Incident response

Lost or stolen staff laptop: UK SME day-one checklist

A plain-English day-one plan for UK SME owners when a staff laptop goes missing: locate, lock or wipe, cut off Microsoft 365 and Google access, rotate vault items, and know when file recovery helps.

A laptop left on a train. A car window smashed in a car park. A bag gone from a café chair. It happens to careful people every week.

The laptop itself is the cheap part. The expensive part is what it can still open. Email. Files. Banking. The company password manager. Saved browser logins.

This checklist is for UK owner-managers with roughly 5 to 50 staff and no IT team. It covers day one. Work down it in order. It reduces risk. It does not guarantee nothing leaked.

First 15 minutes: get the facts

Before you click anything, spend five minutes on facts. Ask the staff member, calmly:

  • Which laptop? Make, model, and the name it shows on the network if you know it.
  • When and where did they last have it?
  • Was it switched on, asleep, or shut down?
  • Did it need a password, PIN, or fingerprint to open?
  • Is the disk encrypted? BitLocker on Windows. FileVault on a Mac.
  • What was signed in? Email, Teams, Slack, the password manager, banking, accounting.
  • Was their phone taken too? That changes the MFA picture.

Write the answers in one note with the time. Insurers and the police will ask the same questions later.

If it was stolen, report it to the police. Use 101 or your force's online form. Ask for a crime reference number. Your insurer will want it. Do not chase the laptop yourself from a tracking map. Pass the location to the police instead.

Locate, lock, or wipe

What you can do depends on one question. Was the laptop managed?

Managed means it was enrolled in a tool like Microsoft Intune, Google endpoint management, or a Mac device management service. Unmanaged means someone set it up by hand and nobody can push commands to it.

If the laptop is managed

  1. Open the device in your admin console. Check when it last checked in.
  2. Lock it if your tool offers a remote lock. Add a message with a phone number for returns.
  3. Decide on a wipe. If there is no realistic chance of getting it back today, wipe it.
  4. Wipe straight away if the disk was not encrypted or it held customer personal data.
  5. Note the time you sent the wipe. The command runs when the laptop next goes online.

If the laptop is unmanaged

  • Windows: try Find my device in the Microsoft account the laptop was set up with. It can show a location and lock the device. It only works if the feature was switched on.
  • Mac: use Find My in the Apple Account that set up the Mac. You can mark it as lost or erase it.
  • If neither was switched on, you cannot reach the laptop. Move on to revoking access. That is where the real protection is.

Wiping feels drastic. A wiped laptop is still cheaper than a breach. If work files live in OneDrive, SharePoint, or Google Drive, a wipe loses very little.

On Windows, find the BitLocker recovery key now. For work laptops joined to Microsoft Entra ID, it is usually stored against the device in the admin centre. You will need it if the laptop turns up.

Revoke Microsoft 365 access

Do this even if you sent a wipe. A wipe command can sit waiting for days. Open sessions do not wait.

  1. Reset the user's password in the Microsoft 365 admin centre. Use a new, unique password.
  2. Revoke sessions. In the Microsoft Entra admin centre, open the user and choose Revoke sessions. This signs them out of apps on every device.
  3. Check their sign-in methods. If the phone was also taken, remove the old authenticator and phone number. Enrol fresh methods on a replacement phone.
  4. Disable or delete the lost laptop under Devices in Entra. That stops it acting as a trusted device.
  5. Check the mailbox for new forwarding and inbox rules. Do it again tomorrow.
  6. Look at the user's recent sign-ins. Odd locations or unknown apps are a reason to get help.

If the laptop belonged to an admin, do the same for their admin account. Then check nobody added a new admin today.

New to MFA settings? Use OwnerSec's MFA for Microsoft 365 beginners guide.

Revoke Google Workspace access

  1. In the Google Admin console, open the user. Reset the password.
  2. Reset sign-in cookies for the user. That signs them out of Google in every browser.
  3. Review 2-Step Verification. If the phone went too, remove old methods and issue new backup codes.
  4. Under Devices, find the laptop. Sign the account out of it, or wipe it if your edition allows that.
  5. Revoke app passwords and any third-party app access the user does not need.
  6. Check Gmail forwarding and filters on that account.

Personal Gmail used for work is harder. You cannot reset it from an admin console. Ask the person to change the password and sign out of all other sessions from their Google account security page. Then move them to a work account. The shared-login guide explains why.

Rotate vault items

A locked password manager on an encrypted laptop is hard to break into. The risk sits in the gaps around it. Browser-saved passwords. A vault left unlocked. Shared logins the person could open. Recovery codes in a desktop folder.

Rotate in this order:

  1. The password manager account itself. Change the master password. Sign the lost laptop out from the device list, or ask an admin to suspend and re-invite the user.
  2. Banking, payroll, and payment tools. Xero, FreeAgent, Sage, card portals, payment links.
  3. Shared logins the person could open. Supplier portals, social accounts, the domain registrar, hosting.
  4. Anything saved in the browser on that laptop. Chrome and Edge passwords often sync from a personal profile. Treat them as exposed.
  5. Office Wi-Fi and any VPN or remote-access logins stored on the laptop.
  6. Backup codes and API keys kept in files. Replace them and store the new ones in the vault.

Put every new secret in the company vault. Not in chat. Not in a spreadsheet.

If you have no company vault yet, start one this week. Named accounts with shared folders turn the next lost laptop into a short job. See OwnerSec's password manager guide and stop password reuse checklist.

NordPass Business is a sensible fit for a small UK team that wants shared folders, admin controls, and a price you can check on the vendor site. OwnerSec has a live affiliate link. Commission does not change the order of this checklist. Revoking access comes first.

1Password and Bitwarden are fair alternatives. Compare them in 1Password vs Bitwarden. The habit matters more than the logo.

Other things signed in on that laptop

Email is not the only door. Run through these with the staff member:

  • Teams, Slack, and Zoom desktop apps. Sign the user out from the admin side where you can.
  • WhatsApp Desktop. On the phone, open Linked devices and log out the laptop.
  • Banking. Tell the bank a device with saved access was lost.
  • Remote-access tools such as TeamViewer or AnyDesk. Remove the laptop from the account.
  • Sync apps such as Dropbox. Remove the device from the account.
  • Endpoint protection. Mark the device as lost in the console. See the cheap endpoint guide.

When Recoverit helps, and when it does not

File-recovery software gets suggested a lot after a lost laptop. Most of the time it is the wrong tool. Be clear about what it can and cannot do.

Recoverit cannot help when:

  • The laptop is gone. Recovery software needs the drive in your hands.
  • A remote wipe has already run. Expect that data to be gone. That is the point of a wipe.
  • The files lived in OneDrive, SharePoint, or Google Drive. Restore from there instead. Check the recycle bin and version history first.

Recoverit can help when:

  • The laptop comes back and files were deleted, or the drive was quick-formatted rather than securely wiped.
  • A USB stick or external drive with the only copy of some files was deleted or reformatted in the rush.
  • A spare laptop you reissue as a stopgap has files someone deleted by mistake.

Always try a known-good backup first. Recovery is a last resort, not a plan. If a laptop comes back after days away, treat it as untrusted. Recover files onto a clean machine, then rebuild the laptop.

The real lesson is that local-only files are fragile. OwnerSec's backup and restore test guide covers a quiet quarterly drill.

Do you need to tell anyone?

Sometimes. It depends on what was on the laptop and whether it was encrypted.

  • ICO. If personal data was on the laptop and the loss could put people at risk, UK GDPR expects you to report it to the ICO within 72 hours of becoming aware. A fully encrypted laptop with a strong sign-in is a very different risk from an unencrypted one. Record your reasoning either way.
  • Insurer. Read your cyber or office policy. Many want notice quickly. Give them the crime reference number.
  • Clients. If client data was exposed, you may need to tell them. Check your contracts.
  • Staff. Tell the team a device was lost. Ask everyone to deny MFA prompts they did not start.

This is general information, not legal advice. If personal data may have left, get proper advice early. The 72 hours runs fast.

Get the person working again

  • Issue a spare or new laptop. Set it up properly: encryption on, enrolled in management, updates on.
  • Sign in with the new password and fresh MFA methods.
  • Restore work files from OneDrive, SharePoint, Google Drive, or backup. Not from old email attachments.
  • Reinstall the password manager and sign in. Check the vault looks right.
  • Ask them to list anything that only lived on the old laptop. That list is your backup gap.

Day-one checklist

Copy this into a note the owner can see.

First hour

  • Facts written down: device, time, place, locked or not, encrypted or not
  • Theft reported to police and crime reference number noted
  • Device located, locked, or wiped where possible
  • Microsoft 365 or Google password reset and sessions revoked

By lunchtime

  • Lost laptop disabled or removed in Entra or Google Admin
  • MFA methods checked, and phone methods replaced if the phone went too
  • Password manager master password changed and lost device signed out
  • Banking and payment logins rotated

By end of day

  • Shared logins, browser-saved passwords, Wi-Fi, and VPN rotated
  • Mailbox forwarding and rules checked
  • WhatsApp, Slack, Teams, and remote-access tools signed out
  • ICO, insurer, and client decision recorded
  • Replacement laptop issued and files restored from cloud or backup

This week

  • Mailbox rules and sign-ins checked again
  • Every company laptop confirmed encrypted
  • Asset list updated with who has which device
  • One restore test booked if you have never done one

Make the next one boring

You cannot stop every lost bag. You can make it a small event.

  • Turn on BitLocker or FileVault on every laptop. Check it. Do not assume it.
  • Enrol laptops in device management so you can lock and wipe.
  • Use MFA on every account. Authenticator apps beat SMS. See the authenticator apps checklist.
  • Keep work files in the cloud with a separate backup.
  • Keep a simple asset list: device, serial number, owner, encrypted yes or no.
  • Use a company vault so rotation takes minutes, not days.

These habits also help with Cyber Essentials and insurer questionnaires.

FAQ

Should we wipe a lost laptop straight away?
If it is managed and you cannot get it back today, yes. Wipe at once if it was not encrypted or held customer personal data. A wipe is cheaper than a breach.
Is changing the password enough?
No. Also revoke sessions so apps already signed in on the laptop stop working. Then rotate the vault items and saved logins the laptop could open.
What if the laptop was encrypted?
The risk is much lower if it was shut down or locked. Still revoke sessions and rotate saved logins. A sleeping laptop with open sessions is the weak spot.
Can Recoverit get files back from a stolen laptop?
No. It needs the drive in your hands. It can help if the laptop comes back with deleted files, or a USB copy was deleted. Restore from cloud or backup first.
Do we have to report a lost laptop to the ICO?
Only if personal data was at risk. If you need to report, the deadline is 72 hours from becoming aware. Encryption matters. Record your decision and get advice if unsure.

Bottom line

Get the facts. Lock or wipe the laptop if you can. Then cut off access: new password, revoked sessions, a disabled device, and fresh MFA. Rotate the vault items and saved logins it could open. Use file recovery only on drives you actually have, and only after backups fail. Then make the next lost laptop boring with encryption, device management, and a company vault.

Written for UK SME owners. More guides · How we make money