Why insolvency ITAD is different
Insolvency, administration, restructuring and accelerated site closure can bring together several competing priorities: protect company and personal data, identify which assets actually belong to the business, preserve evidence and records, secure valuable equipment, release premises quickly and recover value where authorised.
That makes IT asset disposition more than a clearance exercise. A controlled project should connect asset ownership, technical decommissioning, data treatment, custody, valuation and final disposition without allowing commercial urgency to bypass information security.
The insolvency practitioner controls the legal process
The precise powers and duties of an insolvency practitioner depend on the formal procedure and circumstances. ITAD providers should not make legal ownership or disposal decisions on the practitioner's behalf.
The Insolvency Service explains that insolvency practitioners may act in roles including liquidator, provisional liquidator, administrator, administrative receiver, supervisor of a voluntary arrangement and adviser. The appointed practitioner or other authorised decision-maker should define what equipment can be collected, sold, returned, retained or destroyed.
Do not assume equipment on site belongs to the company
A closing office or data centre can contain leased laptops, financed servers, rented printers, telecoms equipment, employee-owned devices, customer equipment and assets supplied by managed-service providers.
Ownership should be established before resale, destruction or recycling. Create an ownership-status field in the inventory and quarantine disputed or uncertain assets until the authorised party resolves them.
Preserve records before irreversible action
Some systems may contain accounting records, employee information, customer records, contracts, correspondence or other information needed during the insolvency process. Do not sanitise or destroy storage merely because the operating business has stopped trading.
The authorised stakeholders should determine what information must be retained, exported, imaged, archived or otherwise preserved before irreversible sanitisation or destruction.
Secure the premises and the IT estate
When staff leave rapidly, IT equipment can become vulnerable to loss, unauthorised removal or informal resale. Identify server rooms, comms rooms, build areas, stores, desk equipment and portable devices, and place high-value or data-bearing equipment under controlled access.
Record who is authorised to enter staging areas and who can release equipment.
Create a rapid but defensible inventory
Time pressure does not remove the need for asset accountability. Capture manufacturer, model, serial number, asset tag, location, storage type, apparent condition, ownership status and proposed disposition where practical.
For large estates, prioritise data-bearing and high-value assets first. Lower-value peripherals may be managed by approved quantity-based processes where serial-level control is not proportionate.
Reconcile against existing records
Compare physical discovery with available fixed-asset registers, CMDB records, lease schedules, finance records and supplier information. Expect discrepancies in distressed environments.
Missing and unexpected assets should remain visible as exceptions rather than being silently removed or added simply to balance totals.
Identify technical dependencies before shutdown
A company in restructuring may continue to trade, operate selected sites or preserve systems for a buyer. Before shutting down servers, storage or networks, identify dependencies and obtain technical authorisation.
An ITAD collection team should not disconnect infrastructure solely because equipment has resale value or the building is being cleared.
Separate live operations from disposal stock
Create a clear physical and documentary boundary between equipment still required for operations and assets formally released for disposition.
Use status labels or controlled staging zones so that clearance contractors cannot accidentally remove equipment supporting payroll, communications, security systems, backups or a continuing business unit.
Handle user devices carefully
Laptops, desktops and mobile devices may contain locally cached company information and personal data. Devices recovered from leavers should be inventoried and secured before they enter reuse, resale or recycling channels.
Account disablement, MDM removal and asset-register updates do not themselves sanitise local storage.
Servers and storage systems
Servers, hypervisors, SAN/NAS arrays and backup appliances may hold critical business records and credentials. Determine whether workloads or records need preservation before retirement.
Identify local disks, RAID members, flash modules, cache devices, removable media and failed drives. Do not assume that deleting virtual machines or storage volumes alone satisfies media-sanitisation requirements.
Network and security appliances
Routers, switches, firewalls and VPN appliances can retain configuration, credentials, certificates and topology information. Technical decommissioning should include appropriate revocation and sanitisation actions before external release.
NCSC advises revoking certificates associated with network devices before disposal, changing or revoking other credentials as appropriate and following relevant media-sanitisation guidance.
Printers and other embedded storage
Printers, multifunction devices, CCTV equipment, access-control systems and specialist appliances can contain storage. Identify ownership and data-bearing capability before these assets are returned, sold or recycled.
This is especially important where landlords or general clearance teams are also removing equipment from the premises.
Chain of custody during distressed-site clearance
Record responsibility when equipment moves from the company site into staging, transport and processing. Relevant information can include releasing and receiving parties, date/time, site, consignment and asset/container references.
NCSC guidance recommends appropriate tracking during transfer and more detailed chain-of-custody controls for sensitive or valuable assets.
Secure staging
Equipment awaiting valuation, collection or data treatment should remain in a controlled area. Separate unprocessed assets from sanitised assets and from equipment whose ownership is disputed.
Do not leave data-bearing equipment in loading bays, corridors or unsecured rooms simply because the premises are closing.
Transport and receipt
The custody trail should connect the release from site to receipt by the authorised processor, valuer, purchaser or other destination. Record discrepancies when equipment arrives.
Where multiple contractors are involved, define which party has custody at each stage instead of relying on informal handover.
Data sanitisation before resale
Residual value can be important in an insolvency estate, but data security should remain a gate before external reuse. Select the sanitisation method according to the information, media, organisational requirements and authorised disposition.
NIST SP 800-88 Rev. 2 provides the Clear, Purge and Destroy framework and emphasises verification and validation of sanitisation outcomes.
Failed media
A failed drive can still contain recoverable information. If an approved logical sanitisation process cannot be completed or validated, quarantine the media and follow the authorised exception route.
Where required, this may lead to physical destruction rather than resale.
Physical destruction
Destruction can be appropriate for failed media, assets that cannot be sanitised to the required assurance or equipment whose authorised risk decision requires destruction.
Maintain asset identity and custody until the destruction event is complete, then reconcile the destruction evidence to the project records.
Asset valuation
A distressed sale does not mean every IT asset has negligible value. Recent laptops, workstations, servers, network equipment, storage and enterprise components may have recoverable value depending on specification, age, condition, quantity and market demand.
Valuation should occur after ownership and security constraints are understood. A high resale estimate is irrelevant if the asset is leased, subject to retention requirements or cannot be securely released.
Avoid mixing valuation with security approval
The person estimating resale value should not be able to override sanitisation or ownership controls simply because an asset is commercially attractive.
Use separate statuses for ownership, data treatment, commercial grade and final release so that an asset cannot accidentally enter the sales channel before the required approvals are complete.
Transparent asset recovery
Where the authorised party chooses resale, reporting should show which assets entered the recovery channel and the commercial model applied. Depending on the engagement, this may involve outright purchase, revenue share, project credit or another agreed arrangement.
The asset-recovery statement should reconcile to the inventory rather than presenting only a single unexplained payment figure.
Timing and market value
Accelerated clearance can reduce achievable value because equipment may have limited time for testing, grading and route-to-market. Conversely, storing equipment for too long can create additional cost and depreciation.
Agree whether the priority is fastest site release, maximum recovery, or a defined balance between the two.
Landlord-led site clearance
Where a landlord regains premises, establish who is authorised to instruct the handling of IT equipment and what assets remain the property of the insolvent company, third parties or financiers.
A clearance deadline should not be treated as authority to sanitise, destroy or sell equipment whose ownership or records-retention status is unresolved.
Leased and financed equipment
Create a separate return stream for equipment subject to leasing, hire purchase or other finance arrangements where identified. Confirm the authorised return destination and data-treatment responsibilities.
Maintain custody and sanitisation evidence where required before the asset is released.
Employee and remote-worker assets
The physical office may be empty while company equipment remains with remote workers. Maintain an outstanding-assets register and arrange controlled return or other authorised disposition.
The ITAD project should not be declared fully reconciled while material offsite assets remain unresolved.
Backups and removable media
Locate backup tapes, external drives, USB devices and other removable media. These items can be easy to overlook during rapid closure but may contain concentrated copies of business information.
Determine retention requirements and authorised sanitisation or destruction before they leave controlled custody.
Software licences and cloud services
Physical asset disposal should be coordinated with software licensing, cloud accounts, SaaS subscriptions, certificates, domain services and administrative credentials where relevant.
Removing hardware does not terminate the organisation's digital estate. The responsible technical team should manage those services separately as part of the wider closure or restructuring plan.
Personal data and UK GDPR
Insolvency does not make personal data protection irrelevant. Organisations and appointed parties should ensure personal data on equipment remains appropriately protected while its retention and disposal are determined.
The ICO provides guidance on secure disposal and deletion, including maintaining records and obtaining appropriate evidence when third parties perform destruction.
Third-party ITAD provider due diligence
Before appointing a provider, understand where assets will be stored and processed, which services are performed directly, which are subcontracted, how staff access is controlled, how data sanitisation failures are handled and what evidence is produced.
A provider should be able to show how inventory, custody, sanitisation, destruction, asset recovery and downstream recycling are reconciled.
Evidence for the insolvency practitioner or authorised stakeholder
A project evidence pack can include authorised instructions, source inventory, ownership-status register, collection manifest, chain-of-custody records, sanitisation report, destruction evidence, exception register, asset-recovery statement, final disposition report and closure summary.
The exact pack should be agreed with the instructing party and should avoid unnecessary sensitive information.
Exception management
Distressed environments produce exceptions: missing assets, uncertain ownership, unreadable serials, failed drives, unexpected equipment, incomplete records and disputed disposition instructions.
Maintain a formal exception register with owner, status, decision and resolution. Do not resolve uncertainty by quietly assigning the asset to the most commercially convenient route.
A practical insolvency ITAD workflow
Confirm authorised instruction; secure the estate; discover and inventory assets; establish ownership status; identify records-retention requirements; separate live systems; map dependencies; define disposition; securely stage released assets; record handover and transport; sanitise or quarantine data-bearing media; validate results; value authorised reusable assets; process destruction/recycling; reconcile exceptions; report asset recovery; and issue the final evidence pack.
Questions insolvency and restructuring teams should ask
Who owns each material asset? Which systems or records must be preserved? Which assets are still operationally required? Where will equipment be staged? Who has custody during transport? How will data be sanitised? What happens to failed drives? How will resale value be calculated? Which downstream parties are involved? What serial-level evidence will be supplied? How will unresolved exceptions be reported?
Common mistakes
Common mistakes include treating every asset on site as company property; prioritising resale before data sanitisation; destroying equipment before retention decisions; disconnecting live infrastructure without dependency checks; leaving IT assets unsecured during clearance; overlooking printers and network devices; treating failed disks as data-free; accepting generic certificates with no reconciliation; and closing the project while ownership or remote-worker exceptions remain unresolved.
How Compritech can support insolvency and restructuring projects
Compritech combines onsite infrastructure engineering with IT asset disposition. Depending on the authorised project scope, services can include discovery, technical decommissioning, serial-level asset capture, secure staging and collection, chain of custody, data sanitisation, physical destruction, asset recovery, recycling and final reconciliation.
This can be particularly useful where rapid site clearance must be coordinated with live servers, storage or Cisco/Juniper network infrastructure rather than handled as a simple office-clearance exercise.
Final takeaway
IT asset disposal during insolvency or restructuring requires speed, but speed should come from a controlled workflow rather than bypassing controls. Establish authority and ownership first, preserve required records, protect data, maintain custody and recover value only from assets that have been authorised for release.
The strongest outcome is one where the site is cleared on time and the instructing party can still account for what happened to the equipment, the data and any recovered value.
Related Compritech guides
- How to Maintain Chain of Custody During an Office Closure
- What Evidence Should an ITAD Provider Supply?
- NIST SP 800-88 Rev. 2: Clear, Purge or Destroy?
- Secure Data Erasure vs Physical Destruction
Primary guidance
- GOV.UK / Insolvency Service — Insolvency practitioner regulation
- NCSC — Decommissioning assets
- NCSC — Network device lifecycle guidance
- ICO — Disposal and deletion
- NIST SP 800-88 Rev. 2
Need rapid, controlled IT asset clearance?
Compritech provides engineer-led infrastructure decommissioning and ITAD across the UK, including asset discovery, secure collection, chain of custody, data sanitisation and destruction, asset recovery, recycling and reconciliation.
Discuss your projectIT asset disposal servicesSecure data destruction servicesOnsite data destructionIT recycling services