Skip to content
CoreSite's 2026 State of the Data Center Report is Now Available!
DOWNLOAD NOW

Take advantage of our diverse and ever-growing customer ecosystem to quickly identify and connect to IT services available in and across our 11 edge markets.

An entire ecosystem dedicated to solving customers’ most pressing IT challenges.

Discover why Channel Partners prefer to partner with CoreSite.

RESOURCES

Case studies, videos, spec sheets and data center industry insights.

CoreSite-download-reslib-sodc-2026

 

blue and green squiggly lines

How Colocation Supports Compliance in Hybrid IT: Understanding the Shared Responsibility Model

Managing compliance is a shared responsibility between a colocation data center and its enterprise customer. In the simplest terms, colocation data centers like CoreSite are responsible for maintaining a secure, resilient and compliant facility, while enterprise customers are solely responsible for the infrastructure, operating systems, applications and data they deploy within that facility. Because the data center provider does not access or manage an enterprise’s systems or data, enterprise customers retain full responsibility for securing and governing those environments.

Compliance within a Hybrid IT Model

As security and compliance continue to drive hybrid IT strategy planning, organizations in highly regulated industries—including healthcare, financial services and government services—must address rigorous compliance requirements designed to protect sensitive data, avoid cyberattacks and promote uninterrupted operations.

Image of Security Breach financial impact. $7.4M healthcare. $5.5M Financial Services.

Non-compliance with regulatory and security standards can result in serious consequences including large financial penalties, legal action, operational disruptions and reputational damage that can cost millions. The average per-incident cost of a breach in healthcare and financial services totals $7.4 million and $5.5 million,1 respectively, but costs can climb much higher. UnitedHealth initially reported $872 million in losses after a 2024 ransomware attack compromised 190 million patient records. However, actual costs are now estimated to reach $2.45 billion.2 The threat of such staggering losses makes compliance serious business.

As regulated enterprises develop their hybrid IT strategies, the flexibility and scalability of the public cloud is an attractive option. Yet, its shared environment can muddy the waters of compliance. Colocation allows enterprises to retain control over their hardware, providing a secure, resilient environment that enables enterprises to deploy infrastructure supporting sensitive workloads in the data center and less sensitive assets in the cloud.

While colocation provides a secure physical environment, it does not offload the enterprise of its security and compliance responsibilities. Compliance remains a shared duty between the data center and each enterprise customer. Understanding who is responsible for what can help enterprises minimize vulnerability and ensure compliance.

Let’s break down these responsibilities.

  • The colocation data center is responsible for data center infrastructure.
  • The enterprise is responsible for its racks, servers and everything on them.

The Data Center’s Responsibility: The Facility and its Operations

To provide enterprise customers with a certified, compliant environment on which to build their IT infrastructure, the colocation data center manages its physical infrastructure, including site-level power, cooling, physical security and connectivity. Through a combination of robust physical security and built-in redundancies, colocation data centers maintain facility-level compliance with key regulatory standards and frameworks, including SOC1 Type 2, SOC 2 Type 2, ISO 27001, NIST 800-53 (supporting FISMA/FedRAMP), PCI DSS and HIPAA.

Facility Uptime

To help avoid facility-related disruptions that can impact availability and performance, the data center proactively manages and maintains its critical systems and environmental controls, including uninterruptible power supplies (UPS), generators, cooling systems, and fire detection and suppression systems.

The data center also offers redundancy across all critical data center functions to protect against system failures, cut cabling and other unexpected events. Through diverse utility feeds and carrier connections, the data center provides alternate power sources and connections if one route is unavailable. Redundant systems are also employed, allowing the data center to utilize a secondary UPS, generator or cooling system, if the primary system fails. This redundant environment offers a necessary level of resiliency to meet compliance obligations.

Physical Security

The data center is also responsible for the physical security of the facility. Using perimeter fencing, trained security personnel, biometric scanners, surveillance cameras and card readers, the data center deters and prevents would-be intruders. The data center also maintains a detailed visitor access log that can help enterprise customers demonstrate compliance during external audits. Data center compliance documentation is also available for audit support and may be accessible on demand through the colocation provider’s service delivery platform.

The Enterprise’s Responsibility: Logical Security and Everything within its Deployment

While an enterprise can leverage the compliance-ready colocation data center environment to build its digital infrastructure, each enterprise is fully accountable for meeting its own regulatory requirements. This includes the compliance of its racks and everything in them, including hardware, the operating system (OS), applications and data. At each of these levels, the enterprise must assign and continually update both physical and logical access controls and other security solutions to heighten security.

Hardware: Racks, Servers and Network Devices

The enterprise is responsible for managing and maintaining the hardware within its racks, including its servers and its storage and network devices, in a colocation data center. This includes properly installing and configuring systems. Although the data center serves as the physical gatekeeper, the enterprise must grant and enforce strict role-based employee and vendor controls to limit access to its physical equipment. Enterprises must also continually review and adapt permission sets to reflect organizational changes, including employee turnover, employee role shifts and vendor changes.

For an added layer of physical security, the enterprise can also utilize and manage private cages and suites, locked racks and rack-level biometrics, which are often offered by the data center and integrated into the data center’s systems.

Operating System, Applications and Data

Healthcare, financial services and government organizations are highly regulated because they store and manage private data, including private health information (PHI), financial records and tightly controlled government intelligence. Enterprises are responsible for implementing a security program that fortifies their network perimeter and defends their OS, applications and data from bad actors, human error, misconfigured systems and any number of other issues that can expose sensitive information.

Keeping current with the latest system updates and patches is crucial to protect against emerging threats and other vulnerabilities. Establishing and maintaining role-based permissions for this IT layer is also essential to achieve least-privilege access. Strong, unique passwords and multi-factor authentication further strengthen data privacy.

Enterprises should leverage additional security solutions and practices such as next-generation firewalls, intrusion detection/prevention (IDS/IPS), penetration testing, encryption for data at rest and in transit, secure key management and change management policies to help secure the network perimeter and further mitigate risk. Ultimately, the right mix of security solutions depends on the enterprise.

Monitoring and Updating

Data security is not a one-and-done endeavor. In addition to implementing data privacy best practices, enterprises need to review and update security policy and controls regularly to ensure their appropriateness with the evolving threat landscape and the needs of the business. Enterprises should also continuously monitor their own networks and systems for unusual activity to address new threats more quickly.

Resiliency Planning

Just as the data center has a strategy in place to ensure its resiliency, the enterprise must establish its own solutions to limit data loss and promote uptime. Backups and a disaster recovery plan are powerful options. Colocation data centers like CoreSite can support an organization’s business continuity strategy by providing geographically diverse facilities and resilient infrastructure; however, customers remain responsible for designing and managing their own disaster recovery and business continuity plans.

Compliance Accountability

As enterprises in highly regulated industries continue to leverage the benefits of the public cloud, a compliant colocation data center can serve as a powerful component of a hybrid cloud strategy, providing a secure, high-performing environment for the enterprise’s sensitive data and workloads. Understanding the responsibility split between the data center and the enterprise customer can help eliminate the gray areas of compliance.

In the end, the colocation data center can help an enterprise meet its compliance demands, but, ultimately, ensuring the safety of its data, applications and systems—and its own compliance—falls squarely on the enterprise’s shoulders.

Know More

Does colocation make sense as part of your hybrid cloud strategy? Reach out to us today.

The CoreSite logo.

 


References

  1.  (2025), Cost of a Data Breach Report 2025, IBM. (source
  2. Langley, Mitchell (2025), UnitedHealthcare Data Breach Update: 190 Million Impacted in Change Healthcare Cyber Attack, Security Daily Review. (source

 

 

Lindsay Utts
Lindsay Utts is the Director of Compliance at CoreSite, offering 20+ years’ experience in strategic and solutions-oriented risk management. She is also a Certified Information Systems Security Professional, Certified Public Accountant and Certified Information Systems Auditor.

RELATED ARTICLES