
Security during a relocation
A relocation temporarily suspends most of the controls an organisation relies on. Equipment leaves its usual environment, access control is inconsistent while two sites are partly occupied, unfamiliar people have physical access, and everyone is focused on the deadline rather than on procedure.
The exposure is short but it is real, and it concentrates in a few predictable places.
Equipment in transit
The risk is loss, not interception. Devices go missing during moves: left on a trolley, loaded onto the wrong vehicle, taken home by someone being helpful. Deliberate theft happens too, but simple loss is far more common.
What actually protects you is full-disk encryption on everything that moves, verified before the move rather than assumed. A lost encrypted laptop is a hardware replacement. A lost unencrypted one is a data breach with notification obligations.
Verify encryption status across the fleet as a specific pre-move task. There are always a few devices where it silently failed or was never applied, and the week before a move is the last convenient moment to find them.
Chain of custody. Every item that moves should be on a manifest, with someone signing it out at the old site and someone signing it in at the new one. This sounds bureaucratic and it is the only way to know quickly whether something is missing. Reconcile the manifest within days, not weeks. A device discovered missing a month later has an unusable investigation window.
Servers and storage. These hold the most and are the most attractive. Move them separately from general office equipment, with named responsibility, and do not leave them unattended in a loading bay or a corridor at either end.
The two-site period
Most moves involve a period where both sites are partly occupied, and this is where physical access control is weakest.
The old site becomes progressively emptier and less supervised while still containing equipment. Doors get propped open for movers. Reception coverage lapses because the receptionist has moved. Access cards for the old building remain active because nobody has decided when to disable them.
What helps:
- Decide in advance when old-site access is revoked, and for whom. Not "when we're finished". A date.
- Keep the last remaining equipment in one lockable room rather than distributed across empty floors.
- Ensure someone is accountable for the old site each day it still holds anything.
- Do not prop open secure doors. If access is needed, arrange it properly for the period.
Movers and contractors
People you have not vetted will have physical access to your premises and your equipment.
Reasonable precautions:
- Ask the moving company about their own vetting and confirm who will actually attend. Subcontracting is common.
- Have a named member of staff present throughout at both sites. Not to supervise every box, but so that there is always someone accountable and visible.
- Clear desks completely before movers arrive. Documents, notes with passwords, and unattended devices are the realistic exposure, and a clear-desk sweep the evening before removes most of it.
- Secure or remove anything holding sensitive material before the move rather than during it.
The comms room at both ends
At the old site, the comms room is often the last thing dismantled and is frequently left unlocked during the final days because people are coming and going. It contains the network equipment and, often, documentation on the wall.
At the new site, it is frequently accessible to building contractors during fit-out. Cabinets should be locked from the moment equipment is installed, not from the moment the move completes.
Check who has keys or access to the new comms room, including the landlord and building management. Some buildings retain access as a matter of policy, and that is worth knowing rather than discovering.
Network changes made under pressure
Temporary configurations made during a move have a strong tendency to become permanent.
The common ones: a firewall rule opened to get something working on the move weekend, a temporary connection between old and new sites, wireless configured with a simple pre-shared key to get people online quickly, remote access relaxed so the team can work from either building.
The fix is to record every temporary change as it is made, with an expiry date, and to review the list two weeks after the move. Without a written list, these are found in an audit a year later, if at all.
Disposal of what does not move
Equipment not making the journey is a specific risk, because disposal decisions get made quickly at the end of a move.
Every device with storage (including printers and multifunction devices, which retain scanned and printed documents) needs its data destroyed to a standard you can evidence. For regulated organisations that means certificates of destruction.
Arrange this before the move, with a specific area for equipment awaiting disposal and someone accountable for it. Equipment left in a pile at an empty office for collection is how drives disappear.
Documents
Paper gets neglected because the attention is on technology. Filing cabinets, archived records, printouts in desk drawers.
Decide what moves, what is archived and what is destroyed, and use a secure destruction service for anything sensitive. A skip outside an office being vacated attracts attention, and paper records are frequently more sensitive than what is on the average laptop.
A short pre-move checklist
- Encryption verified on every device that will move.
- Manifest prepared, with sign-out and sign-in owners.
- Clear-desk sweep completed the evening before.
- Old-site access revocation date agreed.
- Named staff present at both sites throughout.
- Secure disposal arranged, with a controlled holding area.
- Comms rooms locked at both ends, with a known key list.
- A written log ready for temporary changes, with a review date two weeks out.
None of this takes long. All of it is much harder to arrange retrospectively.
Want this looked at in your own environment?
Talk to an expert →Keep reading


