Most businesses have two security conversations that never meet. One is about firewalls, passwords, and backups. The other is about door codes, cameras, and who has a key. Different people, different budgets, different vendors, and neither side knows what the other agreed to.

That split made sense thirty years ago. Not now. Your badge reader is a computer on your network. Your cameras write video to a drive somebody has to protect. And an attacker who gets into your building does not care which department owns the problem. CISA defines an insider threat as someone using authorized access to harm an organization’s “mission, resources, personnel, facilities, information, equipment, networks, or systems.” Facilities and networks sit in the same sentence. That is the whole idea: one plan, not two.

The Server Closet Is Not a Storage Closet

We walk into a lot of server rooms. A good share of them hold holiday decorations, extra chairs, cases of paper, and a mop. The door is propped open because the room runs hot. This is normal, and it is a problem.

Everything protecting your data digitally assumes physical control of the hardware. Someone standing at the server with a screwdriver has options no password prevents, and that person does not need to be a criminal mastermind. A cleaning crew, a delivery driver, a temp, or a curious employee all count.

  • Lock the door and keep it locked. If the room runs hot, fix the cooling. Do not solve a heat problem with an open door.
  • Take the storage out of it. The fewer reasons people have to walk in, the more meaningful it is when someone does.
  • Know who holds keys or codes. Write the list down. It is always longer than the owner expects and usually includes someone who no longer works there.
  • Log entry if you can. A badge reader on that one door is cheap and turns “somebody must have” into a timestamp.

Your Door and Camera Systems Are Computers

This is the part that surprises owners. The badge system, the camera recorder, the smart thermostat, the alarm panel with a network cable in it: these are small computers running software. They sit on your network, they have administrator logins, and they need updates. They are usually installed by a low voltage contractor who is excellent at running cable and was never asked to think about network security.

A 2023 joint advisory from NSA and CISA put “default configurations of software and applications” at the top of its list of the ten most common misconfigurations and told organizations to remove default credentials and harden configurations. Physical security hardware is where default credentials go to retire quietly. Nobody logs into the camera recorder for four years, so nobody notices the password is still whatever came in the box.

  • Inventory them. Ask your IT provider for a list of everything on your network that is not a computer, phone, or printer. The length surprises most owners.
  • Change the default logins. All of them, including the installer account. Then find out whether that contractor still has remote access, and whether you want them to.
  • Put them on their own network segment. The same 2023 NSA and CISA advisory flagged lack of network segmentation as a top misconfiguration because it “leaves no security boundaries between the user, production, and critical system networks.” A camera has no business reaching your accounting server.
  • Ask who is responsible for updates. If the answer is nobody, that is your answer. Put it in someone’s contract.

Where the Footage Lives and Who Can Watch It

Camera systems raise two questions nobody asks. Where does the video go, and who can see it?

The recording sits either on a box in your building or in a vendor’s cloud service. Both are fine, and both have consequences. A local recorder can be stolen along with everything else, so a camera pointed at the recorder is not a joke. A cloud service means your video lives with a third party, and you should know who, for how long, and what happens if you cancel.

Access is the harder question. Camera systems accumulate viewers: the manager who left, the installer, the owner’s phone app, a supervisor who asked once. Cameras pointed at employees are a personnel and legal matter too, so decide deliberately who may view live feeds, who may pull recordings, and whether anyone is notified. Write it down and review it when people change roles.

The Person in the Vest, and What Your Lobby Shows

People are helpful. That is a virtue, and it is also the easiest way into most buildings. Someone in a safety vest with a clipboard, or a delivery driver with full hands at a badge door, gets waved in by a friendly employee who does not want to seem rude. CISA lists negligence, including allowing unauthorized entry, among the unintentional insider threats organizations face.

The fix is not suspicion. It is a policy that removes the social pressure from the individual.

  • Give people a script. “Let me walk you to the front desk” is polite and ends the problem. Practice it once in a staff meeting so it feels natural.
  • Make one door the visitor door. Everyone signs in, gets a badge, and is escorted. Consistency is what makes an exception noticeable.
  • Look at your building the way a stranger does. Walk the lobby and the parking lot. Which screens can you read through the glass? Is reception showing a customer record? Privacy filters and turning a monitor are cheap.
  • Set screens to lock quickly. A short automatic lock on every workstation costs nothing and covers the unattended desk.

Laptops in Cars and Paper in Dumpsters

Two habits cause more real data loss for small businesses than anything exotic: devices left in cars, and things thrown away intact.

A laptop in a car is one smash and grab from being someone else’s laptop. The control that turns that from a breach into an inconvenience is full disk encryption, built into current business versions of Windows and macOS and needing only to be turned on and verified. Encrypted and reported quickly, a stolen laptop is a hardware expense. Unencrypted, it is a disclosure problem.

Disposal is the other half. A dumpster should not be a research library. Cross cut shredding for paper is table stakes, and for hardware, deleting files is not enough. NIST published Revision 2 of its Guidelines for Media Sanitization in September 2025, describing sanitization as “a process that renders access to the target data on media infeasible for a given level of effort” and pushing organizations toward a defined program rather than case by case decisions. In practice that means a written rule for old drives, phones, copiers, and backup media, plus a certificate of destruction when a vendor handles it. Copiers surprise people: many store images of everything they scanned.

The Bottom Line

Physical and IT security are one plan viewed from two angles. The building protects the hardware, the hardware protects the data, and the systems controlling the building are themselves computers needing the same care as your servers. Managed separately, the gaps land in the seam between them, which is the same visibility problem we describe in our post on shadow IT and part of why security is no longer optional for mid-sized businesses.

Start with a walkthrough. Lock the closet, list the keys, find the default passwords on your building systems, and look at your lobby the way a stranger would. None of that needs a project plan, and it closes more real risk than most software purchases. If you want a second set of eyes, we do this walkthrough with businesses across Denton County and will tell you plainly what we find. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).