Blog
Plain-language guides to the standards, laws, and decisions behind retiring IT hardware, written by the people who destroy it for a living. Looking for the breach post-mortems? The case studies have their own page, and so do the videos.
Posts
Windows 10 Extended Security Updates End October 13, 2026: The Last Retirement Checklist
The one-year Extended Security Update program that kept Windows 10 machines patched after the October 2025 end of support runs out on October 13, 2026 for consumers and for the first year of the commercial program. Every fleet that bought the year is retiring this fall. Here is the checklist, from inventory to certificate.
CMMC, NIST 800-171, and DCSA: Why We Now Recommend Physical Destruction for CUI Media
The CMMC third-party assessment deadline moved in July 2026. The obligation to sanitize CUI media did not, and the signature on the affirmation is now yours. What NIST 800-171, 32 CFR 2002, DoDI 5200.48, and DCSA's guidance require, why a wipe is harder to prove than it looks, and why we recommend destroying CUI media rather than purging it.
Windows 10 Recycling: A Guide to Secure Disposal and Compliance
Windows 10 has entered its post-support era. What to do with the fleet you are decommissioning: which machines can get a second life, and what NIST 800-88r2, CJIS, and NSA 9-12 require of the rest.
NIST 800-88r2: Navigating Data Disposal
The finalized Revision 2 of NIST SP 800-88 gives businesses a modernized framework for sanitizing data across physical, virtual, and cloud environments. What changed, what the documentation now has to show, and how to choose Clear, Purge, or Destroy.
Ohio HB 96: A Game-Changer for Public Sector Cybersecurity
Ohio Governor DeWine signed House Bill 96 into law, ushering in sweeping new cybersecurity obligations for counties, cities, townships, school districts, libraries, and other political subdivisions across the state. Here is where hardware disposal fits.
Is Reselling Old IT Hardware Online Safe? How We Do It, and When Wiping Is Enough
Reselling retired hardware can recover some of its cost, but only if the data is gone first. How we handle it (disassembly, destruction, parts only), and when a verified NIST 800-88 wipe is a reasonable choice for organizations that do not need high-security destruction.
Understanding DOD 5220.22-M and Its Relevance in Today's Data Sanitization Standards
The three-pass overwrite was the gold standard for a generation of hard drives. Here is where it came from, why it no longer fits today's media, and why NIST 800-88 replaced it.
Navigating HIPAA Security Compliance: Essential Strategies for Data Protection with NIST 800-88
The HIPAA Security Rule sets strict requirements for protecting electronic health information. Here is how NIST 800-88 fits into a practical compliance strategy, from risk assessment to secure disposal.
Case studies
In the field: a CJIS destruction day for the City of Mansfield
Eighty-seven assets from a storage room to a signed certificate in one day, including the ones that turned out to be empty
What a routine municipal job looks like when it is done right: an inventory by asset tag, media logged by serial, hard drives degaussed and shredded, SSDs disintegrated, empty chassis recorded as inspected, the city's representative witnessing, and a certificate dated the same day.
The FBI's Media Destruction Program
Right machines, wrong everything before them: what the DOJ Inspector General found in 2024 and 2025
The FBI's central destruction facility ran a degausser, a shredder, and a disintegrator to NSA and NIST standards, and the contractor met its deliverables. The Inspector General still found Secret-marked drives in torn shrink wrap on a warehouse floor, extracted hard drives nobody counted, pallets waiting up to 21 months, and 395 people with access. Every mistake was upstream of the shredder.
The Morgan Stanley Data Breach
Due to improper sanitization of IT hardware
How a global bank's decommissioned data-center hardware ended up in strangers' hands after a vendor was paid to wipe it, and what it cost: a $35 million SEC penalty, a $60 million OCC fine, and a $60 million class-action settlement.
HealthReach Community Health Center Data Breach
A wake-up call on proper data disposal and HIPAA compliance
Improperly disposed hard drives exposed the records of more than 115,000 patients at a community health center. What HIPAA requires at the end of a record's life, and how to build a disposal program that would have prevented it.
HAMR Drives and Classified Environments
Plan the disposition before you deploy the drives
Heat-assisted magnetic recording drives cannot be degaussed, and the NSA's February 2026 reissue of Policy Manual 9-12 now says incineration is the only approved sanitization for them. What that means for a cleared facility, and how to identify a HAMR drive before it becomes a problem.
Ohio's Data Protection Act and Data Destruction
The digital safe harbor law, and how documented media sanitization helps you qualify
Ohio's Data Protection Act gives businesses an affirmative defense against breach lawsuits when they follow a recognized cybersecurity framework. Documented NIST 800-88 sanitization is part of qualifying. A plain-language comparison, not legal advice.
NIST 800-88 Media Sanitization and the Reasonableness Standard
Why regulators judge disposal against reasonableness, and how a documented sanitization plan proves your decisions were defensible
Courts and regulators ask whether an organization acted reasonably. NIST 800-88 is how you show it. A comparison of the technical framework and the legal standard, and why an ITAD vendor's business model belongs in your risk assessment.
