RedCyferBusiness technology Call (870) 876-3016

Back to Writing

The first hour after a laptop is stolen

Picture a laptop stolen from a vehicle in a parking lot. The owner reports it to the police, calls the office, and then starts to think about what was on it. Email logged in. Accounting software with saved credentials. Browser with ten tabs still open, including the bank. Customer spreadsheets in the downloads folder. The question is not whether the data is sensitive. The question is whether the thief can get to it, and the answer depends entirely on what was configured before the laptop left the building.

If the disk is encrypted and the laptop requires a password at boot, the data is unreadable without that password. If the disk is not encrypted, everything on it is accessible the moment someone pulls the drive or boots from a USB stick. Disk encryption is not exotic. Windows Pro and Enterprise include BitLocker. macOS includes FileVault. Both can be turned on in under five minutes, and both make the data inaccessible if the device is stolen while powered off or locked. The laptop itself still has value to a thief, but the data does not.

The other scenario is the laptop that was asleep, not shut down, and still has active sessions. If the device wakes without requiring a password, or if the password is written on a note in the laptop bag, encryption does not help. The thief is not breaking encryption, they are just using the session that is already open. That is where remote wipe becomes relevant, but only if the laptop is online and the wipe command actually reaches it before the device is powered down or wiped by the thief.

Remote wipe only works if the laptop checks in

Microsoft 365 and Google Workspace both offer remote wipe for enrolled devices. Apple offers it through Find My. MDM platforms offer it for managed devices. The wipe command is issued from a web console, and the next time the device checks in with the management service, it erases itself. The problem is that the device has to be online and has to check in. If the laptop is off, or if the thief immediately wipes it to resell, the command never executes. Remote wipe is useful in the narrow window where the device is still on, still connected, and still enrolled. It is not a guarantee.

The more reliable step is to assume the laptop is gone and to revoke its access to everything else. Sign the user out of email, file shares, and any service that allows remote session termination. Microsoft 365 allows you to revoke all active sessions for a user from the admin portal. Google Workspace has the same feature. That signs the user out of email, OneDrive, SharePoint, and any other service where they were logged in. If the laptop wakes up and tries to sync, it is forced to reauthenticate, and the credentials have already been changed.

What to configure now

Turn on disk encryption for every laptop that leaves the office. Windows Pro includes BitLocker, and it can be enabled from the Settings app under Privacy & Security, then Device encryption or BitLocker, depending on the version. macOS includes FileVault, enabled in System Settings under Privacy & Security. Both require a recovery key. Store that recovery key somewhere other than on the laptop. A password manager shared with the IT contact is a reasonable place.

Require a password after sleep or screen lock. The setting is in Windows under Power & sleep, then Screen and sleep, then additional power settings. On macOS it is in System Settings under Lock Screen. Set it to require a password immediately. That ensures that a laptop stolen while asleep is still protected by the login screen.

Enroll laptops in a device management platform if you are using Microsoft 365, Google Workspace, or an MDM tool. That enables remote wipe, but more importantly it gives you visibility into which devices are signed in and the ability to remove them from the list of trusted devices. If you are not using a management platform, document where each user is signed in and how to revoke those sessions. Know where the "sign out of all sessions" button is before you need it.

Keep a list of which devices have access to which services. If a laptop is stolen, you need to know whether it had saved credentials for the bank, for payment processing, for customer databases. That list determines which passwords get changed and which accounts get locked. Without the list, you are guessing.

Where this sits

Device security is part of what we configure when setting up a new user or a new machine. Disk encryption, password policy, and session management are not optional steps. For clients on a Care plan, we track which devices are enrolled and can remotely revoke access or wipe a device if it is reported missing. The goal is to make the first hour after a theft a series of quick, documented steps instead of a scramble to figure out what was exposed.

Want this looked at for your own business?

Tell us what is going on and Chris will reply. Call (870) 876-3016, text (870) 641-5054, or send a note.

Talk to Chris