Incident Playbook
Lost & Seized Devices
Summary
A phone, laptop or storage device has been lost, stolen, or taken by authorities or others.
- Category
- Devices and malware
- Typical severity
- High
- Response led by
- Incident lead, with technical support; legal support if authorities are involved
First 15 minutes
- If someone has been detained, put their safety first: contact a lawyer and your support network.
- From another device, sign the lost device out of email, cloud storage, messaging apps and social media.
- Change the passwords for every account that was on it.
1. Overview
A phone or laptop that is lost, stolen, or taken by police, border officials or others. The risk isn't just the device: it's everything stored on it, and every account it is still signed in to, from email and messaging to cloud storage and banking.
2. How it happens
- Theft on public transport, in public places or during a break-in.
- A device left behind in a taxi, hotel or meeting.
- Confiscation during protests, arrests, raids or border crossings.
- Short PINs, unencrypted disks and saved passwords can be opened with forensic tools.
- A device returned after seizure may have been copied or tampered with.
3. Indicators
Signs that this incident may be happening:
- The device is missing, or was out of your control even briefly.
- Log-in alerts from the device after it was lost.
- Messages read or sent from your accounts that you didn't open or write.
4. Triage questions
Answer these first to understand scope and severity:
- Who had the device, and is that person safe?
- Was it lost, stolen, or taken by authorities?
- Was it encrypted, and protected by a strong passcode? Was it locked or switched off?
- Which accounts were signed in, and what data was stored on it?
- Whose information could be exposed: staff, partners, sources, beneficiaries?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | Encrypted, switched off, with no sensitive data or signed-in accounts. |
| Medium | Encrypted, but accounts were signed in; sessions now revoked. |
| High | Unencrypted, or holding sensitive organisational data. |
| Critical | Taken by authorities or hostile actors, or holding data that could put people at risk. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- If someone has been detained, put their safety first: contact a lawyer and your support network.
- From another device, sign the lost device out of email, cloud storage, messaging apps and social media.
- Change the passwords for every account that was on it.
- Lock the device remotely. If authorities took it, get legal advice before erasing it.
- Warn people whose details or conversations were on the device.
- Write down what happened: when, where, who took it, and what was on it.
7. Communication
Who to inform, and when:
- Incident lead and technical support, immediately.
- A lawyer, if the device was taken by authorities or the person was detained.
- People whose details or conversations were on the device.
- Your mobile operator and bank if a phone with banking apps was lost.
- Police, if a report is needed for insurance and it's safe to do so.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- When and where the device was lost or taken, and by whom.
- Details of any seizure: names, badge numbers, documents, what was said.
- A list of accounts signed in and data stored on the device.
- Account activity after the device was lost.
- Records of every action taken: sessions revoked, passwords changed, remote lock or erase.
9. Recovery and review
- Assume the data was seen, and assess the risk to everyone involved.
- Check accounts for activity after the device was lost.
- If the device is returned, don't use it until an expert has checked it, or reset it fully.
- Review what staff carry day to day, and reduce it.
- Record the incident and update your plan.
10. Prevention checklist
- Use a strong passcode (at least six digits, or a passphrase) and turn on full-disk encryption.
- Keep as little sensitive data on devices as you can, and back up the rest.
- Turn on remote locate, lock and erase features before you need them.
- Set messaging apps to delete old messages automatically where appropriate.
- Keep a list of which accounts are signed in on which devices.
- For high-risk travel or events, take a clean device that holds only what you need.
- In high-risk situations, switch the device off: this makes it harder to unlock than one that's simply locked.