Back to blog
SecurityPublished on August 31, 20268 min read

Company Laptop Stolen: What to Do Within the Hour

A stolen work laptop can expose all your data. Encryption, remote wipe, key recovery, GDPR: the step-by-step response to follow after a theft.

A laptop vanishes from a car, a train, or a coffee shop. In seconds, it is not just hardware that is lost: it is emails, client files, confidential documents, and saved logins. Depending on how prepared you were, the incident will be a simple administrative formality or a major data breach that puts the company's liability on the line. The difference is not decided at the moment of the theft, but months earlier, in how the device was configured.

Panic is a poor advisor, and improvisation is expensive. Having a clear procedure, known in advance, lets you act fast and in the right order. A stolen laptop is one of the rare incidents where a few well-spent minutes make all the difference between a non-event and a crisis. Here are the moves to make the moment you discover the theft, then the preparation that makes them genuinely effective.

The immediate reflexes

As soon as the theft is confirmed, the goal is twofold: cut off any access in progress and neutralize the device's data. These actions are triggered from the admin console, without needing to physically recover the machine.

  1. 1Revoke the affected account's active sessions in Entra ID to cut off any access in progress.
  2. 2Reset the password and confirm MFA is enforced on the account.
  3. 3Trigger a remote wipe of the device from the Intune console.
  4. 4Record the time, place, circumstances, and potentially exposed data.
  5. 5File a police report and inform your security lead or DPO.

Why the order matters

Revoking sessions before resetting the password stops an already-signed-in attacker from keeping a valid session while you act. The remote wipe only takes effect the next time the device connects to the internet: the earlier you trigger it, the better its chance of applying before someone isolates the machine from the network.

Encrypted and managed: a stolen laptop becomes a mere paperweight.

What makes the difference: preparation

None of these actions matter unless the device was properly configured beforehand. An unencrypted, unmanaged laptop escapes the remote wipe and hands its disk to anyone who removes it. Three protections, put in place before the incident, turn a theft into a non-event.

  • BitLocker on Windows (or FileVault on macOS): without the key, the disk is completely unreadable.
  • Intune enrollment: the essential condition for managing and wiping the device remotely.
  • Recovery keys backed up in Entra ID, so you never lose legitimate access to your own data.
  • MFA and Conditional Access, so a credential saved on the machine is not enough to sign in elsewhere.

One last point deserves your full attention: recovery-key management. If BitLocker asks for a key at startup and nobody knows where to find it, the legitimate device becomes unusable and you lock yourself out of your own data. Automatically backing up these keys in Entra ID avoids that trap and guarantees a technician can always unlock a machine, while still denying access to a thief. That is the balance you want: data unreachable from the outside, yet perfectly recoverable from the inside. Test this procedure before you need it, not on the day of the incident, so a stressful theft never turns into a second, self-inflicted crisis of lost access.

The GDPR angle

GDPR requires you to assess whether the theft is a breach that must be notified within 72 hours to the supervisory authority. An encrypted, remotely wiped device sharply reduces the risk to data subjects. That reduction is a key factor in justifying your decision and, in some cases, avoiding a mandatory notification altogether. But you must be able to prove it: keep evidence that encryption was active and that the wipe was triggered.

Document every step in your breach register: date and time of discovery, data present on the device, technical measures in place, actions taken. That trail turns a stressful incident into a defensible file, and demonstrates your diligence if the supervisory authority questions you later.

A concrete example

A sales manager has her laptop stolen on the train. The machine was encrypted with BitLocker, enrolled in Intune, and covered by MFA. On arriving at the station she alerts support: sessions are revoked in two minutes, the password reset, the remote wipe scheduled. Because the disk is encrypted, the client files stay unreadable to the thief.

The DPO reviews the incident and concludes, with encryption evidence in hand, that the risk to individuals is low: the breach is logged in the internal register but does not require notification to the authority. The same theft, on an unencrypted and unmanaged laptop, would have forced a 72-hour notification, a possible communication to clients, and a serious reputational risk. Preparation made all the difference.

Every minute counts: revoke, reset, wipe, document.

Common mistakes to avoid

A stolen laptop often reveals configuration gaps you could have fixed effortlessly. Here are the ones that cost the most at the moment of the incident.

  • Not encrypting disks, which makes remote wipe almost useless against a disk pulled from the machine.
  • Forgetting to back up recovery keys, and locking yourself out of your own devices.
  • Not enrolling devices in Intune, which removes any remote lever to act.
  • Discovering the procedure on the day of the theft instead of having tested it calmly.
  • Neglecting GDPR documentation, without which a correct decision becomes indefensible at audit.

How AuPoint prepares you

AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. The platform deploys encryption, compliance, and recovery-key backup across your entire fleet in a few clicks, with an impact preview before applying and one-click rollback. It documents these measures for your GDPR file and aligns them with ISO 27001 and NIS2. On the day of the theft, you follow a ready-made procedure instead of improvising, and you already hold the technical evidence you need.

Frequently asked questions

Does remote wipe work if the laptop stays switched off?

The wipe command applies the next time the device connects to the internet. If the thief never turns it on or keeps it offline, the wipe does not happen — but encryption still protects the data at all times. That is why encryption and wipe complement each other and do not replace one another.

Can an encrypted disk really be considered safe?

A disk encrypted with BitLocker or FileVault is unreadable without the key. As long as the key is not compromised and the machine was locked, the data stays protected. That is precisely what lets you consider, under GDPR, the risk to individuals as strongly reduced.

Do I always have to notify the supervisory authority?

Not systematically. If the breach is unlikely to result in a risk to people's rights and freedoms — for example because the data was encrypted — notification to the authority is not mandatory. You must, however, log the analysis and the decision in your internal register.

Connect your Microsoft tenant to AuPoint and secure your laptops before the theft, not after, with an impact preview and guaranteed rollback, no PowerShell. Start free at aupoint.io.

Secure your tenant in 15 minutes

Free trial