Old hardware disposal: wipe, log, prove it before the truck leaves
Saturday, 10:20. The upgrade pile finally goes to e-waste: two dead laptops, a monitor, a five-year-old NAS, and the office copier nobody will miss. Someone does a last courtesy check of the top laptop — and finds the finance director's browser still signed into the company drive, remembered. Nothing malicious, just machines nobody formally owned at the end. That is what a disposal process prevents: the moment of handoff is the last moment your data is your problem, and it is the moment most small teams treat like a trash run. The asset inventory tells you what you own; this checklist is the exit lane for what you stop owning — wipe, log, prove, then let the truck take it. The one rule that runs the whole page: no storage device leaves the building until its data state is verified and written down.
1. The pile gets an inventory row before anything powers off
- Every device, one row: serial, assignee, data state, planned method. The inventory row that was opened when the device arrived is closed by this checklist, not by the recycling bin. Six rows beat a shoebox of "laptops, assorted" — because the row is what you hand the client who asks "what happened to the laptop with our quarterly decks on it?"
- Copiers, printers, and NAS boxes are computers too. The office multifunction printer has a hard disk holding every scan and copy of the last five years; the NAS holds the actual backups. The pile that gets taken seriously is the pile with screens; the pile that leaks is the one with paper trays. Check the printer fleet checklist — its storage section is the first half of this one.
- Photograph the pile as you tag it. Ten seconds per device: serial number, condition, anything visibly damaged. When a recycler's manifest and your rows disagree later, the photos end the argument in your favor before it starts.
- Pull the drive from any machine that will not boot — then it stops being "the dead laptop." A machine that powers on to a firmware error is not exempt from the rule; its disk is exactly as full as it was the day it died. The dead machine gets dismantled at the bench, its drives join the pile as first-class devices, and the empty chassis is the only thing that was ever truly garbage.
2. Deregister before you wipe, or the wipe creates ghosts
- MDM and enrollment first. Remove the device from the management console (the BYOD policy's exit step, applied to company-owned hardware) before erasing — a device wiped while still enrolled comes back from the dead on someone else's login screen, still claiming to belong to your company. The console entry is also the source for the serial-and-assignee row you just wrote.
- Activation locks and BIOS/EFI passwords second. The Mac that "went to the recycler" and came back with an activation lock still set is un-recyclable and un-sellable, and the fix now needs the original owner's account credentials. Check for Find-My-style locks and firmware passwords on every Mac and every enterprise laptop before the wipe, because after the wipe those checks need the machine to cooperate.
- Software licenses and subscriptions third. The decommissioned laptop still holds a paid seat of the design suite, and the NAS a perpetual license nobody transferred. Cancel or reassign the seats while the device is still in the building and the licenses are still findable; after disposal, the seat is a monthly bill attached to a serial number in a landfill. The annual review finds these too, but it finds them a year late.
- Shared accounts the device was holding last. The shipping-label kiosk, the door-code tablet, the conference-room screen — the peripheral that everyone forgot was even a computer. Rotate the shared credentials it knew, the same sweep the offboarding checklist runs for people, extended to machines.
3. The wipe, per device class — one method, verified
- Company laptops and desktops: built-in secure erase, or pull the drive. Modern machines with self-encrypting drives (FileVault or BitLocker on, per the encryption baseline) can be safely released by a signed-in erase that destroys the encryption keys — the data is mathematically gone. For anything older or unencrypted, the honest method is physical: pull the SSD, wipe it as a drive, recycle the empty chassis. "I deleted my files and emptied the trash" is not a wipe; the file table lost the address, not the data.
- Phones and tablets: factory reset is enough — after deregistration. Post-MDM-removal, the built-in reset cryptographically scrubs a modern phone's keys, same physics as the laptop. The trap is order: reset before removing MDM and you get a locked orphan; skip the reset entirely and you get a phone that boots to the ex-employee's photo album.
- External drives and USB sticks: these are the ones that walk out in desk drawers. Small, unencrypted, unlogged — and frequently holding the client folder someone copied "just for the meeting" in 2023. Wipe or shred them like any other disk; the drawer is not an archive, and the key escrow page explains where things that must survive should live instead.
- NAS and server disks: wipe, then verify with a read-back. These hold the backups themselves, so the stakes are highest — and the "extra copy for safety" instinct is strongest exactly here. The rule: the restore test already proved the backups live somewhere safe; the disk that held the old copy is wiped, verified, and logged like any other device. Sentiment is not a data-retention policy — the retention schedule is.
- Verify, don't assume: boot it one last time. The verification step for every wipe is the same: power the device back on and confirm it behaves like an empty machine — setup assistant on a laptop, setup wizard on a phone, blank on a wiped drive in an enclosure. "It ran the erase and I watched the progress bar" is a claim; "it booted to the setup screen afterward" is evidence.
4. Drives that cannot be wiped get destroyed — and destruction gets documented too
- Failed-drive triage: three erase attempts or one ball-peen hammer, but never "send it and hope." A drive with firmware errors may resist software erasure; that is the moment to switch from wipe to destroy, not to hand the un-wiped drive to the recycler with a note. A degauss or a professional shred service destroys the platters and the data together; a hammer through a spinning drive is crude but effective at 2 a.m., as the breach runbook's containment section will attest.
- Solid-state drives change the math. Shredding an SSD works only if the shred is fine enough — every NAND chip holds data, so the standard is "no chip larger than a grain of rice." Platter drives are more forgiving. If your recycler can't state their shred particle size for SSDs, their truck is not your destruction method; their truck is a transport risk with your logo on the boxes.
- The certificate of destruction is the point. For anything destroyed rather than wiped, keep: the drive serial (from the inventory row), the method, the date, and the provider's certificate or receipt. This is the document that answers the client question, the insurer question, and the access review's "and what about disposed assets?" line — all with one PDF.
5. The paper trail: one spreadsheet that closes the loop
- Columns: serial, description, assignee, data state, method, date, initials, receipt. The whole paper trail is seven columns, and the evidence it produces is disproportionate to the effort: for any disposed device, in one row, you can answer what left, what was on it, what you did about it, and who saw it done. Auditors, clients, and cyber-insurance questionnaires all read this document; none of them read the recycling bin.
- Close the asset inventory row the same day. Disposal is the end of a device's life in your inventory, and a row that says "disposed 12 Sep, wiped, verified" is the difference between an inventory and a museum. The same review cycle that flags stale access flags the stale asset rows — the pile in the corner is the physical version of the account nobody deprovisioned.
- Keep the rows as long as the data's risk, not as long as the sentiment. The disposal log is subject to the same discipline as every other ops artifact: a stated retention period, a named owner, a calendar reminder. The log retention policy already sets the pattern — extend it to one more artifact rather than inventing a new one.
6. The handoff: choose the recycler, watch the boxes out the door
- Pick a recycler with a chain-of-custody answer, not just a bin. The question is one sentence: "if a device from my box shows up resold in another country, what is your accountability?" Certified recyclers answer with a certification name and a manifest; the free drop-off bin behind the electronics store answers with a shrug. A wiped device in an uncertified bin is a modest risk; an unwiped one there is an incident with a delivery confirmation.
- You hand it over; you do not leave it in the lobby. The handoff is the moment custody transfers, so it is the moment the manifest gets signed — take the paper (or photo) and put the serials next to your inventory rows. The physical security rule applies: a stack of wiped-but-unverified hardware by the fire door is an opportunity for whoever walks past it.
- Reuse and resale are the same checklist with one extra step. Selling or donating a machine is legitimate — after the wipe, the verification boot, the deregistration, and a fresh OS install so the new owner gets a working machine rather than a mystery. The resale listing that says "wiped, factory reset, ready to go" is honest only because the checklist above it made it true.
The whole discipline fits one sentence a five-person team can keep: every device that leaves is wiped or shredded, every wipe is verified by a reboot, every fact is a row, every row has a receipt. The pile in the corner is the last unmanaged copy of your company's data; this checklist is how it stops being yours, on paper, deliberately.