Download our PDF Whitepaper: “Why End-of-Life Asset Disposal is Your Hidden Cybersecurity Risk”
Closing the Data Security Gap: Why End-of-Life Asset Disposal Is Your Hidden Cybersecurity Risk
With how often personal data is shared with companies in today’s modern world, it comes as no surprise that data breaches are on the rise. According to Statista, in 2024, 3,158 cases were reported in the U.S. alone, with 1.35 billion people affected globally. According to the Identity Theft Resource Center’s findings for the first half of 2025, the U.S. has already seen 1,732 compromises affecting over 165 million people. This is a 5 percent increase over the same period in 2024, and it isn’t expected to slow down.
Many assume that the primary target of these cases is small businesses. While small businesses are hit exceptionally hard, it’s not just small organizations that are being targeted, but also renowned companies with extensive cybersecurity policies. Even with highly trained security teams and exorbitant firewalls, software, and training, Google, TransUnion, Connex, Manpower, and Air France are listed as some of the most recent breaches as of September 2025.
Whether an organization has thousands or millions of dollars to dedicate to its data security, there are common overlooked areas across every industry; in particular, end-of-life data stored on hard drives, tapes, and paper records.
The Overlooked Risk in Cybersecurity
Do you know what happens to every print-out with customer names or every user password stored on a media device when it reaches its end-of-life stage? Does it get tossed, shredded, recycled, wiped, or resold? Are your employees writing it down in a notebook, saving it on a personal device, or taking home documents to review for a later project?
The fact of the matter is that many organizations do not fully understand or properly implement the correct procedures for destroying end-of-life data. Too often, data items are mishandled or purposely misappropriated, allowing them to fall into the hands of malicious individuals and compromising the security of a company.
A 2017 study by the National Association for Information Destruction (NAID) found that 40 percent of devices resold through publicly available channels contained personally identifiable information (PII). PII can include:
- Credit card information
- Contact information
- Usernames and Passwords
- Company and Personal Data
- Tax Details
- So much more
The scariest part of this study was that NAID employed only basic measures to extract data. They used only publicly available downloadable shareware to find this PII data, meaning that even the most basic technology device user would be able to do the same, let alone a malicious individual with training or experience in hacking.
You may be thinking, “Why would my data get resold? I would never do that!” Unfortunately, cases like this happen more often than people realize, including an exhausting case with Morgan Stanley Smith Barney, which we will cover here shortly.
To aid your business in taking the proper steps, this paper will demonstrate how secure disposal integrates into a comprehensive data security strategy. To fully understand how to maximize the benefits of your data security and stay compliant, we will discuss the lifecycle of data, the real-life consequences of mishandling data, proper destruction techniques, and six steps you can implement today to enhance your end-of-life data disposal practices.
Understanding the Data Lifecycle
The lifecycle of data of any kind typically goes create → store → access → archive → dispose. First, the user creates or generates the data, whether physically on paper or using a media device. The item is then stored in a folder for later access. Eventually, the data is no longer relevant, so it is classified as “archived,” often by being moved to a storage room or storage device. Finally, when it is deemed no longer usable for any reason, it is ready to be disposed of.
Unfortunately, it is that last step, “disposal,” that is often skipped or handled by uncertified vendors. It is not uncommon for businesses to let storage rooms fill to the brim with banker boxes’ worth of paper or media devices, all of which could be vulnerable to unauthorized access. Alternatively, those who do take the final step towards disposal often leave critical PII unprotected by using uncertified, inexperienced third-party vendors to handle data destruction.
Depending on your business industry, that final step may be required to meet a certain standard by governing bodies. For example, if your business falls under the compliance requirements of HIPAA, FACTA, or GLBA regulations, each governing body will have strict rules regarding data destruction methods.
For example:
- HIPAA (Health Insurance Portability and Accountability Act) – Protects patients’ medical records
- FACTA (Fair and Accurate Credit Transactions Act) – Requires businesses to securely dispose of consumer information
- GLBA (Gramm-Leach-Bliley Act) – Mandates financial institutions to protect customer data
Whether you fall under these three acts or alternative ones, you will be held responsible for securing and destroying data that is no longer needed to prevent unauthorized access or use. Should you mishandle or misuse this sensitive data, the consequences are harsh and far-reaching.
What Happens When End-of-Life Data Isn’t Properly Destroyed
Unprotected data is a potential goldmine for malicious individuals, as it doesn’t take much information to steal or threaten a company or individual’s livelihood. Whether getting rid of paper or electronic data, if it isn’t properly destroyed, there is always a chance that it will end up in someone else’s hands who will use it for their own agenda.
Unauthorized data recovery occurs in a wide array of formats. Everything from dumpster diving to reselling “recycled” assets to the use of high-tech forensic tools on electronic devices. Regardless of how it ends up in a bad actor’s hands, the financial and reputational fallout can be detrimental.
Take, for example, the $35 million settlement Morgan Stanley Smith Barney (MSSB) had to pay in 2022. The U.S. Securities and Exchange Commission (SEC) began investigating MSSB after it had failed to dispose of devices containing its customers’ PII properly.
There were multiple instances where MSSB hired a moving and storage company to decommission thousands of hard drives and servers with the PII of millions of customers. The moving and storage company, which had no proof of experience in data destruction, sold thousands of those MSSB devices to a third party, which were then listed on an internet auction without removing the customer PII.
That wasn’t all. MSSB was also found to have failed to properly dispose of PII and consumer report information when it decommissioned local office and branch servers as part of a broader hardware refresh program. It was revealed that 42 servers went missing, potentially compromising data along with them.
In the press release of this settlement, Gurbir S. Grewal, Director of the SEC’s Enforcement Division, stated, “MSSB’s failures in this case are astonishing. Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and MSSB fell woefully short in doing so.”
As we can see from this example, not properly disposing of data can lead to disastrous consequences. Not only can businesses face direct losses like the $35 million settlement above, as well as litigation costs, violation fines, sales decreases, and more, but there are indirect costs too.
While not precisely measurable, when a business faces a case like this, it can cause long-term operational distress. Often, companies will face negative publicity, reputation damage, and a decrease in employee trust. This, in turn, can lead to customer abandonment, stock devaluation, and other critical losses.
Physical Destruction as the Gold Standard
When it comes to data destruction, the methods fall into two categories: non-destructive and destructive. Non-destructive methods typically preserve the equipment (media) while targeting the internal data, whereas destructive methods completely obliterate the item (media or paper).
While we delve deeply into this topic in our white paper, “Is Your Data Really Gone? Think Again,” we will provide a brief overview here.
Non-Destructive:
There are two methods of non-destructive data removal: wiping and degaussing. Wiping is the process of permanently deleting information from the device. However, depending on the software that is used, the information can be retrieved by experienced hackers.
The other method, degaussing, uses magnets to destroy the magnetic fields of the media device. Unfortunately, this method doesn’t work on all media, and the tools to verify that the media is actually gone are costly.
Typically, these two methods are only recommended for low to medium-risk data and have a trusted internal environment. It rarely meets the minimum standard for industries that have a regulating body.
Destructive:
Physical destruction is considered the gold standard of data disposal as it is the most secure, and often the most cost-efficient, method to get rid of end-of-life data. Physical destruction of data uses shredding as its method. At CI Information Management, here is what we do to secure your data disposal:
For paper products, they are put through an industrial shredder that cuts the paper so fine it is smaller than confetti; this is way smaller than home or office shredders can ever achieve. Then, we recycle all the shredded paper with trusted partners, helping to keep the world a little greener.
For media destruction, devices are put through a machine that bends, breaks, and mangles the device’s hard drive and its internal components beyond the point of repair. After that, those parts are then separated into specific categories, such as copper or plastic. These collections are then sent to be recycled or melted down for reuse, leaving no trace of your device behind.
Physical destruction is the preferred data disposal method for any data that falls under strict compliance regulations or is considered to be high-risk, as it is 100% irreversible.
Action Plan – Closing Your Organization’s Disposal Gap
As a business, it is your responsibility to do everything in your power to ensure the safety and security of your data, both internal data about your company and the data that is entrusted to you by customers. Strengthening your end-of-life data disposal practices doesn’t have to be overwhelming. By following a few simple steps, you can safeguard your organization, protect your customers, and maintain your reputation.
6 Steps to Improve Your End-of-Life Disposal Practices
Step 1: Identify All Storage Data in Use
The first step is to identify where data is stored in your business. It’s not just the paper on a desk or the electronic data in a desktop computer; data can live on sticky notes, journals, calendars, phones, hard drives, SSDs, backup tapes, copiers, mobile devices, and even embedded systems. Performing a deep dive of any place where sensitive data can be stored will ensure a smooth disposal system so nothing slips through.
Step 2: Audit Your Current Process
After you have identified all of your data locations, it is time to review how your business handles inactive data and the decommission process of active data. For example, are outdated laptops, servers, or external drives being stored in a closet? Do you have a secure shred policy and storage for sensitive papers? Are disposal methods documented, or is it more “out of sight, out of mind”? Identifying gaps in your current process is the first step toward closing them.
Step 3: Complete Your Disposal Compliance Checklist
Once you have audited your current process, it is time to make improvements. Creating a system for data disposal may feel overwhelming, so starting off by following a Disposal Compliance Checklist can help streamline the process. At the end of this paper, we have supplied a Disposal Compliance Checklist for your reference; use this to start your process and add modifications as needed to suit the unique needs of your organization.
Step 4: Vet Your Disposal Vendors
Once you have a complete picture of your data disposal needs, it is time to get with a trusted vendor to set up a disposal process. However, we want to caution that not all vendors follow the same standards. A reputable partner should comply with NAID AAA and meet the requirements of the governing body under which you operate, such as HIPAA. We encourage you to vet them carefully. Ask questions about their chain of custody, how they transport devices, and what destruction methods they use.
Step 5: Require Certification and Documentation
At the end of every destruction service require a Certificate of Destruction. If your chosen vendor doesn’t offer this, switch vendors prior to your next service. A Certificate of Destruction not only proves compliance with state and federal privacy laws during audits but also serves as insurance in the event of a breach investigation. This piece of paper is your “I did my due diligence” get out of jail free card.
Step 6: Educate Staff on Disposal Protocols
Security protocols mean little if your staff does not comply, either due to lack of interest or ignorance. Often, the average individual does not know how vulnerable data is, how easily sensitive data can be spread or lost among paper and devices, or the ramifications of a data breach. Taking the time to educate staff on disposal practices, as well as providing standard operating procedures they can use as reference material, is critical.
Your staff should understand what constitutes sensitive data, why proper disposal is important, the steps to take when disposing of various data types, and when to raise concerns. Of course, you don’t want to do this just once; rather, it is wise to have regular refreshers to keep people cautious.
Bonus Step: Use CI Information Management’s Secure Method
If you are located in the Pacific Northwest and are looking for a secure way to dispose of your organization’s data, we at CI Information Management are here to help. As a NAID AAA Certified destruction provider, we help you mitigate the risks of unauthorized access to your information.
CI Information Management: Your Secure Partner in Data Disposal
Serving Eastern Washington and Northeastern Oregon, CI Information Management has been a trusted provider of secure document and media destruction to businesses and the community for over two decades.
In an era where safeguarding customer, client, employee, and organization privacy is more important than ever and compliance with state and federal laws is non-negotiable, CI Information Management delivers the expertise you need to permanently destroy data of every type.
Our trained, background-checked, bonded, and insured employees follow a strict chain of custody during the entire destruction process. Additionally, each destruction operation is accompanied by a Certificate of Destruction, ensuring compliance with state and federal privacy laws.
We offer a variety of data destruction services to our business clients, including the following:
One-Time Purge Shredding: A mass shredding operation designed to destroy a backlog of accumulated documents, particularly when businesses are performing clean-outs, renovations, or office moves.
Recurring, On-Site Shredding: Designed for companies with a need for routine document shredding, our mobile truck comes directly to your business to perform secure shredding on-site.
Drop-Off Shredding: Ideal for companies with minimal data disposal needs, secure drop-off is available for locals, allowing them to dispose of their data at our primary facility.
Media Destruction: Specifically designed for media destruction, this service shreds media devices, including optical media, HDD/SDD, flash drives, zip disks, tapes, and floppy disks.
Product Destruction: A specialized service focused on the secure disposal of product materials, including overstock, expired/defective items, and outdated merchandise.
Why Choose CI Information Management?
Unlike other shredding companies that are in the industry for business only, CI Information Management operates as a division of Columbia Ability Alliance, a nonprofit dedicated to empowering individuals with disabilities. Every dollar spent with us helps fund critical initiatives that strengthen our community. By choosing us, you not only protect sensitive information but also support an organization committed to inclusivity and social impact.
Beyond our social impact, we are dedicated to sustainable practices. In paper shredding alone, redirecting shred to recycling prevents unnecessary landfill waste while conserving natural resources, reducing energy consumption, and minimizing pollution. In 2024, we recycled 4,203,339 pounds of paper.
So if you are a business located in Yakima, Tri-Cities, Walla Walla, Moses Lake, Wenatchee, Pendleton, and beyond that is searching for a reliable, community-driven company that treats your organization’s security with the highest industry standards for excellence, we at CI Information Management are your ideal partner.