← Devices & Networks

runbook

Prepare a Lost or Stolen Device Runbook

A preparation-only runbook for assigning device-loss roles, authority, evidence ownership, continuity, and qualified handoffs before an incident occurs.

For

An owner or operations lead preparing a non-live role-and-decision card before a work-relevant device is lost or stolen.

Not for

Live tracking, lock, wipe, account or session action, evidence collection, forensics, recovery, notification, police/insurer contact, or emergency support.

Failure addressed

People improvise through unsafe channels, take destructive or unauthorized actions, destroy evidence, delay escalation, or discover there is no viable continuity path.

Prepare decisions before a device goes missing

A report that a work-relevant device may be lost or stolen can create pressure to act immediately. That pressure does not establish what happened, where the device is, who has it, whether anyone accessed it, which information is affected, or which action is safe and authorized. A useful runbook prepares ownership and handoffs before that pressure arrives.

CISA’s stored-data guidance explains that inadequately protected data may be exposed when a device is stolen and that data may be permanently lost when a recoverable copy does not exist. NIST SP 800-114 Rev. 1 distinguishes organization-controlled, user-controlled, and third-party-controlled telework devices and supports preparing organizational policies and reporting procedures.

Those sources support advance preparation and the limited consequences described above. They do not prescribe the ten concepts, eight stages, nine states, 18 fields, evidence boundary, tabletop, completion criteria, escalation model, or review cadence below. Those are PlainFort editorial judgment—not CISA or NIST requirements, an incident-response standard, certification, compliance proof, legal advice, a security guarantee, or a universal response model.

In this guide, first actions means preparing a trigger, roles, safe communication, decision authority, evidence ownership, continuity, and qualified handoffs. It does not mean performing a response. A completed card does not prove that a device is found, contained, inaccessible, uncompromised, recoverable, or safe.

Keep ten preparation concepts separate

  1. Trigger category and confidence: a report of loss, theft, or possible loss, kept separate from conclusions about what occurred.
  2. Known facts and assumptions: category-level facts, unverified statements, and missing information recorded separately.
  3. Device reference, ownership, and admission state: an existing DN-16 or DN-17 category, without identifying, inspecting, admitting, or changing a device.
  4. Internal accountability and coordination: accountable owner, coordinator, qualified operator category, genuine backup, and escalation authority.
  5. Safe reporting and communication: an approved route and fallback without copied identifiers, locations, messages, screenshots, or incident detail.
  6. Decision authority and prohibited-action boundary: who may authorize later qualified work and which live actions this card cannot authorize.
  7. Evidence ownership and location category: who owns preservation decisions and where an approved reference may exist, without collecting or inspecting evidence.
  8. Account, access, data, and workflow handoffs: dependencies routed to dedicated guides or qualified response without account, session, credential, or device action.
  9. Continuity and qualified escalation: safe work interruption, fallback, and privacy, legal, HR, insurance, records, or external-review categories.
  10. Residual risk, tabletop evidence, completion, and review: what remains unknown, what the exercise demonstrated, and when the card must be reopened.

Do not collapse these concepts into one Device handled, Contained, Secure, Recovered, or Incident closed checkbox. A report is not confirmation. An assigned owner is not proof of authority or capability. An evidence owner is not evidence preservation. A completed preparation card is not containment, recovery, investigation, or incident closure.

Use eight stages to prepare the handoff

The sequence, concepts, states, fields, fact threshold, stop conditions, tabletop design, completion criteria, and review cadence are PlainFort editorial judgment. A small team may keep answers short, but it must not hide missing authority, backup, evidence ownership, continuity, escalation, or a dedicated-guide dependency.

1. Define the trigger and preparation-only boundary

Choose the minimum report that activates the card, such as Reported lost, Reported stolen, or Possibly missing. Preserve the reporter’s wording as a category without turning it into a conclusion. The trigger does not prove theft, malicious access, compromise, a current location, custody, affected identity, data exposure, or business impact.

State the card’s boundary beside the trigger: it prepares coordination and routes decisions, but it authorizes no device, account, evidence, notification, or external action.

2. Assign internal roles, backup, and authority

Name an internally accountable owner, a responsible coordinator, a qualified operator category for any later authorized work, a genuine backup, and the escalation authority. Keep these functions distinct even when one person fills several of them.

A name or title does not create competence, capacity, independence, availability, or authority. A provider, contractor, insurer, law-enforcement body, employee, or device user may later supply authorized help, but cannot silently acquire internal accountability, decision authority, or evidence ownership.

3. Define safe reporting and category-only intake

Record an approved reporting route and a safe fallback. The intake should ask only for the minimum categories needed to route the report: trigger category, device ownership or admission category, general work-impact category, and whether another dedicated handoff may be required.

Use Device-loss preparation record — identifiers and incident details not copied. Do not request or copy a person, device identifier, serial number, phone number, account, email, domain, precise time or location, tracking result, message, screenshot, attachment, log, telemetry, credential, recovery material, or evidence content.

4. Reference device and workflow dependencies

DN-16 owns the steady-state company-laptop baseline. DN-17 owns personal-device admission, privacy, separation, support, and exit. DN-20 owns the general remote-work baseline. Consume the available category and evidence state from those guides without repeating their checks or inspecting, admitting, configuring, approving, locking, or removing a device.

AA-09 owns access revocation triggered by an authorized departure. A missing or stolen device changes the trigger; DN-18 cannot convert it into offboarding or perform account revocation.

5. Assign evidence ownership without collecting evidence

Name the internal role that owns preservation decisions and the approved location category in which an inert reference may later be held. Use Approved evidence location — no evidence collected until qualified, authorized work establishes something more.

Evidence ownership does not mean collecting, preserving, imaging, accessing, copying, exporting, moving, deleting, or inspecting a device, account, message, log, telemetry record, or other evidence. A provider statement or reporter statement remains reported information, not inspected evidence.

6. Prepare continuity and qualified handoffs

Record the safe work-stoppage condition, an already-approved fallback category if one exists, unavailable-owner coverage, and the receiving role for qualified assistance. Do not activate a replacement, move data or work, restore a backup, recover access, or test a live system.

EP-15 owns preparation for suspected mailbox compromise. Route mailbox-compromise suspicion there without accessing or changing a mailbox. BR-24 is reserved for a future guide on general incident roles and communication; until it is separately drafted and approved, record Future BR-24 handoff — qualified incident coordination required rather than pretending that guide exists today.

7. Exercise the card without touching a live device or account

Use a category-only tabletop to check whether the trigger, roles, backup, authority, safe route, evidence owner, continuity path, and qualified handoffs are understandable. Do not use a real device, account, mailbox, location service, provider, credential, backup, message, log, telemetry source, evidence item, or plausible live incident.

The exercise must stop at the handoff. Do not locate, track, ping, ring, connect to, lock, disable, wipe, erase, reset, recover, restore, reconfigure, sign in, revoke, rotate, inspect, preserve, notify, or contact anyone.

8. Close preparation with residual risk and a review trigger

Preparation may close only when every field is truthful, internal accountability and authority are visible, a genuine backup and safe route exist, the evidence owner and action boundary are clear, continuity and dedicated handoffs are usable, and every blocker or unknown has an owner and review trigger.

Use Preparation card complete — containment not established only for the preparation record. Reopen it when device categories, admission decisions, roles, authority, communication routes, evidence rules, continuity dependencies, sibling guidance, providers, contracts, legal or privacy constraints, or official guidance change.

Use preparation states, not incident verdicts

  • Trigger reported — facts unverified
  • Acknowledged — preparation card activated
  • Evidence owner assigned — no evidence collected
  • Qualified handoff required
  • Continuity dependency unresolved
  • Unknown — follow up through approved route
  • Blocked — authority or safe channel missing
  • Tabletop complete — no live action performed
  • Preparation card complete — containment not established

These are preparation positions, not incident severity, device status, legal classification, evidence quality, response outcome, or a security score. No state implies that a device is located, controlled, inaccessible, uncompromised, recoverable, or safe. Never choose a convenient state merely to make the card look complete.

Stop before live or high-impact action

Stop and route the matter to qualified, authorized help before anyone attempts to:

  • locate, track, ping, ring, connect to, inspect, or monitor a device;
  • lock, disable, wipe, erase, remove, reset, recover, restore, or reconfigure a device;
  • sign in, reset a password, rotate a credential, alter MFA, revoke a token or session, disable an account, or change privilege;
  • access or preserve logs, messages, backups, telemetry, cloud consoles, provider portals, or evidence;
  • perform forensics, investigation, containment, recovery, notification, police or insurer reporting, legal, HR, privacy, or records determination, or external communication.

Also stop when privileged access, sensitive or regulated data, suspected compromise, a personal-device privacy conflict, no surviving administrator, uncertain authority or evidence ownership, material financial or operational impact, a disputed employment matter, a contractual or insurance issue, or an unavailable safe communication or continuity path is involved.

These are escalation triggers only. This article provides no commands, provider steps, universal deadlines, destructive-action ordering, or assurance that a live action is safe.

Keep dedicated guides separate

DN-16 owns steady-state company-laptop controls and evidence categories. DN-18 consumes its state without re-running the baseline.

DN-17 owns personal-device admission, privacy, separation, support, and exit. DN-18 does not create or change a personal-device decision.

DN-20 owns the general remote-work baseline and its loss or theft handoff. DN-18 consumes that handoff without repeating remote-work conditions.

AA-09 owns access revocation triggered by an authorized departure. DN-18 owns a different trigger and performs no offboarding.

EP-15 owns preparation for suspected mailbox compromise. DN-18 routes that suspicion without accessing or changing a mailbox.

BR-24 will own general incident roles and communication design if it is later drafted and approved. DN-18 reserves a future handoff but does not claim that the guide currently exists.

DN-18 owns the device-loss or theft preparation card and the trigger-to-qualified-handoff boundary. It does not absorb steady-state controls, personal-device admission, remote-work policy, departure offboarding, mailbox-compromise preparation, or a general incident program.

Use an 18-field vertical preparation card

Use one vertical card for the preparation boundary. Do not turn it into a wide table, live-response checklist, device inventory, tracking record, evidence log, contact list, recovery plan, insurer or police form, legal assessment, incident timeline, or compliance scorecard.

  1. Trigger category and preparation threshold: the minimum report that activates the card and the conclusions it does not support.
  2. Approved report route and safe fallback: inert route categories, accessibility needs, unavailable-channel path, and no copied contact detail.
  3. Non-identifying device-reference category: company-managed, personal admitted, third-party controlled, unknown, or another approved category—never an identifier.
  4. Ownership and admission state: existing DN-16 or DN-17 state and whether it is documented, reported, unknown, or blocked.
  5. Internally accountable owner: organizational role and any competence, capacity, independence, or authority gap.
  6. Responsible coordinator: role that activates the card, maintains the record, and routes decisions without performing live response.
  7. Qualified operator category: receiving capability for later separately authorized action; no person, provider, or contact detail.
  8. Genuine backup and continuity authority: actual availability, handover trigger, and authority rather than a nominal name.
  9. Safe communication path: approved primary and fallback categories without copied message or incident content.
  10. Decision authority and prohibited live-action boundary: who may decide later work and the tracking, device, account, evidence, notification, and external actions this card cannot authorize.
  11. Evidence owner and approved location category — no evidence collected: responsible role, inert location reference, and current evidence state.
  12. Account and access handoff: qualified receiving path and any EP-15 or other dedicated-guide dependency, without account action.
  13. Data and workflow impact category: generic sensitivity and interruption categories, known facts, assumptions, and unknowns.
  14. Continuity and safe-fallback condition: approved fallback category or stop-work condition, unavailable-owner route, and unresolved dependency.
  15. EP-15, AA-09, and future BR-24 handoffs: applicable trigger boundary, receiving role category, and explicit non-reproduction.
  16. Legal, privacy, HR, insurance, records, and external-escalation categories: issues requiring qualified review, without decisions or contacts.
  17. Residual risk, unknowns, and stop result: what may remain accessible, offline, unrecoverable, incorrectly identified, shared, personal, linked, or outside control.
  18. Tabletop evidence, next exercise, and review trigger: what the non-live exercise established, unresolved blockers, and the event that reopens the card.

Fictional example — do not copy as a completed device or network record.

  1. Trigger category and preparation threshold: Example Co. activates the card for Possibly missing; the report does not establish theft, compromise, location, custody, or impact.
  2. Approved report route and safe fallback: Approved internal report route — contact details not copied; the fallback is an approved internal role category.
  3. Non-identifying device-reference category: Organization-managed portable-device category; no identifier, make, platform, or location appears.
  4. Ownership and admission state: DN-16 category is Reported — evidence not inspected; no device check is performed.
  5. Internally accountable owner: Operations lead; authority for later technical action is not inferred from the title.
  6. Responsible coordinator: Operations coordinator, limited to card activation, record maintenance, and handoff.
  7. Qualified operator category: Qualified device-response support required; no provider or person is named.
  8. Genuine backup and continuity authority: Backup coverage is Unknown — follow up through approved route, which blocks completion.
  9. Safe communication path: Device-loss preparation record — identifiers and incident details not copied; no message content is stored here.
  10. Decision authority and prohibited live-action boundary: The accountable owner may stop work and escalate; the card authorizes no tracking, lock, wipe, account, evidence, notification, or external action.
  11. Evidence owner and approved location category — no evidence collected: Operations lead; Approved evidence location — no evidence collected.
  12. Account and access handoff: Qualified handoff required; no password, MFA, token, session, privilege, or mailbox action is performed.
  13. Data and workflow impact category: Work-data category and service-interruption category are unknown; no content or business detail is copied.
  14. Continuity and safe-fallback condition: Stop the affected work category and use only an already-approved fallback; backup authority remains unresolved.
  15. EP-15, AA-09, and future BR-24 handoffs: Mailbox suspicion routes to EP-15; departure-trigger work remains with AA-09; general incident coordination is Future BR-24 handoff — qualified incident coordination required.
  16. Legal, privacy, HR, insurance, records, and external-escalation categories: Qualified review required; no conclusion, report, notification, or contact is made.
  17. Residual risk, unknowns, and stop result: The device may remain accessible, offline, unrecoverable, incorrectly identified, or linked to accounts and data; state is Blocked — authority or safe channel missing.
  18. Tabletop evidence, next exercise, and review trigger: The category-only exercise found the missing genuine backup; no live action occurred, and the card reopens when coverage or any dependency changes.

The missing backup and unresolved authority prevent this fictional card from becoming a false completion.

Where this guide stops

This guide prepares roles and handoffs; it does not determine location, custody, compromise, scope, evidence sufficiency, legal or notification duties, safe containment order, or recovery success. It cannot prove that a device, account, workflow, backup, communication route, or response capability is secure or effective.

Seek qualified IT, security, privacy, legal, HR, records, insurance, financial, or incident-response help when authority is unclear, sensitive or privileged access may be involved, evidence decisions matter, a safe fallback is absent, or any live action could cause exposure, interruption, lockout, evidence loss, or data loss.