Home » Resources » Physical Destruction Isn’t a Free Pass: Rethinking Data Security Risk in 2026

Physical Destruction Isn't a Free Pass: Rethinking Data Security Risk in 2026

Stephen Connolly As a content writer for Blancco, Stephen uses his 10+ years of experience researching and writing about technology to explain how data sanitization is the secure, compliant, efficient, and sustainable choice for end-of-life data management.

In November 2025, Anthropic disclosed that a Chinese state-sponsored group had used its Claude Code tool to carry out what the company called the first documented large-scale cyberespionage campaign conducted mostly by an AI agent.  

Then, in the summer of 2026, OpenAI and Anthropic were involved in claims that they had both engineered AI agents that “escaped” sandboxed environments to autonomously attempt to hack other organizations. 

Data security risk has reached an inflection point. Finding and exploiting weak points in an organization’s data handling is getting faster and cheaper for attackers. 

That shift not only changes one half of an old risk management equation, but it also highlights that now is the time to control as many security variables as possible. One vector it’s essential to control, regardless of autonomous AI agents, is how you dispose of data when it’s no longer needed, and assets when it’s time to retire or redeploy them. In line with the advice contained within IEEE 2883.1-2025, this article offers key strategies to keep your data sanitization security solid as attack vectors multiply.

Risk is still loss times likelihood, but likelihood is increasing 

IEEE 2883.1-2025, the new Recommended Practice that accompanies the 2022 sanitization standard frames data security risk as a function of two variables: the magnitude of loss if data is exposed, and the likelihood that exposure happens. 

When attackers can automate reconnaissance and exploitation, the likelihood goes up even if nothing about your storage or your data has changed. 

One question IT and security leaders need to ask is how to reduce that likelihood when it comes to all the data stored on assets that are ready to be redeployed internally, returned to leasing companies, or shipped externally for dispositioning by ITADs.  

IEEE 2883.1-2025 gives organizations a structured way to think about that likelihood based on adversary skill level. Its risk table breaks attackers into three tiers: 

Mapped against sanitization methods, the results are stark. 

Unsanitized media is rated “almost certain” to yield meaningful data regardless of attacker skill.  

Clear-level sanitization drops to “unlikely” against a novice but rises back to “likely” against an expert and “almost certain” against a virtuoso. 

Purge, by contrast, is rated “almost impossible” against both novice and expert attackers, and only “unlikely” against a virtuoso with lab-grade equipment. 

Sanitization method Adversary capability 
 Novice Expert Virtuoso 
None Almost certain Almost certain Almost certain 
Clear Unlikely Likely Almost certain 
Purge Almost impossible Almost impossible Unlikely 
Destruct Almost impossible Almost impossible Almost impossible 

Table recreated from “Table 2—Example likelihood of data recovery after sanitization” in IEEE 2883.1-2025

This initial table feeds into a second set of considerations tracking the level of risk for the organization. One aspect of this is reproduced below to illustrate the advice that when unsanitized, even drives and devices containing low-impact data should be considered a medium data security risk. That risk level rises with the importance of the data. 

Likelihood of retrieving meaningful data Magnitude of loss 
 Low  Medium High 
Almost certain Medium High Very high 

Table adapted from “Table 4—Risk as a function of likelihood and magnitude of loss”

This table is a useful anchor for governance, risk, and compliance conversations (GRC) because it turns “we sanitize our drives” into a specific, defensible claim about which threat actors that sanitization actually defeats and what level of risk your organization is willing to tolerate. For employee laptops containing customer data, the risk assessment and sanitization decision tree are likely to be far removed from in-office smart TVs that have no locally stored data. 

One non-negotiable: it’s essential to act 

There’s a simple point worth pulling out: doing nothing raises your risk position to “almost certain” to be breached if your physical storage media falls into the hands of bad actors. Even in cases where the magnitude of loss would be low, failing to sanitize your media in any way results in an elevated level of risk. 

At a time when other threat vectors are increasing, and easy-to-implement, Purge-level data erasure software is available, why take the risk? 

Destroying IT assets is not automatically foolproof 

It is tempting to read a table showing Destruct as “almost impossible” to defeat and conclude that the method removes risk by default. There’s more nuance here, though, and it’s worth considering the downsides and limitations of the physical destruction of IT assets. 

First, not all of the common physical destruction methods even conform to Destruct now. In the 2022 edition of IEEE 2883, pulverizing and shredding were downgraded. 

“Although pulverize and shred were once adequate forms of destruct, improvements in reconstruction technology and increases in the density of information on the storage media have rendered these techniques ineffective for storage media other than for low-density storage media (e.g., hardcopy and floppy disks).” 

Secondly, IEEE 2883.1-2025 builds on this to list three conditions that have to be true for a Destruct operation to deliver a legitimately sanitizing result: 

  1. The destruction technique matches the physical media type (degaussing accomplishes nothing on solid-state storage, for example) 
  1. The equipment is properly maintained 
  1. The operators are trained to recognize malfunctions and follow the correct procedure 

Skip any one of those conditions and the “almost impossible” rating in the risk table changes. A shredder running with the wrong particle size setting, or a degausser under-rated for high-coercivity tape media, may increase the chance of leaving recoverable data on the resulting material. Destruct is a technique, not a guarantee, and its reliability depends on execution. 

And there’s another risk factor that has surfaced multiple times in news stories about data breaches in recent years: chain-of-custody failures. 

In 2019, a Japanese recycling firm contracted to destroy decommissioned government hard drives. Before they were destroyed, however, an employee stole and resold 18 of them, containing 27 terabytes of tax records, employee data, and corporate filings, on public auction sites. The investigation later found the same employee had resold roughly 3,900 storage devices over nearly four years, all of which were supposed to have been destroyed under contract. 

The case is a clear illustration of chain-of-custody risk: a policy that says “we destroy our drives” only holds if every hand the drive passes through before destruction can be verified, and relying on Destruct as a single point of protection may leave that entire window exposed. An additional option is to erase data with Clear or Purge before physical destruction closes that gap, regardless of what happens to the drive afterwards. 

The place of cryptography and crypto erase in enterprise data security 

Cryptographic erasure (CE) carries a note of caution within the IEEE 2025 Recommended Practice document. 

“Cryptography is a powerful tool in cybersecurity, but too often it is regarded as a sort of magical talisman that makes all security problems suddenly disappear, rather than a tool that should be used both wisely and well” 

For it to be used “wisely” within a sanitization method, the IEEE 2883-2022 standard had set specific conditions for it to count as Purge: namely, data has to be encrypted before it is ever written to the media, the algorithm and key strength both need to meet a 128-bit minimum, and every copy of the encryption key has to be sanitized. 

Much of this approach will be standard in CE tools and processes, but IEEE 2883.1-2025 adds a new scenario worth flagging to any security team relying on encryption. If an attacker manages to capture an encryption key before it is ever changed, perhaps through a compromised leasing arrangement or a supply-chain foothold, a later cryptographic erase does nothing, because a working copy of the key already exists outside the device. The ciphertext becomes potentially recoverable the moment that key resurfaces. 

What this means for your data security risk assessment 

A few practical takeaways follow from putting the two IEEE 2883 documents next to each other: 

None of this requires predicting exactly how autonomous the next attack campaign will be. It requires building a sanitization program that holds up whether the adversary on the other end is a bored contractor with an undelete tool or a well-resourced group running an agentic AI pipeline. Build a solid foundation with fundamentals that will serve you no matter how the attack landscape changes. 

Data Erasure Tools Built for Compliance

Blancco Drive Eraser is product-certified by ADISA for both NIST 800-88 Rev.2 and IEEE 2883 erasure.