The Command Said It Worked. They Recovered the Data Anyway.

A UK operator ran the manufacturer's own sanitization command on the manufacturer's own switches — and pulled the customer's network back off them. Network equipment is the biggest unaddressed data-security gap in IT asset disposition, and the standards have not caught up.

By Marcus Holt·Published Aug 6, 2026·10 min read
What a sanitization command leaves behind

Every enterprise has a process for hard drives. Wipe to a standard, or shred to a particle size, certificate of destruction, done. Two decades of regulation, certification schemes and audit practice sit behind that process.

Almost none of that applies to the switch in the rack above the server.

What followed was the most technically specific forty-five minutes of either day, and the most uncomfortable.

"We've recovered data from Juniper switches"

Adam Burrett is the founder of NovaFox, which builds automated erasure processes for network hardware. He took the panel through what happens when a manufacturer changes firmware.

Older Juniper kit runs version 13, 14, or 15 of the operating system, he explained. Past version 15 or 16, the commands that used to perform a sanitization no longer do.

"They say they work," Burrett said. "Say they've completed. But we've recovered data from Juniper switches where you've run the correct command — because most of them have it — but it leaves log files, it leaves configuration backups, it leaves metadata."

And then the sentence that should stop any ITAD operator reading this:

That is not a theoretical vulnerability. It is a first-party account of forensic recovery from devices that had been correctly sanitized according to the manufacturer's documented procedure, by a company whose business is knowing the difference.

Juniper's published documentation supports the underlying mechanism. The company's own technical documentation for the QFX Series describes request system zeroize as an operation that "unlinks all user-created data files, including customized configuration and log files, from their directories" — and states that to erase user-created data so that it is unrecoverable, a separate command, request system zeroize media, is required. Unlinking a file removes the pointer to it. It does not overwrite what the file contained.

The failure mode is silent by design. "The firmware will change," he said, "and there'll be no warning in the documentation that says, after this version, this command no longer works. It just doesn't hit in the background. So we have to verify within our own business" that each new version still works with the process previously developed.

Cisco has its own version of the problem. Burrett described the "factory reset secure three pass" command on more modern switches: "You think, brilliant, we're doing a three-pass wipe — but only on the files that still exist on that switch." Anything sitting in slack space is untouched. On a PC, the equivalent would be shredding the documents in a folder while leaving everything in unallocated space intact.²

What is actually on the device

The industry's mental model of network gear is that it does not hold data. It holds configuration.

Configuration, on a switch, is a map.

"You're looking for things like VLANs, IP addresses, usernames, passwords," Burrett said. On more advanced equipment, "layer three things where it will advise like routing — and basically a map of your network from the inside."

Then he made the observation that reframes the whole risk category. A device is retired because it is being replaced. The replacement sits in the same rack, doing the same job, on the same network.

The exposure is not historical. It is live. A switch sold on the secondary market with its configuration recoverable does not describe a network as it existed three years ago — it describes, in most cases, the network as it exists today.³

Doing it wrong is expensive in the other direction too

There is a commercial argument here that runs alongside the security one, and it is the reason this problem persists.

Getting erasure wrong destroys the asset.

The number he put on it: "You could end up processing a device and devaluing it by 80% just by processing it wrong."

Some manufacturers have built the trap in more deliberately. On Dell's OS10 switches, the license file is a separate artifact from the operating system. Lose it during processing and the device does not fail immediately — it fails later. "If you lose the license file, that switch will kill itself in 120 days," Burrett said. "So suddenly the switch is worthless."

Which means an ITAD provider without a validated process faces a choice between two bad outcomes: destroy value by processing carelessly, or destroy value by shredding equipment that had a market. The panel's collective view was that the industry has historically chosen the second, and lost a great deal of recoverable value doing it.⁴

Meraki is next, and AI is not the answer

Two forward-looking problems came up that operators should have on their radar now.

What a buyer should ask

If you are retiring network equipment, three questions separate a provider who has solved this from one who has not.

Which manufacturers, models, and firmware versions is your process validated against — and when was it last revalidated? The correct answer names the manufacturers and concedes a ceiling. No provider covers every permutation; the panel's own estimate was that the practical target is 90 to 95% coverage with the remainder handled manually. A provider claiming universal coverage is describing a process they have not tested.

How do you verify erasure, rather than trusting the command's exit status? Burrett's entire finding is that the device reports success while retaining data. A provider whose verification is "the command completed" has not verified anything.

What happens to the operating system and license file during your process? If they cannot answer, they are either bricking your assets or shredding them — and in both cases you are not getting the residual value you were quoted.

Why this sits at the centre of what we do

Compare ITAD's argument is that certification tells a buyer less than they assume. Network equipment is the clearest available case.

That is precisely the sort of thing a buyer should be able to look up rather than discover.



Sources

Every quotation above links to the moment it was said in the ITAD Summit 2026 mainstage livestream, publicly available in full. All statements are from "Beyond the Factory Reset: Solving the Network Equipment Challenge in Global ITAD," Day 2, Bellagio, Las Vegas, August 5, 2026.

1. Casey Dingfelder, EVP of ITAD, Dynamic Lifecycle Innovations, moderating. 07:04:48

2. Adam Burrett, Director and Founder, NovaFox. Juniper recovery, 07:09:43. What remains on the device, 07:09:58. Cisco three-pass and slack space, 07:13:18. Juniper's documentation of request system zeroize as an unlink operation, and of request system zeroize media as the command required for unrecoverable erasure: Juniper QFX Series technical documentation. Platform exclusions including QFX10002-60C: Juniper Zero Touch Provisioning documentation. Virtual Chassis behaviour: Juniper CLI reference.

3. Burrett. What is recoverable, 07:14:01. Layer 3 routing, 07:14:09. Replacement device configuration, 07:15:06

4. Burrett. License key and operating system loss, 07:08:31. 80% devaluation, 07:08:46. Dell OS10 120-day termination, 07:38:43.

5. Burrett. Meraki, 07:30:05. Trust and verify the technology, 07:22:27. Third-party forensic examination, 07:22:08

Also appearing on this panel: Roger Gagnon, President and CEO, Extreme Protocol Solutions; Giles Ward, Chief Operating Officer, Vyta.

This article draws on the ITAD Summit 2026 mainstage livestream. Statements by speakers are reported as made. A concurrent breakout track and a pre-conference workshop day ran alongside the mainstage and are not reflected in this coverage. Compare ITAD is not affiliated with the event or its organisers, and takes no payment from ITAD vendors it covers editorially. Our full citation policy is published at /editorial-standards/source-attribution.

Marcus Holt is Compare ITAD's senior industry editor, covering vendor assessments, marketplace mechanics, certification standards, and technical analysis of ITAD operations. Marcus is presented by Compare ITAD as an AI-rendered editorial voice; his work synthesizes industry research, public source material, and editorial review by the Compare ITAD team. Full disclosure framework at /editorial-standards.

Published in The ITAD Brief — Compare ITAD's editorial publication of record for the IT asset disposition industry.