July 20, 2026
Data centers and cyber risk: Shared responsibility for mitigation is essential
As the growth of AI and other technologies diversify data center models, cyber underwriters need to adapt their cybersecurity risk management strategies.
Data centers have expanded from on-premises to public cloud and edge computing deployments, with some dedicated to single enterprise users and others are co-located, serving multiple tenants. First-party and third-party cyber exposures vary among these different models. With data centers forming the backbone of the digital economy, the stakes are high. Regardless of the data center model, cyber underwriters should look closely at how cybersecurity and insurance programs can work together to address the next frontier of risk.
The popularity of multi-tenant and outsourced data center models leaves a significant margin for error in mitigating cyber risks. Effective management of cyber risks in these data centers types therefore is less dependent on the physical location of a data center and more reliant on clear understanding of, and compliance with, a shared responsibility model. Clarity is essential for cybersecurity teams as well as cyber underwriters.
The following table summarizes key exposures and risk profiles for different data center operating models. Risks vary somewhat across these categories, but virtually all of them require trust and dependency on operators and vendors.
Delineating responsibilities
Across data center types, providers and customers each have responsibility for cybersecurity. These vary but have important delineations for each party.
For example, in a public cloud environment, the provider is responsible for security in the underlying infrastructure, facilities, hypervisors and core networking. Customers of the public cloud are responsible for securing their data, operating systems, application code, network traffic, identity and access management (IAM), and configuration of the cloud services they use.
In colocation data centers, providers are responsible for owning and managing the multi-tenant facility and its physical infrastructure – power supply, cooling systems, and physical security. Tenants, or customers, own and manage their servers, operating systems, software and application-layer security within their racks or cages in the colocation facility.
Managed hosting of data centers shifts more lower-level management responsibility to the provider. This includes the operating system and platform, while the customer is responsible for applications and data.
These delineations are critical to underwriters’ assessment of cyber risk and exposure. A shared responsibility model also is key in allocating the liability and claims that arise from cyber issues. Operational control in a shared responsibility model, paired with robust segmentation across both physical sites and data, serves as a main source of mitigation for ransomware and operational risks.
Identifying exposure areas
Cyber underwriters assessing data center risks in a shared responsibility model have at least seven categories of concern and expectations for addressing each one. These categories include:
Segmentation. How is the segmentation for tenants and the system designed and tested? Ideally, each customer’s environment is segmented and failure testing occurs regularly.
Access and patching. What governance is in place for privileged access, patching and vulnerability management? Full access governance with high patching cadences, and vulnerability management through scanning, penetration testing and incident response exercises are preferred.
Ransomware. How are ransomware preparedness and data backup structured? Underwriters look for data immutability, isolation and testing, with backups stored in a separate location.
Incident response (IR). What are the insured’s incident response and escalation capabilities for multi-customer events? Preferred practices include strong IR capabilities and logging of downtime.
Operations technology (OT) security. How are OT systems secured and isolated from information technology (IT) networks? Underwriters are looking for isolation, with the OT environment on a different network unconnected to the IT environment.
Uptime tiering. Is the data center certified by the Uptime Institute, or designed to an Uptime Institute tier? Cyber underwriters usually accept data center risks with Tier II (limited redundancy) or greater uptime tiers. Tier I (basic) features a single distribution path with no redundancy, which typically leads to the longest amount of annual downtime.
Contractual terms. How is cyber liability allocated contractually with customers? Data centers typically set the terms in their contracts, using hold-harmless clauses and limitations of liability.
It is incumbent on cyber underwriters, data center operators and their customers to understand their shared responsibility for mitigating cyber risks. A thorough review of the cyber risk management programs, including cybersecurity practices, governance and incident response, is critical to evaluate and fix vulnerabilities. Organizational resilience depends on doing so.
Meet the Author

Maria Long
Chief Underwriting Officer, Resilience
Maria Long is Chief Underwriting Officer for Resilience, where she holds global responsibility for underwriting strategy, policy, and risk assessment. Long has nearly 20 years of experience in insurance including in cyber risk management program design and leadership, and underwriting leadership with a strong focus on holistic risk mitigation. Her thoughtful approach to the sustainability and performance of insurance products has been a consistent trait throughout her career.
Maria is an active volunteer in organizations that support women, including as a leadership advisory board member of International Women’s Cyber Alliance and as an advisory board member of the University of New Haven’s Women in Leadership Program. Additionally, she is a member of Aphinia, an invitation-only networking organization of senior cybersecurity executives.
News Type
PLUS Blog
Business Line
Cyber Liability, Professional Liability
Contribute to
PLUS Blog
Contribute your thoughts to the PLUS Membership consisting of 45,000+ Professional Liability Practitioners.
Related Podcasts
Icons & Innovators Episode 3
Icons & Innovators is a podcast series spotlighting influential leaders and forward-thinking changemakers…
Related Articles
Data centers and cyber risk: Shared responsibility for mitigation is essential
As the growth of AI and other technologies diversify data center models,…
HUD Issues New Guidance on Emotional Support Animals Under the Fair Housing Act
The U.S. Department of Housing and Urban Development (“HUD”) withdrew its 2013…
Applying Emotional Intelligence in Claims Management – Webinar Recap
Emotional intelligence (EQ) applies to professional liability and claims work in a…