← All playbooks

Incident Playbook

Lost & Seized Devices

SIIRF-PB-03Devices and malwareTypical severity: HighVersion 1.0 · October 2026

Summary

A phone, laptop or storage device has been lost, stolen, or taken by authorities or others.

Category
Devices and malware
Typical severity
High
Response led by
Incident lead, with technical support; legal support if authorities are involved

First 15 minutes

  1. If someone has been detained, put their safety first: contact a lawyer and your support network.
  2. From another device, sign the lost device out of email, cloud storage, messaging apps and social media.
  3. Change the passwords for every account that was on it.

1. Overview

A phone or laptop that is lost, stolen, or taken by police, border officials or others. The risk isn't just the device: it's everything stored on it, and every account it is still signed in to, from email and messaging to cloud storage and banking.

2. How it happens

  • Theft on public transport, in public places or during a break-in.
  • A device left behind in a taxi, hotel or meeting.
  • Confiscation during protests, arrests, raids or border crossings.
  • Short PINs, unencrypted disks and saved passwords can be opened with forensic tools.
  • A device returned after seizure may have been copied or tampered with.

3. Indicators

Signs that this incident may be happening:

  • The device is missing, or was out of your control even briefly.
  • Log-in alerts from the device after it was lost.
  • Messages read or sent from your accounts that you didn't open or write.

4. Triage questions

Answer these first to understand scope and severity:

  1. Who had the device, and is that person safe?
  2. Was it lost, stolen, or taken by authorities?
  3. Was it encrypted, and protected by a strong passcode? Was it locked or switched off?
  4. Which accounts were signed in, and what data was stored on it?
  5. Whose information could be exposed: staff, partners, sources, beneficiaries?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowEncrypted, switched off, with no sensitive data or signed-in accounts.
MediumEncrypted, but accounts were signed in; sessions now revoked.
HighUnencrypted, or holding sensitive organisational data.
CriticalTaken by authorities or hostile actors, or holding data that could put people at risk.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. If someone has been detained, put their safety first: contact a lawyer and your support network.
  2. From another device, sign the lost device out of email, cloud storage, messaging apps and social media.
  3. Change the passwords for every account that was on it.
  4. Lock the device remotely. If authorities took it, get legal advice before erasing it.
  5. Warn people whose details or conversations were on the device.
  6. Write down what happened: when, where, who took it, and what was on it.

7. Communication

Who to inform, and when:

  • Incident lead and technical support, immediately.
  • A lawyer, if the device was taken by authorities or the person was detained.
  • People whose details or conversations were on the device.
  • Your mobile operator and bank if a phone with banking apps was lost.
  • Police, if a report is needed for insurance and it's safe to do so.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • When and where the device was lost or taken, and by whom.
  • Details of any seizure: names, badge numbers, documents, what was said.
  • A list of accounts signed in and data stored on the device.
  • Account activity after the device was lost.
  • Records of every action taken: sessions revoked, passwords changed, remote lock or erase.

9. Recovery and review

  • Assume the data was seen, and assess the risk to everyone involved.
  • Check accounts for activity after the device was lost.
  • If the device is returned, don't use it until an expert has checked it, or reset it fully.
  • Review what staff carry day to day, and reduce it.
  • Record the incident and update your plan.

10. Prevention checklist

  • Use a strong passcode (at least six digits, or a passphrase) and turn on full-disk encryption.
  • Keep as little sensitive data on devices as you can, and back up the rest.
  • Turn on remote locate, lock and erase features before you need them.
  • Set messaging apps to delete old messages automatically where appropriate.
  • Keep a list of which accounts are signed in on which devices.
  • For high-risk travel or events, take a clean device that holds only what you need.
  • In high-risk situations, switch the device off: this makes it harder to unlock than one that's simply locked.