Sector

Lightning risk assessment for data centres

A data centre can lose service to thousands of users from a single induced surge, with no fire and no direct strike anywhere on the building. That puts continuity of service, not the structure itself, at the centre of the assessment. This guide explains why data centres are an extreme case for lightning risk, which risks dominate, and how an IEC 62305 study has to be shaped around the electronics inside.

Rows of server racks in a modern data centre, where a lightning surge threatens continuity of service

A data centre can lose service without anything catching fire and without a single direct strike on the building.

One surge induced on an incoming power or data line is enough to reach the racks and take down internal systems, and the outage that follows hits every user the facility serves. That is why the asset a data centre has to protect is continuity of service, not the structure, and why an IEC 62305 risk assessment for one looks different from an assessment of an ordinary building.

The standard and its method do not change for a data centre; what changes is where the risk sits. The value and the vulnerability are in the electronics, so the failure of internal systems from a strike-induced surge becomes the central concern, the frequency of damage to those systems carries the weight, and the many lines entering the building become the paths the engineer has to worry about most. This guide explains why data centres are an extreme case, which risks dominate, why internal-system failure leads, how incoming lines drive the result, how the assessment supports uptime expectations, and what makes modelling one different in practice.

What is different

Why a data centre is an extreme case

The same IEC 62305 method applies, but three things about a data centre move the assessment away from the ordinary-building case and put the electronics at the centre of it.

Continuity is the asset

What a data centre cannot afford to lose is service, not the building. A few seconds of interrupted power or a failed switch can stop everything the facility delivers, so the assessment is really about keeping internal systems running, not about the shell around them.

A surge alone can take it down

No direct strike is needed. A nearby strike to the ground or to a service line drives a surge onto the cables that enter the building, and that surge can destroy electronics deep inside without any fire or physical damage to point to afterwards.

Many lines, dense electronics

A facility connected to power feeds and a large number of data and telecom lines, packed with racks across many rooms, has far more surge entry paths and far more to lose than a simple structure. The risk is spread across all of them.

Which risks lead

The frequency of damage carries the weight, and the economic case with it

IEC 62305 produces a risk of injury to people, R, and a separate frequency of damage, F, for the availability of the internal systems, and it recognises three kinds of loss, L1 to L3 (injury to human beings, physical damage to the structure and its contents, and failure of internal systems). The 2010 edition had a fourth, purely economic loss, which the 2024 edition removed. For most occupied buildings the risk R leads, because the worst outcome of a strike is harm to the people inside. A data centre shifts that balance. The buildings are often lightly staffed or unmanned, but they deliver a service that many people and businesses depend on, and an interruption is expensive by the hour.

So the frequency of damage F, the availability of the internal systems, usually carries the most weight in a data centre study, and under the 2024 edition it is also the figure that covers pure economic loss and loss of service. An outage affects every customer the facility serves, F measures how often a strike would cause it, and what rides on that count is the cost of the downtime, the lost transactions, the broken service-level commitments and the recovery work. The risk of injury to people R still has to be assessed and still has to pass, because staff and visitors can be present, but it is rarely the figure that decides the protection. This is close to the reverse of a hospital or a crowded public building, where life safety is the whole point, and it changes which loss the assessment is really driving down.

New to how R and the frequency of damage F are built? The IEC 62305-2 risk method sets out how each is assembled from its components, and what is IEC 62305 covers the damage and loss model the risks rest on.


The central concern

Why internal-system failure is the heart of it

The standard groups what a strike can do into three types of damage: injury to people from touch and step voltages (D1), physical damage such as fire or explosion (D2), and the failure of electrical and electronic systems caused by the lightning electromagnetic pulse, or LEMP (D3). In most buildings the first two lead the assessment. In a data centre the value sits in the racks, so D3, the loss of internal systems, is the damage type that carries the risk, and the whole study is shaped around reducing the chance and the consequence of that failure.

LEMP is the mechanism. A strike radiates an electromagnetic field that induces surges on the wiring inside the building, and a surge arriving over an incoming line travels straight toward the equipment. Servers, switches and storage fail at low surge levels, far below what a strike can induce, so the protection of internal systems is not a refinement here. It is where the risk is won or lost.

This is where the assessment credits the protection measures. Coordinated surge protective devices on the incoming lines clamp the surge in stages before it reaches the equipment. A thorough equipotential bonding network stops dangerous voltage differences from building up between racks, cabinets and the building steel. Shielding of the most sensitive cable routes and rooms reduces how much of the field couples onto the wiring in the first place. And a lightning protection zone (LPZ) scheme divides the building into zones that step the surge environment down as you move inward, so the racks sit in the most protected zone of all. Part 4 of the standard sets out exactly how these measures work together against LEMP, and the risk method gives the engineer credit for them by lowering the probability of internal-system damage.

For how the surge protective devices are graded and coordinated, see SPD types under IEC 62305, and for the zone scheme itself see lightning protection zones (LPZ).


The entry paths

Incoming lines are how the surge gets in

A data centre is one of the most heavily connected buildings there is. Beyond its power feeds it takes in a large number of data and telecom lines, often from more than one provider and over more than one route for redundancy. Every one of those connections is a path a strike-induced surge can travel along into the facility, which is why the lines, rather than the roof, are usually where the assessment finds most of the risk.

Two properties of each line drive its contribution. The length of a line sets how much of the surrounding ground a strike near it can couple into the cable, so a long external run collects more than a short one. The routing, whether the line runs overhead or buried, screened or unscreened, alongside other services or alone, changes how much of a nearby strike actually reaches the building. Together these set the line-related risk components, and on a facility with many long connected lines those components often outweigh the risk from a direct strike on the structure itself.

This is the part of the IEC 62305 method that a single occupied building rarely stresses and that a data centre stresses hard, much as a telecom site does for the lines feeding its equipment shelter. Getting the count, the lengths and the routing of the connected lines right, and the SPDs that protect each entry, is what decides the answer for this kind of facility.

Continuity of service

A data centre does not fail because the building burns. It fails because the load drops.

Protection

The measures that move the result

For a data centre the protection that matters is mostly about keeping surges away from the electronics. The assessment decides which measures a facility needs and where, so the spend lands on the entries and zones that carry the risk.

Coordinated SPDs on every entry

Surge protective devices on the incoming power and data lines, sized for the chosen protection level and coordinated so each stage hands the surge down to the next. With so many lines entering, this is usually the single most effective set of measures, because the lines are where the surge arrives.

A thorough bonding network

An equipotential bonding system tying the racks, cabinets, cable trays and building steel together gives a surge a common reference and stops the voltage differences that destroy equipment. Without solid bonding the SPDs have nothing dependable to clamp against.

Shielding and a zone scheme

Screening sensitive cable routes and rooms, and dividing the building into lightning protection zones that step the surge environment down inward, reduces what ever reaches the racks before any device has to clamp it. The most sensitive equipment sits in the most protected zone.

Protection that fits the risk

The assessment decides which measures a given facility actually needs, so a critical entry is not left under-protected while a low-risk one is over-specified. The numbers, not a blanket rule, place the protection where the risk is.

Resilience

How the assessment supports uptime expectations

Data centres are built and sold on availability. Uptime tiers and the redundancy behind them, duplicated power paths, backup generation, redundant cooling, exist to keep service running through a fault. Lightning is one of the threats to that availability, and it is one the redundant mechanical and electrical design does not fully answer, because an induced surge can reach equipment on more than one power path at once.

An IEC 62305 assessment supports the availability target by putting a number on it. It estimates how often a strike-related event could cause an outage and shows that the surge protection, bonding, shielding and zoning bring that frequency below an acceptable level. It does not replace the redundant power and cooling that uptime tiers are built on, and it is not the same exercise as a tier certification. What it gives is the recognised evidence that the lightning threat to continuity has been assessed on the numbers and controlled, rather than left as an assumption that the building is probably fine.

In practice

What makes modelling a data centre different

Four features of a real facility push the model away from the simple single-box case and have to be reflected for the answer to hold up.

A large footprint

A big building over a wide plot has a large collection area, so it gathers more strikes near and on it over a year than a compact structure. The geometry of the building feeds straight into how often a dangerous event is expected.

Rooftop plant

Chillers, dry coolers and other mechanical plant on the roof are exposed equipment in their own right, with their own cabling running back into the building, and the assessment has to account for that exposure rather than treating the roof as bare.

Dense internal systems

The value and the vulnerability are concentrated in racks across many rooms, so the loss tied to internal-system failure is high and the protection of those systems carries most of the assessment.

Many connected lines

Power feeds plus a large number of data and telecom lines mean the risk is spread across many entries, and each has to be modelled with its own length and routing rather than rolled into one figure.

How Lumex handles it

A data centre, modelled to the clause

Lumex models a data centre as a structure with its zones, its incoming power and data lines and its protection measures, then runs the IEC 62305-2 method across them. It shows how coordinated SPDs, bonding, shielding and the zone scheme bring the risk of internal-system loss below the tolerable level, and it lets an engineer add lines, adjust their lengths and routing, and see the line-related risk move, which is exactly the part of the picture a heavily connected facility lives or dies on. Every figure traces back to the clause behind it, so an operator, auditor or insurer can follow the reasoning rather than take a single number on trust.

New to the standard? Start with what is IEC 62305, then see the Lumex platform for how a facility is assessed end to end.

FAQ

Questions answered

Why do data centres need an IEC 62305 risk assessment?

Because the asset a data centre has to protect is continuity of service, and lightning can take that away without any fire or direct strike. A single surge induced on an incoming power or data line can reach the racks and bring down internal systems, causing an outage that affects every user the facility serves. An IEC 62305 risk assessment is how an engineer decides what surge protection, bonding, shielding and zoning the building genuinely needs to keep that from happening, and proves the decision to operators, auditors and insurers.

Which IEC 62305 risks matter most for a data centre?

The frequency of damage F, the availability of the internal systems, usually carries the most weight, because an outage interrupts a service many people depend on and costs a great deal per hour. Under the 2024 edition F is also the figure that covers pure economic loss and loss of service; the 2010 edition's separate economic loss type no longer exists. The risk of injury to people R still has to be assessed, but for an unmanned or lightly staffed facility the availability of the internal systems is what dominates. That balance is quite different from an ordinary occupied building, where life safety leads.

Can lightning damage a data centre without a direct strike?

Yes, and that is the central concern. A strike to the ground or to a service line near the building radiates an electromagnetic pulse and drives a surge onto the power and data cables that enter the facility. That surge travels in to the electronics and can knock out servers, switches and storage even though nothing was hit directly and nothing caught fire. The failure of internal electronic systems, not physical destruction of the building, is what the data centre assessment is mostly about.

What is D3 damage and why does it dominate a data centre assessment?

D3 is the failure of electrical and electronic systems caused by the lightning electromagnetic pulse (LEMP) a strike radiates. In most buildings D1, injury to people, and D2, physical damage such as fire, lead the assessment. In a data centre the value and the vulnerability sit in the racks, so D3, the loss of the internal systems, is the damage type that carries the risk. The whole study is shaped around reducing the chance and the consequence of that internal-system failure.

How do incoming power and data lines affect data centre lightning risk?

Incoming services are the main way a surge gets in. A data centre is connected to power feeds and to a large number of data and telecom lines, and every one of them is a path a strike-induced surge can travel along into the building. The length of each line and the way it is routed drive the line-related risk components, so a facility with many long connected lines collects more of its risk from surges arriving over those lines than from a direct strike on the roof.

How does an IEC 62305 assessment support data centre uptime tiers?

Uptime and availability targets are about keeping service running, and lightning is one of the threats to that availability. An IEC 62305 assessment puts a number on how often a strike-related event could cause an outage and shows that the surge protection, bonding and zoning bring that frequency below an acceptable level. It does not replace the redundant power and cooling that uptime tiers are built on, but it is the recognised evidence that the lightning threat to continuity has been assessed and controlled rather than assumed away.

What protection measures matter most for a data centre?

Coordinated surge protective devices on the incoming power and data lines, a thorough equipotential bonding network, shielding of the most sensitive cable routes and rooms, and a lightning protection zone scheme that steps the surge down as it moves toward the racks. The assessment credits these measures by reducing the probability of internal-system damage, so the study is what decides which of them a given facility needs and where, rather than fitting the maximum everywhere.

What makes modelling a data centre different from an ordinary building?

A data centre tends to have a large footprint, heavy rooftop plant such as chillers and dry coolers, dense internal electronics across many rooms, and a large number of connected lines. Each of those pushes the assessment away from the simple single-box case: the collection area is large, the rooftop equipment has its own exposure, the internal systems carry most of the value, and the many lines spread the risk across power and telecom entries. The model has to reflect that detail to give a trustworthy answer.

Does Lumex handle data centre lightning risk assessments?

Yes. Lumex models a data centre as a structure with its zones, its incoming power and data lines and its protection measures, runs the IEC 62305-2 method across them, and shows how coordinated SPDs, bonding, shielding and the zone scheme bring the risk of internal-system loss below the tolerable level. Every figure traces back to the clause behind it, which is what an operator, auditor or insurer expects to see in a facility this dependent on continuity.

What Lumex does, and what stays with you

Lumex computes the IEC 62305-2 method and shows the working. It does not certify a structure. You may not issue or submit a Lumex output until a competent person, qualified where the structure is located, has reviewed the inputs and the result and signed it.

The tolerable risk in IEC 62305-2 is not a fixed constant. Clause 7.3 NOTE 1 gives RT = 1×10-5 per year as a representative value of tolerable risk and adds that another value may be set once the case has been investigated in detail. Printed p.12 then lets national or local regulations fix RT, the tolerable frequency of damage FT, and the Annex A, B, C and E calculation rules and parameter values. Every Lumex assessment states the jurisdiction it was computed under and the values that applied.

Get started today

Assess a data centre to the clause, and file it the same day

Contact our team