ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Playbook
PB-014

Lost & Stolen Device

1. Purpose & Scope

  • Purpose:

    Provide a structured response for lost, misplaced, or stolen organisational devices. Use this playbook to validate the report, assess device and data exposure, contain access, coordinate device recovery or replacement, and restore the user safely.

  • Scope:

    Applies to corporate-owned or managed laptops, desktops, mobile phones, tablets, removable media, and other endpoints that may contain organisational data or provide access to organisational systems.

2. Incident Identification & Criteria

Incident Type: Lost & Stolen Device

Trigger Conditions:

Initiate this playbook when any of the following occur:

  • User, manager, physical security, asset management, or law enforcement reports a lost or stolen organisational device
  • Managed device reports unexpected location, tampering, jailbreak/rooting, or suspicious check-in activity
  • Device containing organisational data, credentials, certificates, or privileged access is unaccounted for
  • Recovered device shows signs of unauthorised access, tampering, malware, or policy bypass

Severity Levels:

SeverityDescription
Sev 3Device misplaced or recovered quickly; encryption and management controls appear intact
Sev 2Device remains missing or stolen; encryption and management controls are confirmed
Sev 1Device may expose sensitive data, credentials, privileged access, or critical business systems
Sev 0Device theft is targeted, linked to active compromise, or creates major business/customer impact

3. Roles & Responsibilities

  • Incident Commander: Sets severity, coordinates response, approves containment, and owns escalation decisions.
  • Incident Responder / Forensic Analyst: Validates the report, assesses exposure, reviews activity, and preserves evidence.
  • Communications Lead: Coordinates affected-user, management, legal, and stakeholder communications.
  • Other Roles:
    • Endpoint / MDM Team: Confirms device posture and performs remote lock, wipe, or access removal.
    • Identity & Access Team: Locks accounts, revokes sessions, resets credentials, and validates safe access restoration.
    • Physical Security / Asset Management: Supports theft reporting, asset tracking, recovery, chain of custody, and replacement.
    • Legal / Compliance: Assesses sensitive data exposure, law enforcement coordination, regulatory obligations, and customer impact.
    • User's Manager: Supports employee verification, business continuity, and replacement device coordination.

4. Initial Actions

  • Immediate Steps:

    Decision Point:

    • If the device is recovered quickly and no exposure is identified โ†’ document evidence and close or downgrade.
    • If the device remains missing, stolen, tampered with, or untrusted โ†’ continue investigation and containment.
    • If suspicious account, device, or network activity is observed โ†’ begin containment in parallel.

5. Investigation & Analysis

6. Containment, Eradication & Recovery

  • Containment Actions:

  • Eradication Steps:

    • Remove cached access, stale device objects, certificates, local admin rights, and device trust relationships.
    • Rotate exposed credentials, certificates, tokens, API keys, or secrets identified during exposure analysis.
    • Treat recovered devices as untrusted until inspected, rebuilt, or re-enrolled according to endpoint standards.
  • Recovery Steps:

7. Communication & Escalation

8. Post-Incident Activities

  • Lessons Learned:

    • Conduct a PIR covering reporting speed, employee verification, device posture, lock/wipe timing, access containment, data exposure, communications, and replacement workflow.
    • Review device encryption, MDM/EDR coverage, asset tracking, conditional access, remote wipe readiness, and user reporting guidance.
  • Documentation Updates:

    • Update asset inventory, device recovery records, lost-device procedures, endpoint baselines, detection content, and this playbook as needed.

9. References & Linked Resources

10. Appendices

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.