Summary
- The Netherlands brought its NIS2 and critical entity resilience laws into force on 15 August, while the UK is preparing separate incident reporting duties for qualifying data centres.
- Colocation separates responsibility for facility infrastructure from customer IT, leaving operational evidence and impact data distributed across several organisations.
- The UK's proposed 24 and 72-hour reporting timetable will depend on information moving quickly between operators, tenants, service providers, and equipment suppliers.
The Netherlands brought two substantial pieces of resilience legislation into force on 15 August. Its Cyberbeveiligingswet implements the EU’s NIS2 Directive, imposing cyber risk management, registration, incident reporting, and governance requirements across 18 sectors, including digital infrastructure. The Wet weerbaarheid kritieke entiteiten implements the Critical Entities Resilience Directive and covers physical and operational threats to organisations designated as critical.
Britain is following a separate legislative route. The Cyber Security and Resilience (Network and Information Systems) Bill has passed the House of Commons and is now before the Lords, with the Government proposing to regulate data centres with a rated IT load of at least 1MW, or 10MW for enterprise facilities, as essential services under Ofcom.
The definition proposed for a data centre service reaches well beyond the server hall. It includes electricity supply, heating, cooling and ventilation, environmental controls, physical security, and resilience systems, bringing much of the infrastructure that keeps IT operational within the regulatory perimeter.
Commercial colocation, however, is built around divided control. Operators run the facility, while customers retain authority over the computing environments installed inside it. Serious incidents can cross that boundary long before either side has a complete picture of what has happened.
One facility, several lines of sight
Written evidence submitted to Parliament by VIRTUS Data Centres sets out the division in practical terms. The operator said its responsibilities cover physical infrastructure including power, cooling, environmental controls, physical security, and building resilience, while customers remain responsible for their IT equipment, networks, software, data, and cyber security controls.
VIRTUS also said it does not routinely monitor customer networks, inspect customer traffic, or operate customer security tooling. That separation is deliberate. A business renting secure data centre space does not normally expect the building operator to inspect its application traffic, while confidentiality and data protection obligations place further limits on what information can be exchanged.
A ransomware attack confined to a tenant’s servers provides the clearest boundary. Power and cooling continue normally, no environmental alarms appear, and the facility operator may have no technical indication that an incident has occurred. The customer or its managed service provider sees the compromise through its own security systems and controls the forensic investigation.
The position changes when an incident passes through shared infrastructure. If a remote maintenance credential used by a cooling, controls, or electrical supplier is compromised, the first visible symptoms could appear in several places at once. The operator might see an abnormal control state or environmental alarm, the equipment manufacturer might hold the remote access logs, and individual customers could begin to see thermal warnings, workload errors, or application failures.
Those organisations are looking at different parts of the same event. The operator may understand the physical sequence without knowing the application consequences, while a tenant can measure the impact on its own services without access to the BMS, electrical, or cooling records that explain the cause.
A short facility disturbance creates another problem. An operator could contain an electrical or thermal issue quickly enough for it to appear as a limited degradation or near miss, while one tenant suffers a much greater downstream interruption because its workload architecture, redundancy, or failover arrangements respond badly to the disturbance.
The UK Bill specifically contemplates significant continuity events and near misses for data centres, including incidents where network systems are not directly affected. Government guidance says the proposed tests will cover significant effects on systems used to provide the data centre service, continuity of that service in the UK, and other significant UK impacts. The detailed factors used to determine significance are expected to follow through secondary legislation.
Facility operators can therefore be responsible for identifying and reporting events whose full consequence may be visible only inside customer systems.
VIRTUS has argued that requiring an operator to report incidents occurring solely within customer managed environments could lead to duplication and inaccurate reporting because the operator may lack both the technical context and the authority to disclose customer information. The legislation has not yet settled those boundaries, but the evidence highlights a practical limit: an organisation cannot independently describe impact that sits inside systems it neither operates nor observes.
Reporting depends on the information chain
The Government proposes an initial notification within 24 hours of becoming aware of a significant incident, followed by a fuller report within 72 hours. The first notification does not require a completed forensic investigation, while the subsequent report is expected to include information about timing, nature, impact, and whether another regulated organisation contributed to the disruption, where those details are known.
Root cause can remain uncertain at the beginning of that timetable. An operator that first sees cooling alarms may know that service continuity is threatened without knowing that compromised supplier access caused the problem. An equipment manufacturer could hold authentication records needed to establish how a control system was accessed, while having no view of the tenants affected. Customers may understand the commercial consequences but know little about the facility sequence behind them.
Detection, diagnosis, recognition of significance, and confirmation of impact can therefore occur at different times and in different organisations. The point at which a regulated operator has enough information to classify an event may depend on how quickly those organisations communicate.
Customer notification creates the same dependency in reverse. Under the proposed incident reporting regime, regulated data centre operators and certain digital providers would also need to inform customers where they are likely to have been affected by an incident.
The operational arrangements underneath those duties become critical. A tenant contract may need to define when customer side incidents affecting facility services must be disclosed. An equipment supplier may need to retain and provide remote access logs within an agreed period. Managed service providers need clear routes for escalating suspected facility dependencies, while clocks across BMS, DCIM, access control, security systems, and customer platforms need to be sufficiently aligned to reconstruct events accurately.
Many mature operators already use versions of these controls, but an escalation process designed mainly to restore service is not automatically capable of assembling regulatory evidence from several companies within a day.
Resilience exercises expose a similar divide. A site can successfully prove that generators start, cooling remains available, networks fail over, and workloads recover without ever testing whether operators, tenants, equipment suppliers, and service providers can combine their records quickly enough to establish a common incident timeline.
The technical recovery and the information recovery are separate disciplines.
Neither the Dutch legislation nor the UK Bill removes the shared responsibility model, and giving a facility operator routine access to every tenant environment would introduce its own security, privacy, and commercial problems. A workable reporting system instead depends on clear boundaries around what information must cross between organisations, when it must be exchanged, and how much detail is needed to establish significance without exposing unrelated customer data.
A highly resilient data centre can still produce a fragmented account of an incident when telemetry, contractual rights, and operational knowledge sit across several businesses. The new reporting deadlines place a fixed timetable around that longstanding division of control, leaving operators, customers, suppliers, and regulators to make sure the information chain is as dependable as the physical infrastructure beneath it.

