DOCS / EN

Lost work phone runbook

A concise procedure for the employee, manager, and IT after a work phone is lost or stolen.

This procedure helps limit risk without destroying evidence or putting anyone in danger while recovering a phone. Start with the company emergency channel. If you do not know it, contact your manager and IT or security from another trusted device. You can use the short lost-phone checklist in parallel.

1. Employee: report and record the facts

Provide as soon as possible:

  • the time you noticed the loss and the last time the phone was under your control;
  • the location, circumstances, and whether this appears to be a loss or theft;
  • the phone number, model, asset tag, and IMEI or serial number, if available without searching on the missing device;
  • whether the phone was unlocked, who may have seen the code, and which apps were open;
  • whether the case contained badges, cards, or documents;
  • recent alerts, suspicious messages, MFA prompts, and the types of data known to be stored locally.

Record the times of later actions, case numbers, and decision-makers. Keep screenshots of location and alerts, but do not publish them or send codes, full card details, or identity documents through an unsecured channel.

2. Employee: locate and lock safely

From a trusted device, open the official Apple or Google service, preferably from your own bookmark or a manually typed domain. Enable lost mode or remote lock and provide a contact number other than the missing phone’s number. Playing a sound is useful when the device is probably nearby.

Do not travel alone to an address shown on the map or confront someone who may have the phone. Pass the location to IT, site security, or police under company procedure. Do not follow links in “we found your phone” messages, and never disclose the unlock code or an MFA code.

Do not remove an iPhone from the Apple account if doing so would disable Activation Lock. Do not hastily sign the device out of its Apple or Google account either: IT should first check the effect on location and device protection. Remote erasure can be appropriate, but it may end further tracking; IT/security and the data owner should make that decision together based on risk.

3. IT/security: contain access

IT or security opens a case, preserves the timeline, and checks MDM for compliance state, last contact, encryption, ownership, work profile, and available commands. Depending on platform and risk, the team may issue a lock, lost-mode command, passcode rotation, selective wipe of company data, or full erase. Record every command, result, and time; an offline device may not execute a queued command until it reconnects.

End work sessions or revoke tokens for email, VPN, SSO, messaging, and business apps. Do not automatically choose “sign out everywhere” if that might impair location tracking—first separate application sessions from the account used for device protection. If there are signs of takeover, also use the account takeover emergency card, and inspect MFA methods, email rules, and recovery details.

The carrier should suspend the SIM or eSIM and arrange a replacement under company authorization. Ask whether it can block the IMEI, bearing in mind that policy differs by carrier and country. Suspending the number does not end existing app sessions.

4. Manager and data owner: assess impact

The manager helps set priority, arrange cover, and establish a safe way to contact the employee. The data owner identifies what may have been accessible: email, customer data, offline files, secrets, a digital wallet, or payment approval. With security, they decide whether to notify legal, privacy staff, customers, the insurer, or authorities. Do not promise that encryption or biometrics completely rule out access.

The employee should call the bank using an official number if the phone held banking apps, cards, or payment approval. Report theft to police in line with local rules; the IMEI, proof of purchase, description, and saved location evidence may help.

5. Closure and return to service

Before a recovered phone returns to use, IT checks its MDM state, updates, configuration, unknown profiles, and sign-in events. If there is doubt, the device should undergo a controlled wipe and re-enrolment. A replacement receives newly issued or safely restored MFA, eSIM, and role-appropriate access; old tokens remain revoked.

Close the case only after confirming carrier actions, sessions, accounts, MDM commands, reporting duties, and ownership of the replacement device. A short post-incident review should identify what worked, where contacts or asset records were missing, and whether MDM, backups, training, or data-storage rules need improvement—without turning the review into blame.

Want this in a lab or on production?

Docs stay free. The form is for scope, not a paywall.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.