Operational ITAM Podcast

Bill Van Nort

Thirty years of enterprise IT, distilled into something you can use on Monday morning. Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet. No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on. New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.

  1. 9h ago

    The Standards Body: FOCUS Put Our Name on the Door

    The FinOps people wrote the bill down as a standard and invited ITAM in. Here is how to speak FOCUS before your CFO asks. On June fourth the FOCUS Steering Committee ratified version 1.4 of the FinOps Open Cost and Usage Specification: two new datasets, forty-seven new columns, and an Invoice Detail dataset that joins a consumption record to the physical invoice on one identifier. The same month the Linux Foundation announced Tokenomicon, a conference whose front page names tokenomics, FinOps, and ITAM practitioners in the same sentence. The meter readers built themselves a language. Then they walked across the building to our side, and put our name on the door. Bill walks into the second room of the Grid, the standards body, and breaks down what FOCUS means for ITAM: the eight columns out of sixty-five you actually need, the handful of tests any standard has to pass before you bet a program on it, the ISO 19770-3 entitlement tag he has never once received from a publisher, and the five steps that get a SaaS and licensing estate speaking the language, including the one only ITAM can do. Along the way: what the State of FinOps 2026 survey says about who now reports on licensing and the data center, UnitedHealth Group expressing a VMware data center in FOCUS, and the 1904 Baltimore fire that explains why your vendor's billing format is a thread pitch. Plus, a listener question from Angela in Madison: the cloud FinOps team told the CFO that cloud spend is FOCUS-reconciled, and the CFO wants to know why ITAM's SaaS and licensing numbers cannot be. What do you actually say? IN THIS EPISODE FOCUS 1.4 explained for ITAM: the release history, the eight columns that matter, and how last week's effective rate became Effective Cost over Pricing QuantityThe provider table as of this week: who ships 1.2, who ships 1.3, nobody ships 1.4, and why "conformant" currently means self-declaredISO 19770 held up against the same tests, and an opinion, clearly labeled: FOCUS will become the language ITAM reports cost in, and what it will never carryFive steps to speak FOCUS: ask which version, learn the columns, put your contract register in the Contract Commitment dataset, run it in parallel, and put the export in the contractWhat FOCUS 1.5 brings in December, the Great Baltimore Fire of 1904, and the one-hour homework that produces your first invoice in the languageCHAPTERS (00:03) - Standards Body Visit (01:27) - The FOCUS Standard (03:56) - Core Columns (07:46) - AI Billing Examples (09:38) - ITAM Workflow (15:01) - Baltimore Hydrant Lesson (17:02) - Trust Is the Standard (18:41) - Next Rate Case TRANSCRIPT Click here to view the episode transcript. SOURCES & FURTHER READING Introducing FOCUS 1.4, FinOps Foundation (June 2026): https://www.finops.org/insights/introducing-focus-1-4/What is FOCUS, release history and license: https://focus.finops.org/what-is-focus/FOCUS provider support table: https://focus.finops.org/docs/implementation/get-started/get-started-with-focus-datasets/FOCUS 1.5 release scope: https://focus.finops.org/focus-1-5-release-scope/FOCUS practitioner stories, UnitedHealth Group and STMicroelectronics: https://focus.finops.org/adoption/finops-practitioners/Linux Foundation announces Tokenomicon (June 2026): https://www.linuxfoundation.org/press/linux-foundation-announces-tokenomicon-a-new-conference-for-the-economics-of-aiState of FinOps 2026, Linux Foundation / FinOps Foundation: https://www.linuxfoundation.org/press/state-of-finops-survey-ai-value-and-skills-top-priorities-as-finops-matures-across-technology-value-98-manage-ai-90-saas-64-licensing-48-data-center-1NISTIR 7158, Major U.S. Cities Using National Standard Fire Hydrants, One Century After the Great Baltimore Fire (NIST, 2004): https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=861321ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com The Operational ITAM Podcast is an EpicB Media LLC production.

    The Standards Body: FOCUS Put Our Name on the Door
  2. Sep 3

    The Meter Room: Read the Meter Before the Invoice Does

    AI consumption pricing turned software cost into a meter. Here is how to read yours before the bill does. Software used to be priced at the signature. Now it accrues at the meter. Ramp's payments data shows AI token spend up twenty point seven times in thirteen months, and the FinOps Foundation reports ninety-eight percent of practitioners now manage AI spend, up from thirty-one percent two years ago. A seat is a price you approved once. A meter is a price you discover every month. Bill walks into the first room of the Grid, the meter room, and breaks down the four parts of every consumption agreement: the unit, the rate, the commitment, and the true-up. Along the way: why the median business pays two thousand dollars a month while the average pays one hundred forty thousand, how Coinbase cut its AI bill nearly in half while usage grew, the controller who found ten thousand dollars a month in a term he had never heard, and the arithmetic that turns any invoice into a meter reading. Plus, a listener question from Elena in Cincinnati: finance wants next year's AI budget as one fixed number, and consumption pricing makes that feel impossible. What do you actually give them? IN THIS EPISODE The anatomy of a meter: the unit, the rate, the commitment, and the true-up, and why you need all four named for every consumption agreement you ownRamp's April benchmarks: a sixty-times gap between median and average AI spend, and the twenty-times price difference decided by a model defaultHow Coinbase halved AI spend while usage grew: better defaults, routing, and caching, not friction and spend alertsThe AngelList controller who learned the phrase "prompt caching" from a spend briefing and recovered ten thousand dollars a month the same dayThe three numbers to hand finance instead of one fixed budget, and the one-hour homework that produces your first meter readingCHAPTERS  (00:15) - Meter Room Opens (01:16) - Reading the New Bill (04:12) - What a Meter Is (07:32) - Real-World Savings (09:31) - How to Read Usage (12:55) - Budgeting the Unknown (14:21) - Utility Lessons (15:48) - Measurement Discipline (16:38) - Homework and Next Steps TRANSCRIPT Click here to view the episode transcript. SOURCES & FURTHER READING Ramp, AI token spend controls launch (July 2026): https://www.prnewswire.com/news-releases/ramp-launches-ai-token-spend-controls-302827389.htmlRamp, AI token cost benchmarks (April 2026 data): https://ramp.com/blog/ai-token-cost-for-businessesState of FinOps 2026, Linux Foundation / FinOps Foundation: https://www.linuxfoundation.org/press/state-of-finops-survey-ai-value-and-skills-top-priorities-as-finops-matures-across-technology-value-98-manage-ai-90-saas-64-licensing-48-data-center-1Coinbase CEO Brian Armstrong on cutting AI cost: https://finance.yahoo.com/markets/crypto/articles/coinbase-ceo-halved-ai-costs-130000536.htmlFOCUS 1.4, FinOps Foundation: https://www.finops.org/insights/introducing-focus-1-4/ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com The Operational ITAM Podcast is an EpicB Media LLC production.

    The Meter Room: Read the Meter Before the Invoice Does
  3. Aug 27

    The AI Estate: The First Asset Class With a Regulator Attached

    The EU AI Act's Article 50 transparency obligations began to apply on August 2, with penalties up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. It is the first time in the history of this discipline that an asset class arrived with a regulator already attached, and most organizations cannot tell you what is in it. Flexera's 2026 State of ITAM Report puts accurate AI visibility at 31 percent, while the FinOps Foundation's State of FinOps 2026 found 98 percent of FinOps teams now manage AI spend and 73 percent blew through their AI cost plans. This episode delivers on the promise made at the end of Episode 10: defining the newest asset class in the estate. Bill lays out the five forms AI takes on its way into your organization: embedded (AI switched on inside software you already own), subscribed (standalone AI SaaS), metered (consumption-priced APIs where spend scales with enthusiasm), hosted (models you run yourself), and hidden (all four, unrecorded). Then the four questions from Episode 1, pointed at the AI estate: what you have across five forms, where your data actually goes, what it costs across five different budget lines, and when it leaves, faster than any asset class ever tracked. Then the regulator in practitioner terms: the four Article 50 situations, the December 2, 2026 marking transition, the honest note on Article 26's deferral to December 2, 2027, and why every transparency obligation presupposes an inventory. Plus a listener question from Priya in Ann Arbor on where a CIO-mandated AI inventory even starts, the library closing with full honors as the show moves into the grid, and a one-hour shadow AI census: expense data, SSO log, asset register, three numbers on one page. Sources cited: EU AI Act Article 50 and European Commission implementation guidelines (July 20, 2026); EU Digital Omnibus; Flexera 2026 State of ITAM Report; FinOps Foundation State of FinOps 2026; IBM Cost of a Data Breach Report 2026; Zylo 2026 SaaS Management Index. Case files wanted. One situation, one page, anonymized: what the constraint was, what you did, what happened. If you are the person who just got handed the AI inventory question, Bill especially wants yours. Details at https://www.operationalitam.com Next episode: the meter room. Token-based pricing, GPU hours, and reading the meter before the invoice does. Chapters:  (00:02) - AI’s Regulator Arrives (01:57) - The Numbers Behind AI Risk (04:06) - Five Forms of AI Assets (07:26) - The Four Questions Applied (10:13) - Article 50 Explained (12:53) - How to Inventory AI (14:45) - From Library to Grid Click here to view the episode transcript. Operational ITAM Podcast · https://www.operationalitam.com · Bill Van Nort on LinkedIn: https://www.linkedin.com/in/billvannort/

    The AI Estate: The First Asset Class With a Regulator Attached
  4. Aug 15

    Do You Actually Need a Tool? The Readiness Test

    Flexera's 2026 State of ITAM Report says complete visibility into the IT estate has dropped to 36 percent, down eleven points across three years, over the same stretch that organizations bought more asset management tooling than at any point in the discipline's history. We bought more and saw less. This episode explains why, and answers the question Mike from Columbus asked back in Episode 001: should we buy a tool, and how would we know? Bill lays out the Readiness Test, five questions to answer honestly before any purchase order: Who owns the data? When two systems disagree, which one wins? Can you produce entitlements as documents? Does a lifecycle event change a record today, without a tool? Can someone write down what the tool is for, in one sentence, with a number in it? Fail any one and a platform makes your problems more expensive instead of more visible. Then the case for tools, made fairly: what platforms genuinely do well according to Gartner's January 2026 Market Guide, the estate where the tool is a license term rather than a maturity choice (IBM sub-capacity and ILMT), the honest cost picture, and the four signals that it is actually time to buy. Plus, a listener question from Dana in Dayton on what to do when the platform is live and nobody trusts it, the catalog room in the library, and a one-hour homework assignment that will save some organizations two years. Sources cited: Flexera 2026 State of ITAM Report; Gartner Market Guide for Software Asset Management Tools (January 2026); IBM Passport Advantage sub-capacity licensing terms; Forrester (2013); EU AI Act Article 50. Case files wanted. One situation, one page, anonymized: what the constraint was, what you did, what happened. Details at https://www.operationalitam.com Next episode: the AI estate, the first asset class to arrive with a regulator attached. Chapters: (00:03) - Tool Question Answered (04:31) - Readiness Test (07:42) - Market Tells On Itself (09:24) - What To Do Instead (11:22) - When Tools Make Sense (13:55) - When To Buy (16:45) - The Library Catalog Lesson (18:10) - Tooling Is Judgment (19:23) - Homework And Next Episode Click here to view the episode transcript. Operational ITAM Podcast · https://www.operationalitam.com · Bill Van Nort on LinkedIn: https://www.linkedin.com/in/billvannort/

    Do You Actually Need a Tool? The Readiness Test
  5. Aug 4

    Renewals: The Negotiation You Can Actually Win

    Microsoft gave everyone seven months of warning. Almost nobody had a plan. The gap between the memo and the plan is the whole episode. An audit arrives on somebody else's schedule. A settlement is negotiated from behind. Shadow IT happens whether you sanction it or not. Disposal's best possible outcome is that nothing happens to you. The renewal is different. It is the only recurring event in asset management where the date is known years in advance, where the other side needs something from you, and where you decide when the work begins. And we blow it consistently as a profession. This one is the 18-month clock — four positions, each with exactly one job — and the five traps written into paper you have already signed. The thesis is not subtle: in a renewal, timing beats tactics. The clever negotiator who starts 60 days out loses to the mediocre one who started 18 months out. Every lever in this episode takes months to build and four seconds to deploy. A listener in Indianapolis writes in six weeks from a renewal whose quote just doubled, and gets an honest answer rather than an encouraging one. IN THIS EPISODE - Why 61% of IT leaders cut a project or initiative to pay for unplanned software cost increases — renewals are now cancelling roadmap items, not headcount- Flat application counts and 8% more money: the growth is not sprawl anymore, it is price- The 18-month clock — count, decide, build, ask — and the 60-day cliff most programs are actually standing on- The version of shelfware that survives every audit and fails every business case: deployed, assigned, compliant, and completely idle- Why leverage is a documented, costed, credible answer to "and what if we don't" — and why it never has to be executed- Broadcom/VMware and Oracle Java as live worked examples, including opening quotes that overstated the actual footprint by 20 to 40%- Five traps: the notice window, the uplift clause, the co-term, the discount shell game, and the multi-year commitment- Why you should never negotiate against list price, and the one discipline that catches more money than every other tactic combined- The University of California walking away from Elsevier, and the single reason they could CHAPTERS (00:03) - Renewal Power Plays (03:15) - The 18-Month Clock (05:56) - VMware and Java Leverage (09:22) - Renewal Traps (13:58) - Six Weeks Left (15:46) - The Serials Department TRANSCRIPTClick here to view the episode transcript. SOURCES & FURTHER READINGMicrosoft 365 pricing and packaging updates — the official notice. Announced 4 December, effective 1 July 2026, covering Enterprise, Business, Frontline, and Government commercial equivalents. Office 365 E3 moves from $23 to $26 per user per month, Microsoft 365 E5 from $57 to $60, with Frontline plans rising as much as 43%.https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates Zylo 2026 SaaS Management Index — 305 applications and roughly $55.7M average annual SaaS spend, up about 8% year over year on a flat application count. Also the source for 54% average license utilization, 79% of IT leaders seeing a renewal price increase, 78% hit with unexpected consumption or AI charges, and 61% cutting a project to absorb unplanned software cost.https://zylo.com/2026-saas-management-index VMware distributor Arrow says minimum software subs set to jump from 16 to 72 cores — The Register, 28 March 2025. The primary reporting on the minimum core-count change and the 20% penalty for subscriptions not renewed by the anniversary date.https://www.theregister.com/2025/03/28/arrow_vmware_licensing_change/ VMware Cloud Foundation — current product and licensing informationhttps://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation Oracle Java SE Universal Subscription — the per-employee licensing metric introduced in January 2023https://www.oracle.com/java/java-se-subscription/ Organizations are parting ways with Oracle Java for open-source alternatives — IT Brew, 29 July 2025, reporting on the joint ITAM Forum and Azul survey of 500 IT and software asset management professionals, which found 79% of organizations have migrated away from Oracle Java or plan to.https://www.itbrew.com/stories/2025/07/29/organizations-are-parting-ways-with-oracle-java-for-open-source-alternatives OpenJDK distributions referenced in this episode: Eclipse Adoptium, Amazon Corretto, Azul Zulu, Red Hat build of OpenJDK, and the Microsoft Build of OpenJDK UC terminates subscriptions with the world's largest scientific publisher in push for open access — University of California, 2019. The Elsevier walk-away referenced in the library segment.https://www.universityofcalifornia.edu/press-room/uc-terminates-subscriptions-worlds-largest-scientific-publisher-push-open-access A note on evidence: settlement terms and negotiated pricing are almost universally covered by non-disclosure, so no public dataset of renewal outcomes exists. The advisory-firm figures on VMware settlement ranges and quote overstatement are reported observations rather than published research, and the negotiation guidance in this episode reflects thirty years on the customer side of the table. It is offered as practitioner knowledge, not as study findings. THE COMPANION TOOL The 90-Day Pre-Renewal Readiness Checklist executes what this episode describes — 57 checks across intake, waste signal analysis, business owner validation, and negotiation preparation, with an owner and an evidence artefact named for every item. Free, no email required.https://www.operationalitam.com/pages/resources.html RELATED EPISODES Episode 003 — Software Asset Management: Proving What You OwnEpisode 004 — Surviving a Software Audit, Part One: The Letter LandsEpisode 005 — Surviving a Software Audit, Part Two: The Settlement LISTENER CASE FILES Got a renewal you cannot justify, or a notice window closing faster than your data is coming together? Send it over — anonymized, sanitized, no company names. Just the situation, what you did, and what happened.https://www.operationalitam.com/pages/podcast-ask.html ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com

    Renewals: The Negotiation You Can Actually Win
  6. Aug 2

    Surviving a Software Audit, Part One: The Letter Lands

    The first seventy-two hours decide the outcome. Five opening moves for the moment the audit notice arrives. Part one of two. The letter arrives — or, increasingly, the friendly invitation to a "SAM engagement" that is an audit wearing a nicer coat. What you do in the first seventy-two hours shapes everything that follows. Bill lays out five opening moves: contain it, read the contract, control the terms, build your own position before you share anything, and control the data. Along the way: which publishers audit most aggressively, why third-party audit firms are paid by the vendor and what that means for you, why unverified script output drives more inflated claims than actual non-compliance does, and the single most expensive instinct in this situation — panic-buying licenses after the notice arrives, which frequently doesn't count toward the findings anyway. Plus a listener question from Sandra in Grand Rapids on the soft-audit trap. Part two picks up when the findings document lands. IN THIS EPISODE - The five opening moves for the first seventy-two hours- Soft audits and "SAM engagement" invitations — the audit wearing a nicer coat- What your contract's audit clause actually permits, and what it doesn't- Why third-party audit firms are paid by the publisher, and what that changes- Building your own license position before you share a single data point- Controlling the data: what you provide, in what format, and what you never send- Why unverified script output drives more inflated claims than real non-compliance- The most expensive instinct in the room: panic-buying licenses after the notice- Which publishers audit most aggressively, and what the current data shows CHAPTERS (00:03) - Audit Defense Begins (02:11) - Audit Reality Check (05:10) - Five Opening Moves (08:00) - Negotiating Audit Terms (09:35) - Build Your Position (11:08) - Control the Data (13:29) - Settlement and Takeaways TRANSCRIPTClick here to view the episode transcript. SOURCES & FURTHER READINGFlexera 2026 State of ITAM Report — audit activity by publisherhttps://www.flexera.com/blog/it-asset-management/state-of-itam-2026/ ISO/IEC 19770-1 — IT Asset Management Systemshttps://www.iso.org/standard/68531.html Audit incidence and publisher behavior in this episode is drawn from licensing advisory practice and from thirty years of firsthand audit response. Where a figure rests on industry survey data rather than primary research, it is stated as such on air. ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com

    Surviving a Software Audit, Part One: The Letter Lands
  7. Aug 2

    Welcome to Operational ITAM: Know What You Own

    Thirty years in enterprise IT, distilled into four questions every asset program has to answer. The pilot episode. Host Bill Van Nort opens the series with three decades of enterprise IT leadership behind him — banking, mortgage, automotive — and a straightforward thesis: buried inside a boring-sounding phrase are millions of dollars, real career leverage, and some of the best war stories in enterprise technology. This episode establishes the four fundamentals every program must answer: know what you have, know where it is, know what it costs, know when it leaves. Bill explains why asset management is ultimately a trust discipline rather than an inventory discipline, states his biases up front — evidence over enthusiasm, customer over publisher, simple over clever — and previews the season ahead. Plus: a listener question from Mike in Columbus on what to do when leadership says an ITAM tool isn't in the budget. IN THIS EPISODE - Why nobody notices asset management until it's broken- The four fundamentals: know what you have, where it is, what it costs, when it leaves- Why IT asset management is really about trust, not assets- How the same fifteen questions wear two hundred different outfits- Starting an ITAM program with no tool and no budget- What license compliance actually costs when nobody is keeping score- The show's format, biases, and what's coming this season CHAPTERS (00:23) - Podcast Opening (01:15) - Why Asset Counts Matter (02:05) - The Four Fundamentals (02:46) - Invisible Until Broken (03:16) - The Cost of Chaos (04:16) - Human Side of ITAM (05:01) - Show Format Explained (05:29) - Bill’s Background (06:17) - ITAM Is About Trust (06:59) - What’s Coming Next (07:16) - Start Without a Tool (08:04) - Why This Podcast Exists (08:45) - Show Biases and Principles (09:24) - Season Preview (10:09) - Listener Case Files (10:35) - Who This Show Isn’t For (11:01) - New Names, Same Discipline (11:46) - Closing Thanks (12:21) - Final Takeaway TRANSCRIPTClick here to view the episode transcript. FURTHER READINGISO/IEC 19770-1 — IT Asset Management Systems standardhttps://www.iso.org/standard/68531.html IAITAM — International Association of IT Asset Managershttps://www.iaitam.org LISTENER CASE FILES Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com

    Welcome to Operational ITAM: Know What You Own
  8. Jul 31

    The Last Mile: Disposal, Data Destruction, and Chain of Custody

    Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed nine months ago. At the end of life, a device stops being an asset and becomes a liability with a serial number. Disposal is the only gate in the lifecycle where getting it wrong doesn't cost you efficiency or budget — it costs you a regulator. This episode covers what actually changed when NIST published SP 800-88 Revision 2 in September 2025 and withdrew Revision 1 the same day: the shift from a device-by-device technical manual to a program-level governance framework, the deferral of technique detail to IEEE 2883, the retirement of degaussing and multi-pass overwriting, and new language on establishing trust in a vendor's implementation. Then the regulatory stack — GLBA, FACTA, HIPAA, PCI DSS, Sarbanes-Oxley, Regulation S-P — and why one device can sit under five frameworks at once. The centerpiece is a public enforcement case. Morgan Stanley paid $95 million across two regulators after handing roughly 4,900 devices to a moving and storage company with no data destruction experience. Devices reached an internet auction site with unencrypted customer information intact. Every control that failed was an asset management control. Plus a listener question from Marcus in Fort Wayne on whether wiping drives in-house before they reach the ITAD vendor is duplicated effort. IN THIS EPISODE - NIST SP 800-88 Revision 2 — published September 2025, Revision 1 withdrawn the same day- Why the media-specific tables were removed and what replaced them- Clear, Purge, Destroy — what survived and what didn't- Why degaussing and multi-pass overwriting are the wrong answer for modern media- Cryptographic erase, and why it's the one technique NIST kept- Should you wipe in-house before the ITAD vendor? A listener question- The Morgan Stanley case: $95 million, 15 million customers, 42 unaccounted servers- The regulatory stack, and why one device sits under five frameworks- R2v3, e-Stewards, and NAID AAA — what each actually verifies- The downstream gap auditors find over and over- What makes a certificate of destruction defensible, and what makes it worthless- Deaccession, the ledger, and why the shredder isn't the point CHAPTERS (00:03) - Disposal’s Hidden Liability (01:31) - NIST 800-88 Changes (05:47) - The $95 Million Failure (10:21) - Rules, Vendors, and Proof (15:50) - The Ledger Matters Most TRANSCRIPTClick here to view the episode transcript. SOURCES & FURTHER READINGNIST SP 800-88 Rev. 2 — current standard, published 26 September 2025https://csrc.nist.gov/pubs/sp/800/88/r2/final NIST announcement and summary of changes from Revision 1https://www.nist.gov/news-events/news/2025/09/guidelines-media-sanitization-nist-publishes-sp-800-88r2 NIST SP 800-88 Revision 1 — withdrawal noticehttps://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf IEEE 2883 — Standard for Sanitizing Storagehttps://standards.ieee.org/ieee/2883/10277/ SERI — R2v3 standard and certified facility directoryhttps://sustainableelectronics.org e-Stewards certified recycler directoryhttps://e-stewards.org/find-a-recycler/ i-SIGMA — NAID AAA certificationhttps://isigma.org Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version. LISTENER CASE FILES Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com ABOUT THE SHOW Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet. Consulting enquiries and listener case files: operationalitam.com

    The Last Mile: Disposal, Data Destruction, and Chain of Custody

Ratings & Reviews

5
out of 5
2 Ratings

About

Thirty years of enterprise IT, distilled into something you can use on Monday morning. Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them. Host Bill Van Nort has led IT asset management, end-user computing, and workplace technology at large organizations across banking, mortgage, and automotive, reclaimed millions in software spend, and survived audits from the biggest publishers on the planet. No vendor pitches disguised as advice. No jargon for its own sake. When something is an opinion, he says so. When the honest answer is "it depends," he tells you what it depends on. New episodes cover the fundamentals that never change: know what you have, know where it is, know what it costs, know when it leaves.