Firm Found No Wipe Certificates After 340 Leased Laptops Were Returned
A logistics and asset management firm discovered a critical data security gap after 340 leased laptops were returned to their lessor last spring without verified sanitisation records. An auditor's question revealed that while the company maintained a careful chain of custody for the physical devices, no process existed to confirm that data stored on them had been wiped. The problem extended further: 28 laptops were never returned by users, pre-2021 devices lacked full-disk encryption, and four multifunction printers were sent back on a separate lease with drives that had been caching scanned finance documents. In response, the company overhauled its disposal process so that sanitisation now occurs before collection, with destruction certificates reconciled against the asset register on a per-serial-number basis. Lost devices are now treated as security incidents rather than simple financial write-offs, and all storage-bearing equipment — including printers and network devices — falls under the revised policy.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in