Seems to me that this is another case of managers substituting expert opinion for formal business analysis, and later blame experts on poor judgement. How can this be a technical/IT dilemma?
In my opinion your job is to collect data, present results, not make the final call, or even speculate on better choice between the scenarios – because that is what you will end updoing in the end, nothing more than speculate.
The choice could/should be seen from the cost/benefit and risk analysis figures of two scenarios. I don’t know what your environment is, but the smaller the shop, the more often I see this happen.
And another thing – you correctly pointed out the risks involved in scenario #1, but don’t forget physical security risks present in both of them!