Retiring a wireless access point, router, firewall, or managed switch is a security process—not an electronics-disposal task. Network devices may retain credentials, configuration backups, certificates, VPN material, cloud-management associations, logs, and information about internal networks long after they leave service.
Executive takeaway
Decommissioning should remove trust as well as data. The device must be removed from inventories and management planes, credentials and certificates must be revoked, configuration and storage must be sanitized using a verified method, and the final disposition must be recorded.
Why factory reset is not enough by itself
A reset may not remove removable storage, vendor support accounts, cloud-controller records, exported backups, certificates, or credentials shared with other infrastructure. Reset behavior also varies by model and firmware. Organizations need a documented, testable process for each device class.
A practical decommissioning workflow
- Confirm the asset, owner, location, dependencies, and replacement status.
- Export only records needed for legal, operational, or incident-response purposes and protect them according to data classification.
- Remove the device from wireless controllers, cloud portals, monitoring, configuration management, DNS, network access control, and support contracts.
- Revoke device certificates, API tokens, VPN credentials, local administrative accounts, and any shared secrets that cannot be proven unique.
- Sanitize internal and removable storage using vendor guidance aligned with organizational media-sanitization policy.
- Verify the device no longer connects, authenticates, or appears in management systems.
- Record the chain of custody and final disposition through an approved recycler, resale process, return program, or destruction service.
Questions leaders should ask
- Do we decommission the digital identity of a device as rigorously as the hardware?
- Which credentials are shared across devices and therefore require rotation?
- Can we prove sanitization and removal from cloud management?
- Are third-party disposal providers contractually accountable for custody and evidence?
Shawn’s perspective
The most common gap is not a missed reset button. It is an orphaned trust relationship: a certificate, cloud enrollment, VPN profile, or shared secret that remains valid after the device is gone. Asset retirement should close every technical and administrative relationship the device created.
