Stop Destroying the Value of Secure IT
Key Highlights
- Implement risk-cost-benefit analysis to determine when physical destruction of IT assets is necessary versus when software-based sanitization suffices.
- Establish verifiable, policy-driven sanitization processes that ensure data security while enabling device reuse and recycling.
- Develop comprehensive lifecycle policies for data sanitization, covering procurement, deployment, and final disposition to maximize asset value.
- Regularly review and update sanitization practices to keep pace with technological advancements and evolving industry standards.
- Adopt a value-centric approach to data security that balances regulatory compliance, cost savings, and environmental sustainability.
Expanding privacy and cybersecurity regulations can impose high direct and long-term costs on businesses. In its economic-impact analysis of the California Consumer Privacy Act (CCPA) cybersecurity, risk-assessment, and automated decision-making regulations, the California Privacy Protection Agency estimated that the proposed rules would cost businesses $4.8B in direct costs over a decade.
These cost pressures aren't isolated to California; they reflect a growing global trend. In our 2026 State of Data Sanitization research report, 59% (70% in the U.S.) of 1,460 global IT, cybersecurity, compliance, and sustainability leaders said that their data protection and compliance spending increased by an average of 40% as compared to last year.
As data security regulations worldwide evolve, every enterprise IT budget is absorbing the shock, putting unprecedented pressure on IT and security teams.
IT Costs Exacerbated by Inefficiencies
Unknowingly, enterprise IT teams are worsening financial pressures by letting cybersecurity anxiety obstruct efficiencies that could otherwise offset some of the budgetary burden. Specifically, these anxieties, driven by heightened concerns about breaches and data leakage, are leading to the unnecessary destruction of IT assets as a data-protection measure.
According to the research, while many respondents (77%) preferred reusing devices rather than physically destroying them, 56% reported that data security concerns are barriers to advancing their sustainability and efficiency goals. This matters because more than a third of enterprise laptops, smartphones, and other IT assets are fully functional at the time of destruction, including 43% of mobile devices, 35% of laptops and desktop PCs, and 44% of data center assets, per the report.
Meanwhile, hardware replacement costs are hitting historic highs. A laptop that could have been sanitized, then redeployed or remarketed, is now being junked at a moment when asset replacement carries a 17% price premium and availability is shrinking, according to Gartner.
Rather than allowing cybersecurity anxiety to dictate decision-making, organizations can take practical steps to reduce risk while getting more use out of their technology investments.
Rather than allowing cybersecurity anxiety to dictate decision-making, organizations can take practical steps to reduce risk while getting more use out of their technology investments. Let’s look at four strategies that may help:
1. Creating a plan that bases sanitization decisions on risk-cost-benefit, not blanket destruction
As technology advances, the notion that data security always requires device destruction is becoming increasingly outdated. While physical destruction can be appropriate in certain cases – e.g., when a device is damaged or otherwise incapable of performing a reliable sanitization operation – it is often avoidable and can result in financial and environmental costs.
Increasingly, standards bodies are emphasizing a risk/cost-benefit-based approach, where organizations can select non-destructive, software-based data sanitization methods, as long as those methods provide assurances. Standards and guidance documents like NIST 800-88, IEEE 2883, and IEEE 2883.1-2025 provide frameworks, recommended methods, decision criteria, and risk-based guidance for selecting and implementing appropriate storage sanitization practices throughout the media lifecycle.
Organizations should establish a plan to assess functional devices based on risk/cost-benefit analysis and the organization’s priorities. Building a plan that reflects these priorities may involve scoring IT assets on the potential value that can be recouped and establishing processes that flag devices for reuse, resale, donation or recycling. These actions don’t just protect data. They unlock additional lifespan from functional devices and advance corporate social responsibility (CSR) goals.
2. Replacing uncertainty with verifiable processes
The review process above only works when organizations consistently apply verifiable, software-based sanitization methods to ensure data security without resorting to physical destruction. This means implementing processes that ensure sanitization is executed properly, the right methods are applied for each device type and data sensitivity classification, and sanitization levels match the required level of data protection. Policy-based automation streamlines these processes, reduces human error, and helps prepare devices for subsequent use.
Once verified, carefully document and store sanitization results for compliance and peace of mind. Typically, this is delivered as a certified report proving that data has been irreversibly removed. Beyond documented verification, lock-tight chain-of-custody controls across asset handoffs are also critical.
3. Applying consistent data sanitization protocols throughout the asset lifecycle
To maximize the value you can extract from your hardware investment, create a data sanitization framework that spans the IT lifecycle. Start by developing policies that govern data sanitization from procurement through final disposition, emphasizing “recover-first” actions that support redeployment, repair, resale, and recycling goals. Not only can sanitization be applied at various stages after acquiring new devices, it can also enable you to confidently take advantage of refurbished enterprise assets.
Sanitizing before provisioning lets you securely deploy pre-owned devices into your environment without the premium of buying new. Whether for new or refurbished devices, sanitization practices should be tied to the above-mentioned industry standards (i.e., IEEE 2883 Standard for Sanitizing Storage, and its companion best practices document, IEEE 2883.1-2025). Additionally, it’s vital to establish internal ownership and accountability for data security at every stage.
4. Regularly reviewing full lifecycle data sanitization policies as technology advances
Technology is evolving at every turn. Today’s primary catalyst is the relentless advancement of AI, which has accelerated data storage requirements and hardware refresh rates. To meet organizational demands within constrained budgets, IT and security teams monitoring evolving threats must also track data storage advancements and risks, industry standards developments, and the sanitization needs of new technologies. Regularly reviewing sanitization and disposition practices against the latest standards helps ensure assets can be safely recovered and redeployed.
Becoming more knowledgeable about how sanitization techniques render data unrecoverable on various devices, and which methods to apply when, can also ease both budget and security concerns as ever-advancing data center and end-user assets enter the market and stay in circulation.
All in all, security anxiety can lead to costly decisions. For many organizations, the mere potential for risk is driving the destruction of devices that still have significant operational value; however, organizations can adopt a value-centric mindset without compromising security. Rising costs and uncertainty in today’s environment call for a shift to more efficient, sustainable outcomes that help organizations extract greater value from enterprise IT investments.
About the Author
Fredrik Forslund Fredrik Forslund
VP and GM, International, for Blancco Technology Group
With more than 30 years of experience in IT security, Fredrik Forslund is a sought-after speaker and author on the topics of data sanitization, data center and cloud erasure, and sustainable IT asset reuse. As VP and GM, International, for Blancco Technology Group, he leads teams across EMEA and APAC, traveling often from his home base in Sweden. Before Blancco, he co-founded SafeIT Security, a security software company focused on encryption and selective data erasure. He is also a co-author of the industry guide, Net Zeros and Ones: How Data Erasure Promotes Sustainability, Privacy, and Security.
