The matter of your server security. You may store hot wallet, database and other sensitive data in the encrypted folder, which automatically unmount on every root/user login. You may use the first server like a transparent proxy to your main server, which send you sms on every unauthorized login, etc. There are many similar simple solutions, but very often exchangers are managed by enthusiasts, not bank-level security specialists.