Incident Response

📱 Lost or Stolen Device

A laptop, phone, or other device with organizational access is missing.

Right now
  • Remotely lock and, if available, wipe the device using your MDM tool or the device's built-in remote-wipe feature (e.g. Find My iPhone, Google Find My Device).
  • Change the passwords for any accounts the device had active sessions for (email, file storage, VPN).
  • Revoke any active sessions/tokens for that device in your identity provider (e.g. Google Workspace, Microsoft 365, Okta).
  • Notify your Incident Lead.
First few hours
  • File a police report if the device was stolen — you may need this for insurance and to document due diligence.
  • Determine what data was on the device and whether it was encrypted (most modern laptops/phones encrypt by default, but confirm).
  • Check whether the device had access to sensitive systems beyond what was remotely revoked.
Recovery
  • Issue a replacement device with fresh credentials, not restored from the lost device's backup without review.
  • Confirm all revoked sessions/accounts are fully locked out.
  • Document what happened for your records and any required notifications.
Notification obligations

If the device was unencrypted or contained personal data and the device was not confirmed encrypted, this may trigger breach notification requirements. If the device was encrypted and the encryption key wasn't also exposed, notification is often not required — but confirm with legal counsel rather than assuming.

Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →