When Loyal Equipment Becomes Your Biggest Liability
Part two of The Three Deaths of a Device — cyber security across the device lifecycle
The server was not new. That was precisely why nobody wanted to touch it.
At Kōwhai Regional Services, it lived in a corner of the comms room behind a tangle of labelled cables and a decade’s worth of institutional confidence. It ran a finance-adjacent application. It had survived office moves, restructures and three different IT managers. Every month it did its job. Every month it generated the same quiet conclusion: leave it alone.
When the vendor announced end of support, the email went into a shared mailbox. When a vulnerability advisory followed, the server was still working. When the security team asked for an inventory of unsupported systems, its name did not make the first cut.
That is how legacy equipment becomes dangerous: not with a bang, but through a series of reasonable decisions made in isolation.
The old system is rarely a problem because it is old. It is a problem because it has become invisible — absent from the asset register, outside the patching routine, and owned by nobody with the authority or budget to retire it. Meanwhile, it remains connected to a modern environment full of identities, data and pathways an attacker would be very happy to inherit.
Why the Riskiest Day of a Device's Life Is Day One
Part one of a three-part series on the cyber security implications of device lifecycle management.
There's a particular kind of optimism in the air when new equipment arrives. The boxes are stacked in the server room, still smelling of cardboard and the factory floor. Someone's taking photos for the company Slack. The IT manager is quietly relieved that the budget finally came through, and everyone else is just glad the ancient laptops are going in the bin. New gear feels like a fresh start. Clean. Safe. Yours.
It is, statistically, one of the most dangerous days that hardware will ever have.
Let me tell you how it usually goes wrong…
What's Happening to Your Freight Bill Right Now
FAF REACHES 49%
Six weeks ago, shipping freight around New Zealand looked a lot like it had for the past two years. The Fuel Adjustment Factor - the surcharge your carrier applies on top of every base freight rate - was sitting at 13.6%. Predictable. Budgetable. Something most supply chain teams had largely absorbed into their planning.
Then March happened. In the space of four weeks, New Zealand's FAF surged from 13.6% to nearly 50%. This week, several major NZ carriers are publishing rates above 49%.
The Ghost in the Machine
Here are the primary ways these "ghosts" manifest in decommissioned hardware:
• Lingering "Shadow Data": Even after primary files are deleted, "shadow data" such as browser cookies, saved passwords, and API keys frequently remain hidden deep within application folders.
• Hidden Memory in Peripherals: It is not just computers that hold sensitive data. Devices like printers, VoIP phones, and smart IoT devices contain Non-Volatile Memory (NVRAM) that secretly stores contact lists, call logs, and even cached copies of scanned documents.
• Trapped Data Fragments: Traditional "magnetic wiping" is often ineffective on modern Solid State Drives (SSDs). Because SSDs utilize a process called "wear leveling," data fragments can remain trapped in memory cells that standard software-based wipers simply cannot reach
5 Hidden Dangers in the "Forgotten" Stage of IT
Maintaining a secure chain of custody is extremely important to your cybersecurity because the physical hand-off of retired IT equipment to a disposal vendor is considered one of the most dangerous moments in an asset's lifecycle. Even the most sophisticated technical data-wiping methods are useless if poor process management allows the physical asset to be lost or stolen before it is actually sanitised.
Why Your Hardware Strategy is Quietly Draining Your Profits
Outsourcing Device Lifecycle Management (DLM) transforms IT from a complex, reactive internal burden into a streamlined external service. By shifting from an asset ownership model to a service-based utility, Small and Medium Enterprises (SMEs) can access enterprise-grade technology and expertise without the need for enterprise-level budgets or staff.