Physical Security of Compute
Cyber defenses are moot if an attacker can walk up to the hardware, so protecting the physical machines is part of security, not separate from it.
Physical Access Beats Most Cyber Controls
An attacker with physical access to a computer can often bypass software protections entirely: booting from external media, pulling drives, attaching hardware implants, or resetting configurations. Physical security is therefore a foundational layer, not an afterthought. The strongest firewall is irrelevant if someone can carry the server out the door or plug a device into a control cabinet.
Layers of Physical Control
- Perimeter: fences, gates, controlled entry to the site
- Building: access badges, mantraps, visitor escort
- Room: locked server rooms, cabinet locks, restricted zones
- Device: tamper-evident seals, port controls, secure enclosures
- Environmental: power, cooling, fire suppression protecting availability
Detection and Deterrence
Physical security combines prevention with detection: cameras, intrusion sensors, and access logs record who went where and when. Tamper-evident and tamper-responsive hardware raises an alarm, or erases secrets, if an enclosure is opened. As in cyber defense, assume some access will be gained and ensure it is detected and constrained.
Media and Ports
Removable media and open ports are a favorite crossing point, especially into isolated networks. Disabling unused ports, controlling USB, and securing maintenance interfaces close paths that even an air gap cannot address on its own.
Fusion Context
A fusion plant's control cabinets, safety instrumentation, and compute rooms are protected physically as well as logically, because physical access to a controller could bypass network segmentation entirely. In the Hyperion breeder and burner designs, the most safety-critical equipment sits in restricted zones with controlled access and tamper detection, and maintenance interfaces are secured so that the deepest network isolation is not undone by an unattended port.