1. Purpose & Scope
-
Purpose:
Provide a structured response for lost, misplaced, or stolen organisational devices. Use this playbook to validate the report, assess device and data exposure, contain access, coordinate device recovery or replacement, and restore the user safely.
-
Scope:
Applies to corporate-owned or managed laptops, desktops, mobile phones, tablets, removable media, and other endpoints that may contain organisational data or provide access to organisational systems.
2. Incident Identification & Criteria
Incident Type: Lost & Stolen Device
Trigger Conditions:
Initiate this playbook when any of the following occur:
- User, manager, physical security, asset management, or law enforcement reports a lost or stolen organisational device
- Managed device reports unexpected location, tampering, jailbreak/rooting, or suspicious check-in activity
- Device containing organisational data, credentials, certificates, or privileged access is unaccounted for
- Recovered device shows signs of unauthorised access, tampering, malware, or policy bypass
Severity Levels:
| Severity | Description |
|---|---|
| Sev 3 | Device misplaced or recovered quickly; encryption and management controls appear intact |
| Sev 2 | Device remains missing or stolen; encryption and management controls are confirmed |
| Sev 1 | Device may expose sensitive data, credentials, privileged access, or critical business systems |
| Sev 0 | Device theft is targeted, linked to active compromise, or creates major business/customer impact |
3. Roles & Responsibilities
- Incident Commander: Sets severity, coordinates response, approves containment, and owns escalation decisions.
- Incident Responder / Forensic Analyst: Validates the report, assesses exposure, reviews activity, and preserves evidence.
- Communications Lead: Coordinates affected-user, management, legal, and stakeholder communications.
- Other Roles:
- Endpoint / MDM Team: Confirms device posture and performs remote lock, wipe, or access removal.
- Identity & Access Team: Locks accounts, revokes sessions, resets credentials, and validates safe access restoration.
- Physical Security / Asset Management: Supports theft reporting, asset tracking, recovery, chain of custody, and replacement.
- Legal / Compliance: Assesses sensitive data exposure, law enforcement coordination, regulatory obligations, and customer impact.
- User's Manager: Supports employee verification, business continuity, and replacement device coordination.
4. Initial Actions
-
Immediate Steps:
- Verify the employee and collect the report details before making high-impact access or device changes.
- Validate device ownership, assigned user, device type, asset ID, last known location, last seen time, and loss/theft circumstances.
- Start the incident record and preserve available MDM, EDR, IdP, VPN, SIEM, and asset inventory telemetry.
- Notify Incident Commander, endpoint/MDM team, identity team, asset management, and physical security as required.
Decision Point:
- If the device is recovered quickly and no exposure is identified โ document evidence and close or downgrade.
- If the device remains missing, stolen, tampered with, or untrusted โ continue investigation and containment.
- If suspicious account, device, or network activity is observed โ begin containment in parallel.
5. Investigation & Analysis
-
Evidence Collection:
- Collect host, MDM, EDR, asset, location, and endpoint telemetry for the missing device.
- Collect identity, authentication, VPN, session, MFA, and device-trust telemetry for the assigned user.
- Document device owner, asset identifiers, last known activity, security controls, accessible data, credentials, and containment actions.
-
Analysis Steps:
- Validate device management, encryption, EDR, compliance, remote lock/wipe capability, and last check-in status.
- Assess local data, cached data, synced files, credentials, certificates, tokens, and business data exposure.
- Review authentication activity, MFA events, VPN use, device trust, and geographic anomalies for the assigned user.
- Review user, endpoint, network, file access, and authentication activity associated with the missing device.
Decision Point: Run the post-detection phases (Analysis โ Recovery) of any relevant sibling playbook concurrently alongside this one based on what was observed:
- If account compromise or credential abuse is suspected or identified โ execute PB-004: Account Takeover concurrently.
- If data exposure, staging, or exfiltration is suspected or identified โ execute PB-005: Data Exfiltration concurrently.
- If malware or suspicious execution is suspected or identified โ execute PB-003: Endpoint Malware Infection or PB-011: Suspicious Execution concurrently.
- If privilege escalation is suspected or identified โ execute PB-009: Privilege Escalation concurrently.
- If lateral movement is suspected or identified โ execute PB-010: Lateral Movement concurrently.
- If targeted theft, insider involvement, or physical access abuse is suspected โ execute PB-006: Insider Threat concurrently.
6. Containment, Eradication & Recovery
-
Containment Actions:
- Lock affected accounts, reset credentials where needed, and revoke active sessions, tokens, VPN sessions, and device trust.
- Remotely lock or wipe the missing device when approved and technically available.
- Remove device registrations, certificates, conditional access trust, managed app access, and endpoint management access for untrusted devices.
-
Eradication Steps:
- Remove cached access, stale device objects, certificates, local admin rights, and device trust relationships.
- Rotate exposed credentials, certificates, tokens, API keys, or secrets identified during exposure analysis.
- Treat recovered devices as untrusted until inspected, rebuilt, or re-enrolled according to endpoint standards.
-
Recovery Steps:
- Verify the employee before restoring access, issuing replacement hardware, or re-enrolling MFA.
- Restore user access only after containment is complete and account/device integrity is validated.
- Provision a replacement device, enforce security baseline, validate encryption/EDR/MDM, and update asset inventory.
7. Communication & Escalation
-
Internal Communication:
- Notify security leadership, endpoint/MDM team, identity team, physical security, asset management, user manager, and affected business stakeholders.
- Notify the affected user with required actions after verification.
- Use geo handoff when the incident spans response shifts.
-
External Communication:
- Coordinate legal, law enforcement, customer, regulator, and executive communications through approved escalation processes.
-
Escalation Criteria:
Condition Escalate To Account compromise or credential abuse suspected or identified PB-004: Account Takeover Sensitive data exposure, staging, or exfiltration suspected or identified PB-005: Data Exfiltration Malware or suspicious execution suspected or identified PB-003: Endpoint Malware Infection / PB-011: Suspicious Execution Privilege escalation suspected or identified PB-009: Privilege Escalation Lateral movement suspected or identified PB-010: Lateral Movement Targeted theft, insider involvement, or physical access abuse suspected PB-006: Insider Threat Major business/customer impact or regulated data exposure PB-019: Major Security Incident Management
8. Post-Incident Activities
-
Lessons Learned:
- Conduct a PIR covering reporting speed, employee verification, device posture, lock/wipe timing, access containment, data exposure, communications, and replacement workflow.
- Review device encryption, MDM/EDR coverage, asset tracking, conditional access, remote wipe readiness, and user reporting guidance.
-
Documentation Updates:
- Update asset inventory, device recovery records, lost-device procedures, endpoint baselines, detection content, and this playbook as needed.
9. References & Linked Resources
-
Playbooks:
-
Runbooks:
- RB-TRIAGE-006: Lost & Stolen Device Validation
- RB-EVIDENCE-002: Host-Based Log Acquisition
- RB-EVIDENCE-003: Identity & Authentication Log Acquisition
- RB-ANALYSIS-007: Authentication Log Analysis
- RB-ANALYSIS-026: User Activity Validation
- RB-ANALYSIS-032: Device Security Posture Assessment
- RB-ANALYSIS-033: Device Data Exposure Assessment
- RB-CONTAIN-001: Account Lockdown
- RB-CONTAIN-005: Session & Token Revocation
- RB-CONTAIN-011: Remote Device Lock & Wipe
- RB-RECOVERY-003: User Recovery & Access Restoration
-
SOPs:
10. Appendices
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
