When the Heat is On: the Information Security Risks Nobody Briefs Their Team About
I was visiting a client a few summers ago when I noticed the server room door was propped open with a fire extinguisher. A desk fan had been placed just inside the doorway to push cooler air in. It was ingenious, in a way. It was also a fairly significant security incident waiting to happen.
That client isn’t unusual. When temperatures climb, people make practical decisions in the moment — and information security tends to lose out to basic human comfort every time.
So here’s a round-up of the risks that actually happen in hot weather, none of which involve phishing emails or password policies.
The propped door problem
Access control is one of the cornerstones of physical security. You invest in key fobs, pin pads, or swipe cards — and then someone wedges a door open because it’s stuffy and nobody’s thought through the implications. Fire doors, entrance doors, and yes, server room doors all get the same treatment. One door held open can defeat an entire access control system.
This isn’t about blaming staff. It’s about recognising that your policies need to account for what people actually do when it’s 28°C in the office.
Windows and what they reveal
Open windows are a gift to anyone with an interest in what’s on your screens or your desks. Ground floor windows are the obvious concern — a screen visible from outside, a document left on a desk, a phone call conducted at a window. But it’s worth thinking about sightlines from neighbouring buildings too, particularly in city offices. Shoulder surfing doesn’t require someone to be physically in the room.
Nobody challenges the tailgater in a heatwave
Tailgating — following someone through a secure door without using your own credentials — is much easier when doors are slow to close, propped, or when people are moving around more than usual. And in hot weather, challenging someone feels socially awkward in a way that it somehow doesn’t in January. “Excuse me, can I see your pass?” is a harder conversation when you’re both overheated and distracted.
The roaming worker
Summer brings a particular kind of hybrid working behaviour: people migrate to wherever it’s coolest. That might be a café, a garden office, a co-working space, or the kitchen at home with the back door open. Each of those environments carries its own set of risks around screen visibility, overheard conversations, and unsecured connections. A privacy screen and a bit of situational awareness go a long way — but only if your team knows to think about it.

Heat and the human brain
This one’s worth taking seriously. Cognitive performance is genuinely affected by heat. Concentration dips, decision-making slows, and people skip steps they’d normally follow automatically. In information security terms, that means more clicks on things that shouldn’t be clicked, more oversights, and less willingness to stop and query something that feels slightly off. It’s not about intelligence — it’s basic physiology.
Server rooms and the cooling question
If you still have on-premise infrastructure, summer is the time to check your cooling arrangements. Overheating kit is a real risk, and as the server room example above shows, the instinctive fix — “let some air in” — creates an entirely different problem. Cloud services have reduced this risk for many organisations, but they haven’t eliminated it entirely, particularly for those with hybrid infrastructure or local networking equipment. Cooling also costs more when it’s hot, which can tempt facilities teams to turn it down — worth a conversation before the next heatwave hits.
What actually helps
A short briefing. Literally five minutes in a team meeting, or a quick message to staff, is enough to put these risks on people’s radar. Remind them what a propped door looks like from a security perspective. Remind them that working from a café terrace with a client document open on screen is not the same as being in the office. And if you have server room access, make sure the cooling is reviewed before temperatures peak rather than after something fails.
Summer is a good time to remember that most security incidents don’t start with sophisticated attacks. They start with a fan, a fire extinguisher, and the best of intentions.
f you’d like to build physical security awareness into your team’s training, our Introduction of Information Security covers exactly this kind of everyday risk — and a lot more besides.





