top of page

Small Business IT Maintenance: Network Closets, Server Rooms and Secure Equipment Disposal

  • Writer: Shay
    Shay
  • Apr 18, 2025
  • 24 min read

Updated: Aug 27

Small Business IT Maintenance blog cover from SNL-Tech Services about network closets, server rooms and secure IT equipment disposal.
Small business IT maintenance includes more than keeping equipment running. Network closets, server rooms, documentation and secure equipment retirement all need ongoing attention.

Updated August 2026

Small businesses have a way of accumulating technology over time. A switch gets added because more network ports are needed. Another wireless access point gets installed when the business expands. A server gets replaced, but the old one stays in the server room for a while just in case. Computers get upgraded and the old ones end up on a shelf. Battery backups sit underneath desks or at the bottom of network racks for years. Eventually, someone opens a closet and realizes there is a lot of technology in there and nobody is completely sure what all of it does.


I originally wrote this article in 2025 as a spring cleaning checklist for small business technology. I am updating it in 2026 because small business IT maintenance is much bigger than spring cleaning. Your network closet, server room and the equipment inside them need ongoing attention throughout the year.. Your network closet, server room and the equipment inside them need ongoing attention throughout the year. Businesses also need a process for what happens as technology changes and eventually leaves the organization. Cleaning up the physical environment is part of that, but so are maintenance, documentation, network diagrams, battery backups, equipment inventories, secure equipment retirement and making sure company data or network configuration does not accidentally leave with an old device.


This is also different from deciding when technology should be replaced. Age alone does not mean I automatically recommend replacing something that is still supported and meeting the needs of the business. I cover that discussion separately in When Should a Small Business Replace Its Computers? A Practical IT Hardware Lifecycle Guide. Here, I want to focus on taking care of the physical IT environment you already have, knowing what is actually in it, documenting it as things change and understanding what needs to happen when equipment is finally ready to leave the business.

“Good IT management does not end when the equipment is installed. You need to know what you have, maintain it, document the changes, and know what happens to the data when that equipment eventually leaves your business.”Shay, SNL-Tech Services

What Should a Small Business Check in a Network Closet or Server Room?

I love cleaning up network closets and server rooms. There is something very satisfying about taking a space full of tangled cables and unidentified equipment and turning it into an environment where you can actually understand what is connected and how everything fits together. There is also a very practical reason for doing it. Your firewall, switches, servers, NAS appliances, wireless infrastructure, battery backups, internet equipment and sometimes security camera equipment may all be sitting in that room. Those devices can be critical to keeping the business running.


A network closet cleanup should not begin by unplugging everything that looks old. I have worked in environments that have grown and changed over many years. Internet providers replace equipment. Vendors add switches. Cameras get installed. Wireless access points are expanded. A temporary network cable becomes permanent. Someone adds a small switch because they need one more port. Years later, nobody remembers why half of it is there. Something that looks like an unused box may still be providing connectivity to a camera, printer, phone, wireless access point, another part of the building or a piece of equipment nobody remembered was connected.


Before removing anything, identify it. Trace connections where necessary, document what the equipment does and understand the effect of disconnecting it. Making a network closet look better is not worth accidentally taking part of the business offline.

What I would review

What I am trying to determine

Equipment identification

Do we know what each device is and what it does?

Cabling and labeling

Can important cables, ports and devices actually be identified?

Airflow and ventilation

Is equipment getting appropriate airflow or sitting in an excessively warm environment?

Dust and physical condition

Are vents blocked, cables damaged or other physical problems developing?

UPS units

Are the batteries healthy, are self tests passing and is critical equipment actually protected?

Firmware and support

Is connected equipment still supported and being maintained?

Physical access

Who can actually get into the network closet or server room?

Old equipment

Is unused or retired equipment sitting there with company information still on it?

Documentation

Does the equipment inventory and network diagram match what is physically installed?

I also do not recommend attacking a running server rack with household cleaning products or a vacuum because you decided it was time to clean the server room. Cleaning around active electronics needs to be done appropriately, and deeper cleaning should be planned so that equipment is not damaged and critical business systems are not unexpectedly taken offline.


A beautifully organized rack is nice to look at, but appearance is not the real goal. What I care about is whether we know what the equipment does, whether it is being maintained, whether someone can troubleshoot it when there is a problem and whether the physical environment is appropriate for the technology running inside it.


Maintenance Is More Than Cleaning the Dust

While I am reviewing the physical environment, I also want to know whether the equipment itself is being maintained. Firewalls, switches, wireless access points, NAS appliances, printers, cameras and other connected devices may have firmware or software that needs to be kept current. I also want to know whether the manufacturer still supports the equipment.


That does not mean every older device automatically needs to be replaced. There is an important difference between a piece of technology that is a few years old and still supported and a device that has reached the point where it is no longer receiving the security, firmware or software support the business needs. When I find the latter, that becomes a lifecycle planning conversation rather than simply a network closet cleanup.

This is also why maintaining an inventory matters. If nobody knows the model of the switch in the closet, when it was purchased or what it is connected to, it becomes much harder to determine whether it is still appropriate for the business. The same applies to firewalls, wireless equipment, servers, storage appliances and other infrastructure.


Does My IT Documentation Need to Change When Equipment Changes?

Yes. This is one of the easiest parts of IT management to overlook.

Documentation can become outdated surprisingly quickly. A firewall gets replaced, a new switch is installed, an internet connection changes, wireless access points are moved, a server is retired or a NAS is added, but the network diagram still shows the environment the way it looked two years ago.

“If your network diagram does not match what is actually plugged in, it is no longer documentation. It is history.”Shay, SNL-Tech Services

When I make changes to an IT environment, I want the documentation to change with it. That includes more than simply updating an equipment inventory. If the change affects how the network is designed or how systems connect, the network diagram should be updated too. The goal is for the documentation to reflect what is actually installed, not what someone remembers being installed.

Depending on the environment, useful IT documentation may include:

  • Equipment make, model, serial number and physical location

  • Device names and assigned users where applicable

  • Firewall, switch and wireless access point information

  • Network addressing and VLAN information

  • Internet connections and ISP equipment

  • Physical connections between important network devices

  • Server, NAS and other storage infrastructure

  • UPS units and the critical equipment they protect

  • Wireless access point locations

  • Network diagrams showing how important systems connect

  • Warranty, support and replacement information

  • Securely documented administrative and management information where appropriate

There are also certain changes that should make you think about documentation immediately. Replacing a firewall, changing internet providers, adding or removing a switch, retiring a server, installing a NAS, changing VLANs, moving wireless access points or significantly changing how equipment connects can all affect existing records.


Accurate documentation makes troubleshooting easier, helps with future upgrades and gives another IT professional a much better understanding of the environment if they ever need to work on it. It also helps the business maintain ownership and visibility into the technology it depends on. Replacing the equipment is only part of the job. The documentation should reflect the change when the work is finished.


Yes, My Label Maker Comes With Me

My wife teases me about my love for labels, and she is not wrong. Our camping bins are labeled. Things around our house are labeled. And yes, my label maker travels with me in my IT gear.


When I work at a client location, I use labels on computers, network equipment, wall jacks and other equipment that someone may eventually need to identify. When I set up computers, I also label them with their computer name based on the naming convention I am using.


It may seem like a small detail until someone calls and tells me that “the computer at the front desk” is not working and there are three computers at the front desk. Being able to identify the correct device immediately makes remote troubleshooting easier. The same principle applies to switches, wireless access points, network jacks and cabling. If I know exactly what I am looking for, I can spend my time solving the problem instead of trying to figure out which piece of equipment someone is talking about.


Good labeling also means the technology environment does not depend entirely on one person's memory. If someone else needs to work on the network later, clear labeling and accurate documentation can make an enormous difference. I genuinely enjoy organized technology, but there is a practical reason behind it. Good labeling and documentation reduce guessing.


How Often Should a Small Business Check Its Battery Backups?

Battery backups are one of those pieces of business technology that are incredibly easy to forget. A UPS can sit underneath a desk or at the bottom of a network rack for years without getting much attention. Because it is not something employees interact with every day, everyone assumes it is doing its job.


The batteries inside a UPS do not last forever. Battery life varies depending on the battery technology, temperature, load, discharge history, operating environment and manufacturer guidance. APC, for example, says most of its VRLA UPS batteries should last approximately three to five years, while also explaining that operating temperature and the number of discharges affect battery life.


That does not mean I recommend blindly replacing every UPS battery on one universal schedule. I want to look at the actual equipment and the environment it is operating in.

UPS check

Question I would ask

Age

How old are the UPS and its battery?

Self test

Is the unit passing its self tests?

Alerts

Is it reporting a battery or hardware warning?

Load

What equipment is connected to it?

Runtime

Does it still provide the runtime the business expects?

Environment

Is it operating in an excessively warm location?

Purpose

What happens to the business if the protected equipment suddenly loses power?

That last question matters. A UPS protecting a single workstation and a UPS protecting the firewall, switches, NAS or server are not necessarily carrying the same operational importance.

The worst time to discover that the battery backup protecting critical infrastructure has almost no usable battery capacity left is during an actual power outage.


What Should I Do With Old Computers and IT Equipment?

Once you understand the equipment that is actively running the business, you can start looking at everything that is not. One of the questions small businesses eventually face is what to do with all the old technology that has accumulated over the years.


Most businesses develop some version of an IT graveyard. Sometimes it is a shelf in the server room. Sometimes it is a storage closet or a box underneath someone's desk. Inside you might find old laptops, desktop computers, hard drives, servers, switches, wireless access points, WiFi routers, power supplies, phones, tablets and equipment nobody recognizes anymore.

Before putting any of it into an electronics recycling pile, I want to answer some questions:

  • What is this device?

  • Is it still connected to anything?

  • Why was it originally installed?

  • Has it actually been replaced?

  • Does anyone still need it?

  • Does it contain company data?

  • Does it contain network configuration or credentials?

  • Is there anything we need from it before it is reset or sanitized?

  • Are there retention requirements affecting the information stored on it?

  • Where is the equipment going after the information is addressed?

An old hard drive may have been part of a backup process. A server may still contain years of company information. A NAS may contain backups or archived files. A retired firewall may still contain the business's network configuration. An old WiFi router may still have wireless settings stored on it. A multifunction printer or copier may contain internal storage. A computer that has been sitting unused for three years can still contain exactly the same company information it contained when someone put it on the shelf.


That is why I treat old technology as an IT asset until we have determined what it is, what it contains and what should happen to it.


If going through the equipment reveals that nobody actually knows what technology the business has, how everything connects or what the business depends on, that is a larger issue than cleaning out a closet. My Business IT Solutions include assessment and documentation work that can help establish what exists in the environment, how it fits together and what needs attention.



What Can Old Business Equipment Still Contain?

A device does not stop containing business information simply because the company stopped using it. Before a computer, server, storage device, printer, firewall, router or other equipment is sold, donated, recycled, returned, given to an employee or otherwise leaves the organization's control, the business needs to understand what information or configuration may remain on it.

Equipment being retired

What may need to be considered before it leaves

Laptop or desktop

Local files, cached business information, credentials, application data and internal storage

Server

Company files, databases, virtual machines, application data, backups and system information

NAS or storage appliance

Company files, backups, storage arrays and all installed drives

External hard drive or USB media

Business data, archives or backups that may have been forgotten

Backup media

Historical copies of company information that may extend well beyond what is on current systems

Multifunction printer or copier

Internal storage that may have processed information associated with printing, scanning, copying, faxing or emailing

Firewall

Depending on the device, network addressing, firewall rules, VPN configuration, certificates, credentials and other management information

WiFi router

SSIDs, WiFi passwords, administrator settings, security settings and other network configuration depending on the device

Managed switch

VLANs, port configuration and management information depending on the equipment

Wireless controller

SSIDs, wireless security configuration, access point management and other settings

Wireless access point

Wireless and management configuration depending on the system

Phone or tablet

Company email, applications, authentication information, local data and device management enrollment

UPS or battery backup

Battery condition and appropriate electronics and battery recycling rather than data sanitization

Not every device stores everything listed in this table. Equipment, configurations and manufacturers differ. The point is to stop treating “old IT equipment” as one generic category. You need to understand what a particular device is capable of retaining before deciding what happens to it.


Can I Give an Old Business Computer to an Employee?

Yes, a business can choose to give an old computer to an employee, but the important question is what happens before the computer changes ownership.


Some businesses allow employees to take an older laptop or desktop home when the company replaces it. There is nothing inherently wrong with giving usable equipment a second life. What I would not do is simply hand over the computer exactly as it was used inside the business.


That machine may contain locally stored documents, cached company information, email data, browser information, application data, saved credentials and other information belonging to the organization. Before ownership transfers, the business needs to determine what information is on the computer and use an appropriate sanitization process.


The same principle applies when equipment is donated to a nonprofit, sold, returned to a leasing company or repurposed somewhere outside of the business. Changing who owns the computer does not automatically remove the information stored on it.


The business also needs to think about anything it may need before sanitization begins. If there are required files, licensing information, application settings or other business information that has not been migrated, deal with that first. Sanitization should be the end of the business's use of the data on the device, not the moment someone realizes something important was forgotten.


How Should a Business Retire an Old Server, NAS or Backup Drive?

Servers deserve additional planning because the amount of information involved can be substantial. Depending on how a server was used, it could contain company files, employee information, accounting information, databases, virtual machines, backups, application data, directory information and other critical business data.


Before sanitizing a server, I first want to make sure the business is actually finished with it. Required data should have been migrated. Applications and dependencies need to be accounted for. Appropriate backups should be confirmed. Applicable record retention requirements need to be considered. If the server hosted virtual machines or databases, those need to be accounted for as well.


You do not want to discover after the drives have been sanitized or destroyed that an old application still depended on something stored on that server.


NAS appliances deserve similar attention because they can contain multiple drives configured together as a storage array. Looking at one drive in isolation does not necessarily tell you everything about how the data was stored across the system. The type of storage media also matters when determining an appropriate sanitization method.


External hard drives, USB storage and older backup media are even easier to overlook because they are small. A drive can sit in a desk drawer for years while still containing an old server backup, accounting files, employee information or customer data. Backup media can be particularly important because an old backup may contain information that has already been removed from the current production environment.


When reviewing old technology, I want removable storage and backup media included in the inventory rather than treating only computers and servers as data bearing devices.


What Should I Do With an Old Firewall, WiFi Router or Switch?

Computers and servers are usually the first things people think about when discussing data disposal, but network equipment can retain information about the business as well.

Depending on the product and configuration, a firewall may contain network addressing, firewall rules, VPN configuration, certificates, credentials or other information about how the business network operates. Routers, managed switches, wireless controllers and other managed network devices can also retain configuration and management information.

Network equipment

Information that may need consideration

Firewall

Firewall rules, addressing, VPN configuration, certificates, credentials and other configuration

WiFi router

SSID, WiFi password, administrator settings, security settings and network configuration

Managed switch

VLANs, port configuration and management settings

Wireless controller

SSIDs, security configuration, access point management and other wireless settings

Wireless access point

Wireless and management configuration depending on the platform

The exact information stored and the correct process for removing it varies by manufacturer and device. I do not use one generic retirement procedure for every network appliance. Before old network equipment is sold, donated, recycled or reused somewhere else, I want to identify the device, determine what information it retains and follow the manufacturer's appropriate process.


There is also an important step before resetting network equipment. Decide what needs to be preserved. That could include a firewall configuration, switch configuration, wireless settings, licensing information or other documentation needed to support the replacement environment. I do not want to discover after a device has been factory reset that it contained the only copy of information we still needed.


Once the new equipment is installed and working, this is also where the equipment inventory and network diagram need to be updated. The old firewall should not still appear as the active firewall six months after it left the building.


Does an Old WiFi Router Still Store My WiFi Password?

It can, and this is something many small business owners may never think about.

I still come across small businesses using standalone WiFi routers from manufacturers such as NETGEAR and similar vendors instead of centrally managed business wireless systems. There is nothing unusual about that, especially in a smaller office, but the router itself retains configuration information.


Depending on the device, that can include the wireless network name, or SSID, WiFi password, administrator settings, security settings and other network configuration information. NETGEAR, for example, specifically states that performing a factory reset on its routers deletes personalized settings including the username, password, WiFi network name and security settings. Simply unplugging the router is not the same thing as resetting its configuration.


Before an old WiFi router is sold, donated, recycled, given to an employee or reused somewhere else, I want to identify what it contains and follow the manufacturer's appropriate process for returning it to its factory configuration or otherwise removing the business's information.


There is an equally important warning here. Do not factory reset a WiFi router simply because you found it in the network closet and nobody recognizes it. First determine whether it is still doing something. It may be providing the primary wireless network, connectivity for another part of the building, a network used by IoT devices or another function that is not immediately obvious. Identify it and document it first. Reset it only after you know it is actually being retired and anything that needs to be preserved has been addressed.


If finding multiple routers, extenders and access points also makes you realize nobody really understands how the wireless network is designed, that is a different problem. I cover wireless coverage, access point placement, building materials, device density, IoT segmentation and managed wireless environments in Managed WiFi for Small Business: What to Check When Your Business WiFi Is Slow or Unreliable.


Do Business Printers and Copiers Store Data?

Some do, and this is another area that is very easy for a business to overlook.

Printers and copiers are usually thought of as office equipment rather than computers, but some multifunction printers and digital copiers contain internal storage. The Federal Trade Commission specifically advises businesses to consider the information stored on digital copier hard drives because those systems can process documents that are copied, printed, scanned, faxed or emailed.


That means I would not automatically send an old multifunction printer or copier out the door without first identifying the model, determining whether it contains internal storage and reviewing the manufacturer's appropriate process for dealing with that storage.

This becomes especially important with leased equipment. A copier may not be going to an electronics recycler. It may simply be going back to the leasing company and eventually to someone else. The FTC recommends considering data security when equipment is returned or disposed of, including whether the copier's hard drive can be overwritten or removed and destroyed.


For businesses handling medical information, financial records, legal documents, CUI or other sensitive information, that forgotten storage inside the copier deserves the same kind of consideration as other data bearing equipment.


Is Deleting or Factory Resetting a Device the Same as Securely Wiping It?

No, and this distinction matters.

Deleting, formatting, factory resetting and sanitizing are often discussed as though they mean the same thing. They do not. What each action accomplishes depends on the equipment, storage media and method being used.

Action

What it generally means

Delete

Removes normal access to files but should not automatically be treated as sanitization

Format

Reinitializes a file system or storage structure depending on the process being used

Factory reset

Returns supported device settings to a manufacturer defined state

Sanitization

Uses an appropriate process intended to make access to target data infeasible for a given level of effort

Physical destruction

Physically destroys media when destruction is the selected appropriate disposition method

This is why I do not tell a business owner that clicking “delete everything” automatically means a device is ready to leave the company.


NIST released SP 800-88 Revision 2, Guidelines for Media Sanitization, in September 2025. The current guidance focuses on establishing a media sanitization program and choosing appropriate techniques and controls based on factors including the sensitivity of the information. NIST defines media sanitization around making access to the target data infeasible for a given level of effort rather than simply assuming that deleting a file means the information is gone.


For a small business owner, the practical takeaway is straightforward. There is not one universal wiping procedure that should blindly be used for every hard drive, SSD, server, storage array or other type of electronic media. The appropriate process depends on the media, information involved and requirements that apply to the organization.


Do Regulated Businesses Have Different Requirements for Old IT Equipment?

They can, which is why I do not want a business with regulated or contractually protected information using a generic equipment disposal checklist without first considering what requirements apply to it.


HIPAA is one example. The HIPAA Security Rule requires covered entities to implement policies and procedures addressing the final disposition of electronic protected health information and the hardware or electronic media on which it is stored. It also requires procedures addressing removal of ePHI from electronic media before the media is made available for reuse. HHS reviewed its guidance on this subject again in August 2026 and continues to point organizations toward appropriate processes for reuse or disposal.


Government contractors handling Controlled Unclassified Information have another set of considerations. NIST SP 800-171 Revision 3 includes the requirement to sanitize system media containing CUI before disposal, release out of organizational control or release for reuse. Importantly, NIST's discussion specifically includes digital media in scanners, copiers, printers, notebook computers, mobile devices, workstations and network components. That is a much broader list than simply “wipe the hard drive in the computer.”


Other businesses may have regulatory, contractual, cyber insurance or internal policy requirements that affect how equipment and media are handled. Those requirements need to be determined for the particular organization rather than assuming every small business follows the same process.


My role at SNL-Tech Services is on the technical side of that work. I can help identify equipment, implement technical controls, perform technical work and document what was done. When a compliance consultant, assessor, legal counsel or another specialist is responsible for determining an organization's regulatory obligations, I work within those requirements rather than treating my preferred technical approach as the regulation itself.


Should a Business Get Proof That a Hard Drive or Device Was Destroyed?

Sometimes, and this is something I would determine before the equipment leaves the business.

Depending on the organization, the information involved and applicable requirements, a business may want or need records showing how media was sanitized, destroyed or otherwise disposed of. Some electronics recyclers or destruction services can provide a certificate of destruction or other disposition documentation.


I would not tell every small business that a certificate of destruction is automatically a legal requirement because that is not universally true. The business needs to determine what documentation its regulations, contracts, internal policies or other requirements call for.

Even when a formal certificate is not required, there is value in maintaining an accurate equipment disposition record. If someone asks six months later what happened to an old server, laptop or hard drive, “I think we recycled it” is not nearly as useful as being able to look at the asset record and see what happened.

A simple retirement record might include:

  • Device or asset identification

  • Serial number where appropriate

  • Date it was removed from service

  • Whether it contained business data

  • Sanitization or destruction method where applicable

  • Who performed or verified the work

  • Final disposition of the equipment

  • Supporting certificate or documentation if applicable

  • Date the asset inventory was updated

How much documentation is appropriate depends on the business and its requirements, but the important part is having a defined process rather than letting equipment disappear from the organization without anyone knowing what happened to it.


How Should a Small Business Dispose of Old IT Equipment?

Only after we know the device is truly no longer needed, preserve anything the business still requires, address the data or configuration appropriately and determine any documentation requirements do we reach the physical disposal stage.


Depending on the equipment and situation, the final destination may be electronics recycling, destruction, return to a leasing company, resale, donation, repurposing or transfer to an employee. Computers, servers, network equipment, UPS batteries and other electronics should be handled through appropriate recycling or disposal channels rather than simply being treated as ordinary office trash.


I also want to know what happens to the equipment after it leaves. If a third party is handling data bearing media, the business should understand the service being provided and determine whether the provider and documentation are appropriate for its needs.

Then there is one final step that is easy to forget.

Update the records.

If the device has left the business, remove or retire it appropriately in the inventory. If the network changed, update the network diagram. If a new firewall, switch, server or wireless access point replaced the old one, document the replacement. If a UPS was replaced, update that information as well.


The process should end with the documentation matching the environment that is actually left behind.


Before IT Equipment Leaves Your Business, Ask These Questions

If you are looking at a pile of old equipment and wondering where to begin, these are the questions I would want answered before anything leaves the organization:

  • Do we know exactly what this device is?

  • Are we certain it is no longer being used?

  • Is it still connected to anything?

  • Does it contain company data?

  • Does it contain network configuration, certificates or credentials?

  • Is there anything we need to preserve before resetting or sanitizing it?

  • Have required files, databases, virtual machines or applications been migrated?

  • Do we have the backups we still need?

  • Are there record retention requirements we need to consider?

  • What type of storage or media does the device contain?

  • What sanitization method is appropriate for the device and information?

  • Does our industry, contract or internal policy impose additional requirements?

  • Do we need documentation showing sanitization or destruction?

  • Where is the equipment going after it leaves?

  • Has our equipment inventory been updated?

  • Does our network diagram need to change?

If you cannot answer several of those questions, I would stop before sending the equipment anywhere and figure those things out first.


When a Network Closet Cleanup Turns Into a Bigger IT Conversation

Cleaning up a network closet sometimes uncovers things nobody expected. You might find a server nobody realized was still running, a UPS battery that has not been checked in years, an old firewall nobody knows how to access, several retired computers containing company data or network equipment that was installed years ago and never documented. You might also discover that the network diagram bears very little resemblance to the network that is actually running the business today.


At that point, I start looking beyond the cleanup itself. If the business does not have an accurate picture of its technology environment, my Business IT Solutions include assessment and documentation work that can help establish what is there, how the environment fits together and what needs attention.


If the bigger issue is aging equipment and deciding whether something should actually be repaired, upgraded, repurposed or replaced, I cover that separately in When Should a Small Business Replace Its Computers? A Practical IT Hardware Lifecycle Guide.

If the network closet reveals a collection of WiFi routers, extenders and access points that have been added over time, the business may have a wireless design problem rather than an equipment cleanup problem. My Managed WiFi for Small Business guide explains why WiFi is not one size fits all and how coverage, device density, interference, building materials, IoT devices, segmentation and wireless management affect the design.

The important part is recognizing when a physical cleanup has uncovered a larger technology problem that needs to be addressed rather than simply making the room look nicer.


What Does Small Business IT Maintenance Really Include?

I like organized network closets. I like labeled equipment. I like being able to look at a rack and understand what I am working with. I also want the documentation and network diagrams to match what I am looking at. If a firewall was replaced, a server was retired or the network design changed, that information should not live only in someone's memory.

But this is not really about my obsession with labels or making cables look nice. It is about maintaining the physical technology a business depends on throughout its lifecycle and understanding that the responsibility for that equipment does not end when someone unplugs it.


Your server room should not contain equipment nobody understands. A UPS should not sit there for years without anyone checking its battery. Old servers should not collect dust with years of company information still sitting on their drives. Retired firewalls and WiFi routers should not leave the business with network configuration intact. An old copier should not be returned without anyone considering whether it contains internal storage. And a laptop should not become someone's personal computer until the company's information has been appropriately removed.


Technology eventually leaves every business. The important part is making sure the business understands what it has while it is in use, maintains it, documents the changes that happen along the way, and makes sure the business's data does not accidentally leave with the equipment when it is retired.


If you look around your network closet, server room or storage area and realize nobody is completely sure what is still being used, what needs maintenance, whether the documentation is current or what can safely leave the business, that is something I can help you sort out.


Frequently Asked Questions

How often should a small business review its IT equipment?

There is not one review schedule that fits every business. The frequency depends on the environment, equipment and business needs. At minimum, IT equipment should not be allowed to sit for years without anyone reviewing its condition, support status, documentation and role in the environment. Significant technology changes should also trigger an inventory and documentation review rather than waiting for a scheduled annual cleanup.


What should be included in small business IT documentation?

Useful documentation can include hardware inventory, serial numbers, equipment locations, device names, assigned users, warranty information, internet and network information, firewalls, switches, wireless access points, servers, storage systems, UPS units and network diagrams. What needs to be documented depends on the environment, and sensitive administrative information should be stored securely.


Should I update my network diagram when equipment is replaced?

Yes. If a firewall, switch, server, wireless access point, internet connection or other significant network component changes, the network documentation should be reviewed and updated as appropriate. A network diagram is most useful when it reflects the environment that actually exists.


Can I give an old company laptop or desktop to an employee?

A business can choose to transfer equipment to an employee, but company information should be appropriately removed before ownership changes. The appropriate process depends on the device, storage technology, information involved and requirements that apply to the business.


Does an old WiFi router still have my WiFi password on it?

It can. Depending on the router, its saved configuration can include the SSID, WiFi password, administrator settings and other network information. Before a router leaves the business, follow the manufacturer's appropriate process for resetting it. Do not reset a router that may still be in service until you have identified its purpose and preserved anything you still need.


Is a factory reset enough before selling a business computer?

Do not assume a generic factory reset is the appropriate sanitization method for every computer or every type of business information. The device, storage media, sensitivity of the information and applicable requirements should determine the process.


Do office printers and copiers store data?

Some multifunction printers and digital copiers contain internal storage used while processing documents. The FTC specifically advises businesses to consider data stored on copier hard drives and what happens to that data when equipment is returned or disposed of.


Should an old server be wiped before recycling it?

Information on an old server should be appropriately addressed before its storage media leaves organizational control. Before sanitization, make sure required data has been migrated, necessary backups exist, application dependencies have been addressed and applicable retention requirements have been considered.


Can an old firewall contain sensitive business information?

Depending on the device and configuration, a firewall can retain network and management information such as addressing, firewall rules, VPN configuration, certificates or credentials. The appropriate manufacturer or organizational procedure should be followed before the equipment leaves the business, and information the organization still needs should be preserved first.


Do UPS batteries eventually need to be replaced?

Yes. UPS batteries are consumable components. Their useful life depends on battery technology, temperature, load, discharge history, operating environment and manufacturer guidance. Battery health, warnings, self tests and expected runtime should be reviewed rather than assuming the UPS will continue protecting equipment indefinitely.


Do regulated businesses have additional requirements for disposing of old technology?

They can. The applicable requirements depend on the organization and the information involved. HIPAA includes requirements concerning the disposition and reuse of electronic media containing ePHI. NIST SP 800-171 Rev. 3 includes a media sanitization requirement for CUI prior to disposal, release out of organizational control or reuse. Other regulatory, contractual or organizational requirements may also apply.


Additional Resources


Related SNL-Tech Services Articles and Resources

Comments


bottom of page