The importance of wiping devices before upgrading
Inside the enterprise: Smartphone users are being encouraged to wipe their handsets before selling them on. Businesses should follow suit.

The average person keeps their mobile phone for two years. And manufacturers are releasing new handsets, and especially smartphones, more and more often.
According to smartphone maker HTC back in 2007 the average shelf life of a phone was three years. Now it is just six months.
This is leading to a growing pile of unloved and obsolescent phones on desks or in cupboards. But as we become more environmentally and economically conscious, more of us are selling or trading in our old devices.
Unfortunately, that green awareness or financial savvy is not going hand in hand with improved awareness of the security and privacy risks posed by the data held on phones.
In a YouGov poll, funded by mobile security company Blackbelt, 41 per cent of Britons have recycled or sold a handset, but only half performed a factory reset of the device before selling it or giving it away. Over a quarter did not even remove the SIM card.
Even relatively innocuous information, such as a phone's address book, could be very damaging in the wrong hands.
Given the way both business and personal smartphones are being used to store company information, or access resources from email to business intelligence, these are statistics that should worry IT managers.
Even relatively innocuous information, such as a phone's address book, could be very damaging in the wrong hands.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Add tablets into the mix, and the picture is even more worrying: with their larger screens, and greater memory capacities, tablets can hold even more sensitive data.
Even so Blackbelt's Ken Garner claims even a factory reset is not guaranteed to wipe all data from a modern phone.
The process may prevent a buyer in the second-hand store from accessing your address book or photo library, but it will not stop a determined hacker from recovering data from the device's flash memory.
Ironically, a technique used to prolong the lifespan of the phone called wear leveling makes it harder for users to erase data permanently.
For businesses, this raises the very real prospect of data leakage. Relying on users to wipe their phones before they sell them is not enough.
Instead, IT managers should use both the remote wiping functions in their mobile device management software to "clean" phones, and consider using either a special data erasure application, or a certified, secure recycling company to dispose of mobile devices.
This might be more expensive than simply trading in the phones, but the security benefits should compensate for the additional cost or lack of resale revenue.
But what about employees' own devices? The simple, and simplistic, answer is to ensure that sensitive data is not stored on them in the first place. Failing that, businesses need to consider using sandbox technology, or virtual desktop environments, to keep business data separate.
Either that, or provide staff with company-issued smartphones, that the business manages and disposes of. It might come at a price, but it is cheaper than a fine from the Information Commissioner.
Stephen Pritchard is contributing editor at IT Pro.
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Two years on from its Series B round, Hack the Box is targeting further growth
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
The CEO's guide to generative AI: Be a creator, not a consumer
Whitepaper Innovate your business model with modern IT architecture, and the principles of trustworthy AI
By ITPro
-
Building a strong business case for GRC automation
whitepaper Successfully implement an innovative governance, risk & compliance management platform
By ITPro
-
Sundar Pichai: AI keeps me up at night
News The Google chief warned that recent AI developments will have a profound impact on society
By Ross Kelly
-
ChatGPT privacy flaw exposes users’ chatbot interactions
News OpenAI has not expanded on the flaw in detail, nor indicated its reach
By Rory Bathgate
-
2022 Magic Quadrant for data integration tools
Whitepaper Using research to evaluate suitable vendors for their existing and upcoming data integration use cases
By ITPro
-
Redefining modern master data management in the cloud
Whitepaper Why you need a modern MDM solution built for the cloud
By ITPro
-
Magic quadrant for data quality solutions
Whitepaper Amplifying analytics for better insights and for making trusted, data-driven decisions
By ITPro
-
Oracle to act as US data auditor for TikTok
News All US traffic on the social media platform will be routed through Oracle's cloud infrastructure
By Rory Bathgate