Lost or Stolen Company Laptop: The First-Hour Checklist for Small Business

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

A laptop goes missing from a rideshare, a coffee shop table, or a car break-in more often than most small business owners expect, and the instinct is almost always to focus on finding it. That instinct is backwards. The location of the physical device stops mattering the moment access to it is cut off and the drive is confirmed unreadable. What follows is the order of operations that actually limits the damage, built around the tools a business already has if its devices are enrolled and encrypted, and a reminder of what's missing if they aren't.

Cut off access before you look for the laptop

The first move is a password reset for whoever was using the device, followed by revoking that user's active sign-in sessions in Microsoft 365 or Google Workspace. A laptop that was logged in when it went missing may still be holding a valid session token, and a stolen token lets someone in without ever needing the password. Revoking sessions invalidates that token immediately, regardless of where the laptop physically is. If conditional access policies are in place, this is also the moment they earn their keep, blocking sign-in attempts from a device that is no longer trusted the instant it tries to reconnect.

Encryption and remote wipe: why the laptop rarely matters

Once access is cut off, the next question is whether the data on the drive itself is a problem. A laptop with full-disk encryption turned on, BitLocker on Windows or FileVault on a Mac, keeps everything on that drive unreadable without the recovery key, even if someone pulls the physical drive out and connects it to another machine. This is the single control that turns "our laptop is gone" into a shrug instead of a scramble. If the device is enrolled in mobile device management, queue a remote wipe regardless of whether it currently shows online. The command sits and waits, and runs the moment the device next touches the internet. None of this works retroactively. It has to be set up before the laptop goes missing, which is the argument for zero-touch enrollment on every device from day one rather than as an afterthought.

Document it, even if nothing sensitive was on it

Write down when and where the laptop was lost, what the user was signed into at the time, whether encryption was confirmed on, and what kind of data typically lived on that machine. This record matters for two audiences beyond your own peace of mind: a cyber insurance carrier, if a claim ever touches this incident, and a determination of whether the loss triggers a legal notification obligation. If the device held unencrypted personal information about California residents, that determination is not a guess an owner should make alone. Treat any lost device that plausibly held customer or employee data as a reasonably suspected incident and get it looked at properly, rather than assuming it's fine because the laptop probably ended up in a landfill instead of an attacker's hands.

The setup that makes this a non-event

Every step above depends on work that has to happen before a laptop ever goes missing: devices enrolled in mobile device management with zero-touch setup, encryption confirmed on rather than assumed, and conditional access policies that require a compliant, known device before sensitive apps will even respond. A business with that in place turns a lost laptop into a same-day replacement and a paragraph in an incident log. A business without it turns the same lost laptop into weeks of uncertainty about what an attacker might have had access to.

Frequently asked questions

What's the very first thing to do when a company laptop is lost or stolen?

Cut off access before you spend time searching for the device. Reset the user's password and revoke their active sign-in sessions so any cached login on the laptop stops working immediately. Finding the laptop later is a bonus. Making sure it is useless to whoever has it is the actual goal.

Does encryption actually matter if the laptop is gone for good?

Yes, and it is the difference between a device replacement and a data breach. A laptop with full-disk encryption turned on, such as BitLocker on Windows or FileVault on a Mac, keeps the data on the drive unreadable without the recovery key, even if someone removes the drive entirely. A laptop without it is a filing cabinet with the lock missing.

Can a laptop still be remotely wiped after it's already offline?

A wipe command queues and runs the next time the device connects to the internet, so it is worth issuing even if the laptop looks offline right now. This depends on mobile device management being enrolled on the machine before it went missing, which is why enrollment has to happen at setup, not after something goes wrong.

Do we have to report a lost laptop to anyone outside the company?

It depends on what was on it and whether it was encrypted. If the device held unencrypted personal information about California residents, state breach notification law may apply. This is a legal determination, not a guess, so treat any lost device that held customer or employee data as a reasonably suspected incident and get it assessed rather than deciding on your own that it's fine.

Not sure your devices are actually set up to survive this?

30 minutes with an engineer with DoD infrastructure experience. We'll check whether your laptops are actually enrolled in mobile device management, whether encryption is confirmed rather than assumed, and how conditional access and cloud backup fit into the picture, plus what our 4-hour notification commitment means if a device ever does go missing.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501