The Chiller Doesn't Get a Security Budget: What the Namecheap Outage Reveals About Data Center Blind Spots
Published on: August 19, 2026
At 3:50 am EDT on August 15, 2026, Namecheap brought the last of its services back online, roughly fifteen hours after a storm knocked out the cooling systems at RadiusDC's Phoenix data center. Shared hosting, VPS, dedicated servers, EasyWP, DNS management, private email, billing, and support all went dark in stages, taken offline because rising temperatures put customer hardware at risk of damage. CEO Hillan Klein called it a rare event in the company's 25-year history and told customers plainly, "We failed you today." (TechRadar, 2026).
Nobody suspects the air conditioning of taking down a hosting provider. Most security budgets funnel toward the network perimeter: intrusion detection, endpoint protection, access controls layered three deep. Cooling and power get treated as a separate operational track entirely, run by facilities rather than security, even though the two intersect the moment one takes the other down. Uptime marketing talks up network redundancy and geographic failover. The chiller doesn't get a slide. The mechanical systems keeping the building itself alive sit outside that budget conversation, run by a separate facilities team on a separate maintenance schedule, disconnected from the monitoring built around the servers they keep cold.
Three Major Cooling Failures, One Six-Month Stretch
That same division between network security spend and mechanical oversight recurs at every operator this failure mode has hit this year. On May 7, 2026, a cooling failure in AWS's us1-az4 availability zone pushed temperatures past safe operating thresholds, and automatic shutdowns took systems down for roughly twelve hours (Network World, 2026) Two months later, an electrical fault on the utility grid upstream of Google Cloud's europe-west4 data center in the Netherlands knocked out power distribution and cooling together, forcing an emergency shutdown of servers, storage, and network switches that lasted nearly fifteen hours (DataCenterDynamics, 2026).
AI Is Driving Demand. Resiliency Can’t Keep Up.
That failure mode is landing as demand on the underlying infrastructure is escalating. Data center electricity consumption grew 17% in 2025 alone, and AI-specific facilities are growing at 50% a year, on pace to triple their electricity use by 2030 (IEA, 2025/2026).
Andy Lawrence, Uptime Institute's executive director of research, put the mechanical consequence plainly: AI is pushing rack densities up in a way that's "reducing the ride-through times of cooling," the buffer that used to give a facility a few extra minutes before a cooling hiccup became a cooling failure. Outage rates have declined for five straight years in Uptime's own data. Lawrence's concern is that this is the factor that reverses it (Data Center Knowledge, 2026).
The Building Layer Is Already Wide Open
A shrinking safety margin would matter less if the systems controlling cooling, fire suppression, and access control were hardened the way core IT infrastructure is. Claroty's Team82 analyzed more than 750,000 cyber-physical systems across major global data centers and found that 88% of building management systems communicate over insecure protocols and 40% run outdated firmware (Claroty, 2026).
A Known Phenomenon for Physical Security Teams
That exposure happened because nobody had the headcount to catch outdated firmware and missing authentication before it piled up at scale, the same math physical security teams have already lived through on a different device category. One VP of Global Security at a data center operator managing tens of thousands of physical security devices described running that fleet with a team of one to three people, and called it hard to stay on top of firmware, password, and end-of-life status at that scale (Compass Datacenters case study). Device counts grew faster than headcount, and visibility was what gave out first.
There's no structural reason cooling and power infrastructure would age any differently, especially with AI-driven buildout adding mechanical capacity faster than anyone is adding people to watch it.
The Next Outage Won't Wait for a Better Monitoring Story
Redundancy commitments like N+1 power and tiered uptime ratings plan for equipment failure. They don't answer whether anyone can see that equipment's health degrading before it fails. That question is only getting louder with every rack of AI hardware plugged in.
Physical security already learned the hard way how to address the issue of device visibility. The building's mechanical systems are next in line, and SecuriThings' Agentic Device Orchestrator is already extending that same operational and cybersecurity rigor into building management and automation systems. The Namecheap outage was just the version of the story that happened to make the news first.

