{"id":2779,"date":"2026-08-12T10:42:58","date_gmt":"2026-08-12T08:42:58","guid":{"rendered":"https:\/\/www.safedx.eu\/?p=2779"},"modified":"2026-08-12T10:43:00","modified_gmt":"2026-08-12T08:43:00","slug":"operational-risks-in-corporate-server-rooms","status":"publish","type":"post","link":"https:\/\/www.safedx.eu\/en\/provozni-rizika-firemni-serverovny\/","title":{"rendered":"Operational risks in a corporate server room: what should be handled by the in-house IT department and what by the data centre"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Logically, the running of a company\u2019s server room tends to be the responsibility of the in-house IT department. However, that does not necessarily mean it should be their main area of responsibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The in-house team is familiar with the company\u2019s applications, the links between systems, data handling and the priorities of individual departments. It is precisely in this area that their experience is most valuable. However, if a significant proportion of their capacity is taken up by solutions for cooling, power supply, physical access or the operation of the data centre, there is less time left for tasks that directly support the company\u2019s operations and development.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question, therefore, is not whether in-house IT should relinquish control. What is important is to decide which responsibilities must remain within the company and which are better entrusted to an environment specifically designed to ensure the continuous operation of the infrastructure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Operational risk is not just a technical detail<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A server room outage rarely affects only the technical equipment itself. It can impact production, customer communications, invoicing, logistics, internal applications or access to data. A technical fault can therefore quickly turn into a business problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Responsibility for such a risk therefore does not lie solely with the infrastructure manager. The company\u2019s management should know which processes are dependent on the server room, how long a downtime the business can still cope with, and who has the authority to make decisions in the event of an incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Only then is it possible to assess meaningfully whether an in-house server room provides an adequate level of security. A more detailed comparison of the physical limitations of both models is provided in the article <a href=\"https:\/\/www.safedx.eu\/en\/corporate-server-room-vs-data-centre\/\">Corporate server room vs. data centre<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What should remain the responsibility of the in-house IT department<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Moving physical infrastructure to a data centre does not mean that a company relinquishes control over its IT. The in-house team remains primarily responsible for the architecture of the environment, system configuration, data management, application security, user management and ensuring that the technology meets the company\u2019s needs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other words: the in-house IT department decides what the infrastructure should do, how the systems should work together, and what requirements they must meet. These are areas in which knowledge of the specific organisation is irreplaceable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The purpose of delegating responsibilities is not simply to shift the work elsewhere. The aim is to free up the capacity of in-house specialists for activities that cannot easily be replaced by external operational support.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"1200\" src=\"https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-900x1200.webp\" alt=\"SafeDX technicians work on the company\u2019s IT infrastructure at the data centre in Prague.\" class=\"wp-image-2681\" srcset=\"https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-900x1200.webp 900w, https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-450x600.webp 450w, https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-768x1024.webp 768w, https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-1152x1536.webp 1152w, https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147-9x12.webp 9w, https:\/\/www.safedx.eu\/wp-content\/uploads\/Flow_IMG_20260304_102800_01_147.webp 1536w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><figcaption class=\"wp-element-caption\">In-house IT retains control over the systems and data, whilst the data centre provides the physical infrastructure.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What a professional data centre can handle<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A data centre can take responsibility for the physical layer of operations: a stable power supply, adequate cooling, physical security, environmental monitoring, connectivity and clearly defined incident response procedures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The difference lies not only in the quality of the individual technologies. The entire operating model is important. It must be clear who monitors the state of the environment, who responds to an incident, how an incident is escalated, and where the provider\u2019s responsibility ends and the customer\u2019s begins.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Service <a href=\"https:\/\/www.safedx.eu\/en\/services\/datacenter\/\">DataCenterDX<\/a> It is designed for companies that wish to run their own applications and services on their own physical infrastructure, but require a secure and reliable environment for doing so. For the specific deployment of their own technologies, this is complemented by the service <a href=\"https:\/\/www.safedx.eu\/en\/services\/rackhousing\/\">RackHousingDX<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Responsibility is not transferred in its entirety. It must be divided up precisely<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even a high-quality data centre does not assume responsibility for all aspects of a company\u2019s IT. The provider may supply the environment and related operational services, whilst the customer remains responsible for its own systems, data, access rights and the way in which the infrastructure is used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is precisely this boundary that must be made clear in advance. A general assurance that \u2018someone will take care of everything\u2019 is not enough. The division of roles should be set out in the contract, operational procedures and the Service Level Agreement (SLA).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A well-designed model eliminates dangerous grey areas. In the event of an incident, both parties then know who is responsible for carrying out a physical inspection, who decides on intervention in the equipment, who communicates the impact to the company, and how escalation takes place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What company management should ask<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Decisions on an infrastructure operating model should not start with a list of technical parameters. First, it is necessary to identify the impact on the company.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which business processes would come to a standstill in the event of an infrastructure failure?<\/li>\n\n\n\n<li>How long can the company cope with individual systems being unavailable?<\/li>\n\n\n\n<li>On which people, supply routes or technologies does today\u2019s operation depend?<\/li>\n\n\n\n<li>How much of the in-house IT capacity is used by the physical operation of the server room?<\/li>\n\n\n\n<li>Who responds to incidents outside normal working hours?<\/li>\n\n\n\n<li>Are the responsibilities of the in-house team and suppliers clearly defined?<\/li>\n\n\n\n<li>Can the course of the operation and access to the infrastructure be verified retrospectively?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The answers will usually reveal whether the current model is appropriate, or whether the company is retaining a level of risk that is no longer commensurate with the importance of the systems it operates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Regulatory requirements also play a part in the decision-making process<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The new Czech Cyber Security Act and related regulations come into force on 1 November 2025. The obligations do not automatically apply to every company; the criteria set out in the regulation on regulated services determine which companies are covered. <a href=\"https:\/\/nukib.gov.cz\/cs\/infoservis\/aktuality\/2372-ohlaseni-podle-noveho-zakona-o-kyberneticke-bezpecnosti-provedlo-pres-4800-organizaci\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">National Cyber and Information Security Agency<\/a> It therefore recommends that organisations check their classification in the light of the specific circumstances.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even for organisations not subject to direct regulation, however, it is useful to be aware of the limits of their liability, to keep a record of any interventions, and to have an incident response procedure in place. This is not merely a matter of fulfilling a formal obligation. It is about being able to maintain the operation of critical services when things go wrong.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A data centre as an operational partner, not just a space for racks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Moving the physical layer to a professional data centre does not mean that the in-house IT department is abdicating its responsibility. It is a more precise division of that responsibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The company retains control over the architecture, systems and data. The operations team takes over those areas for which it has specialised technologies, staff and procedures. The aim is to reduce the need for improvisation during day-to-day operations and when incidents occur, and to free up more of the in-house team\u2019s time for work that drives the company forward.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This illustrates how the physical and operational layers are implemented in practice <a href=\"https:\/\/www.safedx.eu\/en\/data-centre\/\">Introduction to the SafeDX data centre<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Would you like to review the allocation of responsibilities for your infrastructure?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Start with an overview of the service <a href=\"https:\/\/www.safedx.eu\/en\/services\/datacenter\/\">DataCenterDX<\/a>. On the landing page, you will also find a contact form which you can use to describe your current environment and verify the most suitable operating model.<\/p>","protected":false},"excerpt":{"rendered":"<p>Provoz firemn\u00ed serverovny nen\u00ed jen \u00fakol pro IT. Zjist\u011bte, jak rozd\u011blit odpov\u011bdnost za infrastrukturu a sn\u00ed\u017eit provozn\u00ed rizika.<\/p>","protected":false},"author":3,"featured_media":542,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2779","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-clanky"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/posts\/2779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/comments?post=2779"}],"version-history":[{"count":2,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/posts\/2779\/revisions"}],"predecessor-version":[{"id":2781,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/posts\/2779\/revisions\/2781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/media\/542"}],"wp:attachment":[{"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/media?parent=2779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/categories?post=2779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.safedx.eu\/en\/wp-json\/wp\/v2\/tags?post=2779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}