There is a device in your organisation that no security dashboard is watching. It is not the laptop on a desk running software a week behind on patches. It is the one powered off in a store cupboard, stacked with a dozen others, waiting for someone to deal with it later.
Being realistic, end-of-life IT is not the biggest cyber security threat to an organisation, but it is potentially the one that nobody is looking at. And unlike a determined intruder, this exposure is almost entirely preventable.
The exposure is real, and it is documented
Research by Blancco and Kroll Ontrack, which bought second-hand drives and devices online, found that 75% of used drives still held recoverable data from their previous owner, along with 57% of used mobile devices. Every one of those left an organisation that believed the matter had been handled.
That is the gap worth closing. Not because disposal outranks hacking in the statistics, but because it is the one category of risk where the fix is entirely within your control.
The breach that starts in a cupboard
This exposure is easy to miss because it does not look like a threat. A laptop gets swapped out. It sits in storage. Then it gets sold to a broker, handed to a well-meaning charity, skipped, or lost in an office move. If the drive was never properly wiped, everything on it goes with it: customer records, credentials, commercially sensitive files, personal data covered by UK GDPR.
And the cost when it goes wrong is not theoretical. IBM’s 2025 Cost of a Data Breach report puts the global average at $4.44 million. It does not matter that a forgotten drive is a less common route in than a phishing email; the invoice looks the same.
The refresh wave widens the gap
Now factor in timing. The end of Windows 10 support has kicked off the biggest synchronised hardware refresh in a decade, with Canalys estimating around 240 million PCs unable to meet Windows 11’s hardware requirements. Retiring a handful of laptops is manageable. Retiring a few hundred at once is where things slip. Backlogs build. Devices get set aside faster than they get processed. And the bigger the pile, the greater the odds that one machine leaves without anyone being able to say where it went or whether it was wiped.
What actually removes the risk
The answer is not a reassurance that it is all handled. It is proof. That is the difference between a certified process and a hopeful one. Every device wiped to recognised standards, NIST 800-88 and IEEE 2883-2022, under an ISO 27001 certified operation. Device-level asset tagging so nothing is untracked. Reconciliation reports within 48 hours. An individual erasure certificate for every machine. Sealed, GPS-tracked transport. A full chain of custody from the moment a device leaves your building.
With that in place, you can answer the only question that matters after a breach: can you show, device by device, that the data was destroyed? Either you can prove it, or you are guessing. In front of a regulator, guessing is expensive.
You cannot make yourself immune to a determined attacker. You can make sure that every device leaving your estate is accounted for, wiped, and on its way to a secure second life. One of those problems is genuinely hard. The other is a decision. Data, locked down. Carbon, counted. Lives, changed. If you are about to retire IT at scale this year, let’s make sure none of it comes back to haunt you.
Old tech. New beginning.
