The Vulnerability ITAD Still Won’t Address

The Vulnerability ITAD Still Won’t Address

Why the Accountability Gap Is No Longer Defensible

After September 11, the control changed: cockpit doors locked, passengers screened, access controlled.

Imagine an airline arguing that trust in passengers made a locked cockpit door unnecessary. Then imagine the unthinkable happened.

The first question wouldn’t be about the passenger. It would be: Why was the door unlocked?

Because once a vulnerability is understood and a reasonable control exists, choosing not to use it becomes increasingly difficult to defend.

IT asset disposition has its own known vulnerability. Morgan Stanley learned it the hard way.

Morgan Stanley has since paid $161.5 million in ITAD-related penalties stemming from failures that included 42 missing decommissioned servers. But those missing servers weren’t uncovered through Morgan Stanley’s routine ITAD controls. The issues surfaced when Arrow Electronics, its ITAD vendor, announced it was exiting the business in 2019. This led Morgan Stanley to check the assets it thought were sent for destruction against the actual records of what was received and processed.

The reconciliation worked. The problem was when it happened. Had expected versus received been independently reconciled on every project, discrepancies could have been identified while the assets could still be held, not after Arrow left the industry.

That’s the accountability gap. Organizations give data-bearing assets to employees, logistics providers, and disposition vendors. Then, they accept inventories and certificates from that same chain of custody as proof everything worked.

Trust is important. Trust is not a control.

Morgan Stanley’s lesson isn’t “pick a better vendor.” It’s that no organization should rely solely on the people performing a process to prove the process worked.

The control is simple. Establish what is expected before disposition begins. Independently compare that to what the receiving party reports. Require an explanation for every discrepancy from someone who did not create either list.

Expected versus actual. Every asset. Every project. Independently verified.

A control that starts when the vendor’s inventory is created cannot catch an asset that never reached that inventory.

Twenty-five years on, nobody argues that a locked cockpit door signals distrust of pilots. Some controls exist because the cost of failure is too high to leave to trust.

ITAD deserves the same standard.

If another major ITAD breach happens tomorrow, the hard questions won’t be, “Who was your vendor?”

They’ll be:

What did you know about the risk?

What controls did you have?

How did you independently confirm every expected asset was accounted for?

And the hardest one:

If you knew assets could vanish without showing up in your vendor’s inventory, why didn’t you create a control to catch that?

Morgan Stanley gave the industry its warning.

The vulnerability is known. The control exists.

Is it still reasonable to leave the accountability gap open?

Recent Posts

  • In The News

Defensible Asset Disposition Framework

Breach after breach has shown that IT asset disposition is a blind spot. The Defensible…

1 year ago
  • In The News

Certification vs Verification in ITAD

Certification in ITAD proves vendor credibility, while verification ensures ongoing compliance. Veridy Verification enhances security,…

1 year ago
  • In The News

USAID’s Reckless ITAD Gamble

Federal Agency takes risky ITAD gamble with remote wiping. Fired USAID workers will have to…

1 year ago
  • In The News

3 Myths About Fixing Bad ITAD

ITAD fears costing you? Debunk 3 myths! Fixing IT asset disposition is simpler, cheaper, &…

1 year ago
  • In The News

ITAD Asbestos

CISO Alert: Don't let ITAD blind spots become a career-ending SEC fine. Neglected IT disposal…

1 year ago
  • In The News

CISO Guide to ITAD

CISO Alert: Don't let ITAD blind spots become a career-ending SEC fine. Neglected IT disposal…

1 year ago

This website uses cookies.