The threat model tends to skip the walls
Most data center security spend goes to the network. The structure protecting the floor, the generators, and the utility tie-ins often meets nothing tougher than a commercial building code. For a site whose entire value is uptime, that is a real gap between what gets protected and what a loss would actually cost.
A breached wall or a hit to the utility feed takes a data center down as completely as any cyber intrusion.
Match the shell to the load inside it
The fix is not exotic. Size the envelope, the critical rooms, and the standoff to the value of what runs inside, using a real threat basis instead of base code. Colocation and hyperscale operators are increasingly asked for exactly this by the tenants and insurers standing behind the site.
Protecting what runs inside starts with an envelope built to a defined threat basis.