Lost or Stolen Company Devices: When Does a Missing Laptop Become a Data Breach?
Dozens of Scottish Government laptops and mobile phones have reportedly been lost or stolen since the beginning of 2025, raising questions about how organisations should assess the cyber-security and data-protection risks created when corporate devices disappear.
According to reporting published in August 2026, 78 government-issued devices were recorded as lost or stolen between January 2025 and June 2026, including 57 mobile phones and 21 laptops. The Scottish Government said none of the incidents met the threshold requiring notification to the Information Commissioner's Office, pointing to security measures including encryption and remote-wiping capabilities.
The case highlights an important distinction for businesses.
A missing laptop or phone does not automatically mean that personal data has been accessed.
But an organisation should also not assume that losing a device presents no risk simply because encryption, passwords or remote-wipe technology are available.
The real question is:
What information could have been accessed, what security controls were actually in place, and what evidence supports the organisation's assessment of the risk?
Is a Lost Laptop Automatically a Data Breach?
Not necessarily.
A personal data breach involves a security incident affecting the confidentiality, integrity or availability of personal information.
If an encrypted laptop is lost but there is strong evidence that an unauthorised person cannot access the information stored on it, the risk to individuals may be significantly reduced.
The ICO specifically recommends encryption for laptops, smartphones and tablets containing personal information because it provides important protection if a device is lost or stolen.
However, encryption is only one part of the assessment.
Organisations also need to understand:
- What information was stored locally.
- Whether encryption was enabled and functioning.
- How strong the device authentication was.
- Whether the device was unlocked when it disappeared.
- Whether corporate accounts remained accessible.
- Whether authentication sessions or tokens were stored on the device.
- Whether remote access remained possible.
- Whether remote locking or wiping was successfully completed.
- Whether there is evidence of subsequent access to corporate systems.
A lost device is therefore both a physical security incident and potentially a cyber-security incident.
What Should an Organisation Do When a Device Goes Missing?
The first response should be structured and evidence-led.
1. Establish Exactly What Has Been Lost
Confirm the device involved and identify:
- The asset number.
- Device type.
- Operating system.
- Assigned user.
- Serial number.
- Known location when last seen.
- Approximate time it went missing.
- Whether it was lost or believed to have been stolen.
This information helps the organisation determine what technical controls should have been active and what investigative steps are available.
2. Determine What Information Was Accessible
One of the most important questions is whether sensitive information was actually stored on the device.
That may include:
- Customer or employee records.
- Email.
- Documents downloaded for offline use.
- Financial information.
- Legal documents.
- Credentials.
- Personal information.
- Confidential commercial information.
- Access to cloud-based systems.
Many modern organisations store most information in cloud services rather than directly on laptops.
That does not necessarily eliminate the risk.
An authenticated device may still provide access to email, collaboration platforms, file storage or other corporate systems.
3. Confirm Whether Encryption Was Actually Active
It is not enough to have an organisational policy stating that devices should be encrypted.
The incident-response team should establish whether the specific device was encrypted at the time it disappeared.
This distinction matters.
The ICO provides an example involving a lost laptop where the organisation initially believed the device was encrypted and therefore assessed the incident as presenting little risk. It later discovered the laptop had not been encrypted, changing the risk assessment and resulting in notification to both the ICO and affected individuals.
Organisations should therefore be able to evidence technical controls rather than relying solely on policy or assumption.
4. Revoke Credentials and Active Sessions
A laptop or mobile phone may give access to much more than information stored locally.
Where appropriate, incident responders should consider:
- Resetting relevant passwords.
- Revoking authentication tokens.
- Ending existing cloud sessions.
- Disabling device certificates.
- Removing the device from trusted-device lists.
- Revoking VPN access.
- Reviewing multifactor-authentication settings.
- Checking for password or credential exposure.
This is particularly important where the device was logged into corporate services when it disappeared.
An attacker does not necessarily need to defeat full-disk encryption if they can access an already authenticated account.
5. Attempt Remote Locking or Wiping
Mobile-device-management platforms can allow organisations to remotely lock or erase corporate equipment.
This can materially reduce the risk associated with a missing device.
However, organisations should establish whether the command actually reached the device.
A remote-wipe request may remain pending if the device never reconnects to the internet.
Incident documentation should therefore distinguish between:
Remote wipe requested.
and
Remote wipe successfully completed.
Those are not the same thing.
6. Preserve Logs and Digital Evidence
Another important step is preserving evidence before relevant data expires or is overwritten.
Potential evidence may include:
- Authentication logs.
- VPN access records.
- Microsoft 365 or Google Workspace logs.
- Endpoint-management records.
- Mobile-device-management information.
- Cloud application access.
- IP addresses.
- Device connection records.
- Password-reset activity.
- Suspicious login alerts.
These records may help establish whether somebody attempted to use the missing device after it disappeared.
If unauthorised activity is identified, the incident may need to be treated as a broader account or network compromise rather than simply a missing asset.
When Must a Data Breach Be Reported to the ICO?
Not every security incident involving personal information must be reported.
The ICO states that organisations should assess the likely risk to people's rights and freedoms.
Where that risk is likely, the organisation must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the personal data breach. If the risk to affected individuals is high, those individuals may also need to be informed.
The assessment should consider factors such as:
- The type of personal information involved.
- The volume of data.
- Whether special-category or particularly sensitive information was accessible.
- The security controls protecting the device.
- The likelihood that someone could access the data.
- The possible consequences for affected individuals.
- Evidence of actual unauthorised access.
The important point is that the organisation needs to make and document the assessment.
What If the Organisation Decides Not to Report?
A decision not to notify the ICO should still be recorded.
The organisation should be able to explain the reasoning behind that decision if necessary.
That record might include:
- What happened.
- What information was potentially affected.
- Security controls in place.
- Confirmation of encryption.
- Actions taken after discovery.
- Evidence relating to remote wipe or locking.
- Relevant authentication-log reviews.
- Assessment of the likelihood of unauthorised access.
- Assessment of potential harm.
- The final reporting decision and rationale.
This documentation may become particularly important if new information emerges later.
Encryption Significantly Reduces Risk, But It Is Not the Whole Answer
Encryption is one of the most effective protections available for lost or stolen devices.
Appropriate encryption can protect stored personal information against unauthorised access when equipment is lost or stolen.
However, encryption does not solve every security problem.
An encrypted laptop might still present risk if:
- It was unlocked when stolen.
- The attacker obtained the user's credentials.
- Active account sessions remained available.
- Sensitive information was accessible through cloud applications.
- Weak authentication was used.
- Credentials were stored insecurely.
- Remote access or VPN sessions remained active.
The incident therefore needs to be assessed in context rather than classified as safe simply because disk encryption was deployed.
Lost Phones Can Create Different Risks
Corporate smartphones may contain less information locally than traditional laptops, but they can provide access to significant corporate systems.
A phone might contain or provide access to:
- Corporate email.
- Messaging applications.
- Authentication applications.
- Cloud storage.
- Customer systems.
- Contact databases.
- VPN credentials.
- Password managers.
It may also function as a second authentication factor.
This means that losing a corporate phone can potentially affect both data confidentiality and account security.
Organisations should therefore ensure mobile devices can be remotely managed and that appropriate authentication controls are enabled.
What If the Device Was Stolen Rather Than Lost?
A deliberate theft may alter the risk assessment.
If a device disappears during a burglary, vehicle break-in or targeted theft, the possibility that somebody deliberately sought access to the equipment may need to be considered.
Evidence should be preserved where available, including:
- Police reports.
- CCTV.
- Device location information.
- Login attempts.
- Authentication failures.
- Subsequent account activity.
- Remote-management records.
There may still be no evidence that the thief accessed corporate information.
The distinction is important because investigators should separate the fact that equipment was stolen from evidence that information was compromised.
When Does Digital Forensics Become Relevant?
Many lost-device incidents can be handled through an organisation's internal IT and data-protection processes.
More detailed investigation may be appropriate where:
- Suspicious logins appear after the device disappears.
- Accounts associated with the device are compromised.
- Sensitive information may have been downloaded.
- The device is later recovered.
- There are concerns the loss was deliberate.
- An employee's explanation conflicts with technical evidence.
- There is a broader cyber incident connected to the device.
- Litigation or regulatory scrutiny is anticipated.
Digital forensic work may help establish what information existed on a recovered device, whether files were accessed, and whether evidence of compromise is present.
It cannot always establish exactly what happened, particularly where a device remains missing.
Any investigation should therefore clearly distinguish between confirmed findings and unresolved possibilities.
Build Lost-Device Response Into Your Incident Plan
The Scottish Government story illustrates why lost and stolen equipment should be treated as an incident-response issue rather than simply an asset-management problem.
Organisations should have clear procedures covering:
- Immediate internal reporting.
- Device identification.
- Remote locking and wiping.
- Credential revocation.
- Log preservation.
- Data-protection assessment.
- Management escalation.
- Regulatory decision-making.
- Police reporting where appropriate.
- Documentation of the response.
Testing these procedures before a device disappears makes it much easier to establish the facts quickly when an incident occurs.
Cyber Incident Response and Digital Investigation
Conflict International provides Cyber Security Services for businesses, organisations and legal teams dealing with cyber incidents and digital security concerns.
Where a lost or stolen device creates uncertainty about possible unauthorised access, the response may include reviewing available technical evidence, preserving relevant logs and helping establish the scope of the incident.
The objective is not to assume that every missing device has resulted in a data breach.
It is to determine what can be established from the available evidence so that the organisation and its advisers can make informed decisions about containment, regulatory obligations and the next steps.
Has a Company Laptop or Phone Been Lost or Stolen?
If a missing corporate device may contain sensitive information or provide access to business systems, early investigation can help establish the potential exposure and preserve evidence before it becomes unavailable.
Complete the enquiry form below to discuss your cyber-security or digital-investigation requirements in confidence.