Why Information Must Be Destroyed
CSO) The inability to discard worthless items even though they appear to have no value is known as compulsive hoarding syndrome. If the eccentric Collyer brothers had a better understanding of destruction practices, they likely would not have been killed …
Context & Ripple Effects
This 2009 CSO piece argues that keeping every byte of information is a pathology, not a virtue — framing organizational data retention through the Collyer brothers' fatal compulsive hoarding and calling for deliberate destruction practices as part of basic security hygiene.
The argument reads differently across the arc of coverage around it. A decade later, Gizmodo profiled digital hoarders who proudly archive terabytes of otherwise-disappearing internet culture — the same instinct reframed as cultural preservation. And by 2022, an FT investigation found Amazon and Microsoft destroying millions of storage devices annually even when software wiping exists, showing that physical destruction itself became wasteful overkill. The 2009 warning about failing to discard sits oddly between these poles.
First-order effects
- Security teams reading this are pushed to treat deletion as a first-class control alongside backup and encryption — deciding what data has no value and building destruction into retention policy rather than defaulting to infinite storage.
- The Collyer framing gives CISOs a memorable argument against 'keep everything' culture at organizations where legal caution and cheap storage make discarding politically difficult.
Second-order effects
- As destruction becomes standard practice, the secure-erase market splits: software wiping tools compete with physical shredding services, and vendors must justify which method fits which sensitivity level — the dynamic later exposed by the FT's finding that cloud giants physically destroy devices that could be wiped.
- Compliance and e-discovery workflows get more complex, since destroyed data cannot be produced for audits or litigation, forcing organizations to document what was discarded and why.
Third-order effects
- If the pattern holds, data lifecycle governance matures from an IT afterthought into a structural discipline: retention schedules, defensible destruction, and storage-cost accountability become baseline expectations for any organization handling sensitive information.
- The deeper tension remains unresolved — hoarding preserves history and enables future uses (including AI training), while destruction reduces breach surface and cost. The industry still hasn't settled where value ends and liability begins.
The trend: The economics of storage keep colliding with the risks of retention, pushing data destruction from security hygiene toward a core discipline of information lifecycle management.