Physical security checklist for small offices: the server closet nobody locks
Companies spend a year hardening their cloud accounts and then leave the physical network switch, the NAS with the customer backups, and the spare laptop in an unlocked closet that anyone in the building — and the cleaning crew, and the landlord's contractor — can open. Physical security for a small office is not cameras and badges; it is about six decisions: what is actually valuable in this room, who can touch it, what happens when a stranger walks in, and whether the paper on the printer counts as data. Most real-world breaches at small companies don't need the internet — they need an unattended desk. This is the one-afternoon pass, written for the office that has no security team, in the same voice as the network checklist next door: decide once, write two lines, and stop drifting.
1. Inventory what is worth protecting — it is a shorter list than you think
- Walk the office and name the crown jewels out loud. The NAS or backup drive, the network rack, the router, the laptop that runs payroll, the file cabinet with contracts. Five to ten items. If the list is longer, you are protecting everything, which is how you protect nothing.
- Count the paper that is really data. Invoices, signed contracts, printed customer lists, the whiteboard from the strategy offsite. Paper doesn't appear in asset lists because IT doesn't buy it — and it doesn't appear in breach reports because nobody counted it. The breach first-24-hours page applies to a photo of a whiteboard exactly as much as to a database dump.
- Match each item to the threat that actually applies. A stolen backup drive is the same incident as a stolen laptop: data leaves the building. The stolen laptop runbook already tells you the sequence — the drive just never got a line in it.
2. Lock the two rooms that matter
- The server/network closet gets a lock with a named keyholder list. Not "anyone in the office has a key" — two named people, one backup. The switch and NAS being reachable by every visitor, courier, and building contractor is the single most expensive default in the room. If the closet is a shared building utility, a lockable cabinet inside it costs $150 and solves it.
- The router lives behind that lock too. A router an intruder can touch is a router an intruder can factory-reset or tap. The Wi-Fi security checklist hardened the config; the lock protects the config's existence.
- Lock the file cabinet, not the desk drawer. Desks are searched casually; cabinets with real locks require intent. Contracts, HR files, spare hardware, the blank cheque stock — one cabinet, named keyholders, same rule as the closet.
3. Decide who gets in — and write it where the door can see it
- Keys and badges get issued like accounts. Same discipline as the access request/offboarding pair: a physical key is an access grant with an owner and a revocation path. The key cabinet (or a line in the password manager) records who holds which key; offboarding collects them with the laptop. A departed employee's unreturned key is an open door with no audit trail.
- The visitor log is ten lines and starts today. A clipboard by the door: name, company, who they are here to see, time in/out. Its value is not the paper — it is that someone notices a stranger in the office, because noticing requires the expectation that strangers are logged. The contractor checklist gets one more line: "escort on first day, badge after."
- The "no tailgating" rule is one sentence, said kindly. "Let me walk you in — who are you here to see?" turns a held-open door into a hosted visit. Nobody wants to challenge anyone; everyone will host someone.
4. The unattended-desk rule — where most incidents start
- Lock screens: on, short, automatic. A session left unlocked on an unattended desk is admin access to whatever that person can reach — email, CRM, payments. Company policy in one line: "Lock your screen when you leave your desk, always" (Win+L / Ctrl+Cmd+Q). The MFA rollout already made people log in again; this is the same muscle.
- Laptops leaving the office get cable locks or a locked drawer. The remote work checklist covers the cafĂ©; the office after hours is its own threat model — cleaning crews, building staff, other tenants' guests. A $12 cable lock on a docked laptop is not paranoia; it is a rate limiter.
- The printer and copier are paper machines and data machines. The print tray is the most-read document in the office. Rule: collect prints immediately; shred pile lives next to the printer; old copiers with internal drives get wiped or removed before disposal, not sold on eBay with three years of invoices inside.
- shred the paper on a schedule. A "to shred" box that grows for six months is an unsecured archive. Monthly shred (a $20 cross-cut shredder, or a quarterly service) closes it. The monthly maintenance pass gets one added line: empty the shred box.
5. Backup media, drives, and the garbage
- Offsite or fire-safe backup media are on the inventory. The rotation drive in a desk drawer is a single-event disaster: fire, flood, or one thief takes the server and the backup. One offsite copy (bank box, founder's house, or cloud) completes the 3-2-1 rule physically.
- Drives die by shredding, not by binning. Any drive that held company data leaves the building as a shredded brick, not a "maybe still fine" drive in the recycling bin. Wiped-or-shredded is a two-word policy that ends the argument.
- Dumpster-diving is a real, cheap attack. Printed customer lists in the building's shared bins are a data breach with no computer involved. Locked shred bins or the monthly shred pass handle it.
6. Cameras and alarms — proportionate, not cinematic
- A $100 alarm or even door sensors beat an unmonitored camera. For most small offices, the highest-value spend is a loud noise at 2am. Cameras that nobody watches are furniture; a door sensor that texts the founder is a response.
- If you do add a camera: one on the server closet door beats four in the parking lot. Coverage of the two locked rooms (section 2) plus the entrance is the whole design. And the camera system itself gets a password change — default-credential cameras are the shadow IT of the physical world.
- Check the lease and the landlord. Shared buildings mean shared risk decisions. The building's front-door policy is part of your perimeter whether you chose it or not; worth one conversation with the landlord, and a note in the runbook.
7. The quarterly 15-minute walk
- Walk the inventory list from section 1 in order. Each item: still in its locked place? Keyholder list still correct? The annual security review covers the whole program; this walk is just the physical 15 minutes of it.
- Try your own door. The closet lock that has been left ajar for a week, the fire-exit magnet that defeats your lock, the cabinet everyone stopped closing. You are looking for the drift, and drift is normal — that is what the walk is for.
- Recount keys and badges. New hires, departures, the key that went to the landlord's contractor in March. Five minutes, once a quarter, and the door inventory stays true.
8. What done looks like
- Two locked rooms (closet, cabinet), two named keyholders each, keys issued and revoked like accounts.
- A visitor log in use, screens locking automatically, prints collected, shred box emptied monthly.
- A two-line runbook: "New key or badge? Owner, purpose, return path — same as an account. Quarterly: walk the list, try the doors, recount the keys." The office stops being the softest part of the stack.
Physical security is the perimeter behind the perimeter. The incident playbooks that assume someone got in anyway — first 30 minutes, breach disclosures, recovery — are in the Ops Starter Kit ($14), and the recurring reviews that keep every checklist honest are in the Automation Starter Pack ($19). Launch week: 20% off any paid kit with code HIVE20 at checkout.