. Without those, the decision to stop work falls to whoever is on the roof, based on what they can see.
Warning does not reduce the risk to the installed systems. It reduces the risk to people and to scheduled activity, and it is the part of the framework that a facility can implement without touching the installation.
What to check
- Was the lightning risk assessment carried out against the facility's actual function, or against its building classification?
- Does the assessment address S3 and S4 sources at every service entry, or only S1 at the structure?
- Is the surge protection scheme coordinated across zone boundaries, or is it an incomer device?
- Do the redundant power paths share an entry point, an earthing system or a control network?
- Is the ground strike-point density figure site-specific, and is it NSG rather than total flash density?
- Is there a defined thunderstorm warning procedure with thresholds and resumption criteria, or an instruction to use judgment?
The point
HDI's conclusion is that standard approaches to site selection, construction and operation are increasingly insufficient for this asset class in Asia-Pacific. In lightning terms that is not a call for more hardware. It is a call for the assessment to match the function of the building.
A data centre assessed as a commercial property will receive commercial property protection, and it will perform exactly as designed. The gap only becomes visible when the transient arrives on a path nobody assessed.
Sources
- HDI Global Risk Consulting, data centre natural hazard and climate risk findings, published 5 August 2026, as reported in Insurance Business Asia, 6 August 2026
- IEC 62305-1:2024, Protection against lightning, Part 1: General principles
- IEC 62305-2:2024 Edition 3, Protection against lightning, Part 2: Risk management
- IEC 62305-4, Protection against lightning, Part 4: Electrical and electronic systems within structures
- IEC 62793:2020, Thunderstorm warning systems, Protection against lightning
- Uptime Institute, 2025 Annual Outage Analysis
Is your data centre assessed as what it actually is?
We carry out IEC 62305-2 Edition 3 risk assessments against the facility's real function, at site-specific ground strike-point density, with every input and assumption auditable.
Talk to Us About a Data Centre Assessment