The essentials
- Full-disk encryption with a decent password turns a stolen laptop into a brick with resale value — establish encryption status first, everything else follows from it.
- Trigger remote lock or wipe through your device management as soon as possible; it takes effect whenever the machine next comes online.
- Rotate credentials and revoke sessions for accounts that were signed in — cached sessions can outlive the password that created them.
- File the police report with the serial number; insurers and some recoveries depend on it.
- An unencrypted disk with personal data on it is a notifiable-breach analysis, not just a loss.
The instinct after a theft is to mourn the hardware. The real questions are about the data: what lived on the disk, what sessions were live, and whether the disk can be read at all.
Answer those in order and the incident usually shrinks to paperwork — or reveals itself early as something that needs real response.
Do this now
- Report to IT immediately. They can push a remote lock or wipe, check when the device last connected, and confirm from policy whether the disk was encrypted.
- Kill the sessions. From another device, sign out all sessions for email, chat, cloud storage, VPN, and anything else that was logged in — then change those passwords.
- File the police report. Serial number, asset tag, time and place. It anchors the insurance claim and occasionally brings hardware back.
- Establish what was on it. Local files, cached mailboxes, saved credentials, client data. Precision here decides whether notification duties exist.
- Run the exposure analysis. Encrypted with strong authentication: document it and close. Unencrypted or weakly protected with personal data: treat as a potential breach and involve the people who handle notification.
What not to do
- Do not treat it as "just hardware" before checking what data and sessions it carried.
- Do not delay reporting because the bag "might turn up" — the wipe command needs to be waiting when the device comes online.
- Do not go retrieve it yourself if tracking shows a location; give the location to police.
- Do not skip the session revocation because the password "was strong" — live sessions bypass the password entirely.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- Serial number, asset tag, and the police report number.
- Proof of encryption status from device management policy.
- The inventory of data and signed-in accounts on the machine.
- Timestamps: theft, report, lock/wipe command, last device check-in.
Keep a clear head
People sit on laptop thefts for hours out of embarrassment and the hope it will reappear. The organization does not need you to have prevented the theft — it needs the report within minutes so the technical safeguards can do their job.
Questions victims ask
The disk was encrypted. Is the data safe?
With full-disk encryption and a decent password or hardware-backed key, yes — practically speaking, the thief has hardware, not data. Sessions and cached tokens are the caveat, which is why revocation still matters.
Find-my shows exactly where it is. Should I go get it?
No. Confronting a thief over hardware is a bad trade in every scenario. Give the location and report number to the police and let the wipe command handle the data.
It was my personal laptop but had work files on it.
Tell your employer anyway. The exposure analysis is about the data, not the ownership of the device — and doing it now, honestly, is cheap compared to it surfacing later.