Clean Desk, Locked Screen: Physical Security on the BPO Floor

Most security advice is about what happens on the network. This one is about what happens in the room.

An open-plan floor with forty-one desks, shift changes, visitors and cleaners has a particular set of risks, and none of them involve hacking anything. They involve someone walking past a screen, picking up a note, or following a colleague through a door.

Lock your screen. Every time.

Windows key + L. Two seconds, and it’s the single most important habit in this article.

Every time you leave your desk — a break, the bathroom, a quick word with your team leader, fetching a printout. Not just at the end of your shift.

Two reasons it matters more than it feels like it should. First, an unlocked screen with a customer record open is a disclosure to everyone who walks past. Second, anything done under your login is attributed to you. If someone sits down at your unlocked machine and looks up a record they shouldn’t, the audit log has your name on it, and you’ll have no way to show otherwise.

Screens do lock automatically after a period of inactivity, but that period is long enough for real damage. Don’t rely on it.

Clear desk, clear screen

At the end of every shift, your desk should have nothing on it but the equipment. No notes, no printouts, no scraps of paper with account numbers or reference codes.

During your shift, don’t write customer details on paper at all. Not on a sticky note, not in a personal notebook, not on the back of a printout. If you need to hold a number for thirty seconds, hold it in the record, not on paper.

Anything written down sits outside every system we have. It isn’t backed up, isn’t access-controlled, isn’t covered by retention, and can’t be deleted when a customer asks. A note that falls behind a desk is a breach nobody discovers for six months.

Never write down a password. Not on paper, not in a phone note, not in a file called anything. Bitwarden exists precisely so you don’t have to.

If something does need printing, collect it from the printer immediately and shred it when you’re done. Documents left in the tray are the second most common physical finding after unlocked screens.

Phones and cameras

No photographs of screens. Ever, for any reason, including “so I can remember the reference.” A photo of a customer record on a personal phone is customer data on an unmanaged device outside the country’s retention rules and outside our control.

This applies to screenshots too, and to screen recordings.

If you need information from a screen, it’s already in the system — go back to it.

Doors, badges and strangers

Don’t hold the door. It feels rude, and it’s the point. Following someone through a controlled door is the standard way people get into buildings they don’t belong in, and it works because everyone is too polite to stop it. Let the door close. Let the person behind you badge in.

Don’t lend your badge. Same reasoning as your login — access is recorded against you.

Challenge or report. If you see someone on the floor you don’t recognise and who isn’t obviously escorted, don’t confront them yourself if you’d rather not. Tell your team leader or reception. Most of the time it’s a legitimate visitor whose escort stepped away, and nobody minds being asked.

Visitors, contractors and vendors should be escorted at all times. That includes people who say they’re from IT — we don’t send unannounced strangers to your desk.

Shoulder surfing

On an open floor, someone standing behind you can read your screen. That includes visitors, contractors and cleaners as well as colleagues.

Be aware of who’s behind you when a record is open. If someone is standing over your shoulder while you type a password, stop and ask them to step back. That’s a reasonable thing to do and nobody will think worse of you for it.

Equipment

Don’t move equipment between desks. Assets are tracked to desks, and an unrecorded swap breaks the asset register and complicates every future fault.

Don’t plug in personal devices. No USB drives, no personal phones charging from the workstation, no personal peripherals. USB ports are a route in.

Report damaged equipment the day you notice it. A cracked casing or a frayed cable is a fault today and a hazard next month.

Why this is getting more attention

Physical controls are an explicit part of what a regulator looks at, and they’re the easiest thing to inspect — an assessor doesn’t need system access to walk a floor and count unlocked screens and papers on desks.

They’re also the easiest thing to get right. Nothing in this article costs money or takes training. It’s all habit.

The three that matter most

Lock your screen when you stand up. Nothing written on paper. Let the door close behind you.

Read next: Reporting a Security Incident, and Handling Client Data.

Watch: Clean desk policy awareness — short and light-hearted. Then tailgating for the door-holding problem.

Leave a Comment

Your email address will not be published. Required fields are marked *

Supportscreen tag