Back to Blog
Data SecurityMobileiPhoneeSIMData SecurityAsset DisposalITAD

Taking the SIM Out Was Never the Point

Apple’s event is on 9 September, and a few weeks later a tranche of company handsets becomes last year’s phone. The mobile estate is the only part of the IT estate that leaves without a process, and the one habit everybody has for it protects nothing.

NNanosoft Team1 September 20265 min read
Taking the SIM Out Was Never the Point

Apple's next event is on 9 September, the first with John Ternus as chief executive. Whatever is announced, the predictable consequence is the same one that follows every September: a few weeks later, a lot of company handsets stop being the current model, and somebody has to decide what happens to them.

In most organisations, nobody decides. The mobile estate is the only part of the IT estate that routinely leaves without a process at all.

Laptops are collected. There is a form, a person, a room they end up in. Handsets get given to the departing user as a perk, sold privately, traded in individually against a personal upgrade, or put in a drawer that nobody opens for three years. No collection event, no chain of custody, no erasure record. On the device that carries the densest concentration of business and personal data the company owns.

The habit that protects nothing

There is one universal ritual for retiring a phone, and it is worth examining because it is so widespread and does so little.

You take the SIM out.

The SIM never held the data. It holds subscriber identity, a phone number, some carrier configuration. It does not hold the mail, the photos, the messages, the saved passwords, the authenticator app, the VPN profile, the cached documents or the session tokens for whatever the user was signed into. All of that lives on the device.

Removing the SIM stops the handset making calls on your account. That is a billing control, and a worthwhile one. It is not a data control, and it never was. Yet it consistently produces the feeling of having dealt with the device, which is precisely the problem: it is a small physical action that generates disproportionate reassurance.

What eSIM changes, and what it does not

Worth being accurate here, because the position is more nuanced than most coverage suggests.

UK iPhone models currently keep a physical SIM tray alongside eSIM support. The iPhone Air is the exception, being eSIM only worldwide. In the United States, every iPhone since the 14 in 2022 has been eSIM only. Reports suggest the UK and Europe will follow, but that has not happened yet, so if you look at your own handset and find a tray, that is expected.

The trap is not that the tray has gone. It is that a phone can carry an active eSIM profile whether or not it has a tray. Pull the plastic out of a dual-capable handset, feel finished, and the eSIM profile is still sitting on the device.

Apple's own pre-sale guidance is explicit that this needs a deliberate decision, and that it is a decision, not an automatic outcome:

If you sell a device that uses eSIM, choose the option to erase the device and the eSIM profile when asked whether to erase the device and the eSIM profile.

You are offered the choice to keep or delete it, part-way through a flow that most people are clicking through quickly. Choose wrong and the profile leaves with the handset.

There is a mild irony in Apple's own framing, which is accurate but points the other way for disposal. Apple notes that eSIM "is more secure than a physical SIM because it can't be removed if your iPhone is lost or stolen". Entirely true, and the same property that makes it a loose end when the device is being deliberately passed on.

What actually clears a handset

The full erase does the work, and it is worth knowing what it covers so it can be specified rather than assumed. Erasing all content and settings removes cards added to Apple Pay, photos, contacts, music and apps, and turns off iCloud, iMessage, FaceTime and the rest. Apple also confirms that Find My and Activation Lock turn off as part of it.

That last point matters commercially and we have written about the Mac version of it separately: a device that leaves still locked to a departed employee's personal account is worth nothing to anybody. The same mechanism applies to phones, and phones are far more likely to be tied to a personal Apple Account than a company laptop is.

The three questions worth asking this month

None of this requires a project. It requires somebody to own the question before the new handsets arrive and the old ones scatter.

Where are the outgoing handsets going, specifically? "Staff keep them" is a legitimate answer, but only if it is a decision rather than a default, and only if the erase happens before the handover rather than being left to the person receiving it.

Who performs the erase, and what proves it happened? If the answer is the user, on their own, with no record, you have no evidence for any device in the fleet. For regulated sectors that is a gap that shows up at audit rather than at the time.

Is anybody reconciling the list? Handsets are the assets most likely to be missing from an asset register entirely, because they are often bought on the phone contract rather than through IT procurement. A device you never recorded is a device you cannot account for.

The honest summary

Apple will show new hardware on 9 September. The reported expectation is new Pro models and a foldable, though nothing is confirmed until it is on stage, and the specifics matter less than the timing.

What is certain is the pattern. Somewhere between October and Christmas, a tranche of your handsets becomes last year's phone, and in most companies those devices will leave through a dozen informal routes with no erasure evidence behind any of them.

The fix is not technical and it is not expensive. Decide the route before the phones become surplus, erase before handover rather than after, and keep a record against a serial number. The one thing not worth relying on is the SIM tray, which solves a billing problem and has never solved a data one.

Tagged:MobileiPhoneeSIMData SecurityAsset DisposalITAD
N

Nanosoft Team

Writer at Nanosoft - covering ITAD, data security, and sustainable technology lifecycle management.

Found this useful? Share it.

Continue Reading

Related Articles

Deleted Does Not Mean Gone: The Science Behind Data Recovery and What It Means for Your Business
Data Security

Deleted Does Not Mean Gone: The Science Behind Data Recovery and What It Means for Your Business

When you delete a file, the data does not disappear. The computer simply removes the address label and marks the space as available. The file itself sits exactly where it was until something else overwrites it. Here is a plain-English explanation of how data recovery actually works, why SSDs behave differently from hard drives, and what it takes to make data genuinely unrecoverable.

7 minRead
UK Cyber Resilience Pledge and Cyber Shield: What the Government's July 7 Announcements Mean for Your Business
Data Security

UK Cyber Resilience Pledge and Cyber Shield: What the Government's July 7 Announcements Mean for Your Business

On the same day, the UK government launched two major cybersecurity initiatives: NCSC's agentic AI defence programme Cyber Shield, and the Cyber Resilience Pledge with 60 founding signatories. One of the Pledge's three commitments requires Cyber Essentials across the entire supply chain, including every vendor that touches your data, your ITAD partner included.

6 minRead
The New UK Data Complaints Law Is Now in Force: What It Means When Someone Asks What Happened to Their Data
Data Security

The New UK Data Complaints Law Is Now in Force: What It Means When Someone Asks What Happened to Their Data

Since 19 June 2026, every UK data controller must operate a formal complaints process with hard deadlines, no exemptions by size or sector. When a former employee, customer or client complains about what happened to their data, including data on a device you retired, you now have 30 days to respond properly. Here is what the law requires and why a Certificate of Destruction is the only thing that lets you answer that complaint honestly.

7 minRead

Work with us

Ready to Dispose of IT Assets Securely?

Our ITAD specialists help you manage end-of-life IT with confidence, from certified data erasure to compliant disposal.