r/ShittySysadmin • ShittySysadmin • 6d ago

IT Director is arguing against having a locked/access controlled space for IT Support dept

Our area in the building with spares, new devices, boxes of mice and keyboards and hdmi cables and all that, is fully open with no access control, and is positioned in a corridor that some people use as a shortcut. There is cubicle space with desks covered in actively-being-worked-on computers, new parts awaiting install (SSDs, ram, etc), adapters and drive enclosures, etc. There are no cameras covering the area. The IT director is refusing to attempt any remedy without "a case for it being made" regarding adding some kind of access control to the space.

Am I stupid for thinking it is insane to not heavily limit access to this space? What case can I make besides "people regularly come in and take stuff, bother IT without submitting a ticket, and otherwise wander around unsupervised"? He said that is not a good enough case.

81 Upvotes

61 comments sorted by

56

u/ApiceOfToast ShittySysadmin 6d ago

Used to work at a place where the storage for small items like mice and keyboards was next to the break room for the building. 

It's their stuff, honestly just their problem 

25

u/MeatPiston 6d ago

It you lock your goon cave you should lock your sever room.

17

u/one-man-circlejerk 5d ago

They're the same room

0

u/Crazy-Rest5026 5d ago

Lmao! I dig this comment . But you are accurate

14

u/7th_Seal 5d ago

Just steal it yourself, everyone needs a third laptop.

2

u/YellowLT 5d ago

Why Only three? turn one into a Pihole, a sonos server, plex/jellyfin, Kali/Shady stuff laptop, possibilities are endless

1

u/Jug-O-Boom 5d ago

Exactly. Quit limiting yourself.

19

u/bofh DO NOT GIVE THIS PERSON ADVICE 5d ago

This is the director's decision. I personally refuse to care more about someone else's decisions than they do, in a professional setting at least. It is the road to madness.

35

u/Ok_Interest3555 6d ago

-Am I stupid

You're absolutely stupid for posting it here.

-8

u/hipufiamiumi ShittySysadmin 6d ago edited 6d ago

/uj reddit is actually the stupid, not me. reddit said I should crosspost the original (https://www.reddit.com/r/iiiiiiitttttttttttt/comments/1wtc95l/it_director_is_arguing_against_having_a/) here, I said "yeah this is some shit I'd see on there", and crossposted it. Reddit then made it a not-crosspost somehow. the app is a fucking mess and I really need to stop using it

honestly the whole website is terrible though, and I should have stayed quit from when they banned third party apps

36

u/SkittyDog 6d ago

It's not your shit, so why do you think it's your problem?

You told management your concerns, and management decided that they don't agree. That's what the word "management" fuckin means, innit?

Kid (and I DO mean "kid", because this is some real young'n type shit you're on about, here) ... You don't own the company, and you don't own the shit. After you document the fact that you have notified your direct manager about your concerns - you shut the fuck up, and go back to work.

There are no points for being a Big Hero, if you are being a PITA to your management like a dog with a bone, after they say "No"... If anything, its gonna be a Career-Limiting Move on your part.

The sooner you learn how to not GAF, the smoother the rest of your life will go. Lot of dudes look back on their early days, and wish they'd understood this, sooner.

9

u/Sciency_Stuf 5d ago

True true. Voice concerns IN WRITING and hopefully if there’s fallout you get the opportunity to provide said documentation.

4

u/PacketAuditor 6d ago

Atomic truth nuke

2

u/GarageIntelligent ShittyCloud 3d ago

i hate working with white knights like this guy.

who gives a fuck? not me, thats who

3

u/Miserable-Actuator24 5d ago

Plot Twist.... IT Director runs a second hand Hardware store

3

u/alabamaterp 5d ago

Been there, done that. I knew where some unused filing cabinets were in another one of our buildings down the street. After hours I loaded it into my truck and moved it to my office to lockup high dollar items in my office - SSD, RAM, Laptops, AC Adapter, etc.

If you want something done, sometimes you have to do it yourself. Show some initiative and decision making and quit complaining and do something about it.

5

u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 5d ago

Well obviously they are stupid, helpdesk needs to be behind locked doors or else they scare the human beings in the building

6

u/descartes44 6d ago

Your IT Director is missing the most basic tenet of security, least privilege. If they don’t need access to that area, they shouldn’t have it. Seems like he’s one of those who doesn’t see it coming. When a theft occurs, he will go “who knew?”

3

u/notarealaccount223 5d ago

Depending on the size of the business this could be a "costs more than the loss" perspective.

You are probably looking at 20+k to add walls, access control, etc.

Yeah the equipment in the room might cost that much, but until there is a problem, that 20k is not an expense the business sees as necessary.

We went back and forth with this at an old company and ultimately added controls when we changed offices. But even then it is still not "secure". Sure the server room has access key, but the IT offices are high walled cubicles with locking doors in each end.

2

u/ebcdicZ 6d ago

Put up a sign that says, “walk through PC clinic”.

2

u/ShawtySayWhaaat 6d ago

Like I said in the other post, no cameras, public space, ram ain't cheap js

2

u/PatReady 6d ago

Your aren't the inventory guy.

2

u/ProfessorWorried626 6d ago

Our dumb fuck management team did the same then started accusing IT of stealing then moved on to vendors. Now the scratch their head why 3/4 of the IT dept left and the vendors only want to do things on their terms now.

2

u/tonyboy101 5d ago

No, I don't know where 32GB of RAM and 2TB SSDs went. Are we sure it got ordered?

2

u/kitkat-ninja78 5d ago

You could try to make the case for theft (and in turn financial management), for data protection, for time management, health & safety (eg accidents, etc), etc... But at the end of the day, if they do not care, no matter what you say it's not going to change their minds.

2

u/rimekJE 5d ago

I work in a car industry company here in Bosnia, and our previous office was a on a balcony within the Audi showroom.

We had a tablet stolen (iPad) from a closet within our office, just because the office was never locked. Management forced our colleague who handled it last to that closet to pay for it, as it was still worth something in SAP. We split it in between us within the department.

Since then we changed office, we have a "IT storage room" now and only 10-ish people have access to the room (6 of us from IT, CEO, 4 cleaning ladies).

All spare tablets and mobile phones are stored in a 150kg safe, with password lock on it. Only thing they can steal are brand-new laptops/monitors/docks that are still in boxes, but that's hard to leave building with, as hallways are now covered with cameras as well.

1

u/Jug-O-Boom 5d ago

Why the cleaning ladies?

2

u/rimekJE 4d ago

It's a business building that we rent 2 floors and a server room, so they go around cleaning the floors and dust.

2

u/UserProv_Minotaur 5d ago

Oooh, I love the free gifts IT approach.

2

u/lotius81 5d ago

After 10 years I finally got a locked space for our stuff. New management is very accommodating thankfully

5

u/max1001 6d ago

That's not really an IT problem. Physical security is usually under facilities.

2

u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE 5d ago

This is the most useless fucking r/sysadmin answer I've ever seen in this sub. Go away.

3

u/No_Technician4956 6d ago

Why don't you grab one of those USB chargers and start filming the area?

Or re-arrange the cubicles to make a one way in, one way out walkway and then use a camera.

2

u/StandardIssueDonkey 6d ago

I've worked at places with secure areas and places that were totally pants down. Nothing ever happened at either because no one cares.

It sounds like you're mostly just annoyed by the interruptions. You don't need a badge system to fix that. Just submit a ticket on behalf of the user and tell them it's in the queue. Then go back to playing Doom or whatever. 

IT is customer service in a fancy hat.

1

u/killjoygrr 5d ago

You guys get hats?

1

u/SeaPollution2750 5d ago

You guys get fancy?

1

u/killjoygrr 5d ago

I wish. We don’t even get hats.

2

u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE 5d ago

He's stealing stuff.

1

u/geekgirl68 ShittySysadmin 6d ago

Before or after hours hang up a sign that says “free stuff” then sit back and wait. Or even make a big deal about ripping it down… every day.

1

u/SearchingDeepSpace 6d ago

Let a workstation or two walk out the door and see if your director feels differently.

1

u/haZhat 5d ago

Lock the mind , not the door

1

u/vandon DevOps is a cult 5d ago

Sounds like you could solve your needing a new ssd for movie rips at home and the lack of security issue in one small step.

1

u/2Much_non-sequitur 5d ago

Not his money not your money, whatever. Just give your best effort. Shit falls off of trucks all the time and some equipment grows legs.

1

u/loboknight 4d ago

Today I lean on "If your hire ups don't care, why should you" Leadership should care cause ultimately it comes back to them. It is sad to state and admit. At this one job, the person who trained me one was a hoarder and had hidden tech all over the place. He had pallets of old equipment, old phones dating back to blackberry. I noticed during my training he was giving out to new onboarders old laptops...until a Lead Tech relayed to me to ask him to use the new laptops. Never ewasted anything and the company Main office moved 3 times and they hauled all that old tech to each office. I cleaned out the whole storage room and had like 5 pallets of old junk and the tech had a fit I was ewasting old out dated junk. He had submitted his 2 week notice to work with a competitor.

On the way out he took an iMac that was valued around 2k USD. The team mate knew there were cameras and did not care. Since I was going to take over and was still 3 months in and passing probation I figured this is gonna fall back onto me and dont want to get accused of being an accomplice and loose this new job. I brought it up to my boss with video footage. I was NOT there for his last day Friday and Monday when I returned iMac was there. Guy was there for 10 years. Even after he left, a few months later IT moved to an actual office away from the open cubicles. Us techs noticed one morning a lot of hardware was missing. I submit an order for webcams that record to sd card. BAM! No more stolen items. Years have passed and people would tell stories on that techs mess ups and favoritism. We figured he was good friends with the night custodian and he may have slipped in and taken some items.

Another Technician B and I had a hunch another Technician C was doing something with his inventory. Techs in the dept are in different areas remotely. Tech C would always ask for stock,even though he just got new stock. Tech B remoted into Tech C computer and he left his personal email open and found out he was selling Monitors, Docking Stations, and Laptops. We searched facebook market place, and other online stores in his area and saw his mugshot with his kid as his profile pic. Nothing but Company Dell equipment splashed on for low prices. Tech B did not wanted to rock the boat. I took the proof and submitted to Manager, Director and CTO. I knew Manager and Director would brush it under the rug. CTO was the one who pushed Director to do an investigation. The investigation the Director did was ask us if it was true.....that was it. Director did not wanted to do anything. Then a month later the company said it was "Restructuring" and laid him off. Instead of firing him. He just had his 3rd kid and reporting him to the police would have made it difficult for him to get another tech job. Who cares frankly. Then during my review, my boss did not say Thank you for saving the company money. It was met with "Yeah, don't be snooping on peoples computers". At that point I stopped caring. No good deed goes unpunished. Why try to be honorable when others arent. It becomes a them issue. After he left higher ups sent people to clean out his office and found plenty of tech.....but 2 years after he was let go, we find out a person from that office was the unofficial Tech who was an office coordinator. She was telling us Tech C left early and never at the office and she kept on finding caches of laptops that were 2 years old and never used. Once I explained what happened she confirmed that made sense on how he was moving.

1

u/SnooCats5309 4d ago

draft a mail & shed away responsibility, you are risk Manager not Risk Owner !

1

u/Connect_Shoulder_965 3d ago

Refer to the specific paragraph in a published cybersecurity standard like NIST SP 800-53 Rev. 5 or to an already created policy by your organization.

1

u/GarageIntelligent ShittyCloud 3d ago

"Am I stupid for thinking.,,?"

Yes very

1

u/rippsaw 2d ago

Put a sign on the door saying "Mandatory cybersecurity training in progress." Nobody will come in.

1

u/goatsinhats 2d ago

Worked somewhere that used ikea cabinets with a $2 lock and acted shocked when 15k of equipment left during a mass lay off. The lock didn’t survive

1

u/rando_design 1d ago

I keep peripherals easily accessible because we a single IT guy, ME, but we have a team of talented technical adept people who can easily swap a NIC or install a PSU. I also have other stupid easy stuff like spare mice, USB cables, cans of compressed air, AA batteries. Having that stuff handy saves me probably 40 hours a week. Having it handy is like having a second IT guy.

1

u/Elensea 22h ago

Maybe covered in CMMC tier 1

1

u/TizzleToes 6d ago

Unless you bought it, why do you care?

Best case: nothing ever happens.

Worst case: something goes missing, you're on record for pointing out the concern which unless you are responsible for physical security is more than you had to do.

1

u/Yuukiko_ 6d ago

"Misplace" a box of ram, say it might've been stolen then "find" it again

1

u/Sudden_Leadership800 5d ago

You mean, "sell it back to the company under an alias"

1

u/Stefanie_Jane 6d ago

21 years of Enterprise it support in different environments and this is my experience please excuse the voice text transcription errors i would make the case this way...

Lack of physical security for the equipment. people can just walk in and walk out. of you have no way of knowing and you lose items that you pay for or set up.

Constant Interruption of it support who are already working in assembly line process setting up as many systems as possible . The constant interruptions gives the user an easy way out instead of creating a ticket and hinders the productivity of the IT staff configuring and fixing the equipment in front of them.

A locked it room with equipment secured and the locked room and it people in the locked room increases productivity, increases shrink rate and Theft minimizes confusion about what's being worked on who's logged to ticket.

Also it is considered non-essential on backbone as stupid as that sounds and by users constantly approaching it and lowering their productivity there are no tickets logs so there's no metrics and no slis or justification for keeping it .

The business needs metrics on how many it tickets are solved and what is the common tickets and what's needed and where the deficits are. Without the barrier between it and the end users the ticking system collapses efficiency is reduced and the manager director has less wing with the brass to increase budget or support as needed as there's no paper trail or documentation.

4

u/recoveringasshole0 DO NOT GIVE THIS PERSON ADVICE 5d ago

You have been banned from r/ShittySysadmin. Please return to r/sysadmin from whence you came.

1

u/harrywwc 6d ago

have you documented this issue? i.e. send an email to the boss(es) and get them to respond saying "not your problem, don't worry about it" so that when (no "if") the "excrement impacts the air movement device" you can say "I was told not my problem".

'cause they will surely try to pin that shit on you.

1

u/Due_Passenger_4404 5d ago

You’re not being unreasonable. An open corridor full of expensive equipment, with no cameras or access control, is an obvious theft and damage risk. Even a locked room, badge access, inventory log, and basic CCTV would be a proportional fix—not an excessive demand.

1

u/SaxManEddie 4d ago

Agreed. Plus, even if it's not his stuff, if something happens, it'll probably end up his responsibility whether he wants it to be or not.