The Lease Ended and the Racks Were Still Full: Data Centre Decommissioning in Singapore
A composite scenario from Singapore: a colocation lease reaches its end date with two racks still installed, no current inventory, and a restoration clause discovered six weeks out. Why a decommission is four projects rather than one, the ten-stage process in order, the lead times that actually cause missed deadlines, and what a quote really depends on.
Published
Short answer: A Singapore data-centre lease exit is four distinct projects, not one — a documented inventory, certified data destruction, physical un-racking and pack-out, and restoring the space to the condition your contract specifies. Treating it as "clear out the racks" is what produces lease-end scrambles. Scoping typically starts weeks earlier than companies expect, because tooling and logistics have their own lead times.
Why Singapore companies end up with a lease-end problem they never planned for
Singapore has an unusually large amount of colocated enterprise infrastructure for the size of the country, and a lot of it was installed years ago by companies that are no longer configured the way they were when they signed.
Some of that infrastructure is being consolidated after an acquisition. Some is being migrated to cloud, leaving a rack of equipment that used to be the whole environment. Some companies are simply changing providers, or moving from a full cabinet to a half. The common thread is that a colocation contract, unlike an office lease, tends to be managed by whoever originally set it up — and that person has frequently moved on.
What makes a data-centre exit different from an office move is that the obligation runs in two directions at once. You have to get your equipment out, and you have to hand the space back in a defined state. Racks cleared. Cabling removed. Cable trays and floor tiles as they were. Depending on the contract, power and cooling infrastructure returned to its original configuration.
That second obligation is the one that gets discovered late, because it lives in a clause that nobody has needed to read since signature.
The scenario: two racks, a restoration clause, and six weeks
Consider an illustrative composite — not a named client, but a pattern we see with some regularity.
A Singapore company of about a hundred and twenty staff runs a professional-services business with a technical delivery arm. Years ago it took two racks in a colocation facility to host its production systems. Most of that workload has since moved to cloud. What remains in the racks is a mixture: a few servers still doing real work, a storage array that was decommissioned in place and never removed, two switches, a firewall pair, a patch panel, and a bottom shelf of equipment nobody has identified in several years.
The colocation contract reaches its end date in six weeks. The facilities lead — who inherited the relationship, and whose actual job covers premises, vendors and health-and-safety — pulls the contract to check the notice period, and finds a restoration clause. The space is to be handed back in its original condition.
Here is the position she is actually in:
- There is no current inventory. There is an asset register, but it was last reconciled two refresh cycles ago and does not match what is physically in the racks.
- Nobody can say with confidence which drives contain data that requires certified destruction and which are empty. The decommissioned storage array is the obvious question mark, and the bottom shelf is a complete unknown.
- Two of the remaining servers are still in production. They need to be migrated or shipped and re-racked somewhere, not disposed of — and that has to happen before anything else can be pulled.
- The switches and firewalls hold configuration: VLAN tables, routing, credentials, VPN definitions. Wiping a drive does nothing for these.
- The restoration clause is not quantified anywhere. What "original condition" means for this cabinet is a question for the facility, and nobody has asked it.
- Facility access requires registered engineers, and the registration itself takes time.
The internal instinct at this point is usually to call a moving company and book a van. That instinct is what turns a manageable project into a scramble.
What actually goes wrong, and why it costs more than it should
The four failure modes we see at lease-end are all consequences of treating decommissioning as one task rather than four.
The inventory happens after equipment has moved. This is the most expensive mistake available, because it is unrecoverable. Once devices are out of the racks and in a van, the relationship between "what was in position 14 of rack B" and "this server" is gone. If you later need to prove that a specific serial number was destroyed to a specific standard on a specific date — for an ISO 27001 audit, a cyber insurance renewal, or a client's supplier questionnaire — you cannot reconstruct it. The inventory has to be the first step, not a reconciliation exercise afterwards.
Data destruction gets conflated with hardware removal. A logistics company will move your racks competently. It will not wipe your drives to a standard, it will not produce a per-device certificate, and it will not factory-reset your firewalls. Those are separate disciplines with separate evidence requirements, and discovering the gap after the equipment has left is a bad time to discover it.
Network devices are forgotten. Almost every decommissioning checklist we see covers drives and misses switches, routers and firewalls. Those devices carry configuration data and stored credentials, and a drive-wiping process does not touch them. They need a professional factory reset over a console cable — which is a five-minute job per device, and a real exposure if skipped.
Restoration is priced last, after the deadline is immovable. DC condition restoration is genuinely variable work: clearing cabling and trays, returning the cabinet to its handover state, and whatever else the specific clause requires. Its cost and duration depend on how the space was actually built out, which is why it needs to be scoped against the clause and the facility early — not estimated in the final week.
And underneath all four is a timing problem that has nothing to do with effort. Decommissioning depends on physical inputs with their own lead times: booking a suitable van or cargo vehicle takes around two days; buying packing materials — bubble film, tape, secure lockable bins — two to three days; arranging third-party warehouse storage three to five days; a per-project Blancco erasure licence two to three days of order processing; a USB boot drive two to three days; an isolated-lab 4G router two to three days. If certified degaussing is required, our degauss device is physically located in Beijing, and shipping it runs three to five days within China and five to ten days to Hong Kong.
None of those is long on its own. Run sequentially in the last fortnight before a lease-end date, they are exactly how a project misses a deadline that was always achievable.
Brocent's perspective: decommissioning is an evidence project that happens to involve moving hardware
We have run IT asset disposal and site decommissioning across Hong Kong, mainland China, Japan and Singapore for years, and the framing we would press on anyone facing a lease exit is this: the hardware leaving the building is the easy part. What you are actually producing is a documented chain of evidence that survives an audit, and the hardware movement has to be organised around that requirement rather than the other way round.
That reframing changes the order of operations in a way that matters.
If the goal is "empty the racks," you start with a van. If the goal is "be able to prove, per serial number, what happened to every device that was in this space," you start with an onsite inventory in which every device is tagged, photographed and logged against the asset register *before anything moves* — and every subsequent step inherits that identity. The van comes fourth.
It also changes what "done" means. A decommission is not finished when the cabinet is empty. It is finished when you hold a Certificate of Disposal listing every asset by serial number, asset tag, device type, destruction method, destruction date and individual certificate reference — the document that answers an ISO 27001 auditor, a cyber insurer, or a client's supplier questionnaire without further work.
The second thing we would press is that a lease-end scramble is a symptom, not the problem. The reason nobody knew what was in the bottom shelf of rack B is that asset lifecycle was never anybody's ongoing job. That gap does not close by executing one clean decommission project. It closes by putting asset lifecycle governance inside an ongoing IT management arrangement, so that the next refresh, closure or migration starts from a register that is actually current.
What a data-centre decommission actually involves, step by step
Brocent's ITAD process for a site decommission runs as ten defined stages. It is worth reading them in order, because the order *is* the method.
1. Onsite asset inventory. Engineers arrive and conduct a full inventory. Every device is tagged, photographed and logged against your asset register before any equipment is moved. This is where the bottom-shelf unknowns get identified and where the audit trail begins.
2. Un-rack and pack. Devices are carefully de-racked, packed with bubble film to prevent physical damage, and placed in secure sealed bins with padlocks. "Un-rack and pack" is a specific discipline — cable management, rail removal, weight handling and sequencing so the cabinet comes down safely — and it is the step a general moving company is least equipped for.
3. Secured transport. A dedicated van or cargo vehicle takes the sealed bins to the processing facility, with chain-of-custody documentation maintained throughout transit so no device is unaccounted for between the cabinet and the lab.
4. Warehouse intake. Assets are received and stock-checked at the processing warehouse. Erasure licences and USB boot tools are prepared and assigned per batch.
5. Lab setup and data wipe. A local processing lab is set up with network access, and Blancco data wipe is executed device by device to NIST 800-88, DoD 5220.22-M, or another specified standard. Each wipe generates a tamper-proof erasure report carrying the device's serial number, the method applied and a timestamp.
6. Photo and video evidence. Photographs and short videos are taken of each device during and after destruction as supplementary evidence — particularly for HDDs and SSDs that are physically destroyed alongside or after wiping.
7. Network device reset. For routers, switches and firewalls, a console cable is used to perform a professional factory reset, removing configuration data, VLAN tables and access credentials. This is the step most in-house checklists miss.
8. Report review and QA. The erasure report is reviewed to confirm no devices are missing or failed. Any gaps are escalated and resolved before the batch is cleared — because a batch with one unexplained device is a batch that will not satisfy an auditor.
9. Pack for shipment or disposal. Processed devices are re-packed to shipping standards, and arrangements are made either with the certified e-waste recycler or with your designated delivery address.
10. Certificate of Disposal issued. The final certificate lists every asset: serial number, asset tag, device type, destruction method, destruction date, and individual certificate reference.
On destruction method, the honest position is that it depends on the media and on what your obligations require, and the options are genuinely different:
- Blancco data wipe — software overwrite to NIST 800-88, DoD 5220.22-M or a specified standard, with a tamper-proof per-device erasure report. Licensed per project.
- Physical punch or drill — an electric drill applied three times to the platter, rendering an HDD physically unrecoverable. Fast, executable on site, and the right answer when software wiping is not feasible.
- Degaussing — a certified degauss device exposes HDDs to a powerful magnetic field, permanently destroying all magnetic domains. Irreversible and verifiable. Our device is in Beijing, which is why it carries a shipping lead time.
- SSD/HDD bending — a mechanical bender destroys flash-based storage, rendering the chips physically unreadable. Special order from the USA.
- Industrial shredding — a third-party certified shredder reduces media to fine particles. The highest level of physical destruction, and the one typically required by government and financial-institution standards.
- Manufacturer reset — professional factory reset of network and mobile devices over console cable. Available immediately.
Not every device needs the most aggressive method available. A drive that has never held regulated data and is going to remarketing is not the same problem as a drive out of a decommissioned storage array. Matching method to media and obligation is most of the scoping work.
What a decommission quote actually depends on
Because "what does this cost?" is usually the first question, it is worth being specific about what moves the number — and about what we need before we can answer.
Eleven factors drive the effort: device quantity, which sets shipment logistics and labour hours; device dimensions, which set vehicle size and packing requirements; device weight, which sets engineer count and vehicle load; site location and travel; the delivery-site location if equipment is being shipped back rather than disposed of; DC conditions, which set work complexity and the engineer skill set required; work schedule, since overtime and non-business-hours work carry different labour rates; disposal methods and tooling; inventory and audit requirements, which add man-hours; packing materials; and third-party warehouse storage if the equipment needs to sit somewhere.
To scope it properly we ask for a specific list: the complete device list with specifications; site addresses and working hours; the possible date and time range for collection; the type of HDD/SSD disposal method required; whether DC condition restoration is required; the certificate type and format you need; your inventory, audit and report requirements; onsite work instructions and site access guides; engineer registration requirements including NDAs and DC access tickets; and the project deadline.
Two of those deserve highlighting for a lease exit specifically. The restoration requirement should be read directly out of your contract and confirmed with the facility, not assumed — it is the single largest source of scope surprise. And engineer registration with DC access tickets takes real calendar time, which means the access paperwork should start in parallel with the inventory, not after it.
Where hardware retains market value, remarketing or trade-in can offset part of the disposal cost — which is worth assessing before disposal is booked rather than after. And after data destruction, hardware goes through certified e-waste recyclers on a zero-landfill basis, with compliance to local environmental regulation in Singapore, Hong Kong, China and Japan, and ESG recycling certificates provided.
Three ways to handle a data-centre lease exit
Doing it in-house against a fixed deadline
- What it is: your own team inventories, wipes, un-racks and clears the space, coordinating vehicles and access itself.
- Where it genuinely wins: a very small footprint — a couple of devices, no regulated data, no restoration clause — where coordination overhead would exceed the work.
- Where it breaks: evidence and lead times. Producing per-device destruction certificates to an auditable standard requires licensed erasure tooling and a controlled process; assembling that from scratch in six weeks, alongside everyone's actual jobs, is where deadlines get missed.
- The specific risk: an inventory taken after equipment has moved, which cannot be repaired later.
- Honest verdict: viable at trivial scale, and the highest-scramble option at two racks with a restoration clause.
A general moving or logistics company
- What it is: a professional mover handles de-racking, packing and transport.
- Where it genuinely wins: the physical movement. Good movers are good at moving things, and if all you need is equipment relocated intact to a new facility, this is a reasonable answer.
- Where it breaks: everything that is not movement. No certified data destruction, no per-device certificates, no network-device factory resets, no restoration scoped against your clause, and no chain-of-custody documentation designed to survive an audit.
- The specific risk: the gap is invisible until someone asks for evidence — typically at an audit or an insurance renewal, months later, when the drives are gone.
- Honest verdict: fine as one component, insufficient as the whole answer whenever data-bearing media or a restoration obligation is involved.
A specialist decommissioning service covering inventory, destruction and restoration
- What it is: Brocent's model — the ten-stage process above, run as one project: inventory first, chain-of-custody transport, certified destruction matched to media and obligation, network device resets, QA on the erasure report, restoration scoped against the actual lease clause, and a Certificate of Disposal at the end.
- Where it genuinely wins: anything where you will later have to prove what happened. ISO 27001 audits, cyber insurance renewals, client supplier questionnaires, and regulated-sector obligations all ask for per-device evidence.
- What it costs: scoped rather than list-priced, against the eleven factors above. There is no honest single figure for a decommission, because two racks of blade servers with a restoration clause and two racks of switches without one are not the same project.
- Where it needs care: timing. The lead times are real and mostly sequential. Start the scoping conversation earlier than feels necessary.
- Honest verdict: the right model for a lease exit involving data-bearing media, a restoration clause, or any audit obligation — which is most lease exits.
Frequently asked questions
What does "un-rack and pack" actually involve?
De-racking devices carefully, packing them with bubble film to prevent physical damage in transit, and placing them in secure sealed bins with padlocks. In practice it also involves cable management, rail and mounting hardware removal, weight handling for heavier chassis, and sequencing the take-down so the cabinet comes apart safely. It is the step where a general mover is least equipped, because the risk is not just breakage — it is losing the link between a device and its recorded position and identity.
Do we need data destruction certificates for decommissioned drives?
If you hold ISO 27001, carry cyber insurance, answer client supplier questionnaires, or operate under sector regulation, then in practice yes — and you need them per device, not per project. Our process issues a tamper-proof erasure report per device carrying the serial number, method and timestamp, plus a final Certificate of Disposal listing every asset by serial number, asset tag, device type, destruction method, destruction date and individual certificate reference. The reason to insist on per-device evidence is that audits ask about specific assets, not batches.
How long does a full decommission take?
The on-site and processing work is usually not the constraint. The lead times are: van or cargo vehicle around two days; packing materials two to three days; warehouse storage three to five days; a per-project erasure licence two to three days; USB boot drive two to three days; isolated-lab router two to three days; and if degaussing is required, shipping our Beijing-based degauss device runs three to five days within China or five to ten days to Hong Kong. Add engineer registration and DC access tickets, which are facility-dependent. The practical guidance for a Singapore lease exit is to start scoping several weeks before the end date, and to run access paperwork in parallel with the inventory.
What if we do not know what is in every rack?
That is the normal starting position, and it is exactly what stage one addresses. The onsite inventory tags, photographs and logs every device against your asset register before anything moves — so unknowns are identified and classified while they are still in position, which is the only time that identification is reliable. An incomplete asset register is a reason to inventory first, not a reason to delay.
Does this cover facility restoration, or only hardware removal?
Both, and restoration is scoped separately because it varies so much. Our data-centre decommission scenario explicitly covers decommissioning all hosted devices and restoring DC conditions — racks cleared, cabling removed, all data destroyed to standard. Whether restoration is required, and to what standard, is one of the specific scoping questions we ask, and it should be read out of your contract and confirmed with the facility rather than assumed. "DC conditions" is also one of the eleven pricing factors, because it drives both work complexity and the engineer skill set needed.
Can hardware be shipped to another site instead of disposed of?
Yes — that is a distinct scenario rather than an exception. DC decommission and ship back covers wiping all devices and shipping them to your designated location, with destruction certificates issued before shipment. Decommission and relocation covers decommissioning at one site, wiping, and relocating equipment to a new office or warehouse, combining ITAD with an IT relocation project. In a mixed lease exit — some equipment still in production, some retired — both paths run in the same project, which is why the inventory has to classify devices by destination as well as by media type.
What happens if we miss the lease-end deadline?
Commercially that is between you and the facility, and the terms vary — which is precisely why we would rather you did not find out. The mitigation is structural rather than heroic: start the inventory early, run engineer registration in parallel, confirm the restoration requirement against the clause in week one, and order tooling and logistics on the lead times above rather than sequentially at the end. Most missed data-centre deadlines are not caused by the work taking longer than expected. They are caused by a two-day vehicle booking and a three-day licence order being discovered in the final week.
What about the network devices and the equipment still in production?
Switches, routers and firewalls need a professional factory reset over a console cable to remove configuration, VLAN tables and stored credentials — a drive-wiping process does nothing for them, and this is the most commonly missed item on an in-house checklist. Equipment still in production has to be migrated or shipped and re-racked before the pull-out sequence can proceed, which makes it a dependency on the project plan rather than a line on the disposal list. Both get classified during the stage-one inventory, which is another reason it comes first.
Where this belongs: asset lifecycle inside the plan, not a call at lease-end
We would rather help you execute a clean decommission than watch one go badly, so the practical offer is straightforward: if you have a Singapore data-centre lease approaching its end date, the first useful step is a scoping conversation and an onsite inventory, not a quote request.
But the more useful point is about why the scramble happened.
The composite company above did not have a decommissioning problem. It had an asset lifecycle problem that presented as a decommissioning problem. Nobody owned the register, so nobody could say what was in rack B. Nobody had read the restoration clause, because reading contracts you are not currently executing is not anybody's job. A perfectly executed decommission fixes the immediate deadline and leaves that gap exactly where it was — waiting for the next office move, the next refresh, or the next migration.
Closing it means asset lifecycle sitting inside an ongoing IT management arrangement: an inventory that stays current because something keeps it current, hardware whose end-of-life is anticipated rather than discovered, and a named vCIO who tracks contract dates and asks the awkward question a year out rather than six weeks out.
That is how Brocent's managed IT plans are built — a per-user monthly plan carrying monitoring, patching, security governance, backup and disaster recovery, and a named vCIO with a technology roadmap, with asset lifecycle governance running inside it and project services like decommissioning, IT asset disposal and relocation scoped on top when a site event actually requires them. Singapore per-user pricing is published on the pricing page, so the comparison between "one-off project spend at every site event" and "governance that prevents most of them" can be run with real numbers.
If your lease-end date is already in sight, start with the inventory and the restoration clause. If it is a year out, that is a much better conversation to have. Either way, get in touch and we will scope from your device list and your contract rather than a generic template.
*The company described here is an illustrative composite of the decommissioning and asset disposal projects Brocent runs across Singapore and Asia, not a named client. Service scope, destruction methods, process stages, pricing factors and lead times cited are Brocent's published ITAD service details and are confirmed at scoping. Brocent was founded in Beijing in 2007, opened its Hong Kong office in 2016, and has been headquartered in Singapore since 2021.*
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.