Skip to content

Why I stopped chasing Tier III certification

Datacenter Talk by Buenos 33 replies 8.2K views
#31

128 days but this thread is still relevant.

olespete said:
Firewall the IPMI

Off topic but since you brought it up, has anyone actually seen IPMI exposed to the public internet in the wild recently? I scan ranges for work and the numbers dropped off a cliff around 2021. Either people wisened up or the big clouds finally stopped defaulting to routable addresses.

Back on topic though, the insurance angle is interesting. I work with a couple mid-sized hosts, one on Contabo, one self-colo in a Hetzner facility. Neither has ever been asked for Tier anything by their underwriter. They want to see maintenance logs and environmental monitoring, sure. But the certificate itself? Not once.

Maybe the insurance paranoia depends on which country you're writing the policy in.

#32

129 days and this is still the most honest thread on the board

cleardmitri said:
Insurance actually checks Tier III dates? Never seen that happen.

Same, our broker asked about physical security once and never brought it up again

The real thing that bit me later was selling to a bigger fish, they wanted to see "current" certs during due diligence and we had to explain the lapse with a straight face, deal still closed but the lawyer bill was not small brother

#33

137 days and I'm still thinking about this thread.

olespete said:
Firewall the IPMI
Pete, do you mean VLAN-segregated or actual host-level firewall rules? I've only done the VLAN thing and now I'm wondering if I'm being lazy.

Also curious if anyone actually had an insurer ask for Tier III paperwork during a claim. Theoretical risk is one thing, real denials are another.

No logs, no proof. I have logs.
#34

176 days but this thread is still relevant.

cleardmitri said:
Insurance actually checks Tier III dates? Never seen that happen.

I have. Not the insurer directly, but the broker who placed our policy. They asked for current certification during renewal, we handed over expired docs, premium jumped 12 percent that year. Could have been coincidence, could have been the broker squeezing us, hard to prove either way.

What I actually came to say: has anyone here tried the KnownHost self-assessment path instead of full audit? They market it as "audit-ready documentation" you maintain yourself, third party verifies only every three years. Costs about a third. Wondering if it's a middle ground or just expensive paper in a different drawer.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft