# Treat water intrusion as an IT and physical-security outage scenario

> Water can disable power, communications, access control, video, servers, cabling, and safe building entry at once. Map exposure, protect critical equipment, define isolation and life-safety procedures, preserve evidence, and rehearse recovery.

- Canonical URL: https://update.dsesecurity.com/updates/treat-water-intrusion-as-it-physical-security-outage/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-17T12:44:00+00:00
- Modified: 2026-08-17T19:22:10+00:00
- Last reviewed by DSE: 2026-08-17
- Resource type: Checklist
- DSE priority: Advisory
- Topics: Access Control, Business Continuity, IT, Video Surveillance
- Reading time: 4 minutes

## What you need to know

Water can disable power, communications, access control, video, servers, cabling, and safe building entry at once. Map exposure, protect critical equipment, define isolation and life-safety procedures, preserve evidence, and rehearse recovery.

## Potentially affected

Data and telecommunications rooms; electrical and cooling systems; cabling; servers and network equipment; video surveillance; access control and intrusion detection; backup media; remote connectivity; emergency access; and facility recovery.

## DSE recommendation

Map water paths and critical dependencies, reduce avoidable exposure, monitor vulnerable spaces, define qualified shutdown and access procedures, preserve remote operations and records, assess damage safely, and test phased restoration.

## Article

## Source facts: flooding can interrupt facilities, equipment, records, and access

The [Ready Business Inland Flooding Toolkit](https://www.ready.gov/sites/default/files/2020-04/ready_business_inland-flooding-toolkit.pdf) helps organizations assess flood risk, plan protective actions, communicate, protect people and property, and practice continuity measures. It treats flooding as a business interruption with safety, facility, equipment, records, supplier, and recovery consequences.

FEMA [P-936, Floodproofing Non-Residential Buildings](https://www.fema.gov/sites/default/files/2020-07/fema_p-936_floodproofing_non-residential_buiildings_110618pdf.pdf), describes flood hazards and mitigation approaches for non-residential structures. Structural and nonstructural measures depend on flood characteristics, building conditions, codes, occupancy, feasibility, and qualified analysis.

These sources support hazard assessment and mitigation planning. They do not authorize personnel to enter an unsafe building, touch standing water, energize wet equipment, bypass life-safety controls, or decide that a damaged system is suitable for reuse. Those decisions require emergency, electrical, structural, environmental, insurer, manufacturer, and authority-having-jurisdiction direction as applicable.

## DSE recommendation: plan for simultaneous loss of room, power, network, and security

Model the event by water path and service dependency. A small leak above a telecommunications rack can create a different but equally urgent outage from rising regional floodwater.

- Map exposure. Record flood zones and history, grade and drainage, roof and plumbing paths, sprinkler and mechanical systems, floors below grade, penetrations, sump and pump dependencies, nearby drains, water sensors, shutoffs, and the elevation of critical electrical and technology equipment.

- Connect exposure to services. Map power, UPS, cooling, carriers, network cores, IDF and MDF rooms, servers, storage, video recorders, access-control panels, door power, intercom, intrusion, fire interfaces, backup media, and management workstations. Identify equipment that shares one room, riser, panel, or drain path.

- Reduce avoidable vulnerability. Work with qualified professionals to evaluate relocation, elevation, barriers, drainage, leak containment, shutoffs, pumps, rated enclosures, protected cabling paths, and remote replicas. Keep equipment off floors and maintain safe clearance only according to code and manufacturer requirements.

- Detect and communicate early. Place supervised water detection where justified, monitor power and environmental state, test alarms and escalation, maintain offline contacts, and define who can shut off water or request electrical isolation. Avoid automation that creates a new life-safety or property hazard.

- Preserve security during evacuation. Define emergency egress and responder access, manual door procedures, visitor and key control, video and alarm continuity, alternate monitoring, remote administration, and protection against opportunistic entry. Life safety and emergency authority take precedence over ordinary access policy.

- Protect data and evidence. Maintain tested backups and configurations outside the same hazard, preserve relevant video and logs when safe, document equipment location and condition, and control custody of removed devices. Coordinate evidence needs with insurer, legal, incident-response, and law-enforcement processes where applicable.

- Restore only after qualified release. Assess contamination and structural, electrical, mechanical, fire, and equipment damage. Replace, clean, dry, test, or dispose according to expert and manufacturer direction. Restore in dependency order, validate complete business workflows, and monitor delayed corrosion or intermittent failure.

Pre-authorize safe decision paths without pre-authorizing unsafe work. The incident plan should state who can call emergency services, close an area, request utility isolation, invoke alternate monitoring, notify affected parties, contact remediation and insurer resources, and suspend a service. It should also state which assessments must wait for qualified personnel.

During recovery, quarantine assumptions as carefully as equipment. A camera that streams, a door that unlocks, or a switch that passes traffic may still have damaged power, cabling, storage, battery, sensor, or enclosure components. Use documented inspection and soak-testing criteria, then monitor for delayed faults before returning redundancy or spares to ordinary use.

Factual boundary: This checklist is not structural, electrical, environmental, fire, safety, insurance, or code advice. Never assume wet equipment is safe because it dried or powered on. Qualified professionals and the authority having jurisdiction must direct entry, isolation, remediation, re-energization, and occupancy.

Measure critical equipment below planned protection level, untested water sensors, shared hazard concentrations, remote-monitoring gaps, backup separation, emergency-access drills, and corrective-action closure. The desired result is safe continuity and traceable recovery, not preservation of equipment at the expense of people.

## Official references

- Ready.gov, [Ready Business Inland Flooding Toolkit](https://www.ready.gov/sites/default/files/2020-04/ready_business_inland-flooding-toolkit.pdf).

- FEMA, [P-936: Floodproofing Non-Residential Buildings](https://www.fema.gov/sites/default/files/2020-07/fema_p-936_floodproofing_non-residential_buiildings_110618pdf.pdf).

## Primary reference

- Name: Ready Business Inland Flooding Toolkit
- Authority: Ready.gov
- URL: https://www.ready.gov/sites/default/files/2020-04/ready_business_inland-flooding-toolkit.pdf
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat water intrusion as an IT and physical-security outage scenario,” DSE Security, https://update.dsesecurity.com/updates/treat-water-intrusion-as-it-physical-security-outage/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
