Photo by Adi Goldstein on Unsplash
Lost laptop playbook: encryption verification and MDM remote wipe
A lost laptop playbook turns a stressful incident into a repeatable procedure. When a device goes missing, your team needs clear steps: verify encryption, revoke access, initiate MDM remote wipe, and document evidence for auditors and—if required—breach notification analysis. Teams without a playbook lose hours debating who calls whom while credentials remain active.
This guide covers:
- When to trigger lost/stolen device response (vs "I left it at home")
- First-hour actions: access revocation, encryption verification, remote wipe
- How the five endpoint checks (encryption, anti-virus, password policy, screen policy, firewall) affect incident severity
- Evidence collection for SOC 2, ISO 27001, and customer notification decisions
- Prevention through MDM enrollment and SecureSlate continuous monitoring

GIF via GIPHY
Related guides:
- MDM compliance guide
- BYOD and MDM: balancing flexibility and security
- MDM for SOC 2 Type II endpoint evidence
- Building an endpoint security baseline for startups
Key takeaways
- Speed matters — revoke IdP sessions and initiate MDM remote wipe within the first hour.
- Encryption status determines severity — a lost encrypted laptop with strong password policy is lower risk than an unencrypted device.
- SecureSlate Asset Management shows pre-loss 5/5 check status as audit evidence that controls were operating.
- Document every step — timestamps, actors, and outcomes support audit inquiries and breach analysis.
- BYOD devices may require selective wipe instead of full erase—know your enrollment model before an incident.
When to trigger the playbook
Trigger full lost/stolen device response when:
- Device is confirmed lost in a public place, vehicle, or travel scenario
- Device was stolen (office break-in, mugging, airport theft)
- Device is missing and the employee cannot locate it within your policy SLA (commonly 24 hours)
- Device was left unattended in an untrusted location and cannot be verified secure
Do not trigger full wipe for:
- Device left at home but employee is traveling (attempt locate first)
- Device in office locker but employee forgot location
- Device with dead battery but last known location is secure office
Document the distinction in your incident response procedure so helpdesk staff escalate correctly.
First 60 minutes
Execute these steps in parallel where possible:
-
Employee reports to IT / Security — dedicated channel (Slack, ticket, phone); capture device serial, MDM ID, last known location, time discovered missing.
-
Revoke IdP sessions immediately — disable or force re-auth for the employee's accounts; rotate credentials if policy requires.
-
Mark device lost in MDM — enables Lost Mode (Apple) or equivalent; displays contact message on lock screen.
-
Verify encryption status in SecureSlate — confirm HD encryption check was passing before loss; export snapshot for incident record.
-
Initiate remote wipe — full wipe for company-owned; selective/work-profile wipe for BYOD per BYOD and MDM.
-
Disable VPN and certificate access — revoke device certificates if MDM wipe is delayed or device is offline.
-
Notify Security lead and GRC — determine if customer notification, regulatory reporting, or insurance claim is required.
-
Open incident ticket — assign owner; start evidence collection timeline.
Verify encryption status
Encryption is the single most important factor in lost device severity:
| Encryption state | Data exposure risk | Typical response |
|---|---|---|
| Encrypted + strong password | Low — data inaccessible without credentials | Remote wipe; monitor; document; usually no breach notification |
| Encrypted + weak/no password | Medium — encryption bypass possible | Wipe; credential rotation; assess notification |
| Encryption disabled or unknown | High — treat as potential data breach | Wipe; forensics assessment; legal/comms review |
| Encryption was failing in SecureSlate before loss | High — control was not operating | Wipe; root-cause why check failed; audit finding likely |
Pull the SecureSlate Asset Management history for the device. Auditors may ask: "Was encryption enabled at the time of loss?" Pre-loss 5/5 status is your answer.
MDM remote wipe procedure
| Step | Action | Owner |
|---|---|---|
| 1 | Confirm device enrolled in MDM | IT |
| 2 | Check last MDM check-in time | IT |
| 3 | Send remote wipe command | IT |
| 4 | If online: confirm wipe acknowledged | IT |
| 5 | If offline: device wipes on next check-in; keep IdP sessions revoked | IT |
| 6 | For BYOD: confirm selective wipe scope (work data only) | IT + employee |
| 7 | Remove device from asset inventory | IT |
| 8 | Export MDM wipe confirmation + SecureSlate pre-loss status | GRC |
Offline devices are the hardest case. Keep IdP access revoked indefinitely until wipe confirms or device is recovered and re-verified. Do not re-enable access hoping the device will appear.
Apple Lost Mode and equivalent Android features can display a contact number and track location where policy and jurisdiction allow—document whether your organization uses location tracking and disclose in policy.
Five endpoint checks and incident response
SecureSlate monitors five checks that directly affect lost device response:
| Check | Incident relevance |
|---|---|
| HD Encryption | Primary factor in breach determination |
| Anti-Virus | Lower immediate priority; relevant if device recovered and analyzed |
| Password Policy | Strong passcode reduces encryption bypass risk |
| Screen Policy | Short auto-lock limits window for unauthorized access before loss reported |
| Firewall | Limits network attack surface if device is powered on and connected |
A device that was 5/5 passing in SecureSlate before loss demonstrates controls were operating—valuable evidence during audit inquiries about the incident.
Evidence to collect for audits
| Evidence item | Source | Purpose |
|---|---|---|
| Incident ticket with timeline | ITSM | Proves response procedure followed |
| MDM wipe confirmation | MDM console | Proves remote wipe initiated/completed |
| Pre-loss SecureSlate status export | SecureSlate Asset Management | Proves encryption and 5/5 checks at time of loss |
| IdP session revocation log | Identity provider | Proves access removed |
| Employee report / statement | HR / Security | Documents discovery circumstances |
| Management review sign-off | GRC | Closes incident; documents notification decision |
| Root-cause if encryption failed | IT + GRC | Corrective action for audit finding |
Store incident records for at least the audit observation period plus your retention policy—commonly three to seven years.
Response decision matrix
| Scenario | Encryption | Wipe type | Notification | Audit action |
|---|---|---|---|---|
| COBO laptop stolen, 5/5 in SecureSlate | Enabled | Full remote wipe | Usually internal only | Document; sample for Type II |
| BYOD phone lost, work profile enrolled | Enabled | Selective wipe | Usually internal only | Document; verify work data scope |
| Laptop lost, encryption failing in SecureSlate | Disabled/unknown | Full wipe + forensics | Legal review required | Corrective action + finding |
| Device offline >72 hours post-wipe command | Unknown | Keep IdP revoked; monitor | Escalate if sensitive data | Extended incident record |
| Device recovered | Verify intact | Re-enroll; re-verify 5/5 | Close incident | Update asset inventory |
Prevention before loss happens
The best lost laptop response is never needing it:
- 100% MDM enrollment — no unmanaged devices with production access.
- 5/5 checks enforced continuously — encryption, AV, password, screen lock, firewall via MDM profiles.
- SecureSlate weekly monitoring — catch encryption failures before a device is lost.
- Screen lock ≤5 minutes — limits exposure window for unattended devices.
- Employee training — report loss immediately; do not wait until next business day.
- Travel policy — laptops in hotel safes; never checked baggage for work devices.
- Asset tags and inventory — serial numbers in SecureSlate match MDM enrollment.
See building an endpoint security baseline for startups for program setup from scratch.
Roles during an incident
| Role | Actions |
|---|---|
| Employee | Report immediately; cooperate with wipe; do not attempt self-locate via risky means |
| IT / Helpdesk | Revoke access, MDM wipe, update inventory |
| Security lead | Severity assessment, escalation, comms coordination |
| GRC / Compliance | Evidence collection, notification analysis, audit documentation |
| Legal | Breach determination, regulatory notification if required |
| HR | Employee support, policy enforcement if negligence involved |
Publish this RACI in your incident response procedure before the first real incident.
Streamline with SecureSlate
SecureSlate Asset Management gives you pre-loss endpoint status—HD encryption, anti-virus, password policy, screen policy, and firewall—so incident response starts with facts, not guesses. Export device history for audit evidence and breach analysis from one platform.
Pair continuous 5/5 monitoring with MDM remote wipe capability for a complete lost device program.
Get started for free · Free readiness score
FAQ: Lost laptop response
How quickly should we remote wipe a lost device?
Within the first hour is a common target. IdP session revocation should happen immediately—even before wipe confirms.
What if the device is offline and cannot receive wipe command?
Keep IdP access revoked. The wipe executes on next MDM check-in. Treat as high-severity until wipe confirms.
Is a lost encrypted laptop a data breach?
Not automatically—encryption with strong authentication typically means data is inaccessible. Legal counsel should assess based on jurisdiction and data types involved.
Can we recover a wiped device?
No—remote wipe is destructive. If the device is found after wipe, re-enroll from scratch and verify 5/5 checks.
What evidence do SOC 2 auditors request for lost device incidents?
Incident ticket, response timeline, MDM wipe confirmation, and proof that encryption was enabled (SecureSlate export).
Does this apply to BYOD devices?
Yes—use selective wipe for work profiles. See BYOD and MDM.
Should we file a police report?
Many organizations file for stolen devices—especially company-owned hardware. Document the report number in the incident ticket.
How does SecureSlate help after the incident?
Export pre-loss 5/5 check history for audit evidence, track corrective actions if encryption was failing, and maintain incident records alongside control mapping.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
