The decision that determines how painful the next four years will be is made at the purchase order, not at deployment. Buy Apple hardware through a reseller linked to your Apple Business account and every device enrols itself, stays supervised and can be recovered when an employee leaves. Buy the same machine at retail and you inherit a manual process and, eventually, an Activation Lock problem.
This is the end-to-end lifecycle for an Australian business: procurement, enrolment, assignment, redeployment, the Activation Lock trap, residual value, and what the law actually requires when the device reaches the end of its life.
First, a naming change that matters
Apple replaced Apple Business Manager with a service called Apple Business on 15 April 2026. Apple’s own announcement is explicit: “Apple Business Manager and Apple Business Connect will no longer be available once Apple Business launches”, and Apple Business is “available as a free service” across more than 200 countries and regions. Apple Business is Apple’s free web platform for buying, assigning, enrolling and managing company-owned Apple devices, and it now includes built-in mobile device management alongside the brand and location tools that used to live in Business Connect.
Everything below uses the current naming. If your documentation still says Apple Business Manager, or your provider does, that is a small but useful signal. More on that in Apple’s business device portal.
Procurement: the ABM-linked reseller versus retail decision
Zero-touch deployment only works when Apple knows the device belongs to you. Apple’s own footnote on the Apple Business launch says it plainly: “Zero-touch deployment is available when devices are purchased through Apple or Apple Authorised Resellers.”
How the link works. You exchange three identifiers, and people mix them up constantly:
- Organisation ID is your unique identifier in Apple Business. You give this to your reseller.
- Reseller Number identifies the Apple Authorised Reseller or authorised carrier. You add this to your account.
- Apple Customer Number is the account number Apple assigns your organisation for purchasing. Apple notes this is not the same as your GSX account number, and to omit leading zeros.
The step almost everyone misses is in Apple’s own documentation: after the identifiers are exchanged and verified, you must arrange with the reseller to submit your orders through their portal, because “it won’t happen automatically”. Devices do not appear in Apple Business just because you bought them from a participating reseller. Someone has to lodge the order correctly.
Apple publishes a list of Preferred Device Enrolment Resellers for Australia, which is the right place to check before you commit to a supplier. If your incumbent hardware supplier is not on it and will not lodge your Organisation ID, that is a reason to change supplier, not a reason to change your deployment model.
What retail purchases cost you. Devices bought at an Apple Store, JB Hi-Fi or anywhere else can still be added, using Apple Configurator. Apple Configurator for iPhone can add iPhone, iPad, Apple Vision Pro and Mac (Apple silicon or T2, macOS 12.0.1 or later). Apple Configurator for Mac can add iPhone, iPad and Ethernet-model Apple TV, but cannot add Macs.
The catch is real and worth knowing before you rely on it. Apple’s documentation states that after a device is added this way and handed to a user, “they have a 30-day provisional period to release the device from Apple Business, supervision, and the device management service”. A device supplied through the reseller channel has no such escape hatch. If you are buying at retail to save a few days on lead time, understand that you are also handing every new starter a one-month opt-out from management.
You also have to catch each device at a specific Setup Assistant screen (macOS at “Select Your Country or Region”, iOS and iPadOS at “Choose a Wi-Fi Network”). Miss it and you restart the machine and try again. It is fine for one device. It does not scale.
Enrolment and assignment
Automated Device Enrolment is designed, in Apple’s words, for devices an organisation owns, and “lets organisations configure and manage devices from the moment someone removes a device from its box”. A device enrolled this way is automatically supervised on iOS 13, iPadOS 13.1, macOS 10.14.4 and later.
Supervision is not a bureaucratic nicety. Several controls only work on a supervised device. Apple’s Privacy Preferences Policy Control payload, the one that pre-approves your management agent, security agent and backup client for the access they need, states that “supervision is required if you apply this payload using a device management service”. Without it, every agent you deploy throws consent dialogs that users dismiss, and half your tooling silently does nothing.
The assignment checklist that actually matters:
- Device appears in Apple Business with the correct serial number and order.
- Device assigned to your device management service before it is unboxed.
- Enrolment profile set to mandatory and non-removable.
- Managed Apple Account created for the user, so organisational data stays separate from anything personal.
- FileVault enabled with the recovery key escrowed and a test retrieval performed.
- Bootstrap token escrowed to your management service. On Apple silicon Macs this is required for a remote erase to work later.
- Asset record created, linking serial number to person, cost centre and purchase date.
Steps 5, 6 and 7 are the ones skipped under time pressure and the ones you regret. The mechanics sit in enrolment, policy and the bits that break, and the asset side belongs with IT asset management that holds up.
Redeployment when someone leaves
Redeployment is an offboarding problem before it is a hardware problem. The sequence that works:
- Disable the user’s directory account and revoke sessions.
- Confirm their data is in the tenancy, not only on the device.
- Clear Activation Lock before you erase (see below, this order is not negotiable).
- Issue a remote erase from your management service.
- Verify the device reappears in Apple Business unassigned and clear of Activation Lock.
- Reassign to the next user, or route to trade-in or disposal.
If your offboarding process does not include steps 3 and 5, you are building a cupboard full of expensive bricks. This should be wired into your onboarding and offboarding checklist rather than remembered on the day.
Activation Lock: the part businesses get burnt by
Activation Lock ties a device to an Apple Account so it cannot be reactivated without those credentials. Apple now distinguishes two kinds, and the distinction is the whole story.
Organisation-linked Activation Lock requires Apple Business and lets your device management service turn it on and off through server-side interactions. That is the version you want.
User-linked Activation Lock happens when a user signs in with their own personal Apple Account and turns on Find My. Apple’s own device-state table is blunt about the consequences: when user-based Activation Lock is on, it can be turned off in Apple Business, but not through an external device management service.
Three specific traps, all from Apple’s documentation:
The ordering trap. Apple states that “if Activation Lock was already turned on, you won’t be able to turn it off in Apple Business unless the user first turns it off”. If the employee enabled Find My before the device was added to Apple Business, your escape hatch is gone. Add devices to Apple Business first, always.
The bypass code window. On iPhone and iPad the device-generated bypass code is only available for up to 15 days after the device is first supervised. Apple is explicit: “If a device management service doesn’t retrieve the bypass code within 15 days, that bypass code is unretrievable.” Confirm your MDM is actually retrieving and storing these. Confirm it again if you ever change MDM, because Apple warns that on migration you must either receive a copy of the codes or have the outgoing service clear Activation Lock for all enrolled devices.
The macOS 11 trap. For a Mac running macOS 11 or later enrolled via Device Enrolment, Apple notes it “may be possible for Activation Lock to already be turned on when the Mac enrols”, and in that case “you can’t turn it off using a device management service”.
Releasing the device makes it worse, not better. Apple says twice on the same page that “managing Activation Lock using Apple Business isn’t possible after a device is released”, and the interface makes you tick a box confirming you understand the release cannot be undone. Never release a device to try to fix a lock. Also never release a device you are sending to Apple for repair, because if Apple replaces it, the replacement will not appear in your account.
When all else fails, Apple runs an Activation Lock support request process for owners who have proof of purchase documentation. Keep your invoices. This is the entire reason to keep them.
Erasing does not clear the lock. Apple’s guidance is unambiguous: keep Find My on and Activation Lock survives a remote wipe. Clear the lock first, then erase.
Trade-in and residual value
Apple runs Apple Trade In in Australia for both consumer and business customers. Worth knowing how it is structured: Apple’s own terms state that “Apple Trade In is a service provided by Apple’s third-party trade-in vendor”, and the Australian business trade-in runs on a partner platform linked from Apple’s Shop for Business page. It is a real programme; it is not Apple handling your hardware in-house.
Two clauses from Apple’s Australian trade-in terms deserve to be in your process document. First: “You are responsible for backing up and/or deleting data on your trade-in device. Neither Vendor nor Apple will be liable for your data.” Second, the vendor may revise the quoted value if Find My is not removed. Your Activation Lock hygiene has a direct dollar consequence, which is the argument to use when someone asks why offboarding needs to be done properly.
On the buy side, Apple Certified Refurbished in Australia includes a one-year warranty and full functional testing, and AppleCare+ can be added. For non-critical roles it is a legitimate way to lower fleet cost without leaving the managed hardware pool. We do not quote figures here because Apple’s pricing moves and any number in a blog post is out of date within a quarter.
We deliberately publish no dollar amounts for trade-in residual values. Anyone who does is guessing.
Secure erasure: what Apple actually does
On a Mac with Apple silicon or the Apple T2 Security Chip running macOS 12 or later, Erase All Content and Settings performs a cryptographic erase. Apple’s platform security documentation describes the mechanism precisely: volume encryption keys are wrapped with a media key that is “designed to enable swift and secure deletion of data because without it decryption is impossible”, and on these Macs “the media key is guaranteed to be erased by the Secure Enclave supported technology”. Erasing it “renders the volume cryptographically inaccessible”.
Two practical consequences. Disk Utility no longer offers multi-pass secure erase for SSDs at all, and Apple’s advice there is to turn on FileVault instead. And a remote erase on an Apple silicon Mac needs a bootstrap token escrowed to your management service. Without it, Apple’s documentation warns the Mac can fall back to a behaviour called obliteration, after which macOS must be reinstalled before the machine is usable.
Note for anyone quoting ASD: the Information Security Manual’s media guidelines require non-volatile flash memory to be overwritten at least twice with a random pattern and read back for verification, and note that wear levelling means “it is possible that not all memory blocks will be overwritten during sanitisation processes”. The ISM does not address cryptographic erase on self-encrypting devices. Do not claim it endorses the Apple method. Cite Apple for the Apple mechanism and the ISM for the general principle.
Disposal obligations in Australia
Privacy. Australian Privacy Principle 11.2 requires an APP entity that no longer needs personal information, where the information is not a Commonwealth record and is not required to be retained by law, to “take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de-identified”. OAIC’s guidelines note that for electronic information it may be possible to sanitise the hardware, and where hardware cannot be sanitised, reasonable steps must be taken to destroy the information another way.
Losing a device that holds personal information can be a data breach. OAIC lists “a device with a customer’s personal information is lost or stolen” as an example. Whether it becomes an eligible data breach turns on likely serious harm and whether remedial action prevented it, which is exactly where a properly escrowed FileVault key and a verified cryptographic erase become the argument you make to the regulator rather than a line item in your incident report.
A certificate of destruction is not a legal requirement in Australia. It is good practice and it is often a contractual requirement. What OAIC actually expects is that you verify and document destruction, including where you have instructed a third party to destroy information. A certificate is the ordinary commercial way to discharge that. OAIC also warns that relying on certification “may not of itself be considered ‘reasonable steps'”. Do not treat the certificate as immunity.
E-waste in Victoria. E-waste has been banned from Victorian landfill since 1 July 2019 and it is illegal to dump it. Business is treated more strictly than households: EPA Victoria states that most e-waste from business and industry is pre-classified as priority waste under Schedule 5 of the Environment Protection Regulations 2021, and that duties under the Environment Protection Act 2017 “apply to the generator, transporter and receiver of e-waste”. You do not discharge your obligation by handing devices to somebody with a ute.
Note that Sustainability Victoria closed on 30 June 2026. If your disposal procedure names it, update the procedure. EPA Victoria is the regulator.
The national scheme. The National Television and Computer Recycling Scheme gives households and small businesses free access to industry-funded collection and recycling for televisions and computers, including printers, computer parts and peripherals. It now sits under the Recycling and Waste Reduction Act 2020, which replaced the Product Stewardship Act 2011 in December 2020. Two limits worth knowing: mobile phones are not covered by the NTCRS, and the scheme is not designed to absorb a corporate fleet refresh. For volume, use a commercial IT asset disposal provider. The detail sits in secure device disposal and e-waste obligations.
Tax. Disposing of a depreciating asset is a balancing adjustment event, and the ATO requires you to compare termination value against adjustable value, with the difference either assessable income or an allowable deduction in the year the event occurs. Note also that if you stop using an asset and never expect to use it again while still holding it, the termination value is the market value at the time you make that decision. Machines shoved in a cupboard are not automatically worthless. Check current thresholds and rules with your accountant or on ato.gov.au rather than trusting a figure in a blog post.
The one-page checklist
At purchase: Organisation ID lodged with the reseller. Order submitted through the reseller portal. Serial numbers confirmed in Apple Business before delivery. Invoice filed and retrievable.
At deployment: Assigned to your management service before unboxing. Supervised. Managed Apple Account issued. FileVault key escrowed and test-retrieved. Bootstrap token escrowed. Activation Lock managed by the organisation, not the user. Asset record created.
At offboarding: Directory account disabled. Data confirmed in the tenancy. Activation Lock cleared. Remote erase issued and verified. Device shown unassigned in Apple Business with Activation Lock cleared. Reassigned, traded or disposed.
At end of life: Cryptographic erase performed and evidenced. Asset tags and markings removed. Licensed disposal or trade-in provider engaged. Destruction verified and documented. Asset register updated. Balancing adjustment recorded.
If most of that list is news to your current provider, that is worth knowing before your next hardware refresh rather than after it, and it is the practical test in whether your provider can actually support Macs.
Bring us your serial number list and we will tell you which devices are in Apple Business, which are Activation Locked to a person who no longer works for you, and what it will take to fix. Call 1300 028 324 or use https://techassist.au/contact/. It is a quicker conversation than most people expect.
Two things go wrong at the end of a device’s life, and they go wrong in different directions. The data does not get destroyed properly, which is a Privacy Act problem and potentially a notifiable breach. And the hardware ends up somewhere it is not allowed to be, which in Victoria has been illegal since 2019. A disposal process has to solve both, and most SMB processes solve neither.
Media sanitisation is the process of removing data from storage media so that it cannot be reconstructed. Destruction is physically rendering the media unusable. They are different controls, they suit different devices, and they produce different evidence.
A factory reset is a convenience feature, not a data destruction control
A factory reset is designed to make a device usable by the next person quickly. On most operating systems it removes the file system pointers and the user profile. Whether it removes the data depends entirely on the underlying storage and whether encryption was in play.
The Australian Signals Directorate’s Information Security Manual sets out why a straightforward overwrite is not sufficient on a spinning disk. Modern magnetic hard drives keep a host-protected area and a device configuration overlay table that are normally invisible to the firmware and the operating system, so sanitising the readable sectors leaves anything in those regions untouched. They also reallocate bad sectors into a growth defects table, and data written to a sector before it was reallocated will not be overwritten by ordinary software. The ISM’s answer is to reset the host-protected area and device configuration overlay first (control ISM-1065), and to use the ATA secure erase command in addition to block overwriting software so the growth defects table is covered (ISM-1067).
Flash memory has a different problem. Wear levelling deliberately spreads writes across memory blocks, so a single pass has no guarantee of touching every block. The ISM requires non-volatile flash memory media to be overwritten at least twice in its entirety with a random pattern, followed by a read back for verification (ISM-0359). For hybrid drives, it requires separating the magnetic media from the circuit board holding the flash and sanitising each separately.
The ISM is written for government systems, not for private businesses. The OAIC’s own APP 11 guidance points to the ISM’s media sanitisation section and notes that although it applies to Australian Government agencies, it may be of interest to organisations complying with APP 11.2. That is as close to a benchmark as an Australian SMB is going to get, and it is a good one to be measured against in an audit.
Three methods, and when each is defensible
Factory reset or an OS-level wipe. Acceptable only for a device that was fully encrypted from first use and is staying inside your organisation. Not acceptable as the sole control for a device leaving your custody.
Cryptographic erase. The drive is encrypted, and you destroy the key rather than the data. NIST SP 800-88 Rev. 1 recognises cryptographic erase as a purge technique. It is fast, it works at scale, and it is the mechanism behind Apple’s “Erase All Content and Settings” on Macs with Apple silicon or the T2 chip and on iPhones and iPads, where the volume key is held in dedicated hardware and destroyed on erase. Two conditions have to hold: encryption must have been enabled from the moment the device was first used, and you must trust the firmware implementation. If the device spent its first year unencrypted, cryptographic erase does not reach the data written during that year. Note also that the ISM’s sanitisation controls are built around overwriting and use ATA secure erase in addition to, not instead of, software overwriting.
Physical destruction. The only method that does not depend on trusting firmware. The ISM specifies destruction methods by media type (furnace or incinerator, hammer mill, disintegrator, grinder or sander, degausser, or cutting depending on the media) and requires resulting particles to be no larger than 9 mm. It requires the use of Security Construction and Equipment Committee-approved or ASIO-approved equipment, and where a degausser is used, it also requires the platters to be physically deformed afterwards. Destruction is the right answer for any drive that failed, that cannot be verified, or that held sensitive information. The ISM is explicit on this point: media that cannot be successfully sanitised is destroyed prior to disposal (ISM-1735).
The trade-off is straightforward. Destruction gives you certainty and destroys residual value. Sanitisation preserves the resale or redeployment value of the asset and puts the burden of proof on you. Decide per device class, write the decision down, and stop making it case by case at the loading dock.
SSDs, spinning disks, phones and the printer everyone forgets
Spinning disks. Sanitise with a tool that resets the host-protected area and device configuration overlay and issues ATA secure erase, then verify with a read back. If verification fails, destroy it. Old drives under 15 GB or manufactured before 2001 need three overwrite passes under the ISM rather than one.
SSDs and NVMe. Prefer cryptographic erase where the drive was encrypted from day one, or the manufacturer’s sanitise command. Software overwriting alone is unreliable because of wear levelling and over-provisioning. If the drive held anything sensitive and you cannot verify the erase, destroy it. SSDs shred easily and cheaply.
Phones and tablets. Remove them from your MDM and from Apple Business Manager or the Android enterprise equivalent before wiping, then perform the vendor erase. A device still enrolled or still tied to an activation lock is not disposable and is not resellable, and this is the single most common failure we see. Personal devices under a BYOD arrangement need a documented selective wipe that removes corporate data without touching the owner’s photos.
Multifunction devices. This is the one everyone forgets. Business photocopiers and multifunction printers commonly contain an internal hard drive or SSD that has retained images of everything scanned, printed, faxed and emailed through them, sometimes for years. When the lease ends the machine goes back to the finance company with that drive inside it. Before any MFD leaves the building, either have the vendor perform and certify a documented data removal, or buy the drive out of the lease and destroy it yourself. Put this in the lease negotiation, not in the exit conversation.
Everything else with storage. Network video recorders, backup appliances, firewalls with logging, VoIP handsets with local directories, USB sticks in the bottom drawer, and the old NAS in the comms room. If you do not have an asset register that actually tracks devices, you will miss several of these, and the ones you miss are the ones that turn up on a marketplace listing.
The Privacy Act requires you to destroy what you no longer need
APP 11.2 requires an APP entity to take such steps as are reasonable in the circumstances to destroy personal information or ensure it is de-identified once the information is no longer needed for any purpose for which it may be used or disclosed under the APPs, unless an Australian law or a court or tribunal order requires it to be retained. APP 11.3, introduced by the Privacy and Other Legislation Amendment Act 2024 and applying to personal information held from 11 December 2024, confirms that reasonable steps include both technical and organisational measures.
Three points from the OAIC’s guidance change how a disposal process should be built.
Destruction means the information can no longer be retrieved. The OAIC states that for hard copy, disposal through garbage or recycling is not reasonable steps unless the information has already been pulped, burnt, pulverised, disintegrated or shredded. For electronic information, reasonable steps vary with the hardware, and where hardware cannot be sanitised, the information must be irretrievably destroyed another way.
You must deal with all copies, including archives and backups. A wiped laptop does not help if the same personal information is sitting in a backup set you have kept for six years without a retention policy.
Where the information sits on a third party’s hardware, such as cloud storage, and you have instructed them to destroy it, reasonable steps include taking steps to verify that it happened. That is the same discipline as asking where your cloud data actually lives at the start of the relationship.
There is also a fallback the OAIC calls putting information beyond use, for the limited cases where irretrievable destruction is genuinely impossible. It requires that you will not use or disclose the information, cannot give any other entity access to it, surround it with technical, physical and organisational security including access logs and audit trails, and commit to destroying it when that becomes possible. It is a narrow exception, not a filing strategy.
Get this wrong and a lost or stolen device holding personal information is exactly the example the OAIC gives of a notifiable data breach. Knowing which machines held what makes that assessment survivable, which is the practical reason to know which devices held sensitive information before they reach end of life.
Certificates of destruction, and what a real one contains
Most certificates of destruction we see are marketing documents. A useful one is an evidence record. It should contain:
- The serial number of every item, matched to your asset register, not a count of items or a weight
- The media type and the method used for each item, not a generic statement covering the batch
- The date and physical address at which destruction or sanitisation occurred
- The name and signature of the person who performed it and the person who witnessed it
- For sanitisation, the tool and version used and confirmation that verification passed
- For destruction, the equipment used and the resulting particle size
- A statement of the standard the vendor worked to
- Confirmation that the residue was then handled as e-waste under Victorian law
If the certificate cannot be reconciled to serial numbers in your asset register, it proves nothing in an audit. The ISM’s own approach for government is instructive: destruction is supervised, the supervisor confirms it was completed successfully, and where destruction of sensitive media is outsourced it requires a National Association for Information Destruction AAA certified service. Asking a commercial vendor whether they hold NAID AAA certification is a fast way to sort the serious operators from the rest.
Chain of custody is where it actually fails
The data is rarely lost during destruction. It is lost between the desk and the truck.
Devices sit in a store room for eight months. A staff member takes one home because it was “going to be thrown out anyway”. The pallet is collected by a subcontracted driver nobody recognises. A box goes missing between sites and nobody notices because there is no manifest.
Fix it with unglamorous controls. Log every device into a disposal batch at the moment it is decommissioned, with its serial number. Store the batch in a locked area, not the corridor. Do not release a batch without a signed manifest listing every serial. Require the vendor to acknowledge receipt against that manifest within an agreed window, and chase it when they do not. Reconcile the certificate to the manifest and close the batch in your asset register. That whole loop belongs in a documented disposal procedure so it survives the departure of whoever currently does it from memory.
Where devices held highly sensitive information, remove and destroy the drives on site before the hardware leaves, and let the vendor take the carcass. It is cheap and it eliminates the entire chain of custody argument.
Victoria banned e-waste from landfill in 2019
Since 2019 it has been illegal in Victoria to send e-waste to landfill or put it in general rubbish. E-waste is broadly defined: anything with a plug, a battery or a power cord. That includes computers, phones, monitors, whitegoods, batteries and photovoltaic panels.
For a business the obligations go further than “do not bin it”. EPA Victoria regulates the transport, storage and reprocessing of industrial waste, and most e-waste from business and industry is pre-classified as priority waste under Schedule 5 of the Environment Protection Regulations 2021. Duties under the Environment Protection Act 2017 apply to the generator, the transporter and the receiver, which means you carry a duty as the generator and cannot fully delegate it. The general environmental duty applies as well: you must eliminate or reduce the risk of harm from your e-waste so far as reasonably practicable. Used lead-acid and nickel-cadmium batteries are classified as reportable priority waste and attract additional requirements.
Lithium-ion batteries deserve a specific mention. EPA Victoria’s guidance is to manage all e-waste as if it has a battery, and e-waste is treated as a specified combustible recyclable and waste material. A crate of old laptops and vapes in a comms room is a fire load, not just a compliance item.
The relevant Australian Standard is AS 5377:2022, which covers the collection, storage, transport and treatment of end-of-life electrical and electronic equipment. Ask your vendor whether they work to it.
Who to contact now that Sustainability Victoria has closed
Sustainability Victoria closed on 30 June 2026 following the Independent Review of the Victorian Public Service, and its website is no longer updated. Programs that continued, including Detox Your Home and the recycling infrastructure funding streams, transferred to the Department of Energy, Environment and Climate Action (DEECA). For current Victorian information on recycling and waste, go to DEECA. For the rules themselves, and for enforcement of the e-waste landfill ban, go to EPA Victoria. Anything still citing Sustainability Victoria as the authority is out of date.
At Commonwealth level, the Product Stewardship Act 2011 was repealed and replaced by the Recycling and Waste Reduction Act 2020, with the repeal effected by the accompanying Consequential and Transitional Provisions Act. The National Television and Computer Recycling Scheme continues under that framework, administered by the Department of Climate Change, Energy, the Environment and Water, which has also committed to developing a mandatory product stewardship scheme covering small electrical products and solar photovoltaic systems. If a supplier quotes the Product Stewardship Act 2011 at you, they have not updated their paperwork since 2020.
What to require from a disposal vendor
Put these in the engagement, not in an email thread.
- Which EPA Victoria permission they hold, or which permissioned facility their material goes to
- Whether they work to AS 5377:2022, and whether they hold NAID AAA certification for data destruction
- Whether destruction happens on your site, at their site, or at a third site, and who transports it
- What the certificate of destruction contains, with a sample provided before you sign
- Serial-level reconciliation against your manifest, with a stated turnaround
- What happens to devices they on-sell rather than destroy, and what sanitisation they apply first
- Whether any material is exported, and to where
- Their insurance position if a device holding your data surfaces after they took custody of it
The last one is the question that separates a disposal partner from a scrap dealer.
We handle decommissioning, drive destruction and compliant e-waste disposal as part of asset lifecycle work for our managed clients, including the MFD lease exits that usually get missed. If you have a store room full of retired kit and no record of what is in it, call us on 1300 028 324 or get in touch at https://techassist.au/contact/. We will inventory it, tell you what is defensible to sanitise and what has to be destroyed, and give you your Privacy Act obligations in writing rather than in principle.
If your IT provider walked away tomorrow, could a competent replacement pick up your environment and run it without guessing? For most Australian businesses of 10 to 200 staff the honest answer is no. An IT documentation set is the written record of every system, device, account, licence, supplier relationship and recovery procedure your business depends on, kept accurate enough that someone who has never seen your environment can take it over without reverse engineering it.
Undocumented IT is a business risk, not an IT inconvenience
The bill for missing documentation never arrives on a quiet Tuesday. It arrives at five specific moments, and all five are already bad days.
An outage, where the question is not “can we fix it” but “what exactly is running on that box, and who do we ring at the vendor”. A staff departure, where the one person who knew how the ERP integration was configured has just served notice. A provider change, where the incoming team spends its early months discovering your environment instead of improving it, and bills you for the privilege. An insurance renewal or client security questionnaire, where you are asked to list systems holding personal information and you cannot. And a due diligence process during a sale, where an inability to produce an asset register and access records turns into a price adjustment.
The regulatory side is blunter than most owners expect. Australian Privacy Principle 11 requires an APP entity to take reasonable steps to protect the personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it in certain circumstances (OAIC, Australian Privacy Principles quick reference). Reasonable steps is an evidentiary standard. You demonstrate it with records, not with recollection.
The Notifiable Data Breaches scheme sharpens it further. Where you have grounds to suspect an eligible data breach, section 26WH(2) of the Privacy Act 1988 requires a reasonable and expeditious assessment, and you must take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of the grounds. The OAIC’s stated expectation is that 30 days is treated as a maximum, not a target. Assessment means scoping: which systems were touched, whose data sat in them, what left the building. You cannot scope an environment nobody has mapped, and the clock does not pause while you work out what you own.
Worth naming the trade-off honestly: if your business turns over $3 million or less a year, the small business operator exemption may mean the Privacy Act does not apply to you at all. The exceptions are broad, though, and they catch a lot of Melbourne SMBs: health service providers holding health information, businesses trading in personal information, contracted service providers under a Commonwealth contract, and reporting entities under anti-money laundering legislation (OAIC, Small business). Check which side of that line you sit on before deciding it does not concern you. Your clients’ security questionnaires will not care either way.
What a complete set contains
Nine things. If your provider has given you fewer, you have a partial set.
1. Asset register. Every device, physical and virtual: make, model, serial, purchase date, warranty expiry, assigned user, location, operating system and current patch state. This is also where the security frameworks start. The ASD Essential Eight maturity model requires an automated method of asset discovery at least fortnightly under Patch applications, specifically to support subsequent vulnerability scanning. You cannot patch what you have not discovered, and you cannot report on what you have not recorded. If you are still tracking this in a spreadsheet, read our piece on asset management for a growing business before you buy anything else.
2. Network diagram and IP addressing. The ASD Information Security Manual’s Guidelines for networking call for network documentation to be developed, implemented and maintained, including high-level diagrams showing all connections into the network and logical diagrams covering critical servers, network devices and network security appliances, along with their settings. In practice that means a current diagram, an IP address plan, VLAN allocations, firewall rules with a stated purpose for each, VPN configuration and internet service details with account numbers. Add rack elevations and patch schedules for the physical layer, which is where comms room design and documentation meet.
3. Identity and access records. Every user account, service account, shared mailbox and group, with what each one can reach and who approved it. Service accounts are the ones that get missed, and they are the ones that outlive their creators.
4. Licence and subscription register. What you hold, per tenant and per user, with renewal dates, term commitments and the billing owner. This is the single most common source of a nasty surprise at renewal, and the second most common source of an audit exposure.
5. Supplier and account ownership. Every vendor, the account number, the support contract level, the escalation path, the phone number that actually reaches a human, and critically the name of the person at your business who owns the relationship. Domain registrar and DNS belong here, and they are usually the worst documented item in the whole environment.
6. Backup and recovery runbooks. Not “we back up to the cloud”. What is backed up, to where, how often, how long it is retained, when it was last restore-tested, and the step by step procedure to bring each system back. A backup you have never restored is a hypothesis.
7. Standard build and configuration baselines. The known-good state for a workstation, a server, a firewall and a mobile device. Baselines are what let you say “this machine is compliant” without opening it. The ISM’s Guidelines for system management also expect software registers covering workstations, servers and network devices, maintained with versions and patch history and verified regularly.
8. Change history. What changed, when, why, who approved it and how to reverse it. Without this, every incident investigation starts from zero.
9. The credential store. Which is its own conversation.
Credentials do not belong in the documentation system
This is where a lot of otherwise decent documentation goes wrong. Passwords, API keys, certificates, recovery codes and PINs should live in a dedicated secret store, not in a wiki page, not in a spreadsheet called Passwords_FINAL.xlsx, and not in a shared mailbox.
The separation matters for a practical reason. Documentation needs to be widely readable inside your business so it is actually used. Secrets need to be narrowly readable, individually attributable and revocable in seconds. Those two requirements pull in opposite directions, so you satisfy them with two systems and a link between them: the documentation record names the credential, the secret store holds it, and access to the store is granted by role rather than by person.
A business-grade password manager gives you role-based vaults, per-user identity, multi-factor authentication on the vault itself, an audit log of who viewed which secret and when, and the ability to revoke one person’s access without a mass reset. A spreadsheet gives you none of that, and it also gives you no way to answer the only question that matters after a departure: what did they have access to. Our guide to business password management covers the selection criteria in detail.
Two rules that are worth stating plainly. Break-glass credentials for your global admin and firewall accounts should be printed, sealed and stored physically, with a documented procedure for opening the envelope, because a secret store you cannot log into is not much use during an identity outage. And every credential in the store should have a named owner and a rotation trigger tied to your onboarding and offboarding checklist, not to a calendar reminder nobody honours.
The sharp question: if you leave, do you get it?
Here is the part your current provider would rather you did not read.
If you gave notice tomorrow, what would you receive? Not “would they help”, but specifically: which documents, in what format, within how many days, and is any of that written into your agreement? Most SMB managed services contracts are silent on it. Silence favours the incumbent.
The pattern we see repeatedly with new clients is a partial handover: a PDF export missing the credential store, an asset list months out of date, no network diagram at all, and a domain registrar account still sitting under the outgoing provider’s login. That last one is not a documentation failure, it is a control failure, and it is remarkably effective at making a client stay. Anyone who has taken over an undocumented cloud tenancy knows the shape of this: our post on inheriting a tenancy nobody documented walks through the recovery work involved.
Four things to check in your agreement this week.
Ownership. Does it state that documentation, asset records and configuration data relating to your environment are your property, not work product owned by the provider? If it is not stated, assume it is contested.
Format and portability. A handover in a proprietary format you cannot open is not a handover. Ask for machine-readable exports: CSV or JSON for registers, PDF or image for diagrams, and a documented export path from the secret store.
Registrant and tenant control. Your domain registrar, DNS zone, Microsoft 365 or Google Workspace tenancy and your certificate authority accounts should be registered to your business, with a director or nominated staff member holding a global administrator account. Your provider should have delegated access, not sole possession.
Exit and handover. Termination is usually the thinnest clause in an SMB managed services agreement, and it is the one that decides how your last month goes. Look for four specifics by name: a transition assistance clause that lists the deliverables, a timeframe expressed in business days from notice, a stated format for each deliverable, and whether that transition work is included in your fee or billed hourly. Check as well that the intellectual property clause does not quietly claim configuration data and documentation as the provider’s work product, and that there is an obligation to return or destroy your data rather than simply stop using it. If any of those are missing, that is the amendment to raise at renewal, because it is a far easier conversation to have while you are happy than while you are leaving.
Documentation rots, so tie it to change rather than to a review
An annual documentation review is a promise everyone makes and nobody keeps. The moment it slips once, the set is stale, and a stale set is arguably worse than none because people trust it.
The fix is structural. Documentation updates become an exit condition of the change, not a task that follows it. A change is not closed until the record is updated. That means:
- New device deployed? Asset register updated as part of provisioning, ideally automatically from the management platform rather than by hand.
- Staff member starts or leaves? Identity records and credential access updated as part of the onboarding or offboarding run, same day.
- Firewall rule added? Diagram and rule register updated before the change ticket closes.
- Licence purchased or cancelled? Subscription register updated at the point of purchase, by whoever raised the order.
- System restored from backup? Runbook updated with what actually happened, because that is when you discover the runbook was wrong.
Automate the parts that can be automated. Device inventory, software versions, patch state and licence assignment can all be pulled from your management and identity platforms on a schedule, which removes the largest and most tedious category of manual updates. The parts that cannot be automated, meaning the diagrams, the runbooks and the supplier relationships, are the parts a human has to own, and they should be reviewed on a fixed cadence with a named person accountable for each.
The trade-off is real: tying updates to change makes every change slightly slower. That is the cost, and it is worth paying. A change process that produces accurate documentation as a by-product is the only one that stays accurate.
Audit your provider this week
Send one email. Ask for these six items, and give a deadline.
- A current asset register export, in CSV, with serial numbers and warranty dates.
- The network diagram, dated within the last six months, plus the IP addressing plan.
- A licence and subscription register with renewal dates and the billing owner.
- Confirmation of who holds the registrant details for your domain and who holds global administrator on your cloud tenancy.
- The date of the last successful restore test, and which system was tested.
- The clause in your agreement that covers documentation handover on termination.
What comes back tells you most of what you need to know. Items arriving within a couple of days means the documentation exists and is maintained. A request for time to compile means it is being assembled for the first time. Silence, or a phone call asking why you are asking, means the answer is no. If you want a broader sweep of your environment while you are at it, our annual IT audit checklist covers the other governance items worth reviewing in the same pass.
If those six requests come back thin, we will do the documentation build for you and hand it over in a format you own, whether or not you move your managed services across. Call TechAssist on 1300 028 324 or get in touch at https://techassist.au/contact/ and we will scope it against your actual environment.