A laptop left on a train, a phone taken from a vehicle or a tablet that cannot be found can quickly become a business security incident. The device itself can be replaced. The more important questions are what it contained, which accounts it could access and whether anyone else can use it.
The response does not need to be chaotic. A clear process, supported by device management and accurate records, can help a business contain the risk and restore the user safely.
Why the first hour matters
Do not wait until the next working day in the hope that the device turns up. The person who notices the loss should report it to the organisation’s IT contact immediately, even if they are unsure whether it has been misplaced or stolen.
Early action gives the support team a better chance to lock the device, revoke active sessions and review recent activity before information disappears from logs. It also starts a reliable incident record if the loss later needs to be reported to an insurer, the police or the Information Commissioner’s Office (ICO).
1. Record the essential facts
Start a simple incident log and record facts rather than assumptions:
- the user’s name and contact details;
- the device type, make, asset number and serial number, if known;
- when and where it was last seen;
- whether it was locked, switched on or connected to a network;
- which email, cloud, finance or business systems it could access;
- whether files were stored locally; and
- whether the device held personal, confidential or commercially sensitive information.
An up-to-date asset register makes this much quicker. It should connect each device to its assigned user, management status, encryption state and replacement history.
2. Lock, locate or erase the device
If the device is enrolled in mobile device management (MDM), an administrator may be able to put it into a lost mode, lock it or erase it remotely. The right action depends on the circumstances. Location information might help recover a misplaced device, while a remote wipe may be more appropriate when theft is likely or the information risk is high.
The National Cyber Security Centre explains that an MDM-enrolled device can receive a remote-wipe command when it is powered on and has a data connection. A wipe is not guaranteed to happen immediately if the device remains offline, so it should be one part of the response rather than the only control. See the NCSC guidance on erasing devices.
Do not attempt to confront someone shown at a device’s reported location. Pass relevant information to the police where theft is suspected.
3. Secure the user’s accounts
A locked screen does not necessarily end every active cloud session. Review and, where appropriate, revoke the device’s access to:
- Microsoft 365 or Google Workspace;
- business applications and file-sharing services;
- remote-access and VPN services;
- password managers;
- finance, payment and customer systems; and
- administrator or supplier portals.
Reset credentials where there is a credible risk of exposure, beginning with privileged accounts and the user’s primary email account. Check that multi-factor authentication remains under the user’s control and that no new authentication method or forwarding rule has been added.
Review sign-in and security logs for unusual locations, downloads or configuration changes. Preserve anything suspicious rather than deleting it, because it may help establish what happened.
4. Decide whether personal data may be affected
Losing a device does not automatically mean that data has been accessed, but the organisation still needs to assess the risk. Consider the strength of the screen lock and encryption, the sensitivity of the information, whether the device was remotely managed, and the likelihood that an unauthorised person could use it.
The ICO says organisations must keep a record of personal data breaches, whether or not a report is required. If a breach is likely to risk people’s rights and freedoms, the ICO must be notified as soon as possible and, where feasible, within 72 hours. If the likely risk is high, affected people must also be informed without undue delay. The ICO provides a small-business guide to the first 72 hours and a personal data breach self-assessment.
This assessment should be made by an appropriately authorised person and, where necessary, with legal or data-protection advice. Record the reasoning even when the decision is not to report.
5. Restore the user safely
The priority is to get the person working again without recreating the same risk. Supply a known, managed replacement rather than allowing an unprotected personal device to become a permanent workaround.
Restore approved business data from a verified backup or managed cloud service. Reapply security policies, software updates, endpoint protection, encryption and access restrictions before returning the user to normal work. If the missing device later reappears, do not reconnect it automatically; let IT inspect and re-enrol it first.
Controls to put in place before the next incident
The easiest incident to manage is one for which the business is already prepared. A sensible baseline includes:
- full-disk encryption and a strong automatic screen lock;
- MDM or another suitable management platform for company devices;
- multi-factor authentication for important accounts;
- least-privilege access, with separate administrator accounts;
- an accurate asset register and clear joiner, mover and leaver processes;
- tested backups for important business data;
- a written lost-device and personal-data-breach procedure; and
- staff training that makes prompt reporting easy and blame-free.
These controls should cover the complete workplace. Windows PCs, Macs, iPhones, iPads and Chromebooks use different management tools, but the business outcome is the same: know what you own, apply a consistent security baseline and retain the ability to remove access when a device is no longer trusted.
A simple lost-device action plan
When a device goes missing, remember this sequence:
- Report it immediately.
- Record the facts and the systems involved.
- Lock, locate or wipe the device where appropriate.
- Revoke sessions and secure affected accounts.
- Assess the information and personal-data risk.
- Preserve evidence and make any required reports.
- Restore the user on a known, managed device.
- Review what would make the next response faster.
Make device loss a manageable event
MSP247 supports mixed Windows, Apple and Chromebook environments alongside networks, Microsoft 365, backups and business continuity. We can help you review device management, encryption, account security, asset records and recovery arrangements as one joined-up service.
If you are unsure how quickly your business could contain a lost-device incident, book a free IT review or call 0330 301 0500.

