Secure Data Wiping and Device Destruction - A Pivotal Step in Retiring Old Devices

The Importance of Wiping Old Devices

When an old computer, server, hard drive, SSD, USB drive or mobile device reaches the end of its useful life, what happens to the information stored on it?

Deleting files is not the same as securely destroying data. Formatting a hard drive or performing a factory reset may also leave organisations exposed if the underlying storage has not been properly sanitised.

For businesses, government organisations and other organisations handling confidential information, secure data destruction is an essential part of information security and responsible electronic waste disposal.

But what exactly is secure data destruction? What is the difference between data wiping and physical destruction?

This guide explains the major data destruction standards, including NIST SP 800-88 Rev. 2 and IEEE 2883, and explains how organisations can approach the secure destruction of old hard drives, SSDs and electronic devices.

What Is Secure Data Destruction?

Secure data destruction is the process of making information stored on a device inaccessible or infeasible to recover at the level of effort appropriate to the organisation’s security requirements.

The process can involve logical sanitisation, cryptographic erasure or physical destruction, depending on the storage technology and the intended outcome.

The current NIST SP 800-88 Rev. 2 guidance defines media sanitisation around making access to target data infeasible for a given level of effort.

It also recommends that organisations establish a media sanitisation program based on information sensitivity and appropriate controls.

In practical terms, secure data destruction should answer three questions:

  1. What type of storage device is being destroyed or sanitised?
  2. How sensitive is the information stored on it?
  3. Will the device be reused, resold, recycled or permanently destroyed?

The answers determine the appropriate data destruction method.

Deleting Files IS NOT Secure Data Destruction

One of the most common mistakes when disposing of old computers and hard drives is assuming that deleting files permanently removes the information.

In many circumstances, ordinary deletion removes the operating system’s reference to a file without immediately eliminating all underlying data.

The same issue can apply to formatting. A quick format or operating-system reset should not automatically be considered equivalent to secure data destruction.

A discarded device could contain information such as:

  • Customer and employee records
  • Financial information
  • Business documents
  • Emails
  • Passwords and authentication information
  • Photos and videos
  • Intellectual property
  • Medical or other sensitive records
  • Browser and application data
  • Encryption keys
  • Cached information

If the device is subsequently sold, recycled, donated or sent to an electronics recycler, residual information can potentially become accessible to someone who acquires the device.

This is why secure hard drive disposal needs to involve a recognized sanitization or destruction process rather than ordinary file deletion.

What Are The Main Data Destruction Methods?

Modern media sanitisation generally falls into several broad categories.

Clear

Clear techniques are designed to remove data from storage while generally leaving the device usable.

For suitable storage technologies, this can involve appropriate logical overwriting or other device-supported sanitisation techniques.

NIST SP 800-88 Rev. 2 describes clear sanitisation and notes that multi-pass overwriting is not inherently required.


Purge

Purge methods are intended to provide a stronger level of sanitisation than ordinary clearing while potentially allowing the device to remain usable.

Depending on the technology, this can involve techniques such as cryptographic erasure or appropriate device-specific sanitisation methods.

The correct technique depends heavily on the type of storage device.


Destroy

Destruction involves physically destroying the storage medium so it can no longer be used as a functioning storage device and the information cannot reasonably be recovered.

Examples can include:

  • Industrial shredding
  • Crushing
  • Disintegration
  • Pulverization
  • Other purpose-designed physical destruction processes

Physical destruction can be particularly appropriate for highly sensitive information, failed storage devices or equipment that will not be reused.

DoD 5220.22-M: What Is It?

If you have researched hard drive wiping standards, you have probably encountered DoD 5220.22-M.

The name became widely associated with multi-pass data overwriting and is still frequently used in data destruction marketing, software and procurement specifications.

However, there is an important distinction between the historical DoD 5220.22-M document and the modern use of the phrase “DoD compliant.”

DoD 5220.22-M was the National Industrial Security Program Operating Manual (NISPOM). The Defense Counter-intelligence and Security Agency states that the NISPOM rule in 32 CFR Part 117 replaced the previous NISPOM policy issued as DoD 5220.22-M, effective February 24, 2021.

Is DoD 5220.22-M Still a Data Destruction Standard?

This is one of the most important points for organisations reviewing their Information Technology & Cyber Security Policies.

DoD 5220.22-M should not be treated as a universal modern data destruction standard for every type of storage device.

The current NIST guidance specifically addresses the historical use of multiple overwrite passes associated with DoD 5220.22-M and explains that multi-pass overwriting is not necessary for the current clear sanitisation approach.

NIST SP 800-88 Rev. 2 was published in September 2025 and superseded SP 800-88 Rev. 1. The new revision places greater emphasis on an organisation-wide media sanitisation program and recommends using current standards such as IEEE 2883 for applicable sanitisation techniques.

Therefore, if a company’s policy, contract or customer requirement specifically says “DoD 5220.22-M compliant,” it is important to determine exactly what that requirement means and whether a newer approved standard can be used.

For modern storage, simply specifying a fixed number of overwrite passes is not necessarily the best approach

IEEE 2883: Storage-Specific Data Sanitisation Standard

Another important standard is IEEE 2883-2022, IEEE Standard for Sanitizing Storage.

IEEE describes 2883 as specifying methods for sanitising logical and physical storage while providing technology-specific requirements and guidance for eliminating recorded data.

This technology-specific approach is important because a traditional hard disk drive is fundamentally different from an SSD.

A sanitisation technique that is appropriate for one type of storage may not provide the same assurance on another.

IEEE 2883 therefore provides an important reference for organisations looking for a modern storage sanitisation standard.

IEEE 2883.1-2025, IEEE Recommended Practice for Use of Storage Sanitization Methods, was published in June 2025 and is an active standard.

It provides recommendations for using the sanitisation methods specified in IEEE 2883 to appropriately sanitise storage media before reuse, resale or disposal.

This is particularly relevant to IT asset disposition programs where computers and storage devices may be refurbished or resold rather than physically destroyed.

Hard Drive Destruction:
HDDs vs SSDs

One of the biggest challenges in modern data destruction is that not all storage devices work in the same way.

Traditional Hard Disk Drives

Traditional HDDs store information magnetically on spinning platters.

Depending on the circumstances, an appropriate software-based sanitisation method may be suitable when the hard drive is going to be reused.

If the drive is being permanently retired and contains highly sensitive information, physical hard drive destruction may instead be appropriate.

Solid-State Drives

SSDs use flash memory rather than spinning magnetic platters.

They can incorporate technologies such as:

  • Wear levelling
  • Spare cells
  • Internal controllers
  • Over-provisioned storage
  • Logical-to-physical address translation

As a result, simply overwriting the logical locations visible to an operating system does not necessarily provide the same assurance as it might on a traditional HDD.

This is why SSD data destruction should be approached using a method appropriate to the particular storage technology.

USB Flash Drives and Memory Cards

USB flash drives and memory cards also use flash storage and should not automatically be treated like traditional hard drives.

They can contain sensitive business information even though they are physically small.

A comprehensive data destruction service should therefore identify the type of storage before determining the sanitisation or destruction method.

Smartphones and Tablets

Old smartphones and tablets can contain substantial quantities of personal and business information.

Simply removing the SIM card does not destroy the information stored on the device.

A secure device disposal process should account for the internal storage and, where applicable, encryption credentials and other data that could provide access to information.

When Should You Wipe a Device?
and When Should You Destroy It?

The decision between sanitisation and physical destruction depends on the circumstances.

A device may be suitable for sanitisation when:

  • It is going to be reused internally.
  • It is going to be refurbished.
  • It will be resold.
  • The storage technology supports an appropriate sanitisation method.
  • The organisation’s risk assessment permits reuse.

Physical destruction may be more appropriate when:

  • The device is damaged or cannot be reliably sanitised.
  • The device contains highly sensitive information.
  • The device is being permanently retired.
  • Organisational policy requires destruction.
  • The potential consequences of data recovery are particularly serious.
  • The organisation cannot establish sufficient confidence in the sanitisation process.

The key is to make the decision based on risk, information sensitivity and storage technology, rather than using the same procedure for every device.

What Is Cryptographic Erasure?

Cryptographic erasure, sometimes called crypto erase, is another important technique in modern data sanitisation.

Where data is encrypted appropriately, destroying or sanitising the relevant cryptographic keys can make the encrypted information inaccessible.

NIST SP 800-88 Rev. 2 provides updated guidance around cryptographic erase and the types of keys that can be used, as well as key sanitisation.

Whether cryptographic erasure is appropriate depends on how the device was encrypted, how the keys were managed and the organisation’s security requirements.

It should not simply be assumed that because a device says “encrypted” it is automatically safe to dispose of without further consideration.

Why a Chain of Custody Matters

Secure data destruction is not just about what happens at the end of the process.

Organisations should also consider what happens to the device between collection and destruction.

A secure chain of custody can help ensure that a device containing confidential information is not lost, stolen or accessed before sanitisation.

A professional data destruction process may document:

  • Asset number
  • Device type
  • Serial number
  • Collection date
  • Location
  • Transport or custody information
  • Sanitisation or destruction method
  • Processing date
  • Verification or validation information
  • Final disposition
    Certificate of destruction or sanitisation

For organisations subject to contractual, regulatory or internal audit requirements, this documentation can be just as important as the physical destruction process.

Certificates of Data Destruction

A Certificate of Data Destruction or Certificate of Sanitisation provides documented evidence that a device has gone through the required process.

Depending on the organisation and service provider, a certificate may include:

  • Device identification
  • Serial number
  • Date processed
  • Sanitisation method
  • Destruction method
  • Organisation performing the work
  • Relevant standard or policy
  • Verification information
  • Final disposition

NIST SP 800-88 Rev. 2 includes an updated sample Certificate of Sanitization and places emphasis on sanitisation assurance, including verification and validation considerations.

When choosing a secure data destruction company, organisations should therefore ask not only, “Do you destroy hard drives?” but also, “What records and evidence do you provide?

Data Destruction Standards Compared

StandardPurposeModern relevance
DoD 5220.22-MHistorical U.S. defence industrial security manual associated with media clearing and sanitisationFrequently referenced, but should not be treated as the universal modern sanitisation standard
NIST SP 800-88 Rev. 2Guidance for establishing and operating a media sanitisation programCurrent NIST guidance
IEEE 2883-2022Storage sanitisation methods and technology-specific requirementsCurrent storage sanitisation standard
IEEE 2883.1-2025Recommended practice for applying storage sanitisation methodsCurrent guidance for reuse, resale and disposal
Physical destructionPermanently destroys storage mediaAppropriate where risk, condition or policy requires destruction

A Practical Secure Data Destruction Process

A robust organisational process can be structured around the following stages:

  1. Identify the device
  2. Record the asset and serial number where appropriate.
  3. Classify the information
  4. Determine the sensitivity of the information stored on the device.
  5. Identify the storage technology
  6. Establish whether it is an HDD, SSD, flash device, mobile device or another technology.
  7. Determine the disposition
  8. Decide whether the device will be reused, resold, recycled or destroyed.
  9. Select an appropriate sanitisation method
  10. Use a current, technology-appropriate standard or approved organisational procedure.
  11. Perform the sanitisation or destruction.
  12. Verify or validate the outcome where required.
  13. Record the process
  14. Maintain appropriate asset and destruction records.
  15. Issue documentation
  16. Provide certificates or reports where required.
  17. Complete final disposition
  18. Ensure the physical equipment is appropriately recycled, reused or disposed of.

This approach helps turn data destruction from an ad-hoc IT task into a controlled part of an organisation’s information security lifecycle.

Secure Data Destruction Is More Than a "Drive Wipe"

Old computers and storage devices can contain sensitive information long after users believe the data has been deleted.

Secure data destruction requires a deliberate process that considers the type of storage, sensitivity of the information and ultimate destination of the device.

Data Security & Secure Data Destruction
A Paramount Step In the Data Security Lifecycle

Call The Data Security Experts

"Transaction Error: Please Contact Your Financial Institution"

Error: