The National Cyber Security Centre (NCSC) has issued new guidance to organisations in how to decommission digital assets securely.
Outdated or unsupported assets can pose an unacceptable risk to the organisation and can expose vulnerabilities, becoming liabilities.
The NCSC says that while decommissioning occurs at the end of an asset’s lifecycle, it is crucial to consider decommissioning at the start of the procurement process of the asset.
A decommissioning plan should begin with asset discovery and valuation – the NCSC also warned about being aware of the risks posed by shadow IT. This includes unknown assets that are used within an organisation for business purposes.
Validating the accuracy of records, including their asset’s purpose and what data it processes stores, or transmits, is a vital part of this step.
Next, decommissioning plans must include backup, archiving, and recovery plans to ensure that if any part of the process does not go to plan, recovery is possible and no data is lost.
Recovery plans should include a description of software or data that may need to be reinstalled on assets, ways to notify both the individuals and teams most likely to be making the rollback changes, ways to protect critical functions, and checks in place to confirm the rollback was successful.
Another common requirement in decommissioning is the sanitisation of storage media, which can be done to re-use, sell, or repair decommissioned assets.
Recommended reading
- Google: Legacy Tech and GenAI is Leaving UK Firms Vulnerable
- Tech Debt Hindering Digital Transformation Efforts
- 70% Of Bank IT Budgets Go to Maintaining Legacy Tech
The NCSC has specific guidelines for the secure sanitisation of storage media guidance to follow once data has been backed up.
According to the NCSC, communication throughout the decommissioning activities is vital to ensure coordination across the organisation and with third parties, as well as ensuring replacement assets are working and appropriate tracking is in place.
After decommissioning is complete, organisations should take steps to ensure the effectiveness of devices works, coordinate with third party firms to ensure decommissioning tasks were carried out properly, and that asset inventories are updated.
“Even after completing the decommissioning process, it is important to continue monitoring for any unforeseen impacts that may not have been immediately apparent. In such cases, your backup, archiving, and recovery plans will be critical,” the NCSC said.





