Everything here is general guidance, not professional advice. We research carefully and can still be wrong or out of date, so treat it as suggestions to check rather than instructions to follow, and accept that you act on it at your own risk. Full terms.

PlaybooksLaptop lost or stolen
Accessserious25 minutes to prepare

Laptop lost or stolen

A work laptop containing sessions, source code, customer data, or recovery credentials is missing.

01DetectConfirm the signal
02ContainStop more damage
03RecoverRestore control
04VerifyProve it works

Your preparation

0 of 0 safeguards ready
0%
Incident worksheet

Make the next decision with evidence

Protect accounts and local data without destroying useful device evidence, then replace the machine from a trusted baseline.

EvidenceDecisionActionProof

Capture before evidence disappears

  • Record the last known time, location, network, user, serial number, asset ID, encryption status, lock state, and whether the device was powered on.
  • Inventory browser sessions, password-manager access, SSH keys, cloud CLIs, source, customer files, local databases, email, and recovery codes stored on it.
  • Preserve endpoint-management check-ins, location events, sign-ins, VPN logs, token use, and remote-lock or wipe command status.
  • Record police, transport, venue, insurer, and device-provider case numbers without exposing unnecessary customer information.

Decisions that change the response

QuestionAct whenAction
Lock or wipe?The device is online and retrieval is unlikely; evidence and legal needs have been considered.Lock first when possible. Wipe when data risk exceeds the value of retaining the device state.
Rotate credentials?Disk encryption, lock state, keychain protection, or session security is uncertain.Revoke sessions and rotate high-impact keys from a clean device, starting with identity and email.
Notify customers or authorities?Unencrypted or accessible personal, regulated, or contract-protected data was stored locally.Assess the exact data and get qualified privacy advice promptly.

Proof that recovery worked

  • The lost device no longer has active identity, email, password-manager, VPN, Git, cloud, or support sessions.
  • High-impact local keys and recovery material have replacements and old values fail.
  • Remote-management status, encryption evidence, data inventory, and notification decision are documented.
  • The replacement device is enrolled, encrypted, patched, and restored without copying untrusted executables or profiles.

Controls to put in place

  • Require full-disk encryption, short automatic lock, secure boot, updates, and endpoint management.
  • Keep production data off laptops and use short-lived identity-based access instead of stored keys.
  • Enable remote lock or wipe and verify management check-ins monthly.
  • Maintain an off-device inventory of serials, encryption recovery keys, credentials, and customer data exceptions.
Tabletop drill

Declare a test laptop unavailable. From a second device, revoke its sessions, rotate a test SSH key, confirm management status, find its data inventory, and provision a usable replacement from the standard baseline.

Escalate when

Contact law enforcement for theft, and involve security, insurer, counsel, and affected customers when the laptop held accessible regulated data, administrator sessions, signing keys, or evidence of hostile use.

What this means

The device may expose more than local files. Browser sessions, SSH keys, password-manager access, cloud CLIs, source clones, and recovery codes can give an attacker remote access.

Remote lock and erase help only if they were configured before loss and the device connects. Treat the device as unavailable and potentially readable until evidence says otherwise.

Warning signs

  • The device cannot be found after checking the last trusted location.
  • Find My or device management shows an unexpected location.
  • A sign-in or API event appears after the device went missing.
  • Full-disk encryption, screen lock, or remote management was not enabled.
  • The laptop stored customer exports, local databases, keys, or recovery codes.

Recover now

First 15 minutes

  1. Mark the device lost in its management service. Lock it and display safe return information. Do not arrange a personal confrontation.
  2. Record the timeline. Note the last possession, location, device serial number, encryption state, and data or credentials present.
  3. Revoke high-risk sessions. Start with email, password manager, identity provider, source control, cloud, hosting, payments, and banking.
  4. Revoke device credentials. Remove SSH keys, certificates, VPN profiles, API tokens, trusted-device status, and active CLI sessions tied to the laptop.
  5. Report theft when appropriate. Give law enforcement the serial number and location information through the correct process.

Lock the device on your platform

  1. Sign in at iCloud Find Devices with the Apple Account that owns the Mac.
  2. Select the Mac and choose Mark As Lost. This locks the Mac with a passcode you set and shows a return message. Write the passcode down somewhere other than the missing device.
  3. Leave Erase This Device alone for now. A Mac that has been erased stops reporting its location.
  4. Confirm the Mac used FileVault. Without it, the disk can be read by removing it, and every local secret should be treated as exposed.
  5. If the Mac was enrolled in Apple Business Manager or an MDM, lock it there too so the action survives a reinstall.
  1. Sign in at account.microsoft.com/devices and open Find my device for the missing PC. This only works if the feature was switched on beforehand.
  2. Choose Lock, which signs out local users and shows a message on the lock screen.
  3. For an Entra ID or Intune managed PC, use the Intune admin center and pick a remote Lock. Hold Wipe and Retire back until you have decided whether location still matters.
  4. Confirm BitLocker was on. If it was not, treat the disk as readable and rotate every credential that touched the machine.
  5. Retrieve the BitLocker recovery key from the account or Intune record and store it away from the device.
  1. Assume there is no remote lock. Most Linux laptops have no equivalent of Find My, so recovery depends entirely on what you set up in advance.
  2. Confirm whether the disk used LUKS full-disk encryption. If it did not, treat every file, key, and cached session on the machine as read by an attacker.
  3. Revoke the machine’s SSH keys everywhere they were authorized, starting with ~/.ssh/authorized_keys on your servers and the key lists in GitHub, GitLab, and your cloud provider.
  4. Revoke its VPN certificate or WireGuard peer entry, and remove the host from any configuration-management inventory.
  5. Expire the user’s Kerberos, SSO, and browser sessions centrally rather than relying on any action on the device.

Today

  1. Decide whether to queue a remote erase. Remember that some platforms cannot locate the device after erasure.
  2. Rotate credentials stored unencrypted or accessible through an unlocked session.
  3. Review sign-in, source-control, cloud, payment, and application logs from the time of loss.
  4. Identify customer or regulated data stored locally and get legal advice about notification.
  5. Prepare a clean replacement device. Restore only business data from trusted sources.
  6. Keep the missing device blocked even if someone claims to have found it, until identity and chain of custody are confirmed.

Verify recovery

  • The missing device is locked, blocked, or erased according to the chosen plan.
  • Old sessions, keys, tokens, VPN profiles, and trusted-device approvals fail.
  • Audit logs show no unexplained access after the loss.
  • Critical business data exists in business-controlled systems, not only on the laptop.
  • The replacement device uses current patches, encryption, screen lock, and management.

Prepare now

Device

  • Full-disk encryption and a strong automatic screen lock are enabled.
  • Find My or business device management is enabled and tested.
  • The serial number and recovery details are stored away from the laptop.
  • Sensitive local data is minimized and automatically backed up.

Turn on encryption and tracking

  • FileVault is on under System Settings → Privacy & Security → FileVault, and the recovery key is stored in your password manager rather than iCloud alone.
  • Find My Mac is enabled under System Settings → Apple Account → iCloud, and you have signed in to iCloud Find Devices once to confirm the Mac appears.
  • The firmware password or Activation Lock is on, so an erase cannot simply hand a clean Mac to whoever has it.
  • BitLocker is on for the system drive, and the recovery key is saved to your Microsoft or Entra account and to your password manager.
  • Find my device is enabled under Settings → Privacy & security, which requires signing in with a Microsoft account.
  • Secure Boot and a UEFI password are set, and automatic sign-in is off.
  • The root filesystem uses LUKS, and the passphrase is not reused anywhere else.
  • The bootloader is password protected and Secure Boot is on, so a live USB cannot quietly change the boot path.
  • The machine’s SSH keys are hardware backed or passphrase protected, and every server records which key belongs to which laptop.

Access

  • Password-manager access requires a strong independent factor.
  • SSH keys, tokens, certificates, and devices have names and owners.
  • Critical services can revoke one device without resetting every user.
  • Recovery codes are not stored only on the laptop.

Practice

  • A second person can locate the device record, revoke its access, and prepare a clean replacement.

Common mistakes

  • Waiting a day before revoking sessions. A logged-in browser may be more valuable than the files.
  • Erasing before deciding whether location matters. Some platforms stop tracking after erase.
  • Changing every password without a priority order. Secure email, identity, and password manager first.
  • Restoring the whole old device image. It may restore weak settings or malware.
  • Meeting the finder alone. Use safe, documented recovery channels.

Sources

Last reviewed July 27, 2026Guidance changes. Confirm provider-specific actions in the linked official sources.