Office moves / Working continuity
Moving office? Give temporary working an end date

Before the desks leave, decide how people will work while the office is unavailable. Specify the tasks that can continue, the approved devices and services they will use, and the person who can stop or extend the arrangement. Just as importantly, decide how temporary working ends. A furniture delivery can be complete while business files are still scattered across the workarounds created during the move.
This is a different question from whether the van, loading bay and service lift are booked. The removal schedule moves possessions between addresses. The temporary-working plan governs what happens to work while those possessions, connections and rooms are unavailable. Confusing the two can leave staff with a simple instruction to carry on but no agreed way to do so.
The National Cyber Security Centre's Shadow IT guidance, reviewed on 14 August 2026, is a useful starting point. It describes unknown or unmanaged technology used for organisational work, including personal cloud accounts and unauthorised AI services. It also makes an important distinction: unofficial tools often appear because people cannot complete a task using the approved arrangement, not because they intend to cause harm.
An office relocation is a good moment to address that practical gap. This article applies the guidance to a move; it is not a new relocation rule or a claim that every move causes a security incident. Its focus is the short period between the old working arrangement ending and the new one being proven usable.
Begin with the work that cannot wait
Do not begin by promising that everyone can work normally from a laptop. Ask each team which actual activities must continue during the move window. Receiving an enquiry, preparing a document, approving a transaction and retrieving an archive box may all depend on different people, equipment or permissions.
Give each activity a clear outcome. For example, a team might need to acknowledge incoming messages without changing customer records, or review an existing document without issuing a final version. That is more useful than saying the entire department must remain operational. It also makes it easier to pause work that can wait instead of designing a rushed workaround for everything.
Then identify the point at which the normal route stops being available. A workstation can be packed before the end of the working day; access to the old building can end before the new office opens; the person who normally approves an exception may be supervising the physical move. Put those dependencies next to the activity, not in an unrelated packing list.
Keep the physical move brief in the business-ready office moving guide. The temporary-working plan should refer to its timing and responsibilities without duplicating its equipment inventory or confidential-container register.
Use three decisions, not one promise of normal service
For each essential activity, the business should choose one of three positions: continue through a confirmed approved route, pause until a stated condition is met, or ask the responsible person to decide. An unanswered question belongs in the third group. It should not silently become permission to improvise.
The following table is an editorial planning aid, not an official security standard. The business and its IT or information-governance advisers decide which controls suit the information and systems involved.
| Move-window situation | Decision to settle before the move | What ends the temporary arrangement |
|---|---|---|
| Staff need shared documents while desks are packed | Name the approved service, authorised users and permitted tasks; identify work that must wait | The normal working route has been tested and the team knows which version is authoritative |
| A needed paper file is scheduled for transport | Decide whether the task pauses or an authorised custodian keeps that file available through a separate controlled arrangement | The receiving custodian reconciles the file and the temporary access record is closed |
| Someone needs to approve work during loading | Nominate an available approver and an established contact route, without sharing their credentials | The usual approval arrangement is restored and any pending decisions are reconciled |
| A member of staff proposes a personal device or account | Refer the proposal to the business's responsible IT person; do not treat convenience as approval | An approved route is available, or the task remains paused |
| The destination connection or room is not ready | Decide which activities can continue elsewhere and which must stop; set the next decision point | The specified readiness check passes, rather than the furniture merely arriving |
| A temporary copy or access permission was authorised | Record its purpose, owner, permitted use and review point within the business's controlled system | Required work is reconciled and the authorised owner closes access or handles copies under the applicable retention policy |
The final column matters as much as the first. An arrangement described as temporary can survive for weeks if nobody owns its closure. Avoid automatic deletion instructions: some records may need to be retained, and the person coordinating a move may not be authorised to decide what should be erased.
Test a representative task before packing the equipment
A successful sign-in does not prove that a team can do its work. Ask the relevant business owner and IT provider to test a representative, non-customer-impacting task using the approved temporary setup. They should establish that the necessary document can be reached, the permitted action works and any required approval can be obtained.
Use dummy or appropriately authorised test material. Do not create a real payment, send a customer message or alter a live record merely to prove that the setup works. If a meaningful test needs specialist supervision, schedule it before the move rather than asking the removal crew to judge whether a system is ready.
Also check how staff will receive instructions if their usual communication tool is unavailable. The fallback contact route should be established in advance. A late message from an unfamiliar account asking people to upload business files elsewhere should not become trustworthy simply because the office is in transit.
Record what was tested and what was not. A working document service says nothing by itself about telephony, printing, an accounts application or a building access credential. Describe the result narrowly enough that the next person can rely on it without assuming more than was checked.
Cloud access and a backup solve different problems
Being able to open a file online helps someone work. It does not, by itself, prove that the business can recover from loss or an incorrect change. The NCSC's guidance on backing up critical cloud data says organisations should check both backup coverage and restoration. It cautions against relying solely on a service's previous-version or deleted-file features, and recommends an independent copy in another safe place or service.
Your authorised IT team should decide the backup and recovery approach. For the move coordinator, the useful question is whether that team has confirmed readiness for the planned interruption and knows who will make a recovery decision. The answer belongs in the business's controlled records, not on a crate label or a public move schedule.
Do not ask staff to email themselves a bundle of files as an informal backup. If they cannot perform an essential task through the approved setup, take that limitation back to the named decision-maker. A deliberate pause is easier to account for than an unknown collection of working copies.
Keep the removal instructions free of sensitive content
The crew needs the agreed item list, access arrangements, destination labels and authorised handover contacts. It does not need passwords, recovery codes, customer files or a copy of the business's internal network configuration. Separate those records before sending the logistics brief.
The ICO's records movement guidance calls for physical records to be tracked and secured in transit and off-site. Its page is under review following the Data (Use and Access) Act, so organisations should check the current guidance and their own requirements. A general-purpose moving label is not a substitute for the controls chosen by the responsible business.
Use the existing office removals plan for the transport scope and responsibility split. Men With Van transports released, labelled equipment within the agreed removal scope; it does not access business systems, perform IT disconnection or reconnection, or certify cybersecurity. Specialist systems and sensitive handling requirements need separate assessment before any booking is treated as covering them.
A worked example: the office is delivered, but not ready
Consider a hypothetical small consultancy moving on Friday, with staff expected at the new office on Monday. Its desks and packed equipment can be delivered on schedule, but the destination's planned working connection has not yet passed the business's readiness test. This is an invented planning example, not a Men With Van customer story or a claim about installation lead times.
Without a separate working plan, Monday can become a series of individual decisions. One person proposes using a personal file-sharing account; another wants to retrieve an archive crate; a third assumes that an old laptop left behind is available for anyone to use. None of those decisions is settled by the successful furniture delivery.
Before Friday, the office manager instead identifies two tasks that genuinely must continue: acknowledging incoming correspondence and preparing internal draft work. The authorised IT provider confirms an existing approved route for those tasks and identifies the people who can use it. Other work waits until the normal setup is ready. No one is asked to choose a new service under pressure on move morning.
The plan also names a Monday decision-maker and a review time. If the connection is still unavailable, that person can extend the agreed limited arrangement or pause more work. An extension is recorded, not assumed. The team receives a clear update explaining what remains available and what is still on hold.
When normal working resumes, the business reconciles the drafts produced during the temporary period. The relevant owners identify the authoritative versions, close any approved temporary access that is no longer needed, and deal with copies according to policy. The office move is not used as permission to delete records indiscriminately.
The lesson is not that every business needs this particular arrangement. It is that the continuation decision, extension decision and closure decision need owners. The transport completion and working-readiness decisions are separate milestones.
Treat equipment retirement as a separate decision
A move may uncover old devices, leased equipment or something nobody recognises. Do not send an unknown device to the new office, return it to a supplier or put it into a disposal collection merely because the room must be emptied. The business needs to establish what it is, who owns it and who can authorise the next step.
NCSC's decommissioning guidance distinguishes asset retirement from a simple physical move. It addresses recovery planning, secure storage while assets await their next stage, appropriate tracking and evidence that delegated disposal work was completed. Apply the relevant specialist process rather than adding a casual disposal instruction to the removal brief.
For network equipment specifically, NCSC transport guidance emphasises traceability, an identified recipient and checking tamper-evident packaging. That is guidance for the responsible technical team, not a claim that an ordinary office removal automatically provides a specialist network-equipment service.
Routine recycling at the destination is another distinct arrangement. Our office recycling handover article covers that transition; it does not authorise data destruction or decide which devices may leave the business.
An exception is not simply an unpacking problem
If a file, device or container cannot be accounted for, use the agreed incident route promptly. Record the last confirmed location, the people involved in the handover and the time the issue was noticed. Share the information with the authorised business contact, without circulating sensitive contents widely or trying to investigate accounts without permission.
The ICO's small-organisation breach guide says reportable personal-data breaches must be notified without undue delay and within 72 hours of awareness. Not every incident meets that threshold. The business must assess the circumstances using the current guidance and appropriate advice; do not wait until unpacking is finished to escalate a concern. This page also carries an under-review notice.
Close the temporary office, not just the old address
The final review should answer three practical questions. Can the agreed work now be performed through the normal approved route? Has work produced during the interruption been reconciled? Has the responsible person closed or explicitly retained each temporary arrangement?
Keep unresolved items visible with an owner and next review point. A missing answer should not disappear because the keys have been returned or the team is sitting at its new desks. For the next move, those exceptions provide more useful planning evidence than a blanket description of the relocation as seamless.
Sources and method
Research checked on 29 September 2026. This is operational editorial analysis for UK office moves, not individual legal advice, a cybersecurity assessment or a compliance certificate. The decision table and consultancy example are original planning aids, not prescribed forms or observed customer outcomes.
The timely source is NCSC's Shadow IT guidance: published 27 July 2023 and reviewed 14 August 2026. Its review date is not presented as a new statutory requirement. Supporting NCSC sources are the cloud-backup guide, published and reviewed 11 January 2024; decommissioning guidance, published and reviewed 20 May 2025; and network-device guidance, published and reviewed 25 September 2016. Their age is stated rather than disguised as new advice.
The two linked ICO pages were checked on the research date; a publication or update date was not established from their displayed pages. Both flag review following the Data (Use and Access) Act. Follow their latest versions when assessing a real situation. No incident rate, downtime saving, legal outcome or security guarantee is inferred from these sources.