Iron Mountain is typically very stringent on their retention/disposal policies.

Storytime, since I'm no longer under NDAs for the company, over a decade ago somewhere that I worked, a disgruntled employee who decided to quit, made a point to within a week of quitting, take a whole bunch of important physical documents they had (because, FBOW, our email and other data retention was so bad, it was safer to have them as prints) and threw them all in our fancy Iron Mountain 'disposal' bin.

Apparently due to the agreement with them, short of a court order, only specific employees/titles in the company were allowed to be the persons to retrieve them.

Keeping that situation in mind, it's clear that this dance for better or worse is part of their posturing as a retention center with very strict rules to ensure compliance while also avoiding snooping.

As a whole, I'd say it's for better. Obviously Nine PBS's situation is shitty and fuck "OSS" for putting them in that position, but they are not Iron Mountains customer. They are strangers to Iron Mountain who just demanded 50TB of customers data from Iron Mountain. The only sane response is to tell Nine PBS to come back with a court order, and (hopefully) to tell their lawyers to just make sure Nine PBS is in fact the rightful owner and if so, not to fight them on it.

Anything else is the sort of stuff that causes blog posts and news articles about data breaches to be written.

Yeah; I haven't read TFA but IMO especially if Iron Mountain is aiding the procurement of said court order through giving some (potentially redacted as required for privacy purposes) "sample" court documents that could be readily used as reference so the lawyer on the Nine PBS side (filing with the court to get a judge to order Iron Mountain to release that data to Nine PBS) doesn't need to waste their time repeating all the drafting from scratch for what I'm assuming would be a (from the legal perspective) straight-forward request (that nonetheless has to specifically account for the particular legal data possession/ownership/access-rights situation under which the data in question is stored at Iron Mountain), especially as relevant for the situation at hand allowing Nine PBS to put a temporary data retention legal hold on these 50TB giving them a fair deadline (not merely "legally 'reasonable'") either on charity (understanding the gravity of the "this Nine PBS data is a public good (at a cursory glance)"/"information wants to be free") or offering general reasonable list price of what they bill for retaining 50TB stored under the storage model at play for "just one more month" (or whatever fair deadline) paid by Nine PBS.

Indeed. That said it’s not that different from say someone backing up to someone like Druva and they ran their infra on AWS and say hypothetically Druva went out of business you would not go to AWS directly and say “hand me over my data.” It’d have to go through proceedings, etc., not to mention that without the engineers from Druva you would not get useable unencrypted data.

It’s exactly like the above but it’s presented as if the data sits neatly on two drives stored in a safe and all you have to do is mount them to see the unencrypted data.

Er... I assume a little time with a lockpick and/or an angle grinder could have recovered the documents?

Hope you have (best case) a good lawyer or (worst case) good health insurance as well if you attempt physical intrusion. Their physical asset security team is hardboiled [0][1].

I've dealt with them as well - they don't like being in this kind of position either.

[0] - https://ironmountain.jobs/manassas-va/armed-officer-safety-s...

[1] - https://ironmountain.jobs/boyers-pa/security-officer-armed/6...

I think you've misunderstood. I believe the comment you're responding to was talking about opening a secure bin that was presumably still on site.

They weren't talking about breaking into the Iron Mountain facility

Well... Again this is far out of NDA time, the documents were not on site anymore.

That said, I would be willing to bet that doing such an act, even as a client, would be problematic on other levels.

Let's remember; part of this whole contract with a company like this, is they are guaranteeing that your organization is following document retention processes. The sort of stuff that makes it really easy to pass things like a SOX audit.

Cause, I've worked at other places. The kinds of places where you come in on a Saturday, there's a whole bunch of document bins out in the middle of the office that weren't there on a Saturday, everything is gone by Monday, and a bunch of people one to two slots under the C level resign within a week, and within the next 6-12 months all of the office gossip is either the bankruptcy proceedings impacting operations or the civil RICO lawsuit from the departed founder.

Angle grinders are amazing tools, but with such amazing tools comes amazing responsibility... Yes, that's an allegory...

If Iron Mountain is shooting people for picking locks, they’re the ones who had better have good lawyers.

Right, but if they show up and try to stop you, your options for escalation are limited and you'll have to comply (stop).

I smell a Jason Statham movie

I smell a felony case with a non-trivial chance of lead poisoning or a visit to a trauma center.

I accidentally dropped something into an iron mountain bin years ago, and just pried it open with a screwdriver.

[flagged]

Oddly aggressive comment on something so mundane. Guess it's a pet peeve of yours?