What to Do When a Work Laptop Is Lost or Stolen

A missing work laptop creates two parallel problems: recover the device if that can be done safely, and contain access to business and client information. Changing every password immediately can be the wrong first move if it destroys evidence, locks out the response team, or overlooks active sessions and tokens.

This first-hour guide helps a freelancer or small team coordinate decisions. It is not a promise that remote location, locking, erasure, or account revocation will work after the device is gone.

Method note: This response flow was reviewed against current Apple, Microsoft, and Google documentation on August 12, 2026. It is documentation-based and uses a fictional incident record; no real theft or client incident is claimed.

Lost work laptop first-hour responseA timeline from establishing facts through device controls, account containment, erase decision, and operational recovery. A missing work laptop: the first 60 minutesProtect people first. Keep a timeline. Contain access while preserving authorized evidence. 00–10 minFacts and safetystart incident log 1010–20 minAvailable controlslocate / lock status 2020–35 minContain accessidentity, email, tokens 3535–50 minLock or erase?authority and evidence 5050–60 minRestore operationstrusted spare device Do not confront a suspected thief. Do not erase before checking authority, backups,evidence, and reporting duties.
The first hour coordinates safety, evidence, account containment, device decisions, and continuity; it is not a universal erase-first sequence.

Minute 0–10: Establish Facts and Safety

Record the last known time and location, device make/model, serial or asset number if available, signed-in user, whether the screen was locked, and what business systems may be reachable. Check nearby locations and trusted lost-property channels, but do not confront a suspected thief or travel to an unfamiliar mapped location. Contact local law enforcement where appropriate.

Designate one coordinator and start a time-stamped incident log. If client, regulated, privileged, or payment data may be involved, contact the organization’s authorized security, privacy, legal, insurance, or client representative promptly under the applicable plan.

Minute 10–20: Determine the Device Controls Available

Remote tools normally must have been configured before loss and may depend on power, connectivity, account type, location settings, and administrator policy.

  • Apple’s lost or stolen Mac instructions explain Find My, Lost Mode/locking, erasure, and the consequences of erasing. Apple notes that Find My must have been set up beforehand for those location and remote actions.
  • Microsoft’s Find and lock a lost Windows device guide states that the feature must already be enabled and uses a personal Microsoft administrator account; it does not work with work or school accounts.
  • For a managed device, use the employer’s device-management process rather than assuming consumer controls apply.

Capture the displayed status and time. A stale map position is not proof of the device’s current location or who has it.

Minute 20–35: Contain High-Impact Access

Prioritize the routes that can lead to other systems: primary email, identity provider, password manager, cloud workspace, source-code or client portals, financial administration, and remote access. Follow the provider’s session-revocation and device-removal procedures, not just password changes.

Google’s lost device account guidance describes signing a device or session out and notes that multiple sessions may need separate action. Other providers have their own controls.

  1. Use a known-clean, trusted device and network.
  2. Secure the primary identity/email route first so later resets cannot be intercepted.
  3. Review recent sign-ins, sessions, forwarding, recovery methods, OAuth/app access, and administrator changes.
  4. Revoke the lost device and suspicious sessions where authorized.
  5. Rotate exposed credentials and tokens in a controlled order, recording owners and dependencies.
  6. Notify relevant administrators and clients using an established channel when required.

Do not put new passwords, backup codes, or recovery keys in the incident log.

Minute 35–50: Decide About Locking or Erasure

Remote lock can reduce access when supported. Remote erase is a consequential step: it can remove data, affect later location, complicate evidence preservation, fail while offline, or interfere with insurance and law-enforcement instructions. Confirm authorization, backups, contractual obligations, management ownership, and recovery consequences before erasing.

For an employer-owned or managed computer, the owner’s authorized administrator should make the decision. For suspected crime, regulated data, litigation, or a material breach, obtain qualified direction.

Minute 50–60: Protect Operations

Identify work due in the next day, obtain an approved replacement device, and restore only from known recovery sources. Do not sign in to every business account from an untrusted borrowed computer. Check whether multifactor authentication depended on the missing laptop and use prepared recovery routes.

Tell collaborators only what they need: which communication channel is trusted, whether requests from the lost device should be rejected, and who approves urgent changes. Avoid announcing sensitive incident details broadly.

Fictional First-Hour Record

A fictional two-person studio notices at 3:10 p.m. that its encrypted laptop is missing after transit. The owner records the serial number, confirms the screen was locked, and calls the transit lost-property service. At 3:18, the administrator sees an old device location and does not attempt retrieval. At 3:25, the email and workspace sessions are reviewed and the laptop session is revoked. At 3:38, the password-manager device is removed and high-impact tokens are rotated. The studio consults its insurer before deciding whether to erase, then switches client communication to an approved spare device.

This example demonstrates sequencing only. It is not evidence that encryption, revocation, or remote tools prevent every disclosure.

Containment gaps should become follow-up work, not disappear with the incident log. Retest the affected account with the recovery-readiness drill, reconsider device-dependent authentication choices, verify the replacement-device recovery plan, and use the offboarding access map if another person or unmanaged account still controls work data.

After the First Hour

Preserve the timeline and relevant provider alerts. Review mailbox rules, login history, file-sharing events, API tokens, payment changes, and unusual client messages. Follow applicable notification, insurance, contract, privacy, and law-enforcement requirements. After containment, document what failed: missing serial record, unavailable recovery code, unconfigured device location, excessive local data, or unclear ownership.

Boundary: This is general security information, not legal, privacy, insurance, employment, or incident-response advice. Immediate professional help may be appropriate when sensitive data, active compromise, financial loss, personal safety, or reporting duties are involved.

Comments

Popular posts from this blog

A Digital Security Baseline for Freelancers and Small Teams

Passkeys, Authenticator Apps, and Security Keys: How to Choose

Verify a Vendor Payment-Change Email Before Sending Money