I agree with trevor. There's nothing more insecure than user docs scattered all over with no real backup plan in place. And besides not being able to survive without their data, if someone leaves the company, you may or may not ever find it all.
Now I would also agree a server with dual processors is a little overkill for an office of 5 people, so perhaps #1 should be "size hardware appropriately". Most 5 user offices also don't need a RAID5 array with 146Gb drives either.
Keep Up with TechRepublic