Skip to main content
Dig IT Solutions logo

Guides & Checklists

Opening a second office: how your IT requirements change and what to plan first

IT decisions to make before a second office opens: connectivity lead times, linking sites, cloud as the shared layer, one identity and one phone system.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Opening a second office turns IT into a connected-business problem. Order connectivity first because lead times run to weeks or months, link the sites with a site-to-site VPN, put shared files and email in Microsoft 365 rather than one office's server, manage users from one identity system, run one cloud phone system and standardise hardware so support stays simple.

A second office usually means demand has outgrown the first building. Property, staffing and fit-out get careful attention. IT gets a budget line for computers and broadband, and the assumption that what works in one office will work in two. It will not, and the gap shows up on opening day. This guide covers what changes and the order to tackle it in, drawn from Dig IT's work with multi-site clients such as Mr Plant Hire, a plant and tool hire business with multiple depots we have supported for over 15 years.

Start with connectivity, because it takes longest

Every other decision depends on the new office having reliable internet, and connectivity has the longest lead time of anything on the list.

  • Check availability before you sign the lease. Openreach full fibre (FTTP) has reached many but not all business premises in Hertfordshire and London. Industrial estates and older commercial buildings are often the last to be covered. Use the Openreach availability checker for the exact address.
  • Allow realistic lead times. Where FTTP already serves the building, installation is typically a few weeks. Where you need a leased line, allow two to three months as a typical range, and longer if excess construction charges apply because new duct or fibre has to be laid. SoGEA (fibre to the cabinet without a phone line) is usually quick but tops out at around 80Mbps.
  • Decide between leased line and business broadband based on how the office works. A leased line gives symmetrical, uncontended bandwidth and a fix-time service level, which matters if the office will run VoIP and video all day or host anything the other site depends on. FTTP is far cheaper and adequate for many small offices. The leased line versus business broadband comparison covers the trade-offs.
  • Plan failover. With two sites depending on each other, an outage at one affects both. A 4G/5G or second FTTP connection on automatic failover is inexpensive relative to a day of downtime.

Linking the two sites

Once each office has a connection, they need to behave as one network. The standard approach is a site-to-site VPN between a business-grade firewall at each location, so that printers, any remaining servers, CCTV and management tools at one site are reachable from the other. For Mr Plant Hire, site-to-site VPNs between depots, fibre cabling within the buildings and teleworker gateways for staff at home give every location the same access to the company's Windows servers and SharePoint.

For three or more sites, or where you want one console for everything, cloud-managed platforms such as Cisco Meraki or Ubiquiti UniFi make VPNs, VLANs and Wi-Fi configuration consistent across locations and visible from anywhere. Dig IT's multi-site connectivity service covers the design.

Retire the consumer router at the original office at the same time. It will not support the VPN or the segmentation you now need.

Cloud becomes the shared layer

The single biggest simplifier for a two-office business is moving shared data and applications out of one building. When files, email and core applications live in Microsoft 365 or a cloud host, both offices get identical access and performance, nothing needs to be synchronised between servers, and a third office or a home worker is just another user.

In practice this means email and files in Microsoft 365, with SharePoint libraries planned around teams rather than copied wholesale from the old file server (see SharePoint and Teams setup), line-of-business applications cloud-hosted or reached over the VPN with the performance implications understood, and backup that covers both sites and the cloud. Microsoft 365 retention is not a backup: Dig IT typically pairs a local Synology backup with cloud backup so recovery does not depend on one building.

Cloud does not remove the need for a good local network. It increases it, because every task now crosses the internet connection.

One identity system, managed centrally

Two offices means more accounts, more starters and leavers, and more scope for the wrong person to keep access. Manage users from one place: Microsoft Entra ID for sign-in, with MFA enforced everywhere, role-based permissions, and conditional access that requires a company-managed device for anything sensitive.

Onboarding and offboarding need to be a process rather than an email to whoever is around. Dig IT's client portal provides new-starter and leaver forms for exactly this, and the IT onboarding checklist sets out what to have ready.

Security applied consistently at both sites

Growth periods are when security slips: equipment is installed in a hurry, new staff join without training and temporary workarounds become permanent. The controls do not change with a second office, but they must be applied identically:

  • a business firewall at each site, managed from one console, with the same rule set
  • EDR and RMM patching on every device regardless of location
  • MFA on every account, including the firewalls and the VPN
  • guest and visitor Wi-Fi on a separate VLAN at both sites
  • physical security for the comms cabinet: locked, and not in a shared corridor

Personal data will now move between sites, so check the ICO's guidance for organisations at ico.org.uk. Access control, laptop encryption and staff training cover most of the practical obligations.

Standardise hardware and processes

Buying whatever is cheapest that month, office by office, produces an estate of mixed laptops, printers and access points that costs more to support than it saved. Standardise on one laptop family (HP or Dell business ranges are Dig IT's usual choice), one printer platform, one Wi-Fi and switching platform, and keep a spare of each so a failure is a swap rather than a wait.

Standardise processes too: where documents are saved, how software is requested, how security issues are reported. Two offices with two ways of doing things is the start of the sprawl described in why growing businesses need structure, not more software.

One phone system across the business

Separate phone systems per office cause missed calls, awkward transfers and two sets of reporting. A cloud VoIP platform such as 8x8 puts both sites under one main number, with shared queues, transfers between offices, voicemail to email and extensions that follow staff to either office or home. With the PSTN switch-off due in January 2027, there is no reason to install anything else at a new site. See VoIP and business phone systems.

Support that does not depend on driving between sites

When every fault needs an engineer to travel, small problems cause long waits. Remote monitoring and management resolves most issues without a visit, and on-site time is reserved for hardware and cabling. This is the model Dig IT uses for multi-site businesses, and it is what makes a second office supportable at a sensible cost.

Continuity: two sites are not automatically resilient

Two offices only add resilience if they are designed to. If both depend on one server, one internet line or one admin account, a single failure still stops everything. Before opening, write down how each site would work if the other was inaccessible, how quickly you could restore after ransomware, and who holds the passwords and documentation, as part of your business continuity plan.

A working timeline

WhenAction
Before signing the leaseCheck FTTP and leased line availability, cabling condition and comms room location
10 to 12 weeks outOrder connectivity, agree the network design, order firewalls, switches and access points
6 to 8 weeks outStructured cabling and Wi-Fi survey, plan SharePoint and identity changes, order laptops and phones
3 to 4 weeks outConfigure and test the site-to-site VPN and phone system from the existing office, set up user accounts
1 week outInstall and test network, Wi-Fi, printers and desk equipment, brief staff
Opening weekEngineer on hand, then handover to normal remote support

What to do next

If a second office is on the cards in the next six months, the connectivity check and network design are the two things to start now. Dig IT plans and installs new office IT across Hertfordshire, west Essex and London and supports it afterwards as one accountable team. Talk to an engineer about the site you are considering.

Frequently asked questions

How early should we involve IT before opening a second office?
As soon as you have a shortlist of premises. Connectivity is the long pole: an Openreach FTTP install is typically a few weeks where fibre already reaches the building, while a leased line commonly takes two to three months and longer if new ducting is needed. Checking availability before signing the lease avoids opening an office that has no usable internet for its first quarter.
Do we need a server in the second office?
Usually not. Email, files and most line-of-business applications can run from Microsoft 365 or a cloud host, which gives both offices identical access without a server to buy, back up and secure at each site. A local server is still justified where a legacy application demands it or where large files are edited constantly on site, in which case the second office connects to it over a site-to-site VPN.
How do we connect two offices together?
The standard approach is a site-to-site VPN between the business firewalls at each location, which makes printers, servers and cameras at one site reachable from the other. Where several sites and cloud services are involved, SD-WAN or a cloud-managed platform such as Cisco Meraki or UniFi simplifies management. A leased line at each end gives the most predictable performance for the link.
Can both offices share one phone system?
Yes, and they should. A cloud VoIP system such as 8x8 lets both sites sit under one main number with shared call queues, transfers between offices, voicemail to email and consistent reporting. Staff keep their extension whether they are at either office or at home. The PSTN switch-off in January 2027 makes cloud telephony the default choice for a new site anyway.
Does a second office increase our cyber security risk?
It doubles the number of internet connections, firewalls and Wi-Fi networks to secure and adds new staff who need training. The controls that matter do not change (MFA, endpoint protection, patching, backups, least-privilege access), but they must be applied consistently at both sites. Central management through Microsoft 365, an RMM platform and cloud-managed networking is what keeps two sites as secure as one.
Should we replace existing IT equipment when we expand?
Not automatically. Assess what you have. Consumer-grade routers and unmanaged switches at the original office usually do need replacing, because they cannot support a site-to-site VPN or VLAN segmentation. Laptops and desktops that meet the Windows 11 hardware requirements can stay. Use the expansion to standardise on one hardware family going forward.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us