Back to GRC

Lost laptop playbook: encryption verification and MDM remote wipe

Photo by Adi Goldstein on Unsplash

Lost laptop playbook: encryption verification and MDM remote wipe

A lost laptop playbook turns a stressful incident into a repeatable procedure. When a device goes missing, your team needs clear steps: verify encryption, revoke access, initiate MDM remote wipe, and document evidence for auditors and—if required—breach notification analysis. Teams without a playbook lose hours debating who calls whom while credentials remain active.

This guide covers:

  • When to trigger lost/stolen device response (vs "I left it at home")
  • First-hour actions: access revocation, encryption verification, remote wipe
  • How the five endpoint checks (encryption, anti-virus, password policy, screen policy, firewall) affect incident severity
  • Evidence collection for SOC 2, ISO 27001, and customer notification decisions
  • Prevention through MDM enrollment and SecureSlate continuous monitoring

Incident response urgency

GIF via GIPHY

Related guides:


Key takeaways

  • Speed matters — revoke IdP sessions and initiate MDM remote wipe within the first hour.
  • Encryption status determines severity — a lost encrypted laptop with strong password policy is lower risk than an unencrypted device.
  • SecureSlate Asset Management shows pre-loss 5/5 check status as audit evidence that controls were operating.
  • Document every step — timestamps, actors, and outcomes support audit inquiries and breach analysis.
  • BYOD devices may require selective wipe instead of full erase—know your enrollment model before an incident.

When to trigger the playbook

Trigger full lost/stolen device response when:

  • Device is confirmed lost in a public place, vehicle, or travel scenario
  • Device was stolen (office break-in, mugging, airport theft)
  • Device is missing and the employee cannot locate it within your policy SLA (commonly 24 hours)
  • Device was left unattended in an untrusted location and cannot be verified secure

Do not trigger full wipe for:

  • Device left at home but employee is traveling (attempt locate first)
  • Device in office locker but employee forgot location
  • Device with dead battery but last known location is secure office

Document the distinction in your incident response procedure so helpdesk staff escalate correctly.


First 60 minutes

Execute these steps in parallel where possible:

  1. Employee reports to IT / Security — dedicated channel (Slack, ticket, phone); capture device serial, MDM ID, last known location, time discovered missing.

  2. Revoke IdP sessions immediately — disable or force re-auth for the employee's accounts; rotate credentials if policy requires.

  3. Mark device lost in MDM — enables Lost Mode (Apple) or equivalent; displays contact message on lock screen.

  4. Verify encryption status in SecureSlate — confirm HD encryption check was passing before loss; export snapshot for incident record.

  5. Initiate remote wipe — full wipe for company-owned; selective/work-profile wipe for BYOD per BYOD and MDM.

  6. Disable VPN and certificate access — revoke device certificates if MDM wipe is delayed or device is offline.

  7. Notify Security lead and GRC — determine if customer notification, regulatory reporting, or insurance claim is required.

  8. Open incident ticket — assign owner; start evidence collection timeline.


Verify encryption status

Encryption is the single most important factor in lost device severity:

Encryption state Data exposure risk Typical response
Encrypted + strong password Low — data inaccessible without credentials Remote wipe; monitor; document; usually no breach notification
Encrypted + weak/no password Medium — encryption bypass possible Wipe; credential rotation; assess notification
Encryption disabled or unknown High — treat as potential data breach Wipe; forensics assessment; legal/comms review
Encryption was failing in SecureSlate before loss High — control was not operating Wipe; root-cause why check failed; audit finding likely

Pull the SecureSlate Asset Management history for the device. Auditors may ask: "Was encryption enabled at the time of loss?" Pre-loss 5/5 status is your answer.


MDM remote wipe procedure

Step Action Owner
1 Confirm device enrolled in MDM IT
2 Check last MDM check-in time IT
3 Send remote wipe command IT
4 If online: confirm wipe acknowledged IT
5 If offline: device wipes on next check-in; keep IdP sessions revoked IT
6 For BYOD: confirm selective wipe scope (work data only) IT + employee
7 Remove device from asset inventory IT
8 Export MDM wipe confirmation + SecureSlate pre-loss status GRC

Offline devices are the hardest case. Keep IdP access revoked indefinitely until wipe confirms or device is recovered and re-verified. Do not re-enable access hoping the device will appear.

Apple Lost Mode and equivalent Android features can display a contact number and track location where policy and jurisdiction allow—document whether your organization uses location tracking and disclose in policy.


Five endpoint checks and incident response

SecureSlate monitors five checks that directly affect lost device response:

Check Incident relevance
HD Encryption Primary factor in breach determination
Anti-Virus Lower immediate priority; relevant if device recovered and analyzed
Password Policy Strong passcode reduces encryption bypass risk
Screen Policy Short auto-lock limits window for unauthorized access before loss reported
Firewall Limits network attack surface if device is powered on and connected

A device that was 5/5 passing in SecureSlate before loss demonstrates controls were operating—valuable evidence during audit inquiries about the incident.


Evidence to collect for audits

Evidence item Source Purpose
Incident ticket with timeline ITSM Proves response procedure followed
MDM wipe confirmation MDM console Proves remote wipe initiated/completed
Pre-loss SecureSlate status export SecureSlate Asset Management Proves encryption and 5/5 checks at time of loss
IdP session revocation log Identity provider Proves access removed
Employee report / statement HR / Security Documents discovery circumstances
Management review sign-off GRC Closes incident; documents notification decision
Root-cause if encryption failed IT + GRC Corrective action for audit finding

Store incident records for at least the audit observation period plus your retention policy—commonly three to seven years.


Response decision matrix

Scenario Encryption Wipe type Notification Audit action
COBO laptop stolen, 5/5 in SecureSlate Enabled Full remote wipe Usually internal only Document; sample for Type II
BYOD phone lost, work profile enrolled Enabled Selective wipe Usually internal only Document; verify work data scope
Laptop lost, encryption failing in SecureSlate Disabled/unknown Full wipe + forensics Legal review required Corrective action + finding
Device offline >72 hours post-wipe command Unknown Keep IdP revoked; monitor Escalate if sensitive data Extended incident record
Device recovered Verify intact Re-enroll; re-verify 5/5 Close incident Update asset inventory

Prevention before loss happens

The best lost laptop response is never needing it:

  1. 100% MDM enrollment — no unmanaged devices with production access.
  2. 5/5 checks enforced continuously — encryption, AV, password, screen lock, firewall via MDM profiles.
  3. SecureSlate weekly monitoring — catch encryption failures before a device is lost.
  4. Screen lock ≤5 minutes — limits exposure window for unattended devices.
  5. Employee training — report loss immediately; do not wait until next business day.
  6. Travel policy — laptops in hotel safes; never checked baggage for work devices.
  7. Asset tags and inventory — serial numbers in SecureSlate match MDM enrollment.

See building an endpoint security baseline for startups for program setup from scratch.


Roles during an incident

Role Actions
Employee Report immediately; cooperate with wipe; do not attempt self-locate via risky means
IT / Helpdesk Revoke access, MDM wipe, update inventory
Security lead Severity assessment, escalation, comms coordination
GRC / Compliance Evidence collection, notification analysis, audit documentation
Legal Breach determination, regulatory notification if required
HR Employee support, policy enforcement if negligence involved

Publish this RACI in your incident response procedure before the first real incident.


Streamline with SecureSlate

SecureSlate Asset Management gives you pre-loss endpoint status—HD encryption, anti-virus, password policy, screen policy, and firewall—so incident response starts with facts, not guesses. Export device history for audit evidence and breach analysis from one platform.

Pair continuous 5/5 monitoring with MDM remote wipe capability for a complete lost device program.

Get started for free · Free readiness score


FAQ: Lost laptop response

How quickly should we remote wipe a lost device?

Within the first hour is a common target. IdP session revocation should happen immediately—even before wipe confirms.

What if the device is offline and cannot receive wipe command?

Keep IdP access revoked. The wipe executes on next MDM check-in. Treat as high-severity until wipe confirms.

Is a lost encrypted laptop a data breach?

Not automatically—encryption with strong authentication typically means data is inaccessible. Legal counsel should assess based on jurisdiction and data types involved.

Can we recover a wiped device?

No—remote wipe is destructive. If the device is found after wipe, re-enroll from scratch and verify 5/5 checks.

What evidence do SOC 2 auditors request for lost device incidents?

Incident ticket, response timeline, MDM wipe confirmation, and proof that encryption was enabled (SecureSlate export).

Does this apply to BYOD devices?

Yes—use selective wipe for work profiles. See BYOD and MDM.

Should we file a police report?

Many organizations file for stolen devices—especially company-owned hardware. Document the report number in the incident ticket.

How does SecureSlate help after the incident?

Export pre-loss 5/5 check history for audit evidence, track corrective actions if encryption was failing, and maintain incident records alongside control mapping.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.8(195 reviews)

Keep reading

Aug 12, 2026 · GRC

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Aug 12, 2026 · GRC

Building an endpoint security baseline for startups

Aug 12, 2026 · GRC

BYOD and MDM: balancing flexibility and endpoint security

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?