
A stolen work laptop is a data problem first and a hardware problem second. If the drive was encrypted and you cut off its access fast, you're usually just buying a replacement.
If it wasn't, you may have a reportable breach. Here's what owners ask, in the order it matters.
Lost or stolen work laptop: what owners ask
What should I do first when a work laptop is lost or stolen?
Cut off access within the hour. Reset the user's password, revoke their sign-in sessions in Microsoft Entra ID, and issue a remote wipe from Intune or your device management tool.
Then confirm the drive was encrypted, file a police report, and write down a timeline. Your insurer and your lawyer will both ask for it.
Does resetting the password lock the thief out?
Not on its own. Tokens that were already issued can keep working until they expire, and apps outside Microsoft 365 keep their own sessions.
Use Revoke sessions on the user in Entra ID to force a fresh sign-in, then sign the user out of any other business apps. Our guide to session hijacking explains why stolen sessions outlive password changes.
Can we remotely wipe a stolen laptop?
Yes, if it's enrolled in Intune or another device management tool. The catch: Microsoft says the wipe sits pending until the laptop checks in. A thief who keeps it offline never gets wiped.
And Intune's remote lock doesn't support Windows at all. Encryption protects you in the meantime.
Is a stolen laptop a data breach?
It depends on encryption and what was on it. Under New York's SHIELD Act, encrypted data doesn't count as breached private information unless the encryption key was also accessed or acquired. HIPAA works the same way: HHS guidance treats properly encrypted health data as secured when the key wasn't compromised.
How do I know if the laptop was encrypted?
Check the device in Intune. It reports BitLocker status for Windows and FileVault status for Macs, and the recovery key should be escrowed in Entra ID.
If you can't confirm encryption for this laptop, assume you can't confirm it for the rest of your fleet either. Check every device today, not after the next theft.
Do we have to notify clients?
Possibly. If unencrypted personal information of New York residents was on the laptop, the SHIELD Act requires notice within 30 days after discovery. HIPAA and other states have their own rules and clocks.
We're not lawyers, and this isn't legal advice. Call your attorney and your cyber insurer before you notify anyone.
Should we call our cyber insurance carrier?
Yes, before you spend money on outside help. Read your policy's notice clause. Carriers commonly expect prompt notice and may want you to use their approved breach counsel and forensics firms.
Hiring your own vendors first can create a coverage fight you don't need. Our guide to cyber insurance requirements covers what carriers check.
How do we keep the next lost laptop from becoming a crisis?
Four controls. Enforce BitLocker and FileVault with a compliance policy. Keep files in OneDrive and SharePoint, not the local drive.
Require Conditional Access so only compliant devices reach company data. And use Windows Autopilot so a replacement laptop is working the same day, not next week.
What about a lost phone with work email on it?
If the phone is personal, you don't need to wipe the whole thing. Intune app protection policies let you do a selective wipe that removes company data from Outlook and Teams and leaves photos and personal apps alone.
That's the right setup for most small businesses. Our BYOD FAQ covers the policy side.
Not sure every laptop in your office is encrypted and enrolled? We'll check.
NetSys runs device management for small businesses across NY, NJ, CT, PA, and Southwest Florida. Book a complimentary risk assessment and we'll tell you where your gaps are.
Related reading
FAQCybersecurity Tabletop Exercises: 10 Questions Owners Ask
Read Article
CybersecurityCyber Attack Response Plan for Small Business: 6 Steps
Read Article
FAQSecuring Remote and Hybrid Workers: 8 Questions for SMBs
Read ArticleAlso on this topic: BYOD for Small Business: 8 Questions Owners Ask
Discuss incident response planning & retainer for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
