← IncidentReady

Employee laptop lost or stolen: the small business checklist

For companies whose entire IT department is one person. Also covers phones and tablets. No SOC, no SIEM assumed. Print this.

The first 15 minutes

  1. Get the facts from the employee directly — phone or in person, not chat: device type/model, last known location and time seen, whether it was locked/encrypted, and what was logged in. Don't assume the answers — most people don't know, so check your MDM/asset record too.
  2. Check device status in your management console right away — Intune (M365), Google Admin console, or the consumer Find My service for a personal/BYOD device.
  3. Locate before you wipe. If the device shows online in a plausible location, a remote lock + alarm is usually the better first move — it preserves recovery odds without destroying data unnecessarily. If theft is suspected, or the location is implausible or unknown, skip straight to remote lock and wipe.
  4. Revoke the device's active sessions and force sign-out (Entra ID for M365, Admin console for Google Workspace) — do this even before the wipe completes.
  5. Reset passwords for every account with an active, unlocked session on the device (email, SSO, VPN), and revoke MFA registration if it was an authenticator or paired security key. Assume tokens on the device are usable by whoever has it until revoked.
  6. Start the "what data was on it" worksheet (below) while details are fresh.

Remote wipe decision tree

The order of operations that avoids wiping a recoverable device and avoids sitting on an exposed one:

Where to issue it: Intune admin center → Devices → [device] → Wipe (or Retire for BYOD, to spare personal data). Google Admin console → Devices → [device] → Wipe device (or Deprovision for a managed Chromebook/desktop). Apple/Google consumer Find My services work too, but the device has to check in to the internet to receive the command — if it never does, the wipe stays queued and you should treat the data as exposed regardless.

Encryption check — confirm, don't guess

Exposure assessment — what was actually on it

Work through this while the lock/wipe is in progress, not after: local files with customer/employee PII or financial data; whether a password manager was installed and its vault unlocked; saved/autofill browser passwords; whether email and VPN clients were configured and actively logged in; locally cached credentials, API keys, or .env files; and whether an SSO app or authenticator was registered on the device. Also confirm the device was actually enrolled and compliant in your MDM before it went missing — an unenrolled personal device has no remote wipe capability, which pushes your severity assessment up immediately.

Score the overall exposure LOW / MEDIUM / HIGH and get it signed off — this is the record your insurer and, if needed, counsel will want.

Police report — when and why

File a police report for any confirmed theft (not simple misplacement) — most cyber insurance policies require it as a condition of a claim, and it puts the device's serial number on record if it resurfaces. For a simple loss with no evidence of theft, a report is optional but still worth filing if the device held sensitive data. Have ready: company name and address, device make/model/serial, approximate value, location and time, any witnesses or camera coverage, and the reporting employee's contact info. State and local requirements vary — this isn't legal advice.

The mistakes that make it worse

This checklist is 1 of 10 runbooks.

The full IncidentReady pack covers lost/stolen devices end-to-end (severity scoring, network and badge containment, breach-notification thresholds, copy-paste employee and customer notices) plus ransomware, phishing/BEC, compromised accounts, and a tabletop kit to rehearse it — written for businesses of 5–50 people. Editable, $29.

Get the pack — $29   Read the free phishing runbook →

Preparedness templates, not legal advice. © 2026 IncidentReady