Back to Blog
    Laptop secured with chain and padlock on a dark desk, surrounded by tech tools, external drive, and server racks in background.

    Employee Laptop Lost or Stolen? Do These 9 Steps Now

    Author: Fix My PC Store Editorial TeamPublished: 8/21/2026Last Updated: 8/21/2026

    A missing laptop is stressful, but panic isn't a plan. Here's the exact order of steps to lock down accounts, protect data, and report the loss the right way, with zero wasted time.

    TL;DR: The first hour after a laptop goes missing matters more than the rest of the week combined. Lock the accounts, wipe the device remotely if you can, notify the right people, and document everything. If your business does not have a plan for this already, this is your plan.

    Okay, deep breath. An employee just told you their laptop is gone, maybe left in a rideshare, maybe stolen out of a car in a parking lot near CityPlace. Your stomach drops because you're thinking about client data, financial records, maybe even patient or customer information sitting on that machine. Here's the good news: you can control what happens next, even if you can't control what already happened. Let's walk through it together, step by step, in the order that actually matters.

    1. Get the exact details from the employee immediately

    Before you touch a single setting, get the facts. When did they last see it? Was it logged in and unlocked, or locked with a password? Was it a company laptop or a personal one used for work (this matters a lot for what you're legally allowed to do remotely)? Was there a physical theft, like a break-in, or a simple loss, like leaving it on a train or in the back of an Uber?

    Write this down. You are not just gathering gossip, you're building a timeline you may need for insurance, for law enforcement, or for a breach notification later. Specific details matter here: the difference between "laptop was locked and encrypted" and "laptop was logged in with the browser open" is the difference between a minor incident and a reportable data breach. Ask calmly and without blame. Your employee is probably scared they're in trouble. They're not the enemy here, the missing device is. Making them feel safe to share everything quickly is the most useful thing you can do in the first five minutes.

    Also confirm the device's asset tag or serial number if you track those, and which applications were installed or actively logged in. A laptop with only a local Word document on it is a very different situation from one with an open session into your accounting software, your HR platform, or a client portal.

    2. Change passwords and revoke sessions right away

    This is the single most time-sensitive step. If the laptop had an active login to email, your CRM, cloud storage, or banking portals, someone with physical access could poke around before it ever locks or times out. Browser-saved passwords make this even worse: a stolen laptop with Chrome logged into Google and passwords autofilled is essentially an open door to every account that employee has ever authenticated.

    Go into your admin console (Microsoft 365, Google Workspace, whatever you run) and:

    • Force a password reset on the employee's account
    • Revoke all active sessions and sign-in tokens
    • Disable any saved app passwords or API keys tied to that device
    • Check whether the employee had admin-level access to anything, and treat those accounts as the highest priority

    If your company uses Microsoft 365, this can usually be done from the admin center in a few minutes. Specifically, you can navigate to the user's profile, select "Sign out of all sessions," and initiate a password reset from the same screen. It's worth knowing how to do this before you ever need it, because fumbling through an unfamiliar admin console while the clock is ticking is not the moment you want a learning curve. If you're not sure how, that's a sign your setup could use a second look from someone who manages this daily, which is exactly what our managed IT clients get built in.

    If the employee reused that same password across other tools that sit outside your main identity provider, like a standalone project management app or an industry-specific platform, change those too. Password reuse turns one lost laptop into a much bigger problem.

    3. Trigger a remote wipe if the device supports it

    Many business laptops have mobile device management (MDM) or endpoint protection installed that allows a remote wipe or remote lock. If yours does, use it now, not tomorrow.

    A remote wipe erases the drive the next time the device connects to the internet. A remote lock at minimum requires a password before anyone can get past the sign-in screen. Neither is perfect: a thief who never connects the laptop to WiFi again can dodge a wipe entirely, which is exactly why disk encryption (more on that below) matters so much as a backstop. But remote wipe still dramatically cuts the odds of someone quietly harvesting files if the device does come online, which it often does. People steal laptops and then use them. When they connect to a coffee shop network, that wipe command is waiting.

    For Windows devices managed through Microsoft Intune, the wipe or retire command can be issued from the Endpoint Manager portal in under two minutes. For Apple devices, Apple Business Manager paired with an MDM solution gives you the same capability. If you're managing a mixed fleet, make sure you know which tool covers which devices before an incident happens.

    If you don't currently have this capability across your fleet of laptops, that's a real gap. It's one of the first things we set up when we bring a business under managed IT support, because it turns a worst-case scenario into a manageable one. Without it, a lost laptop stays lost in every sense of the word.

    4. Confirm whether the drive was encrypted

    This step will either relieve a lot of pressure or significantly raise the stakes. If the laptop had full-disk encryption enabled, like BitLocker on Windows or FileVault on Mac, then the data on the drive is essentially unreadable without the decryption key. Someone who pulls the drive out and connects it to another machine sees nothing useful. That's the best-case scenario for a lost or stolen device.

    If encryption was not enabled, the data is accessible to anyone with basic technical knowledge. At that point, you have to treat every file that was stored locally on that machine as potentially exposed. That changes your breach assessment, your notification obligations, and your conversation with your attorney or compliance officer.

    Check your device management records to confirm encryption status. If you don't have records that tell you definitively which devices in your fleet are encrypted, that's the other gap this incident should motivate you to close.

    Tired of IT that breaks at the worst time? Talk to our business IT team

    5. File a police report

    If the laptop was stolen rather than lost, file a police report as soon as you have the device's serial number in hand. In many jurisdictions, a police report is required before your insurance claim will be accepted. It's also necessary documentation if this incident escalates into a formal breach investigation.

    Don't skip this step because it feels like a formality. It's a formality that protects you legally and financially. Keep a copy of the report number and the name of the officer who took the report.

    Even in cases of simple loss rather than theft, documenting that you made reasonable efforts to report and recover the device matters. Regulators and insurers pay attention to whether you treated the situation seriously from the start.

    6. Assess what data was on the device and who it belongs to

    Now that you've contained the immediate risk, you need to understand the scope of the potential exposure. Sit down with the employee and your IT records and answer these questions honestly:

    • What applications were installed and actively used on that machine?
    • Was any sensitive data stored locally rather than in the cloud?
    • Did the device have access to client records, health information, financial data, or payment card data?
    • Were there any credentials, private keys, or certificates stored on the device?

    The answers determine whether this is an internal incident you manage quietly, or whether it triggers legal notification requirements. Under HIPAA, for example, loss of an unencrypted device containing protected health information is presumed to be a breach until proven otherwise, and notification timelines are strict. State data breach laws vary but many require notification to affected individuals within 30 to 60 days. If you're in a regulated industry, get your compliance advisor or attorney involved at this stage, not later.

    7. Notify the right people inside and outside your organization

    Once you know what you're dealing with, notifications need to go out in the right order. Internally, that typically means your IT team, your legal or compliance contact, your HR team if the employee relationship is complicated, and your leadership. Externally, it may mean your cyber liability insurance carrier, affected clients, and depending on your industry, a regulatory body.

    Do not post about it publicly or send a company-wide email before you've talked to legal. The way you communicate a potential breach matters almost as much as how you respond to it. A poorly worded all-staff email can create liability or cause unnecessary panic.

    If you have cyber liability insurance, call them early. Many policies include incident response support, meaning they will connect you with forensic investigators, attorneys, and breach notification specialists at no additional cost. That's a resource most businesses don't take advantage of quickly enough.

    8. Support the employee without burning them down

    This one isn't on most IT checklists, but it should be. The employee who lost the laptop is probably mortified. If they delayed reporting because they were scared of the consequences, that delay made everything worse, and a culture where people are afraid to report incidents quickly is a security liability all on its own.

    Be clear about expectations going forward. Document what happened and what was done in response. If disciplinary action is warranted because a policy was clearly violated, handle it through HR in the normal way. But don't make an example of someone in a way that teaches everyone else to hide incidents. The faster your team reports problems, the faster you can respond, and speed is everything in these situations.

    9. Close the gaps this incident revealed

    Every incident is also an audit. Whatever this situation exposed about your security posture, fix it before the next device goes missing. Common gaps that lost-laptop incidents reveal include:

    • No MDM or remote wipe capability across the device fleet
    • Inconsistent encryption enforcement
    • No documented incident response procedure for employees to follow
    • Over-reliance on local file storage rather than cloud-based document management
    • Shared passwords or no multi-factor authentication on key systems

    If you're not sure where to start, a managed IT provider can walk through your current setup and identify which of these gaps apply to your environment specifically. It's a much easier conversation to have before something goes wrong than after.

    The hard truth is that laptops will get lost. People are human, travel happens, bags get left behind. What separates businesses that handle these moments well from businesses that don't is almost entirely preparation: the right tools configured before the incident, and a clear plan everyone knows to follow when it happens. You now have the plan. The next step is making sure you have the tools to back it up.


    Tired of IT that breaks at the worst time?

    We run managed IT, backups, and security for South Florida businesses so you can stop thinking about it.

    Talk to our business IT team

    Frequently asked questions

    What should I do first when an employee reports a lost or stolen laptop?

    Immediately gather specific details from the employee, including when they last saw the device, whether it was locked or logged in, and which applications were active. Write everything down to build a timeline for insurance, law enforcement, or potential breach notification purposes. Also confirm the device's serial number and what data was accessible on it.

    How quickly should I revoke the employee's account access and passwords?

    This should happen as fast as possible, ideally within minutes of learning about the incident. Log into your admin console (such as Microsoft 365 or Google Workspace), force a password reset, revoke all active sessions, and disable any saved app passwords or API keys tied to the device. Browser-saved passwords and open sessions can give a thief immediate access to multiple accounts.

    Can I remotely wipe a stolen laptop, and does it actually work?

    If your organization uses mobile device management (MDM) software, you can issue a remote wipe command that erases the drive the next time the device connects to the internet. It is not foolproof since a thief who keeps the device offline can avoid the wipe, but many stolen laptops do eventually connect to a network, triggering the command. Full-disk encryption serves as an important backup measure for situations where remote wipe cannot be executed.

    Does full-disk encryption really protect the data on a lost laptop?

    Yes, full-disk encryption like BitLocker on Windows or FileVault on Mac makes the data essentially unreadable to anyone without the decryption key, even if they physically remove the drive. If encryption was enabled, the incident is far less likely to constitute a reportable data breach. If it was not enabled, you must treat all locally stored files as potentially exposed and assess your legal notification obligations accordingly.

    It depends on what data was on the device and what industry you operate in. Under HIPAA, losing an unencrypted device containing protected health information is presumed to be a breach, with strict notification timelines. Many state data breach laws also require notifying affected individuals within 30 to 60 days. Involving a compliance advisor or attorney early in the process helps ensure you meet the correct obligations.

    How can I prevent this from being a bigger problem next time?

    Use every incident as an audit to close security gaps, such as deploying MDM for remote wipe capability, enforcing full-disk encryption across all devices, requiring multi-factor authentication, and moving away from local file storage toward cloud-based document management. Establishing a clear, documented incident response procedure ensures employees know exactly what to report and how quickly, which significantly reduces response time in future incidents.

    Frequently Asked Questions

    What should I do first when an employee reports a lost or stolen laptop?
    Immediately gather specific details from the employee, including when they last saw the device, whether it was locked or logged in, and which applications were active. Write everything down to build a timeline for insurance, law enforcement, or potential breach notification purposes. Also confirm the device's serial number and what data was accessible on it.
    How quickly should I revoke the employee's account access and passwords?
    This should happen as fast as possible, ideally within minutes of learning about the incident. Log into your admin console (such as Microsoft 365 or Google Workspace), force a password reset, revoke all active sessions, and disable any saved app passwords or API keys tied to the device. Browser-saved passwords and open sessions can give a thief immediate access to multiple accounts.
    Can I remotely wipe a stolen laptop, and does it actually work?
    If your organization uses mobile device management (MDM) software, you can issue a remote wipe command that erases the drive the next time the device connects to the internet. It is not foolproof since a thief who keeps the device offline can avoid the wipe, but many stolen laptops do eventually connect to a network, triggering the command. Full-disk encryption serves as an important backup measure for situations where remote wipe cannot be executed.
    Does full-disk encryption really protect the data on a lost laptop?
    Yes, full-disk encryption like BitLocker on Windows or FileVault on Mac makes the data essentially unreadable to anyone without the decryption key, even if they physically remove the drive. If encryption was enabled, the incident is far less likely to constitute a reportable data breach. If it was not enabled, you must treat all locally stored files as potentially exposed and assess your legal notification obligations accordingly.
    Are there legal notification requirements after a laptop is lost or stolen?
    It depends on what data was on the device and what industry you operate in. Under HIPAA, losing an unencrypted device containing protected health information is presumed to be a breach, with strict notification timelines. Many state data breach laws also require notifying affected individuals within 30 to 60 days. Involving a compliance advisor or attorney early in the process helps ensure you meet the correct obligations.
    How can I prevent this from being a bigger problem next time?
    Use every incident as an audit to close security gaps, such as deploying MDM for remote wipe capability, enforcing full-disk encryption across all devices, requiring multi-factor authentication, and moving away from local file storage toward cloud-based document management. Establishing a clear, documented incident response procedure ensures employees know exactly what to report and how quickly, which significantly reduces response time in future incidents.

    Share this article

    You May Also Like