how to handle a lost or stolen laptop: incident steps
Incident response for a lost or stolen company laptop. Covers remote wipe, credential rotation, and reporting in priority order. Use immediately when a device is reported lost or stolen. Not for misplaced devices found quickly.
TL;DR
Issue the remote wipe via MDM immediately, revoke the user's sessions and rotate credentials that were on the device (VPN, Wi-Fi, SSO), then file the report with asset details. Speed matters more than completeness in the first 30 minutes; inventory and paperwork follow.
The error
(Urgent: device lost or stolen.)Steps
- In the MDM (Jamf/Intune), locate the device and issue a remote wipe/lock now. Expected: command queued. A lock is instant deterrence; a full wipe follows when the device comes online.
- Revoke the user's active sessions in the IdP and rotate the VPN and Wi-Fi credentials if they were device-stored. Expected: sessions killed. A wiped device with live tokens is still a risk until revocation.
- Change passwords for any shared or service credentials the user had access to. Expected: rotated. Assume the thief will try them.
- File the incident: asset tag, serial, user, last known location, police report number if stolen. Expected: ticket with all identifiers. Update inventory state to lost/stolen.
- If the device comes online, confirm the wipe completed in the MDM. Expected: confirmed. If it never comes online, keep the wipe queued and monitor.
When to use
- Laptop reported lost or stolen
- Device missing beyond a reasonable search
When not to use
- Device found quickly (cancel the wipe if not yet executed)
- Phone or tablet (similar flow, different MDM section)
Compatibility
- Jamf Pro, Intune; IdP session revocation
Variants
Device contains regulated data
Trigger the breach-assessment process; a lost encrypted device is usually not a breach, but document the analysis.
Thief is using the device
Do not attempt remote confrontation; work with law enforcement and security.
Why it happens
A lost laptop is a bag of credentials: cached logins, VPN profiles, tokens, and files. The response is about shrinking the window between loss and neutralization.
Edge cases
- Encryption status determines breach severity; confirm FileVault/BitLocker was on.
- If the wipe was issued in error and the device is found, cancel it in the MDM before it executes if possible.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_vJo3CnPEKC23ZqIaaahpqA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.