Data Center Risk Management in Indonesia: Protecting Power, Cooling, Connectivity and Uptime

The most valuable asset inside a modern data center may not be the servers. It is uptime. As Indonesia's data center industry expands toward hyperscale and AI infrastructure, the risks surrounding power, cooling, connectivity, equipment, natural perils and business interruption are becoming increasingly interconnected—and increasingly important to manage.

Indonesia is emerging as one of Southeast Asia’s important digital infrastructure markets. Operational data center capacity was reported at approximately 580 MW, while investors have expressed interest in developing another approximately 1.3 GW, representing potential investment of around US$15–20 billion.

The momentum is also visible through major international investments. In August 2026, AI cloud company CoreWeave announced three new data centers in Indonesia, adding 360 MW of contracted power and marking its first physical data-center presence in Asia-Pacific. ST Telemedia Global Data Centres has also announced a pipeline exceeding 360 MW of AI-ready capacity in Indonesia.

As data centers become larger and more critical to digital services, the question is no longer simply how much capacity can be built.

It is:

How resilient is the infrastructure that is expected to operate continuously?

For data center owners, investors, operators and lenders, risk management therefore needs to go beyond protecting physical assets. It needs to protect the ability of the facility to deliver its most important product:

continuous availability.

Indonesia's Data Center Industry Is Becoming Critical Infrastructure

Indonesia's Data Center Industry Is Becoming Critical Infrastructure

The traditional perception of a data center is relatively simple: a building filled with servers.

That description is increasingly incomplete.

A modern hyperscale or AI-ready data center is an integrated infrastructure ecosystem involving:

Power + Cooling + IT Equipment + Connectivity + Water + Security + Buildings + People + Software + Backup Systems

Every component contributes to the facility's ability to maintain continuous operations.

A transformer failure can affect power availability.

A cooling failure can threaten high-density computing equipment.

A fire can force the shutdown of an entire area.

A network interruption can disrupt customer services.

A flood can restrict physical access.

A prolonged utility outage can force the facility to depend on backup generation and energy storage.

The risk is therefore interconnected.

And because the business depends on continuous availability, the risk management strategy must be interconnected as well.

Power Is Becoming the Foundation of Data Center Resilience

AI is fundamentally changing data center power requirements.

As computing becomes more intensive, rack densities increase and facilities require significantly more electricity. CBRE's 2026 Asia-Pacific outlook highlights power availability as a major constraint on data center development, with new facilities increasingly exceeding 100 MW in size. Regional data center electricity consumption also nearly doubled between 2020 and 2024 and is expected to continue increasing.

For an operator, the critical question is straightforward:

What happens if the power goes off?

The answer cannot simply be, “We have a generator.”

Mission-critical facilities require multiple layers of resilience, potentially including utility power, multiple power feeds, UPS systems, battery energy storage, standby generators, automatic transfer systems, switchgear, transformers, power distribution systems and monitoring and control systems.

Each layer improves resilience.

But every additional component also creates another potential failure point.

This creates a fundamental characteristic of data center risk: redundancy improves resilience only when the underlying systems and failure paths have been properly understood.

Cooling Is Becoming Equally Strategic

Power is not the only infrastructure being transformed by AI.

Cooling is becoming an increasingly strategic component of data center design.

Traditional air cooling faces greater challenges as computing density increases. Liquid cooling is becoming more important for AI infrastructure, but it also introduces additional dependencies involving pumps, heat exchangers, distribution systems, water or coolant management, controls and maintenance.

The relevant question is not simply whether the cooling equipment is insured.

It is:

How long can the computing environment remain within safe operating temperatures if cooling capacity is disrupted?

For high-density computing environments, seconds and minutes can matter.

Cooling resilience therefore deserves the same strategic attention as power resilience.

Connectivity Creates Another Critical Dependency

A data center without reliable connectivity has limited value.

Modern facilities may depend on multiple telecommunications carriers, fiber routes, subsea cables and network connections.

Redundancy is therefore essential.

But redundancy must be real.

Two fiber connections using the same physical route may not represent genuine redundancy.

Two power feeds sharing the same vulnerable infrastructure may also fail simultaneously.

This leads to an important risk-management principle:

Redundancy only creates resilience when the failure paths are genuinely independent.

A Data Center Can Fail Without the Building Being Damaged

A Data Center Can Fail Without the Building Being Damaged

One of the defining characteristics of data center risk is that a facility can suffer a significant business impact even when the physical building remains largely intact.

A loss of power, cooling or connectivity can interrupt operations.

A single transformer, UPS, chiller, generator or switchgear failure can create a prolonged outage.

A cyber incident can affect building management systems, cooling controls, power management, access control or monitoring systems.

A flood may not physically damage the data hall but may prevent personnel, suppliers or emergency services from reaching the facility.

The risk therefore extends beyond conventional property damage.

Backup Power Is Not Risk-Free

Generators and UPS systems are fundamental to data center resilience, but backup infrastructure itself requires careful risk management.

Generators can fail to start.

Fuel systems can be contaminated.

Batteries can degrade.

UPS systems can experience electrical faults.

Switchgear can malfunction.

Transformers can fail.

Even maintenance activities can unintentionally create an outage.

This creates an important principle:

A backup system is only resilient if it can perform when it is actually needed.

Testing, preventive maintenance, redundancy and emergency procedures are therefore as important as the physical presence of the backup equipment.

From a risk perspective, critical equipment should also be evaluated not simply by its replacement value, but by the consequences of its failure.

Fire Risk Has Evolved With Data Center Technology

Fire remains a major property risk, but the consequences can be particularly significant in a data center because of the sensitivity and concentration of electrical and electronic equipment.

Potential ignition sources include electrical systems, UPS equipment, batteries, generators, cabling, transformers and mechanical systems.

The increasing use of battery energy storage systems introduces another area requiring specialized attention.

Fire protection should therefore be integrated into the entire facility design.

Detection, suppression, compartmentation, emergency response and maintenance all matter.

The objective should not simply be:

“How do we put out the fire?”

It should be:

“How do we prevent a localized incident from becoming a business-wide interruption?”

Natural Perils Remain Relevant

Technology does not eliminate geography.

Data centers remain physical facilities located in real places and therefore remain exposed to earthquake, flood, lightning, fire, storm, landslide, extreme weather and other natural catastrophes.

For Indonesia, seismic and flood exposures deserve particular attention.

A data center may have sophisticated technology and extensive redundancy, but if access roads are flooded, external utility infrastructure is disrupted or transmission infrastructure is damaged, operations can still be affected.

Site selection is therefore a risk-management decision.

The relevant question is not merely:

“Can we build here?”

It is:

“Can this facility remain operational here for the next 20–30 years?”

Cyber and Physical Risk Are Converging

The modern data center is also a cyber-physical ecosystem.

Cyber events can affect physical infrastructure.

Building management systems, cooling controls, power management, access control and monitoring systems may all have digital dependencies.

At the same time, physical incidents can disrupt digital operations.

This means the traditional separation between “IT risk” and “physical risk” is becoming less useful.

A comprehensive risk assessment needs to understand the interaction between the two.

The Real Exposure Is the Cost of Losing Availability

The Real Exposure Is the Cost of Losing Availability

The most important exposure for a data center is not necessarily the value of the building or servers.

It is the financial and operational consequence of losing the ability to provide services.

This distinction becomes critical when evaluating business interruption.

Business Interruption Can Exceed Physical Damage

Consider a major incident involving a critical component.

The physical damage may be repairable.

But what if the repair takes six months?

During those six months:

  • Customer services may be disrupted.
  • Revenue may be affected.
  • Service-level commitments may be impacted.
  • Additional operating expenses may arise.
  • Financing obligations continue.
  • Maintenance costs continue.
  • Customer confidence may decline.

The financial consequence can therefore exceed the cost of the damaged equipment.

The key insurance and risk-management question is not simply:

“How much does the building or equipment cost?”

It is:

“How much financial loss could result from the inability to provide data center services?”

That calculation can be significantly more complex.

Equipment Breakdown Can Become a Business Crisis

Not every major loss begins with an earthquake or major fire.

Sometimes the trigger is a single critical component.

A transformer.

A UPS.

A chiller.

A cooling pump.

A generator.

A switchgear system.

A control system.

If that component has a long replacement lead time, a relatively localized equipment failure can create a prolonged operational interruption.

This makes machinery reliability and replacement lead time important parts of exposure analysis.

The risk review should therefore identify not only the equipment with the highest replacement value, but also the equipment with the greatest business criticality.

Water Creates a Location-Dependent Exposure

Data centers are increasingly evaluated not only according to electricity consumption but also water requirements.

Cooling technologies can involve different trade-offs.

Some may reduce water consumption while increasing electricity requirements. Others may reduce energy requirements but depend more heavily on water availability.

The appropriate solution depends on location, climate, water availability, cooling technology, data center density, environmental requirements and local infrastructure.

This is particularly relevant as Indonesia's data center industry expands geographically.

Greater Jakarta remains a major market, while Batam is increasingly attracting attention because of its proximity to Singapore and its potential for large-scale infrastructure.

JLL expects further data center growth across Indonesia in 2026, with Greater Jakarta and Batam identified as key markets.

Location is therefore not merely a real-estate decision.

Location is a risk decision.

Concentration Risk Grows With Scale

The industry is also moving toward increasingly large campuses.

Digital Edge, for example, announced a 1.45 GW PLN power agreement for its CGK campus in Bekasi, structured through two independent feeds to support hyperscale and AI infrastructure.

Larger facilities can provide significant efficiency and scalability.

But greater scale can also increase concentration risk.

When more computing capacity, customers, power infrastructure and capital are concentrated within a single campus, the consequences of a systemic failure can become substantially larger.

This is why risk assessment needs to consider not only individual component failure, but also dependency risk, concentration risk and common-cause failure.

Data Center Risk Management Must Protect Uptime, Not Just Assets

Data Center Risk Management Must Protect Uptime, Not Just Assets

From L&G's perspective, the starting point for data center risk management should not be the question:

“What insurance policy should we buy?”

It should be:

“What could prevent this facility from delivering continuous availability, and what would that interruption cost the business?”

This distinction changes the way the entire risk profile is assessed.

A data center is not simply a collection of insured assets.

It is a business system in which power, cooling, connectivity, equipment, people, technology and external infrastructure must operate together.

Understand the Dependency Chain

The first step is to identify the critical dependencies.

Power depends on utility infrastructure, feeds, transformers, switchgear, UPS systems, generators and distribution systems.

Cooling depends on chillers, pumps, heat exchangers, controls, water or coolant systems and electrical supply.

Connectivity depends on carriers, fiber routes and external network infrastructure.

Operations depend on people, access, monitoring systems, maintenance capabilities and spare parts.

A risk assessment that examines each component independently can therefore miss the most important issue:

How does failure in one system affect the others?

A transformer failure, for example, may not only create a property loss. It may disable cooling systems, affect IT equipment and ultimately trigger business interruption.

The risk should therefore be assessed as a chain rather than a collection of isolated assets.

Test Whether Redundancy Is Actually Independent

Data center operators frequently rely on redundancy as a core resilience strategy.

But redundancy needs to be tested against common failure scenarios.

Two power feeds may ultimately depend on the same external infrastructure.

Two network connections may follow the same physical fiber route.

Multiple systems may share the same cooling infrastructure.

Backup generators may depend on the same fuel system.

Redundancy therefore needs to be assessed not only by the number of systems installed, but by the independence of their failure paths.

This is one area where risk engineering can add significant value.

Measure Equipment by Business Criticality

Traditional property risk assessment often focuses heavily on asset values.

For a data center, this is not enough.

A relatively inexpensive component may be more critical to business continuity than a much more valuable asset.

The relevant questions include:

  • What equipment can stop the facility?
  • What equipment has no practical substitute?
  • What is the expected replacement lead time?
  • Are spare parts available locally?
  • Can specialist engineers be mobilized quickly?
  • What happens if the equipment fails during peak demand?
  • What happens if the failure coincides with another event?

This approach allows the operator to distinguish asset value from business criticality.

That distinction is essential when evaluating Machinery Breakdown and Business Interruption exposure.

Calculate the Cost of Downtime

The boardroom question should ultimately be:

How much downtime can we afford?

Every operator should understand:

  • What is the maximum tolerable downtime?
  • Which systems are truly critical?
  • What are the single points of failure?
  • How long would replacement equipment take?
  • How much revenue could be lost?
  • What additional expenses would be required to maintain service?
  • What happens if the site becomes inaccessible?
  • What happens if power and connectivity are disrupted simultaneously?

These questions should be answered before the incident.

Not during it.

Certification Is Not the Same as Risk Management

Industry standards and certifications are important because they provide benchmarks for design, construction and operational resilience.

But certification should not create a false sense of security.

A certified facility can still experience equipment breakdown, human error, fire, flood, cyber incidents, supply-chain disruption or business interruption.

Certification demonstrates that defined standards have been achieved.

Risk management asks what could still go wrong.

Both are important, but they serve different purposes.

Insurance Should Follow the Risk Profile

A data center insurance programme may involve multiple forms of protection depending on the facility's characteristics and development stage.

For operational facilities, this may include:

  • Property Damage / Property All Risks
  • Machinery Breakdown
  • Business Interruption
  • Cyber Insurance
  • Liability Insurance

For new facilities under construction, additional considerations may include:

  • Construction All Risks
  • Erection All Risks
  • Marine Cargo
  • Delay in Start-Up
  • Third-Party Liability

The appropriate structure depends on the actual risk profile, contractual arrangements, technology, location, financing structure and business model.

There is therefore no universal data center insurance programme.

The insurance programme should be designed after understanding the risk—not before.

From Insurance Placement to Risk Engineering

For L&G, the role of an insurance broker in a complex data center project should extend beyond obtaining an insurance quotation.

The broker should help connect the physical, operational, contractual and financial dimensions of risk.

That means understanding:

  • Power.
  • Cooling.
  • Connectivity.
  • Water.
  • Fire protection.
  • Natural perils.
  • Cyber-physical dependencies.
  • Critical equipment.
  • Supply chain.
  • Business interruption.
  • Contractual obligations.
  • Recovery capability.

Only after these relationships are understood can risk transfer be properly structured.

The objective is not simply to insure the building, servers or mechanical equipment.

The objective is to help protect the facility's ability to continue operating when something goes wrong.

The Real Measure of Data Center Resilience

Indonesia's data center opportunity is significant.

The industry's expansion toward hyperscale and AI infrastructure will require increasingly large amounts of power, cooling capacity, connectivity and supporting infrastructure.

But competitive advantage will not simply be determined by:

“How many megawatts can we secure?”

It will increasingly depend on:

“How reliably can we deliver those megawatts, computing capacity and digital services—24/7, 365 days a year?”

That is the real meaning of resilience.

A data center does not sell servers.

It sells uptime.

And uptime depends on much more than the server itself.

It depends on the resilience of the entire system surrounding it.


The Question Every Data Center Investor Should Ask

“If our facility lost power, cooling or connectivity tomorrow, how long could our business continue—and how much would that interruption cost us?”

If the answer is unclear, the risk assessment is probably not complete.

Because in the data center industry:

Downtime is not just an operational problem.

Downtime is a financial risk.

And ultimately:

Data Centers Don't Sell Servers. They Sell Uptime.

Protect the infrastructure.
Protect the uptime.
Protect the investment.

That is where Risk Management becomes a strategic business decision—not merely an insurance requirement.


L&G Insurance Broker
Risk Management | Insurance Advisory | Project Risk | Claims Advocacy

The Team

Mhd. Taufik Arifin ANZIIF (Snr. Assoc) CIIB

Direktur Utama

Mhd. Taufik Arifin ANZIIF (Snr. Assoc) CIIB

Taufik Arifin adalah pendiri L&G. Ia memiliki lebih dari 30 tahun pengalaman dalam industri asuransi. Ia memegang sertifikat Registered Financial Planner (RFP), Certified Indonesian Insurance Broker (CIIB) dan Ahli Pialang Asuransi Indonesia (APA

Terhubung dengan kami

Mari Diskusikan Kebutuhan Risiko Anda

Hubungi Omar untuk mendiskusikan kebutuhan asuransi dan solusi pengelolaan risiko Anda melalui halo@lngrisk.co.id atau WhatsApp.