Cyber insurance renewals have become a lot more detailed. Underwriters are asking harder questions, premiums are climbing, and businesses that cannot demonstrate disciplined data handling practices are running into coverage issues.
One area catching businesses off guard: what happens to retired IT equipment when it leaves your premises.
The Question Underwriters Are Now Asking
When you apply for or renew a cyber insurance policy, expect to answer questions like:
- How do you handle retired devices that contain customer or business data?
- Do you have a documented process for data destruction?
- Can you produce a certificate of destruction and a chain of custody record for each disposed asset?
Five years ago these questions were uncommon. Today they are standard. And if your answer is “we factory reset our phones and drop old computers at a council bin,” that is a gap your insurer will notice.
Why It Matters
Data recovered from improperly disposed hardware is a genuine breach vector. Basic deletion, quick formats, and factory resets do not meet modern data destruction standards. On HDDs, SSDs, and other solid-state media, data can persist through these methods and be recovered with off-the-shelf tools.
NIST 800-88 Rev. 2 is the benchmark for media sanitisation. It defines three sanitisation levels: Clear (logical overwrite), Purge (cryptographic erase or verified overwrite), and Destroy (physical shredding or degaussing). The right level depends on data sensitivity and device type. A business that cannot point to alignment with NIST 800-88 has a documentation gap that becomes very visible under scrutiny.
ISO 27001, the international standard for information security management, is explicit: secure disposal of assets containing information is a control requirement, not a best practice. If your organisation is ISO 27001-aligned, your disposal process needs to reflect that.
The Victorian Compliance Context
Victorian businesses are operating in a stricter environment than many realise. The state e-waste landfill ban, in place since 2019, means dumping retired IT equipment is already illegal. But the compliance picture is bigger than waste disposal.
Under Australia’s Privacy Act and the Notifiable Data Breaches scheme, organisations must protect personal information across its full lifecycle, including at the point of disposal. Retiring a device without documented sanitisation is a privacy breach exposure, not just an environmental one.
For organisations in healthcare, financial services, legal, and government supply chains, the exposure is higher again. Documented disposal records are increasingly expected at audit, and the cost of being unable to produce them can far exceed the cost of getting the process right in the first place.
What Documented ITAD Looks Like
EWV handles IT asset retirement in alignment with AS/NZS 5377 (the Australian standard for e-waste collection and treatment), ISO 14001 (environmental management), ISO 27001 (information security management), and NIST 800-88 Rev. 2 (media sanitisation). Full certification is on EWV’s roadmap; current operations are built around these frameworks.
Every ITAD collection through EWV includes:
- A full asset register covering serial numbers, device types, and condition on arrival
- Data destruction using methods calibrated to NIST 800-88 requirements
- A certificate of destruction for each asset processed
- A chain of custody record from collection through to final processing
That documentation is what an underwriter, auditor, or regulator will ask for if a question is ever raised. Having it ready is not just good practice, it is increasingly a baseline expectation.
The Practical Case
Engaging a structured ITAD provider is not just a compliance checkbox. It is evidence of due diligence that can be produced quickly when it is needed. A certificate of destruction and a documented chain of custody are the difference between a managed audit response and an expensive liability.
If your next cyber insurance renewal includes questions about data disposal practices, having that paperwork on file is the fastest and most credible way to answer them.
EWV works with Victorian businesses across all sectors to handle IT asset retirement with the documentation that modern compliance requires. If a hardware refresh is on the horizon, reach out to start the conversation.
