A lost device is one of the few security incidents where a business genuinely gets to control the outcome, provided the groundwork was done and the first hour is handled in the right order. Most of the damage in the cases we have seen came from doing the right things in the wrong sequence.
The first hour, in order
- 1Tell IT immediately, before you try to find it yourself. Every minute the device is unreported is a minute company data is exposed
- 2Revoke active sessions for that user across mail, files and any single sign-on. This matters more than the device itself, because a signed-in session survives a locked screen
- 3Force a password reset for the account, which invalidates most saved credentials
- 4Locate or mark as lost, which locks the device and displays a contact message. Do this before wiping, because a wiped device cannot be located
- 5Wipe once recovery looks unlikely, or immediately if the data is sensitive enough that recovery is not worth the risk
- 6Record what was on it, since that determines whether anyone else needs telling
Sessions first, device second
Revoking sessions is the step most people skip and the one that closes the biggest hole. A locked phone with a live mailbox session is still leaking.
What remote wipe actually does
| Company-owned device | Personal device (BYOD) | |
|---|---|---|
| Scope | Full factory reset | Company data only |
| Personal photos and messages | Removed with everything else | Untouched |
| Works offline | Queues until it reconnects | Queues until it reconnects |
| Reversible | No | No |
| Device still traceable after | No | Yes, it is still the user's device |
The queueing behaviour is worth understanding. If a device is switched off or out of coverage, the wipe executes the moment it next connects. That is usually enough, but it is not instant, which is exactly why session revocation comes first.
What has to be in place beforehand
- Devices enrolled in device management, since you cannot wipe what you never enrolled
- A documented process naming who can authorise a wipe, so nobody hesitates at 9pm on a Friday
- Encryption enforced, which makes an unwiped device far less useful to whoever has it
- Screen lock enforced, since a device without one is readable before you get anywhere near a wipe
- A tested wipe on a pilot device, because the incident is the wrong time to discover the process does not work
The reporting question
Depending on what was on the device and which regulations apply to your business, a lost device holding personal data may carry notification obligations. Work out where your business stands on that before it happens rather than during. Confirm your specific obligations with whoever advises you on compliance.
Afterwards
- 1Confirm the wipe completed rather than assuming it queued successfully
- 2Review what the user had access to and whether it was more than the role needed
- 3Reissue with enrolment applied before the replacement leaves IT
- 4Note the cause, because a pattern of devices lost in the same circumstances is worth acting on
Not sure you could wipe a device today?
We enrol fleets, set up the wipe and session-revocation process, and test it on a pilot device so it works when you actually need it.
Frequently asked questions
What is the very first thing to do?
Report it to IT, then revoke the user's active sessions across mail, files and single sign-on. A live session survives a locked screen, so revoking sessions closes a bigger hole than locking the device does. Location and wipe come after that.
Does remote wipe work if the phone is switched off?
The command queues and executes the moment the device next connects to a network. That covers most real cases, but it is not instantaneous, which is precisely why session revocation and a password reset come first in the sequence.
Will a wipe delete my personal photos?
On a company-owned device, yes, because the wipe is a full factory reset. On a personal device enrolled through BYOD, no. A selective wipe removes only company mail, files and work app data and leaves everything personal in place.
Can we wipe a device that was never enrolled?
No. Device management is what gives you the ability to act, and it has to be in place before the incident. An unenrolled device can only be handled by revoking the user's access and changing credentials, which does not remove data already on it.
Should we wipe immediately or try to recover it first?
Mark it as lost first, which locks it and displays a contact message while keeping it locatable. If recovery looks unlikely, or the data is sensitive enough that the risk outweighs recovery, wipe. Once wiped, the device can no longer be located.
Azizi Technologies Team
· Editorial TeamPractical IT and digital marketing guidance from the Azizi Technologies team - an in-house team of certified engineers, SEO specialists, and digital marketers serving Dubai businesses since 2007.
Need a quote for Mobile Device Management Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.