Insight

The Real Cost of Getting ITAD Wrong

"We recycled it" is not the same as "the data is provably gone." The companies that learned that the hard way have the receipts.

Improper IT asset disposition has produced some of the most expensive data incidents on record: nine-figure settlements, regulatory fines, and public breach disclosures, all traceable to retired equipment that left the building with data still on it.

The receipts

Morgan Stanley hired an unqualified vendor to retire thousands of hard drives and servers; the devices resurfaced online with roughly 15 million customers' data still on them, and the total bill in fines and settlements has exceeded $150 million. CVS paid $2.25 million for disposing of customer health information where anyone could find it. Affinity Health Plan paid over $1.2 million after returning leased copiers without wiping the drives, exposing hundreds of thousands of people. None of these were sophisticated attacks. Each was a disposition process that ended one step too early.

Why the risk is climbing

In the age of AI, leaked data is easier to weaponize and harder to contain than ever, and regulators keep raising the penalties. HIPAA, GLBA, FTC Safeguards, and state privacy laws all reach the disposal step explicitly. Meanwhile the volume of retiring equipment is surging: refresh cycles are shortening and the Windows 10 end-of-life wave is still moving through corporate fleets. More devices leaving more buildings means more chances for one untracked drive to become a headline.

The protection is boring, and that's the point

The defense is not exotic: a rigorous, standards-based destruction process (NIST 800-88), a certificate of destruction tied to every serial number, and a complete chain-of-custody record proving where every device went. If your current vendor can't produce that record, you don't have a disposition program. You have a liability with a pickup schedule.

Frequently asked questions

Is deleting files or reformatting a drive enough?

No. Deleted and reformatted data is routinely recoverable. NIST 800-88 defines verified sanitization and destruction methods matched to the media type, and the process should end with a certificate per device.

What should we ask a recycler before handing over equipment?

Ask for their destruction standard (NIST 800-88), whether every device gets a serial-level certificate, whether they can show a complete chain of custody, and where the equipment is physically processed.

Related

Not sure what your current process would survive?

Request a free assessment and we'll walk your disposition path end to end.

Request a Quote