BG Beter Geregeld ICT
Security zonder IT-afdeling · 2 min leestijd · 02 November 2025

Laptop stolen: the first 30 minutes

Someone calls: laptop stolen from the car. The clock is ticking. Here are the 10 steps you MUST take in the first 30 minutes, in order.

Every minute a lost or stolen laptop could be online is a risk. These 10 steps must happen within the first 30 minutes.

\n \n

Minutes 0–10: containment

\n
    \n
  1. Report it to IT / security lead. Record the date and time.
  2. \n
  3. Trigger a remote wipe via Intune / Jamf / Kandji. Now — not later.
  4. \n
  5. Lock the user's account in M365 / Entra. Force sign-out of all sessions.
  6. \n
  7. Revoke MFA tokens — the device is no longer trusted.
  8. \n
  9. Change passwords for the primary accounts used by this user.
  10. \n
\n \n

Minutes 10–20: scope

\n
    \n
  1. What was on it? Check OneDrive sync, local files, vault cache.
  2. \n
  3. Any customer data on board? If yes: this may be a data breach — see data breach notification.
  4. \n
  5. Encryption mitigation: was disk encryption enabled? Usually yes (BitLocker / FileVault) — in that case the physical device is inaccessible.
  6. \n
\n \n

Minutes 20–30: police report and communication

\n
    \n
  1. File a police report for insurance purposes and in case the device is recovered.
  2. \n
  3. Log entry in the incident log. Update later as more information comes to light.
  4. \n
\n \n

Prevention (set up in advance)

\n
    \n
  • Mandatory disk encryption on every device (Intune compliance policy).
  • \n
  • MDM enrolment for remote wipe capability.
  • \n
  • No passwords stored as plain text on the laptop.
  • \n
  • Use a password manager — not the browser's built-in password vault.
  • \n
  • Minimal data on device — work cloud-first with OneDrive.
  • \n
\n \n

See also: security pillar, Intune basics.

Onderwerpen

#security #mdm #incident-response #diefstal

Volledige gids: Seguridad para pymes sin departamento de TI: ¿qué haces este trimestre?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →