B BROCENT

Two Hundred Drives in a Store Room: A Singapore Manufacturer's Hardware Refresh Problem

A composite scenario from Singapore: a precision-electronics manufacturer consolidates two sites and refreshes an ageing fleet, and ends up with roughly two hundred drives locked in a store room because nobody can answer "can you prove the data is gone?" What a certified, per-serial disposal programme changes about that question.

A stack of internal hard disk drives on a plain background, representing the roughly two hundred drives a Singapore manufacturer accumulated in a store room after consolidating two sites and refreshing its PC and server fleet
In short: A Singapore manufacturer finished a two-site consolidation and ended up with roughly two hundred drives locked in a store room, because nobody could answer "can you prove the data is gone?" Certified IT asset disposal answers it with a per-device destruction certificate carrying serial number, method and date — plus a documented chain of custody from the moment the equipment is collected.

Why manufacturers end up with a store room full of drives

Singapore's precision-electronics and industrial manufacturers run a particular kind of IT estate. The office side looks like any other company of 150 to 250 staff — laptops, a finance system, Microsoft 365. The production side does not. There are engineering workstations holding CAD and process data, a handful of ageing servers running MES or quality systems, line-side industrial PCs that were commissioned once and never touched again, and tape or NAS archives that exist because a customer's quality agreement said records must be retained for a set number of years.

Two things follow from that shape, and both of them lead to the same store room.

The first is that hardware turns over in lumps rather than continuously. A services firm replaces laptops as they fail or as people join. A manufacturer replaces a whole fleet when a Windows version goes end-of-support, when a line is re-tooled, or when two sites merge and the duplicated kit suddenly has nowhere to go. Thirty machines come out in a week, not one a month. Nobody has a standing process for thirty machines a week, because it does not happen often enough to build one.

The second is that the data on that hardware is somebody else's. A precision-electronics manufacturer's engineering drives hold customer drawings, tolerances, process parameters and yield data — much of it covered by a customer NDA, some of it covered by a quality agreement that specifies how records are handled. That changes the question from "do we care about this old laptop" to "what did we promise a customer about their drawings, and can we still keep that promise once the machine leaves the building?"

Put those together and the honest answer, for a lot of manufacturers, is that the retired equipment goes into a locked room and stays there. It is not a decision. It is the absence of one.

The scenario: two sites become one, and the store room fills up

Here is a composite picture, drawn from how manufacturers of this size actually operate rather than from any one named client.

A Singapore manufacturer consolidates two facilities into one. At the same time, the office fleet is due for a refresh — the machines are five to six years old, several are out of warranty, and the new plant layout is the natural moment to standardise. Both projects are run by the same small internal team: an operations manager who owns the move, and one IT person who is also the helpdesk, the network, and the ERP liaison.

The consolidation goes reasonably well. The lines are moved, the network is rebuilt, the new machines are imaged and handed out. What nobody planned for is the outflow. Old desktops come off desks in batches. Two racks are emptied at the closing site, and the servers, switches and a small SAN come out with them. Drives are pulled from a few machines "to be safe" and put in a box. Someone brings over three shelves of legacy tapes because the closing site had nowhere to leave them.

Six weeks after the move, the store room holds something like two hundred drives — a mix of SAS and SATA spinning disks from the servers, 2.5-inch SATA SSDs from the desktop fleet, a smaller number of NVMe modules from newer workstations, plus the tapes, the switches, and about forty complete machines nobody has opened.

Three separate people have asked what happens to it. The operations manager gets a quote from a recycler that says "secure data destruction included" for a per-kilogram price. It looks cheap. He does not sign it, because when he asks the IT person whether that satisfies the customer NDA and the ISO 27001 evidence file, the answer is a shrug. Nobody signs off, because signing off means personally standing behind a claim — the data is gone — that nobody can currently substantiate.

The store room is not a storage problem. It is an accountability vacuum with a lock on the door.

What that store room is actually costing

It is worth being specific about the exposure, because "we should deal with that at some point" tends to survive until someone quantifies it.

Recoverable customer data is sitting on a shelf. A deleted file is not an erased file, and a quick format is not an erasure. Standard recovery tooling reads data back from drives that were "cleared" by a reinstall or a reformat. On the office side, that means finance and HR records. On the engineering side, it means customer drawings and process data — the material that a customer NDA specifically covers. The drives are physically inside the building, which feels safe, but the moment they leave through any route that is not documented, the exposure becomes real and unprovable in both directions.

There is no serial-level record of what came out of which machine. This is the failure that turns a manageable problem into an unmanageable one. Once drives are pulled and pooled in a box, the link between a physical drive and the machine, user, and data classification it came from is gone. Reconstructing it later is expensive and, past a certain point, impossible. An asset register that says "40 desktops disposed" is not evidence; an auditor's next question is always "which ones, and how do you know?"

An ISO 27001 or cyber-insurance question has no evidence behind it. Media disposal is a standard control area, and the evidence expected is documentary: a record showing what was destroyed, by what method, on what date, by whom. Manufacturers under customer quality audits face a near-identical question from a different direction — a customer's supplier audit asking how records covered by the quality agreement are disposed of at end of life. Both questions are answerable in ten minutes with certificates, and unanswerable without them.

Disposal quotes cannot be compared, because none of them define their terms. Three quotes arrive. One says "data wiped". One says "secure erasure to military standard". One says "certified destruction". None of them says which standard, applied to which media type, evidenced how. Priced per kilogram, they are indistinguishable, so the cheapest wins — and the cheapest is usually the one doing the least. The comparison is impossible not because the buyer lacks expertise but because the quotes were not written to be compared.

Equipment with real residual value is depreciating in a cupboard. Not all of it is scrap. Recent workstations, monitors, and network gear in working condition carry a resale value that falls the longer they sit. Two years in a store room reliably converts a modest recovery into zero, and the storage space was not free either.

Brocent's perspective: disposal is a chain-of-custody problem, not a scrap problem

Brocent has run IT operations across Asia since 2007, from Beijing originally, with a Hong Kong office since 2016 and the group's headquarters in Singapore since 2021. Enough of that work has been decommissioning — office closures, data-centre exits, plant consolidations — to make one thing obvious: the collection is the easy part. Anyone with a truck can collect. The deliverable that matters is the paperwork that lets somebody else verify the claim, years later, when the person who managed the project has left the company.

That reframes what you are buying. You are not buying destruction; destruction is straightforward. You are buying a defensible record that destruction happened, tied to specific serial numbers, produced by a process that is itself documented from the point of collection onward. If the record does not exist, the destruction may as well not have happened, because you cannot demonstrate it.

It also explains why the IT asset disposal service is built around a ten-step process rather than a collection date. Assets are inventoried, tagged and photographed on site against the client's asset register *before* anything moves. They are packed and sealed in padlocked bins. Transport is documented. Intake at the processing facility is stock-checked against the collection manifest. Only then does destruction begin — and each wipe produces a tamper-proof, per-device report with serial number, method and timestamp, with photo and video evidence for physically destroyed media. The final Certificate of Disposal lists every asset: serial number, asset tag, device type, destruction method, destruction date, and an individual certificate reference.

There is a second, quieter point. The same discipline that governs disposal should also prevent the opposite failure — replacing hardware that did not need replacing. A store room full of five-year-old machines is often the visible end of an invisible problem: nobody knows what is deployed, how old it is, or what condition it is in, so refreshes get decided by anxiety and budget cycles rather than by evidence. That is what asset-lifecycle tracking in BCS Beam, the endpoint agent behind Brocent's managed plans, is for — a live inventory of what exists, its age and its health, so refresh decisions are made from data. And where hardware is still serviceable, IT hardware maintenance usually extends the useful life more cheaply than a replacement does.

What a real disposal programme actually includes

Here is what should be in scope when you brief a vendor — and what to expect in return.

Inventory, tagging and sealing at the point of collection. Every device logged, tagged and photographed against your asset register before it leaves your site. This is the step that preserves the serial-to-machine link, and it is the step budget vendors skip, because it is the labour-intensive one. If it is missing, nothing downstream can be trusted.

A destruction method chosen per media type, not per invoice. This matters more than most buyers realise, and it is where a mixed manufacturing fleet gets interesting. Spinning HDDs can be software-erased to a recognised standard, degaussed, drilled, or shredded. SSDs and NVMe modules cannot be reliably degaussed at all — magnetic erasure does nothing to flash — so they need certified flash-aware erasure, mechanical bending, or shredding. Tapes are their own case. Network devices — switches, routers, firewalls — hold configuration, VLAN tables and credentials rather than user data, and need a proper console-cable factory reset rather than a wipe. Brocent supports more than 27 erasure standards, including NIST 800-88 Clear and Purge, DoD 5220.22-M, and cryptographic and firmware-based erasure, and applies certified software erasure (Blancco), degaussing, drilling, bending or third-party certified shredding according to what the media actually is.

One certificate per device, plus a consolidated report. An individual destruction certificate per device carrying serial number, method and date, and a comprehensive disposal report that lists every asset with its certificate reference. This is the artefact you file. When an auditor, an insurer, or a customer's supplier-audit team asks the question, this is the answer.

Certified e-waste recycling with an environmental certificate. Zero landfill, through a certified recycler, with the ESG documentation that increasingly gets asked for in the same breath as the data question — particularly by multinational customers running supplier sustainability programmes.

Residual-value recovery where it exists. Working equipment with a market should be remarketed or traded in, and the recovery should be visible and set against the project cost. It will not fund the project, but it should not be quietly absorbed by the vendor either.

Realistic logistics and lead times. Certified disposal has a supply chain, and a consolidation runs on a schedule, so these should be planned rather than discovered. Erasure licences and USB boot media are ordered per project. Warehouse storage takes several days to arrange. The degauss device is physically located in Beijing, which means three to five days' shipment within China and five to ten days to Hong Kong. Mechanical benders for flash media are a special order. None of this is a problem when it is on the plan; all of it is a problem when it is found on the day.

Multi-site collection coordinated as one project. For a manufacturer with a regional footprint, the practical requirement is one project manager, one certificate format and one consolidated report across sites — not a separate local vendor per country, each with its own paperwork, its own definition of "wiped", and its own idea of what evidence looks like. Brocent's collection reach spans over 100 countries, with processing across Hong Kong, China, Japan and Singapore.

Three ways manufacturers handle retired hardware

DIY wipe and a local recycler

  • What it is: the internal IT person reformats what they can, and a general recycler collects the rest by weight.
  • What you get: the lowest cash cost, and the equipment leaves the building.
  • What you do not get: any per-device evidence, any serial-level record, and any defensible answer to a customer or an auditor. Flash media in particular is frequently handled incorrectly, because a reformat is not an erasure and consumer tools do not address wear-levelled flash properly.
  • When it is genuinely fine: a handful of non-sensitive devices with no regulatory, contractual or customer-NDA exposure.

A general e-waste vendor

  • What it is: a licensed recycler with an environmental mandate, handling the collection and the disposal.
  • What you get: legitimate recycling, a company-level environmental certificate, and correct handling of the waste stream itself.
  • What you do not get: per-device data-destruction records. The environmental certificate proves the material was recycled responsibly; it says nothing about what was on the drives or how it was destroyed. These are two different claims, and they get conflated constantly in quotes.
  • When it is genuinely fine: monitors, cabling, peripherals, chassis — hardware with no storage media in it.

Certified IT asset disposal

  • What it is: a managed programme with inventory and sealing at collection, documented chain of custody, method chosen per media type, and per-device certification.
  • What you get: an individual destruction certificate per device with serial number, method and date; a consolidated disposal report suitable for an ISO 27001 evidence file, a cyber-insurance renewal, or a customer supplier audit; the environmental certificate as well; and residual-value recovery where it exists.
  • What you do not get: the cheapest per-kilogram number. It costs more than a recycler, because the inventory, the per-device processing and the documentation are real labour.
  • When it is the right answer: any volume of storage media that held customer, employee or regulated data — which, for a manufacturer under customer NDAs and ISO-audited processes, is most of it.

Frequently asked questions

Is a factory reset or a quick format enough?

No, and this is the single most common misunderstanding. A format rewrites the file system's index, not the data blocks; standard recovery tooling reads the underlying data back. Certified erasure to a recognised standard such as NIST 800-88 overwrites or purges the actual media and, critically, produces a verifiable per-device report. The report is as much the point as the erasure. A factory reset is appropriate for one category — network devices, where the objective is clearing configuration and credentials rather than user data — and even there it should be done properly over a console cable and documented.

When does a drive need to be shredded rather than wiped?

Software erasure is appropriate for most healthy drives and has the advantage of preserving residual value — a wiped, working drive can be remarketed. Physical destruction becomes the right answer when the drive has failed and cannot be written to reliably, when it will not present to the erasure tool at all, when the data classification or a customer contract requires destruction rather than erasure, or when the media type makes software erasure unreliable. Flash media deserves particular care: SSDs and NVMe drives should never be degaussed, since magnetic erasure has no effect on flash, and they need either certified flash-aware erasure or mechanical destruction. In practice a mixed fleet ends up with a mixed method list, and a good vendor will tell you which method applies to which media before quoting rather than after.

What document should we keep for an ISO 27001 or customer audit?

Two things. The individual destruction certificate for each device — serial number, device type, destruction method, destruction date, certificate reference — and the consolidated disposal report that lists every asset in the batch with its certificate reference. Together they close the loop from your asset register through to end of life. The environmental recycling certificate is a third, separate document that answers the ESG question, not the data question. Keep all three, and file them where the audit evidence lives, not in the project folder that gets archived when the project closes.

Can old equipment be worth anything?

Some of it, and less every month it sits. Recent workstations, laptops, monitors and network equipment in working condition have a resale market. Five-year-old line-side industrial PCs and failed drives generally do not. The practical guidance is to separate the decision from the delay: get the assessment done at collection, when the equipment is still worth assessing, and treat any recovery as an offset against project cost rather than as a reason to postpone. Before disposing at all, it is worth asking whether some of the fleet should simply stay in service — hardware maintenance on serviceable equipment is frequently cheaper than replacing it.

Who is liable if data is later recovered from a disposed device?

The organisation that held the data remains accountable for it; engaging a vendor does not transfer that accountability, in Singapore under the PDPA or in the other jurisdictions a regional manufacturer operates in. What a certified process gives you is evidence that you exercised proper control — a documented chain of custody, a defined destruction method, and per-device certification. That is the difference between an incident you can account for and one you cannot. This is a general description of how disposal evidence works and not legal advice; where a customer contract or a specific regulatory obligation is in play, take it to your own counsel.

Can collection be coordinated across our Singapore and regional sites at once?

Yes, and for a consolidation it is usually the better structure. One project, one manifest format, one certificate format, and one consolidated report across sites is far easier to audit than four local vendors producing four kinds of paperwork. Brocent coordinates multi-office collection across Hong Kong, China, Japan and Singapore, with collection reach in over 100 countries. The main planning constraint is lead time — certain tooling has a physical location and a shipping window, which is why the schedule is agreed before the first collection rather than after.

We have a consolidation deadline. How long does this take?

The processing itself is quick; the preparation is what needs the runway. Vehicle booking, packing materials, warehouse arrangements, erasure licences and specialised tooling each carry a few days to a couple of weeks, and specialised equipment such as the degauss device has a defined shipping time from Beijing. Given a device list, site addresses, access constraints and your required destruction methods and certificate format, the schedule can be built backwards from your deadline. The failure mode is not slow processing — it is discovering on collection day that the method your contract requires needs tooling that has not been ordered.

Where disposal fits: inside the plan, not beside it

The store room is a symptom. The underlying condition is that nobody owns the hardware lifecycle end to end — what is deployed, how old it is, when it should be replaced, what happens to it when it is, and where the evidence lives. Solved as a one-off, disposal clears the room and the same room refills after the next refresh. Solved properly, disposal is simply the last step of a lifecycle somebody is already managing.

That is why the practical recommendation for a Singapore manufacturer at this point is not to shop for a disposal vendor. It is to put the hardware lifecycle inside a managed IT plan — a named team, a live asset inventory, a maintenance path for equipment that should stay in service, and a certified disposal path with per-device certificates for equipment that should not. Brocent's plans are priced per user, per market, and published on the pricing page, so the comparison against your current arrangement is arithmetic rather than a discovery exercise.

Certified IT asset disposal is a real, separately available service, and if the immediate need is to clear two hundred drives with defensible certificates, it can be run as a standalone project. It is simply better value as the end of a lifecycle that is already being managed, rather than as an emergency at the end of a consolidation. If you have a device list and a deadline, get in touch and we will build the schedule backwards from it.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.