GDS Technology — Built, Wired and Secured podcast banner
Watch on YouTube →
Blog Wired

Carrier Diversity for Buildings That Works

A building can have two internet contracts and still lose connectivity from one damaged conduit, one flooded telecom room, or one failed power circuit. Carrier diversity for buildings is not a procurement exercise. It is an availability design decision that must be owned from the property line to the network edge.

For commercial properties, the consequences are wider than slow email. Tenant operations stop. Access control and cameras may lose connectivity to central platforms. Building engineers lose remote visibility into critical systems. Leasing teams face difficult questions about resilience that should have been answered during design, not after an outage.

Carrier diversity for buildings starts with failure domains

The first question is not, "How many carriers serve this address?" The first question is, "What event could take all of them down at once?"

Two services can appear diverse on a contract while sharing the same vulnerable infrastructure. They may enter through the same street vault, use the same underground duct bank, terminate in the same room, depend on the same utility power, or traverse the same local aggregation point. Different invoices do not automatically mean different failure domains.

A meaningful design separates the parts of the service that are most likely to fail together. That includes the outside plant, building entry points, interior pathways, telecommunications rooms, network equipment, power sources, and management process. The goal is not to eliminate every outage. The goal is to prevent one foreseeable failure from becoming a full building outage.

This is where fragmented responsibility causes trouble. The carrier manages its circuit. The electrician manages power. The low-voltage contractor manages cabling. The network team manages the firewall. Property management manages the building. If no one is accountable for the complete path, no one can confirm whether the diversity claim is real.

Map the full path before selecting service

A carrier service should be documented as a physical and operational path, not just a circuit ID. Require a path review before finalizing the design. This review should identify where each service originates, how it reaches the site, where it enters the building, and what it depends on once inside.

Separate the building entrances

The strongest practical control is physically separate points of entry. Services entering through opposite sides of a building have a better chance of surviving a localized excavation incident, fire, water event, or damage near one entrance.

Separate entrances are not always possible, particularly in urban towers, historic properties, or multi-tenant buildings with limited access to exterior walls. When they are not possible, document the limitation plainly. Then reduce concentration elsewhere through protected pathways, separate risers, and clear recovery procedures. Pretending a shared entrance is diverse creates a false sense of security.

The entrance facilities also need to be maintainable. A locked room with no current access list, undocumented conduits, or abandoned cabling is not a controlled environment. Building ownership should know who can access the space, what pathways are active, and which services depend on them.

Keep interior pathways independent

After services enter the building, they can lose diversity quickly. It is common to find primary and secondary circuits routed through the same conduit, tray, or riser because it was convenient during construction. That arrangement may meet a basic installation requirement, but it does not provide meaningful resilience.

Use separate risers and pathways where the building layout allows. Avoid routing both circuits through the same unsecured ceiling space, equipment room, or penetrated fire barrier without a documented reason. Where paths must converge, identify the convergence point in the risk register and define the response plan.

This work belongs in construction drawings, as-built documentation, and final acceptance testing. It should not live only in a project manager's memory or a carrier email thread.

Separate rooms, racks, and power dependencies

Two circuits that terminate on the same router, in the same rack, powered by the same unprotected circuit, are only partially diverse. A telecommunications room failure can still remove both services at once.

At a minimum, assess whether the primary and secondary handoffs can be served by separate network devices or by equipment with redundant components. Evaluate rack location, cooling, physical security, and power. If both circuits must land in one room, use independent power paths where possible and make sure the room is included in generator and UPS planning.

There is a trade-off. Full physical separation costs space, design effort, and operational discipline. For a small office, a second circuit with a properly configured failover device may be proportionate. For a building supporting multiple tenants, security systems, operational technology, and revenue-critical services, a single telecom room is often too large a shared risk to ignore.

Design the network to use diversity

A secondary carrier that never takes traffic until an emergency is not a tested resilience strategy. Failover configurations can fail because of expired credentials, incorrect routing, stale firmware, capacity limits, or monitoring rules that do not recognize a partial outage.

Decide whether the building needs active-passive or active-active connectivity. Active-passive is simpler to govern and often appropriate when the secondary connection is intended for continuity of essential services. Active-active can improve capacity use and reduce switchover concerns, but it adds routing, security, and troubleshooting complexity. The right model depends on application requirements and the team responsible for operating it.

Document which systems must continue during a carrier failure. That list may include building automation remote access, access control administration, video management, tenant internet, voice services, cloud applications, remote support tools, and monitoring platforms. Not every service needs identical performance during an outage, but critical services need defined priorities.

Network segmentation matters here. A failover event should not create a shortcut around security controls or expose building systems to unmanaged internet access. The alternate path must enforce the same policy expectations for firewalling, remote access, logging, and vendor connections.

Verify carrier claims with acceptance testing

Do not accept diversity based on a sales statement or a service order description. Ask for written confirmation of the outside-plant route, local entrance path, and known shared infrastructure. Some details may be limited for security or operational reasons, but the carrier should be able to identify whether two services share a building entrance, conduit, central office, aggregation point, or other material dependency.

Before project closeout, perform a controlled test. Disconnect or disable the primary circuit and verify that required services fail over within the agreed time. Confirm that monitoring generates an alert, designated personnel receive it, and the team can identify the affected path without guesswork.

A useful acceptance record includes:

  • Circuit identifiers, demarcation locations, and carrier contact procedures
  • Exterior entrance points and interior pathway drawings
  • Telecommunications room, rack, device, and power dependencies
  • Failover configuration and tested recovery times
  • Named owners for testing, documentation updates, and incident escalation

Repeat the test on a defined schedule and after any material network change, tenant build-out, riser modification, or equipment replacement. Redundancy degrades quietly when changes are made without lifecycle controls.

Put ownership around the entire service path

Carrier diversity fails most often at handoffs. One party assumes another party has verified the route. A contractor relocates a conduit. An IT team replaces a firewall. A facility team changes room access procedures. Each decision may be reasonable in isolation, yet the building loses a resilience control.

Assign one accountable owner for the end-to-end design standard, even when multiple specialists perform the work. That owner does not need to install every cable or operate every circuit. They do need authority to require documentation, challenge unsupported claims, approve exceptions, and verify final results.

For property portfolios, standardize the questions asked at every site. What are the carrier paths? Where do they converge? What shares power? When was failover last tested? Who owns the runbook? A common standard makes it easier to identify buildings where apparent diversity is really a single point of failure with two provider names.

The most useful next step is simple: walk the service path with the current drawings, the network diagram, and the people who operate the building. If the team cannot explain how each circuit enters, travels, terminates, fails over, and is restored, the building does not yet have carrier diversity it can rely on.