Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Protect accounts and local data without destroying useful device evidence, then replace the machine from a trusted baseline.
Capture before evidence disappears
- Record the last known time, location, network, user, serial number, asset ID, encryption status, lock state, and whether the device was powered on.
- Inventory browser sessions, password-manager access, SSH keys, cloud CLIs, source, customer files, local databases, email, and recovery codes stored on it.
- Preserve endpoint-management check-ins, location events, sign-ins, VPN logs, token use, and remote-lock or wipe command status.
- Record police, transport, venue, insurer, and device-provider case numbers without exposing unnecessary customer information.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Lock or wipe? | The device is online and retrieval is unlikely; evidence and legal needs have been considered. | Lock first when possible. Wipe when data risk exceeds the value of retaining the device state. |
| Rotate credentials? | Disk encryption, lock state, keychain protection, or session security is uncertain. | Revoke sessions and rotate high-impact keys from a clean device, starting with identity and email. |
| Notify customers or authorities? | Unencrypted or accessible personal, regulated, or contract-protected data was stored locally. | Assess the exact data and get qualified privacy advice promptly. |
Proof that recovery worked
- The lost device no longer has active identity, email, password-manager, VPN, Git, cloud, or support sessions.
- High-impact local keys and recovery material have replacements and old values fail.
- Remote-management status, encryption evidence, data inventory, and notification decision are documented.
- The replacement device is enrolled, encrypted, patched, and restored without copying untrusted executables or profiles.
Controls to put in place
- Require full-disk encryption, short automatic lock, secure boot, updates, and endpoint management.
- Keep production data off laptops and use short-lived identity-based access instead of stored keys.
- Enable remote lock or wipe and verify management check-ins monthly.
- Maintain an off-device inventory of serials, encryption recovery keys, credentials, and customer data exceptions.
Declare a test laptop unavailable. From a second device, revoke its sessions, rotate a test SSH key, confirm management status, find its data inventory, and provision a usable replacement from the standard baseline.
Contact law enforcement for theft, and involve security, insurer, counsel, and affected customers when the laptop held accessible regulated data, administrator sessions, signing keys, or evidence of hostile use.
What this means
The device may expose more than local files. Browser sessions, SSH keys, password-manager access, cloud CLIs, source clones, and recovery codes can give an attacker remote access.
Remote lock and erase help only if they were configured before loss and the device connects. Treat the device as unavailable and potentially readable until evidence says otherwise.
Warning signs
- The device cannot be found after checking the last trusted location.
- Find My or device management shows an unexpected location.
- A sign-in or API event appears after the device went missing.
- Full-disk encryption, screen lock, or remote management was not enabled.
- The laptop stored customer exports, local databases, keys, or recovery codes.
Recover now
First 15 minutes
- Mark the device lost in its management service. Lock it and display safe return information. Do not arrange a personal confrontation.
- Record the timeline. Note the last possession, location, device serial number, encryption state, and data or credentials present.
- Revoke high-risk sessions. Start with email, password manager, identity provider, source control, cloud, hosting, payments, and banking.
- Revoke device credentials. Remove SSH keys, certificates, VPN profiles, API tokens, trusted-device status, and active CLI sessions tied to the laptop.
- Report theft when appropriate. Give law enforcement the serial number and location information through the correct process.
Today
- Decide whether to queue a remote erase. Remember that some platforms cannot locate the device after erasure.
- Rotate credentials stored unencrypted or accessible through an unlocked session.
- Review sign-in, source-control, cloud, payment, and application logs from the time of loss.
- Identify customer or regulated data stored locally and get legal advice about notification.
- Prepare a clean replacement device. Restore only business data from trusted sources.
- Keep the missing device blocked even if someone claims to have found it, until identity and chain of custody are confirmed.
Verify recovery
- The missing device is locked, blocked, or erased according to the chosen plan.
- Old sessions, keys, tokens, VPN profiles, and trusted-device approvals fail.
- Audit logs show no unexplained access after the loss.
- Critical business data exists in business-controlled systems, not only on the laptop.
- The replacement device uses current patches, encryption, screen lock, and management.
Prepare now
Device
- Full-disk encryption and a strong automatic screen lock are enabled.
- Find My or business device management is enabled and tested.
- The serial number and recovery details are stored away from the laptop.
- Sensitive local data is minimized and automatically backed up.
Access
- Password-manager access requires a strong independent factor.
- SSH keys, tokens, certificates, and devices have names and owners.
- Critical services can revoke one device without resetting every user.
- Recovery codes are not stored only on the laptop.
Practice
- A second person can locate the device record, revoke its access, and prepare a clean replacement.
Common mistakes
- Waiting a day before revoking sessions. A logged-in browser may be more valuable than the files.
- Erasing before deciding whether location matters. Some platforms stop tracking after erase.
- Changing every password without a priority order. Secure email, identity, and password manager first.
- Restoring the whole old device image. It may restore weak settings or malware.
- Meeting the finder alone. Use safe, documented recovery channels.