Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is secure deletion?

Secure deletion attempts to make normal data recovery difficult through overwriting, wiping, snapshot removal, reformatting or key destruction. Tool presence and visible file absence do not prove the method completed or every copy disappeared.

Establish method and storage context

Preserve the command or tool, target, account and process, start, completion, errors, filesystem, storage type and encryption. Effectiveness differs across traditional disks, solid-state storage, cloud objects, replicas and versioned services.

Do not repeatedly test the original media. Provider snapshots, backups and platform history may be more useful than local recovery attempts.

Separate key loss from erasure

Destroying an encryption key can leave bytes physically present but unusable. Preserve key-management access and deletion events and describe that effect separately from physical data erasure.

Check metadata, logs and remote copies. Current platform behaviour may need specialist or provider verification before concluding destruction.

Key takeaway

Prove which method targeted which data, whether it completed and what replicas or metadata survive, distinguishing key destruction from data erasure.

Reference: CIM-224Cyber Incidents & Offender Methods