
getty
Many companies still replace devices, servers and other hardware on a set schedule, even when the equipment remains secure, supported and capable of doing useful work. As refresh cycles speed up, that approach can drive up costs and electronic waste while also creating new questions about data protection, system reliability and what happens to equipment after it leaves active service.
Smarter lifecycle strategies can help companies get more value from their technology while keeping security, performance and reliability firmly in view. Below, members of Forbes Technology Council discuss practices businesses can adopt to reduce hardware waste without introducing new security or operational risks.
Replace Fixed Refresh Cycles With Risk-Based Reviews
Traditional fixed hardware refresh cycles can be replaced by a risk- and performance-based lifecycle management approach. Health checks, data sanitization and certified refurbishment techniques extend an asset’s lifespan and reduce e-waste without compromising security or quality. - Karan Kumar Ratra, Walmart Global Tech
Choose Hardware With Built-In Secure Erasure
Rethink procurement. Refresh initiatives often default to shredding because software-layer encryption on aging hardware cannot always guarantee data is unrecoverable. Choosing drives with self-encryption built into the controller makes erasure cryptographically verifiable at the silicon level, independent of the OS, so end-of-life sanitization stays fast and waste-free. - Camellia Chan, Flexxon
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Manage Retirement As A Controlled Transition
Treat retirement as a state transition, not a date. Give each device a controlled path from active to reassigned, quarantined, sanitized or recycled with an owner, access revocation and evidence at every handoff. That turns reuse into a managed capability rather than an informal favor. The waste is often not the hardware; it is the unmanaged gap between its last use and its next one. - Mani Padisetti, Emerging Tech Armoury
Prioritize Post-Quantum-Ready Hardware
Never buy or retain hardware unless it is provably capable of running post-quantum cryptography. If a device’s chips can’t handle larger NIST quantum-resistant keys, it becomes a permanent security risk. - Denis Mandich, Qrypt
Verify Device Integrity Before Replacement
Companies should rethink the habit of retiring hardware on a purely time‑based cycle. Frequent refreshes often discard devices that are still secure and fully functional. Instead, use IDV‑anchored attestation to verify the device’s integrity, provenance and configuration. When identity and trust checks prove a device is uncompromised, it can safely stay in service longer, cutting waste without increasing risk. - Henry Patishman, Regula
Map Access Dependencies Before Decommissioning
Rethink hardware retirement through the lens of authority. Devices and servers should not be decommissioned, repurposed or extended without knowing which identities, credentials and service accounts still depend on them. Mapping authority before lifecycle decisions reduces waste while avoiding orphaned access, broken workflows or hidden exposure left behind in legacy infrastructure. - Craig Davies, Gathid
Upgrade And Redeploy Existing Hardware
Instead of defaulting to new purchases, extend the life of existing gear through component upgrades and internal redeployment. A server that is too slow for engineering might run finance just fine. You save money, cut e-waste and stay secure because nothing leaves your sight until it is fully wiped and certified clean. This shift stretches budgets and shrinks your carbon footprint without adding risk. - Rohan Pinto, 1Kosmos BlockID
Measure Hardware By Usefulness, Not Age
We’ve gotten into the habit of measuring hardware by age instead of usefulness. In many cases, a secure refresh doesn’t have to mean immediate replacement. We’ve seen well-managed devices continue delivering value after firmware updates, component upgrades or reassignment to less demanding workloads. The goal should be maximizing the full lifecycle of every asset while applying the same discipline to security, monitoring and data sanitization that we do on day one. - Amirtha Saminathan, Lowe’s
Replace Physical Destruction With Verified Erasure
Rethink the shredder. Most refresh programs still destroy data-bearing devices by default, yet NIST updated its sanitization guidance last September and verified cryptographic erase is now the optimal path to reuse. With memory shortages pushing new PC prices up, wiping and redeploying is also the cheaper move. A signed sanitization certificate per asset ends the security objection. - Nikhil Jathar, AvanSaber Technologies
Buy Repairable, Long-Supported Devices
Cumulatively, decisions made at the time of purchase determine how long a device can remain useful. Can the battery or storage drive be replaced? Will parts still be available in a few years? How long will the manufacturer support it with updates? A cheaper device can cost the company more in the long run if it is difficult to repair or keep in service. - Kostiantyn Gitko, Devox Software
Use Endpoint Data To Guide Refreshes
Ditch arbitrary three-year lifecycles that discard perfectly functional corporate hardware. By monitoring endpoint telemetry, including real-time battery health, thermals and stability, IT teams can pivot to condition-based refreshes. Replacing devices based on actual performance instead of calendar dates dramatically cuts e-waste and optimizes budgets by deploying hardware exactly where it is needed most. - Neil Lampton, TIAG
Base Retirement On Condition And Risk
Rethink fixed refresh cycles based on age alone. Replace calendar-based swaps with condition- and risk-based retirement using actual performance data, security patch support and failure rates to decide what to replace. This avoids the unnecessary waste of healthy hardware while still retiring anything that creates real security or reliability exposure. - Aruna Veerappan, Upwork
Tie Replacement To Vendor Support
Stop refreshing on a fixed calendar. Age isn’t the risk; the end of support is. A three-year-old device still getting patches is safer than a one-year-old model the vendor just abandoned. Tie refresh decisions to end-of-life and support status, not the purchase date. You extend the life of gear that’s still safe, retire what’s genuinely exposed, and cut waste without opening a security gap. Lifecycle should follow risk, not the fiscal year. - Steve Carter, Nucleus Security
Build A Secure Reuse Path
Rethink “replace and discard.” A better practice is a secure reuse path. Many devices and servers can be wiped, reimaged, tested and redeployed to lower-risk teams or noncritical workloads instead of being retired early. That reduces waste, protects data and keeps useful hardware in circulation longer. - Nirmal Jingar, Wayfair
Invest In Modular, Upgradable Platforms
Rethink refresh cycles driven by vendor schedules instead of performance telemetry. Equally crucial is choosing hardware with long-term investment protection in mind. While initially more expensive, modular, upgradable platforms; programmable silicon; and energy efficiency significantly reduce the frequency of lifecycle replacements. The cost of ownership throughout the entire lifecycle always reveals a different narrative than the initial price tag. - Kshitij Mahant, Cisco Systems Inc.
Assign Older Hardware To Lower-Risk Roles
Keep your company’s hiring process in mind when leveraging old hardware. While a new hire may grow into a role that involves security, their starting role usually involves less risk. Most new hires can utilize old systems and still be productive. This strategy prevents both waste and spending money on someone who hasn’t yet proven themselves or become fully invested in your organization. - WaiJe Coler, InfoTracer
Standardize Secure Refurbishment And Disposal
As refresh cycles shorten, the practice to rethink is disposal, not upgrades. Many teams wipe and recycle devices ad hoc, creating both e-waste and data exposure. Standardize a certified data-destruction and refurbishment pipeline so faster refreshes don’t multiply security and environmental risk. - Agung Dwi Sandi, rankpillar Group
Repurpose Decommissioned Hardware For Isolated Workloads
Before retiring hardware, ask what it can still run. A decommissioned POS terminal has idle RAM and a working screen, which is enough to run a lightweight AI workload. Put it on its own network segment, separate from the main system, so it never touches core data. Reuse cuts waste. Isolation means one repurposed device can’t become the weak point for everything else. - Vivek Thomas, AISensum
Right-Size Workloads Before Replacing Servers
Before replacing servers, companies should confirm whether the workloads running on them are properly sized. Many systems are replaced to support capacity that is rarely used or no longer needed. By consolidating, retiring or right-sizing workloads first, organizations may avoid unnecessary hardware purchases. Leaders should still validate performance, resilience and security boundaries so efficiency gains do not create new operational risks. - Salice Thomas, Wipro Limited
Replace Components Instead Of Whole Systems
Component reusability should become the norm. Often, it isn’t the whole system that goes bad but only one component. Yet, in a world of glued-in batteries and sealed servers, we seem to have forgotten how to replace components and instead have decided to trash everything. - Kevin Korte, Univention