Lost and Stolen: the First Hour
The sequence that protects the data, and the mistake of acting on an unverified report.
Wipe · Procedure
A device is reported missing. What happens in the first hour determines both the exposure and whether you destroy something you should not have.
The first step is not a wipe
Revoke access: sessions, tokens, certificates.
This works immediately, does not require the device, and is reversible if the phone turns up in a coat pocket.
For an independent baseline relevant to “Lost and Stolen: the First Hour”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
A wipe is none of those things.
Verification
Confirm who is reporting and about which device.
This sounds excessive until the first time somebody receives a convincing call asking for a device to be wiped.
Call back on a known number for anything irreversible.
The reporting route should be easy and the irreversible action should not be.
Establishing what is at risk
Was it locked? Encrypted? What work data was on it?
A locked, encrypted device with a work profile is a materially different exposure from an unlocked device with cached documents.
Which determines whether this is a data incident or an equipment loss.
The ownership question
Corporate device: full wipe is available and frequently right.
Personal device: selective wipe, and the owner's own find-and-erase tools are theirs to use.
Do not full-wipe personal hardware on a loss report, because devices are found and the action is not reversible.
Waiting
A short wait before irreversible action is usually correct.
Most devices reported lost are found within hours.
Revoke immediately, wait on the wipe unless the data justifies otherwise, and say in the policy what the waiting period is so nobody has to decide under pressure.
The reporting culture
People delay reporting because they fear consequences or hope to find it.
Delay is the real exposure.
Say explicitly that reporting promptly has no consequence, and mean it the first time, because the first case teaches everybody else.
Afterwards
Record: when reported, what was revoked, what action was taken, outcome.
If the device is recovered, re-enrol rather than restoring access to an unverified device.
And review: was it locked, was it encrypted, did the policy work — a loss is the only real test these controls get.
The travel case
Devices go missing abroad more often, and the response is complicated by time zones and by local reporting.
Have a route that works at three in the morning in another country, which usually means a number rather than a ticket form.
What to check
Is there a reporting route that works out of hours?
Do you revoke before wiping?
Is there a verification step for irreversible actions?
And does anybody know what the waiting period is?