Professional laptop theft: six actions to take immediately

  • Defence
  • Cyber

© 123RF

  • Type Insight
  • Published

More than three-quarters (76%) of IT decision-makers report having experienced the theft of professional equipment over the past two years, according to a study published by Kensington. Among them, 46% say they experienced a data breach directly caused by the incident.

A stolen or lost laptop is therefore not simply a hardware issue, but a cybersecurity and data protection concern. Addressing this type of incident requires a twofold approach: adopting the right response in the minutes following the theft, while putting measures in place beforehand to protect data and minimise the impact if a theft occurs.

Laptop theft: the actions that make a difference in the first five minutes

There are two main categories of laptop theft. The first is opportunistic theft, driven by the resale value of the device rather than any particular interest in its contents. It can occur when a laptop is left unattended, for example in a café, on a train or in a coworking space.

The second is targeted theft, where the contents of the stolen laptop are the primary objective. The attacker may first identify an employee holding a key position within the organisation. The laptop may then be stolen in a public place, at the employee's home or even on company premises if security measures are insufficient.

As soon as an employee becomes aware that their laptop is missing, six actions should be taken immediately:

  1. Report the theft or loss immediately to the company's IT or cybersecurity team. This is a critical first step, as it triggers the entire incident response process. Without a report, none of the following actions can be initiated. Every minute of delay gives a third party more time to access the laptop and any professional applications that may still be open.
  2. Attempt to locate the device. This should be done before taking any irreversible remote action on the laptop. Once remote wiping has been initiated, the device may lose its connection and become impossible to locate.
  3. Remotely wipe or lock the device, if the organisation has an MDM (Mobile Device Management) solution that enables remote administration of endpoints. This prevents the thief from accessing company data and professional applications.
  4. Revoke all access associated with the device. Even without an MDM solution, the IT team can disable access or change the credentials of the employee whose laptop has been stolen or lost, including access to corporate email, business applications and synchronised cloud storage.
  5. Notify the relevant authorities and file a police report, particularly if the device has been located. This information may help the authorities recover the laptop and apprehend the perpetrator(s).
  6. Inform the DPO if personal data may be involved. Under the GDPR, a data breach must be reported to the relevant supervisory authority within 72 hours where notification is required, with the deadline running from the time the organisation becomes aware of the breach.

It is essential to train employees on what to do if their professional devices are lost or stolen, so that they can adopt the right reflexes and respond immediately.

How can organisations anticipate and protect against laptop theft and loss?

The first way to protect against laptop theft is to implement an appropriate MDM or EMM (Enterprise Mobility Management) solution that meets the requirements of your device fleet and organisation. These solutions enable you to maintain remote control over your data, even if a laptop is lost or stolen.

They can also provide protection before a theft is even reported: systematic disk encryption makes data unreadable to anyone attempting to physically extract the storage, while automatic locking after a period of inactivity reduces the exposure window from the very first minutes, before the employee has even had time to report the incident. In the event of a confirmed incident, these solutions can also provide precise information about the applications and data present on the device at the time of the theft or loss. This information is valuable when assessing the sensitivity of the exposed data and complying with the GDPR notification deadline.

A second best practice is to secure remote access. When working remotely, an employee connecting to the corporate IT environment creates a potential pathway to the organisation's data. Using a VPN helps secure this connection, but not all VPNs take the same approach. Some enterprise VPN clients rely on certificate-based authentication linked to the device, rather than reusable credentials. This can make it possible to immediately cut off access to the corporate IT environment as soon as a stolen laptop is reported.

This is the approach behind Cybels VPN, a sovereign IPsec/IKEv2 client developed by Ercom for public- and private-sector organisations, designed to provide controlled remote access that can be revoked at any time, regardless of the circumstances.

How can organisations anticipate and protect against laptop theft and loss?

When an employee's laptop is stolen or lost, responding quickly in the first few minutes is critical. However, rapid response should never replace preventive measures such as an MDM solution or a VPN using device-associated certificate-based authentication. By putting these safeguards in place, organisations can significantly reduce the risk of a major data breach or unauthorised access to their IT environment.