Nabel Solutions

Resources

How do you prove which drive was destroyed?

The serial number gets recorded. It just doesn’t get recorded where the destruction happens — and a record made somewhere else, earlier, by someone who then walked the drive across a floor, is an assertion rather than evidence for one.

Applies toUnited States

Published September 10, 2026 · Last checked September 10, 2026

The middle

A diplomatic bag is not trusted. It is accounted for.

A diplomatic bag travels between two secure buildings by way of airports, loading docks and public roads — entirely ordinary places, none of them secure. Nobody resolves this by declaring the journey safe. The bag is sealed, marked, documented and accompanied, so that afterwards the middle can account for itself.

A hard drive leaving a decommissioned rack makes a shorter journey, through fewer hands, often carrying more regulated data than the bag. Its serial number is almost certainly written down. The question this piece is about is not whether it was written down, but where, when, and by whom.

A certificate of destruction is a record of an assertion, not evidence for it. Someone attested to it, and the attestation is only ever as good as the process that produced it.

This is not an accusation. Operators handing over that certificate are meeting the requirement as written, and passing their audits doing it. The gap is structural, not careless — and structural gaps are the ones worth writing about, because nobody has to be at fault for them to matter.

Record and evidence

The serial is captured. It is captured in the wrong place.

The loose version of this argument is wrong and an operator will say so in the first reply. Regulated operators already capture serial numbers. A barcode scanner and a spreadsheet solved that years ago, and any facility carrying a certification worth the name is doing it.

The gap is when and where the record gets made. The serial is read at a bench. The destruction happens later, at a machine, in another part of the building, with a person and an interval in between. Two records exist and nothing binds them to each other. What the second one attests is that a device went into a shredder; what the first one attests is that a particular device was, at some earlier point, in somebody’s hand.

A record and a piece of evidence are not the same object. A record is a statement that something happened. Evidence is what makes the statement difficult to doubt. Contemporaneity means the record being made at the time and place of the event. This is the difference, and it is this which most of our current processes and systems lack.

People are not the weak link because they are dishonest. Insider threat is real but rare; ordinary error is neither. Four hundred devices into a long, repetitive job, typing a serial with two digits the wrong way round, or missing a drive off the sheet, is not a character flaw — it is what happens when you ask a person to do something monotonous, accurately, for hours. Any control resting entirely on sustained human attention is a control with a known failure rate and no instrument to detect it.

What it costs when the middle cannot account for itself

  • Business partner and supply chain compromise carries the longest breach lifecycle in the IBM study — 258 days to identify and contain (IBM, 2026). An IT asset disposition provider is, structurally, exactly that kind of partner.
  • The global average cost of a breach reached $4.99M, and $11.5M in the United States (IBM, 2026).
  • A gap you cannot evidence is a gap you cannot close retrospectively; when the question is finally asked, the drives are already shredded and there is nothing left to re-examine.

The standard

The standard already asks for this. It does not say how.

There is a version of this argument that does not depend on our opinion at all, and it sits inside a certification scheme most operators already hold.

R2v3’s Appendix B governs data sanitization, and it covers physical destruction as well as software erasure. Two requirements in it are worth reading closely.

Appendix B (2) — “For traceability, records shall be kept of the unique identifier of each data storage device or tracking through other means from the point of control by the R2 Facility through the sanitization process” (SERI, R2v3, Appendix B).

Appendix B (5)(f) — effective security controls shall include “Inventory tracking to identify the physical location of any recorded data storage device at any time while in the R2 Facility’s control” (SERI, R2v3, Appendix B).

Read those together and the scheme has already asked for what this piece is about: per-device traceability through sanitization, and the ability to say where a given device is at any moment. What it does not do — deliberately, so that the requirement fits a one-van operator and a national chain in the same document — is say how. Those five words, or tracking through other means, are what make a barcode gun and a spreadsheet a conforming method. Nothing requires the record to be made at the moment, made where the event happens, or bound to the destruction event.

The standard set a floor and left the method open. The floor became the ceiling, because nothing better was offered.

There is also an asymmetry inside the same appendix. For logical sanitization, requirement (10) asks for “electronic records of data sanitization created by the software used to sanitize the data … for each unique identifier of the data storage media” — a record made by the tool that did the work, per device. For physical destruction, requirement (7) specifies methods, requirement (9) requires video recordings of the destruction to be kept for at least sixty days, and the quality control step reconciles quantities processed against quantities received.

R2v3 asks you to record which device you erased, and how many you destroyed.

NIST says the same thing about the middle

The point is not ours alone. NIST’s Guidelines for Media Sanitization, revised in September 2025, sets out what a certificate of sanitization should record — manufacturer, model, serial number, media type and source, method, technique, tool and version, verification method, and who performed it. Then it adds a paragraph about what those certificates are worth:

The value of a certification of media disposition depends on the organization’s handling of ISM over the ISM’s life cycle … If there is a breakdown in tracking at locations other than the post-sanitization destination, sanitization records will only show that specific ISM were sanitized and not whether the organization is effectively sanitizing all ISM that have been introduced into the operating environment.

— NIST SP 800-88 Rev. 2, § 4.6

Where tracking breaks between locations, the records prove that these devices were sanitized — not that everything was. NIST is writing to the organisation that owned the data rather than to the operator destroying it, which is the point: this is the client’s exposure, and the operator is who they need it from.

That is guidance rather than a requirement; 800-88 says should, not shall.

A camera pointed at a shredder evidences that a device was destroyed. It does not evidence which device was destroyed.

The serial is readable in a scanner at a bench. It is not readable in a video of a drive going into a cutting head. So the scheme asks for a hard record of the event and a separate, earlier record of the identity, and leaves the operator to say that the two are about the same drive.

Anyone who has worked in physical security will recognise the shape of this. It is an identity scanner fitted to a door in another room. You can show that someone badged in, and you can show that a door opened, and you cannot show that the same person did both. The answer to that has always been to colocate the two. Or better still, a mantrap — one door at a time, the check made inside the space, nobody through without it — and what a mantrap does is force the two events to happen in the same place.

The certificate is the assertion that stands in for that. The rest of this piece is about what a mantrap looks like for a hard drive.

The audit

What an auditor is actually testing, and how evidence gets graded

An information security audit runs in two halves. The first tests the documentation: what you say you do. The second tests reality: whether you demonstrably do it. Most findings live in the distance between them — and the person who writes a procedure is rarely the person who has to carry it out at pace.

Evidence is graded rather than treated as present or absent, and the grading is published. The Australian Cyber Security Centre’s Essential Eight assessment guidance sets out four levels, and assessors are told to gather the highest quality evidence that is reasonably practicable (ACSC, Essential Eight assessment guidance).

  1. Excellent — Testing a control with a simulated activity designed to confirm it is in place and effective — for example, attempting to run a test application to check application control rulesets.
  2. Good — Reviewing the configuration of a system through the system’s interface, to determine whether it should enforce an expected policy.
  3. Fair — Reviewing a copy of a system’s configuration — reports, screenshots — to determine whether it should enforce an expected policy.
  4. Poor — A policy or a verbal statement of intent: controls mentioned in documentation, or described in an interview with the people who run the system.

Put a decommission against that scale and the picture is uncomfortable. The certificate of destruction is Poor evidence. It is a statement of what was done, offered by the people who did it — the same class as a control described in an interview. The bench scan and the destruction video together are Fair to Good: real system output, reviewed after the fact, each of them true about something. Neither is a test of the control that matters, because neither can be made to answer the question did this drive reach the machine.

An example from well outside this industry, which every organisation will recognise. Annual security training comes round; the dashboard shows the organisation red; people simply click through to the end as fast as the module allows. The requirement was well intentioned and the completion record was accurate. It evidenced nothing. What closed it was not a better policy but instrumentation: a test at the end, automatic loss of email access when training lapsed, a timed test, and the assessor reviewing how long each person had taken to complete the module.

A completion tick is the certificate. Time-on-task is the record that says whether the tick was plausible. Nothing on this scale gets to Excellent by being written down better — it gets there by being tested by the activity itself.

The reframe

What needs recording is the data security state, not just the journey

The objection to everything above is that tracking every inch of a drive’s movement through a facility is unrealistic, and it would be. But the key is not necessarily to know where each asset is precisely. It is to know what data security state each asset is in, when that state changes, and that the necessary safeguards were in place during the movement in between.

Every organisation already works this way somewhere. Take an employee laptop. Its location is not specifically known at any given moment — it is on a train, in a house, in a bag — and nobody treats that as a failure of control. Its data security state is known: full disk encryption, a screen lock, a remote wipe, a policy about what may be held locally. Compensating controls cover the part you cannot see. Nobody asks for the breadcrumb trail, because with those controls in place the data was never at risk.

A drive in a locked rack is in a known state, held there by controls: keys under control, a named list of holders, separation of duties, entries logged. A drive in a sealed media vault is in another known state. What a risk owner and a regulator need is confidence that confidentiality and integrity held across the transition — and, where the device was briefly in a weaker state, that compensating controls covered it.

DATA SECURITY STATE LOCKED RACK keys controlled SEALED VAULT dual control SECURE STORE access control DESTROYED at the cutting head STATE CHANGE 1 Out of the rack two-person rule, scan at removal SCANNED AT A BENCH STATE CHANGE 2 Into the store seal intact, entries logged NO ASSET LINK STATE CHANGE 3 Into the feed covered feed, filmed per R2v3 FILMED, NOT NAMED Every step is recorded. No record is made where the event happens. A MODEL, NOT AN OBSERVATION Derived from published requirements and the controls a risk owner would expect — not from a decommission we have watched. Tell us what we have wrong.
A decommission drawn as states rather than places. The controls under each state change are what a risk owner would expect to hold across it; the pill beneath says what the surviving record can actually establish.
State change Controls that must hold Record made today What it establishes
Out of the rack Two-person rule; keys and holders controlled; scan at removal Serial, scanned at a bench That this device existed and was handled — at a time and place that is not the destruction
Vault into secure store Seal intact; entries logged; access-controlled area, cameras Seal and entry log That a sealed container moved. Nothing at asset level
Store to dock or shredder room Seal intact; handover recorded Consignment note One record per load
Vault into the feed Covered feed; no hand access; inspection of vault and belt after Video recording, per R2v3 Appendix B (9); device count; certificate That devices were destroyed. Not which ones

Each row describes what a certified facility typically holds. What varies between facilities is how much of it is joined up — and that is the question we are asking rather than answering.

Objections

Four answers a reader will want before they go further

“It never leaves our secure floor.” Then why are the racks locked? Access control inside a facility exists because need-to-know does not stop at the front door — not everyone with a badge for the room needs the contents of every rack. A device left out on the floor has changed state whether or not it has changed building. The lock is itself the admission that state varies inside the perimeter.

“We would never get a job out the door.” This is the fair one, and it is why the state framing matters rather than a movement log. Four state changes on a decommission is not four hundred scans of a drive crossing a room. And the diplomatic bag shows it can be done: sealed, marked, accompanied, accounted for — routine, and nobody calls it unworkable.

“We already scan every drive.” The scan is real and the record is real. What the pair of them cannot do is stand as evidence that this drive reached the machine, because the identity was captured in one place and the destruction in another, and a person carried the drive between them. Capture at the shredder head evidences that this drive passed the machine, because once it is in the mouth there is no retrieving it. Scan at the bench and shred at the machine and you have taken the human attestation out at one end and put it back in at the other.

“It is all on camera anyway.” It is, and the schemes require it — R2v3 asks for at least sixty days of recordings covering every area where data-bearing equipment is received, stored or passed through. That is a real control and it does real work. But a camera witnesses a room, not an asset. You cannot ask footage whether serial number X reached the machine; you can only ask it to show you the floor between two o’clock and three. Sixty days of it, against record obligations measured in years. It establishes that activity took place in a space. It was never built to establish the fate of one device, and it is not fair to ask it to.

“Anything bolted to the machine slows it down.” A shredder has a rated throughput and it was bought for it; a scanner that costs seconds per device at the cutting head is a bad trade whoever is paying. But a mantrap does not have to sit at the last door. It sits at the point the state changes — and the state changes when a drive goes into a sealed container, not when it reaches the machine. Account for the contents on the way in, and the machine runs at its rated speed with the record already made before anything reaches it. The assurance and the throughput are only in tension if you insist on doing the accounting at the cutting head.

Limits

Where this argument stops, and what we cannot yet claim

Capture at the shredder answers the last moment well and the middle not at all. It does not witness the rack, the vault, the store or the van, and no amount of instrumentation removes the need for a process around it: dual-person control, access control, sealed containers, logged entries — and evidence that those were followed.

Nor does it produce certainty. The way forward is to create the conditions for a high likelihood that every device in the vault reached the machine, achieved by shrinking the margin for error — a covered feed nobody can reach into, a belt a drive cannot fall from, an inspection of both the vault and the machine afterwards. Where a margin remains, the answer is to know where it is and put a compensating control on it: someone watching the tip point who can return a device that slips. That person is worth more to an auditor than the certificate is.

We do not have the whole of this answer yet. What we are building is a set of capture points — a mantrap at each place the state changes, rather than one clever box.

Capture at the point of destruction is not a new idea. Several equipment makers already sell it: a scanner beside or bolted onto the machine, an operator passes each drive across it, and the record is written as the drive goes in. Those products work, and for an operation processing modest volumes they are a good answer.

Every one of them is reliant on a manual handheld barcode scanner, and that is the part that has not been automated — and the part that costs the time.

Different operators break state at different points, and a control fitted somewhere other than the moment it is protecting is the badge reader in the wrong room again. So the record of destruction is generated where the destruction happens, rather than transcribed by someone standing beside it, and the same record travels back into whatever system the client already trusts.

We are working with design partners across all three sides of this — shredder and equipment manufacturers, the data centre side, and ITAD operators — because none of it works if it is designed in one place and handed to the others. We are deliberately not building against a single manufacturer’s machine. If you want the middle of your own process and the end to account for itself, and you would like to shape what that looks like than wait, get in touch and we will tell you where we have got to.

Summary

The short version

The serial number is recorded. It is recorded at a bench, and the destruction happens at a machine, and a person walks between the two — so the certificate that joins them is an assertion, and on a published evidence scale an assertion is the bottom rung. R2v3 already requires the destruction to be filmed, and the film cannot name the device. This is the identity scanner in the wrong room, and the answer is the same as it has always been in physical security: move the check to where the event happens. How does that look here? — Recording the changes in a device’s data security state; the transitions, and the controls that held across them.

If your process runs differently, we’d be interested to hear how, so please get in touch.

References

What this rests on

  1. IBM Cost of a Data Breach Report 2026, published 29 July 2026, covering 602 organisations breached March 2025 – February 2026. Global average $4.99M; United States $11.5M; supply chain breach lifecycle 258 days.
  2. SERI, R2v3, Appendix B — Data Sanitization. Appendix B covers physical destruction as well as logical sanitization; requirement (9) concerns video recording of physical destruction. Read at source September 2026.
  3. Australian Cyber Security Centre — Essential Eight assessment guidance, Evidence quality. Four levels — Excellent, Good, Fair, Poor — with assessors directed to gather the highest quality evidence reasonably practicable. Quoted as printed.
  4. Founder account — military service and information security audit practice, including physical security control design; conversations with shredder manufacturers. Nabel Solutions.

We're on a mission to bring automation to ITAD

Interested in hearing more, or got something you'd like to talk through? Get in touch.