Perspective
Why critical systems cannot be assessed in silos
A water engineer reviews the reservoir. An energy engineer reviews the load. A cybersecurity team reviews the network. Each produces a clean report. None of them, on their own, tells an investor or a developer whether the site will actually hold up.
Critical infrastructure risk does not organize itself by department. It organizes itself by dependency. A cooling system depends on a water source. A water source depends on a pump, and the pump depends on power. The power depends on a grid interconnection that is itself monitored and controlled by operational technology. Assess any one layer in isolation and the assessment will be accurate and still miss the point, because the failure that actually threatens a project rarely originates and ends inside a single discipline.
The pattern shows up at the worst possible time
During Cape Town's Day Zero drought, a data center's water dependency was not a water problem alone. It was an operating continuity problem, a reputational problem, and, ultimately, an engineering design problem that required an energy and facilities response as much as a water response. The interventions that worked treated the constraint as one system under pressure, not three separate ones being reported on in parallel.
The same pattern holds in reverse. An HVAC control system is, functionally, operational technology. Treating it as a facilities issue rather than a cybersecurity surface leaves a genuine attack path unexamined, not because the facilities team is careless, but because the assessment was never framed to look for it there.
Why the siloed version still gets produced
Siloed assessments are not produced out of negligence. They are produced because organizations are staffed and budgeted by discipline, and each discipline's report is easier to scope, easier to price, and easier to defend in isolation. The water consultant is not incentivized to model energy dependency. The cybersecurity vendor is not incentivized to model watershed risk. Nobody is doing the wrong job. Nobody was hired to do the connecting work.
What a converged assessment actually changes
A converged view does not produce more paperwork. It produces a different priority order. A capital investment that looks marginal from a pure energy efficiency lens can be the highest-value action available once its water and cybersecurity spillover benefits are counted. A permitting risk that looks purely regulatory can be defused earlier once the underlying community concern, usually about water, is treated as the actual constraint rather than a communications problem to manage after the fact.
For data center investors and developers, this converged view is the difference between a diligence process that surfaces the actual risk profile of a site and one that produces three accurate reports that, together, still miss it.
Have a water, energy, or OT/ICS question about a data center site or investment?
Start a conversation