A work laptop was left in a taxi, hotel or train. What to do in the first hour
A lost laptop does not have to become a data breach. Fast reporting, safe recovery and sound company decisions can contain the risk.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 22 September 2026
- READING TIME
- 15 min read
- TOPIC
- Human Security
You leave the train and realise minutes later that the bag is still under the seat. Or the hotel calls after you have checked out. Inside is a work laptop, perhaps with customer documents, email and active sessions. Embarrassment often shapes the first response: “I will try to find it first, and only tell the company if I cannot.”
That delay increases the risk. Reporting is not an admission of guilt. It activates controls an employee cannot use alone: device lock, session revocation, data assessment and legal decisions. Even a well-secured laptop must be reported immediately.
The first five minutes: personal safety and rapid reporting
Stop in a safe place and establish when the device was last seen. Do not return alone to a suspicious location or confront someone at an address shown on a map. Hardware can be replaced; your safety cannot.
Call the company helpdesk, your manager or the incident number. If you do not know the process, use any trusted company contact and ask them to escalate urgently to IT or security. Do not wait until morning simply because the incident happened after hours. Provide:
- your name, team and a safe callback number;
- the device type and asset number, if known;
- the approximate time and place of loss;
- whether the laptop was on, asleep or shut down;
- whether the bag also held a phone, hardware token, access card or documents;
- what data may have been stored locally;
- any unusual sign-ins or messages you have noticed.
Do not guess. “I do not remember” is more useful than false certainty.
Minutes 5–20: recover it through official channels
Contact the transport operator, hotel, taxi company or lost-property office using a number from its official website or genuine app. Describe the bag and device, but never disclose the password or detailed information about files on the disk. Ask for a case or reference number.
If the company has device-location tools, follow IT’s instructions. Do not post a screenshot containing an exact map location on social media. Do not pay someone claiming to have found the laptop until the company or police establishes a safe recovery method.
Report suspected theft to the police. Keep the case number, ride receipt, ticket and correspondence with the location where the device went missing. The insurer and incident team may need those records.
What the employee should not do alone
Do not start changing every password from an unknown hotel lobby computer. That machine may not be trustworthy, and IT should decide the order of containment. Use a known phone or trusted device to communicate.
Do not trigger a remote wipe yourself unless company policy explicitly instructs you to do so. Erasure may be appropriate, but it can also affect location, evidence preservation or recovery. An authorised team should make the decision with an understanding of the device state and data risk.
Do not conceal that a PIN was written in the bag, the laptop was unlocked or a personal account was in use. Those facts change the response. Hiding them does not protect the employee; it removes time from the company.
What the company should do in parallel
The response team should first verify the reporter’s identity and match the device to the asset inventory. Depending on its configuration and risk, the team can then:
- mark the asset as lost and send a lock command through device management;
- revoke active sessions and access tokens associated with the device;
- secure the account if the laptop was unlocked or credentials may be exposed;
- disable an access badge, hardware token and other items from the bag;
- review recent sign-ins, access attempts and alerts;
- confirm whether the disk was encrypted and the device was compliant;
- establish which data was local or accessible without signing in again;
- document decisions and appoint an incident owner.
Full-disk encryption substantially reduces the risk of reading data from a powered-off, properly protected device, but it does not answer every question. The laptop may have been asleep, left with an open session, held offline-synchronised files or provided access to cloud services. “It was encrypted” is therefore not a reason to close the report without assessment.
Is a lost laptop a personal data breach?
It may be, but every loss does not automatically mean that someone accessed the data or that all customers must be notified. The organisation should document an assessment: what information was present, how it was protected, whether the laptop was signed in, what access evidence exists and what the consequences for people could be.
The employee should not decide alone that “nothing happened” or contact customers independently. The data controller assesses the situation with its privacy, legal and security specialists. Prompt facts matter because regulatory time limits may run even if the laptop is eventually recovered.
If the laptop comes back
Do not immediately start a recovered device or connect it to the company network. After time outside organisational control, nobody knows who had physical access or whether the configuration changed. Hand it to IT in the condition in which it was recovered, with details of where, when and from whom it was collected.
The team may inspect, rebuild or replace the device. Sessions and credentials revoked during the incident should remain revoked even if the hardware looks untouched. Do not unwind containment simply because the bag returned after an hour.
A process that encourages reporting
A lost-device procedure should not begin with a threat of punishment. It should fit on a phone screen and answer three questions: who to call, what to report and what not to do. Put the incident number in the intranet footer, on an access card or in travel material—not only on the laptop that has just disappeared.
Businesses should rehearse the scenario with frequent travellers, sales teams, executives and remote workers. Useful foundations include:
- centrally managed full-disk encryption;
- automatic screen locking and sensible sleep settings;
- multi-factor authentication;
- minimal local data storage;
- an asset inventory and remote-lock capability;
- separation of daily and administrative accounts;
- regular access reviews and a practical after-hours reporting channel.
These controls do not replace a human response. They make a rapid report actionable.
Source facts and Breachroad recommendations
The UK’s NCSC advises users to contact the IT helpdesk immediately when a device is lost or stolen, explaining that prompt reporting gives the organisation more opportunity to protect information. The NCSC also describes remote device erasure, including through managed-device tooling. The ICO lists a lost or stolen computer holding personal data as a possible personal data breach.
The first-hour sequence, report contents, advice not to start recovered hardware and blame-free reporting model are Breachroad recommendations. Details should match the company’s technology and local legal duties. If a phone went missing with the laptop, also use our lost or stolen phone response guide. Teams can rehearse this situation during employee cybersecurity training.
