Treat the event as an access incident, not only an asset loss. The first priority is to revoke trust in the device by locking it, wiping corporate data where possible, and invalidating sessions or credentials that could be used from it. That limits exposure before the device is abused or recovered by someone else.
Why Loss or Theft Becomes an Access Problem Immediately
A lost or stolen company device is dangerous because the device is usually already trusted by applications, sessions, and data stores. The first response should focus on breaking that trust chain, not on proving whether the hardware is recoverable. If attackers or bystanders can use the device before controls are revoked, the incident becomes a live access issue.
That is why the practical priority is to make the device unusable for corporate access as fast as possible. Locking the device is only the start; the real objective is to stop any remaining sessions, cached credentials, and synced data from being reused elsewhere.
What to Revoke, Reset, and Contain First
Teams should think in terms of blast radius. The fastest containment actions are the ones that remove the device’s ability to authenticate, authorize, or rehydrate access across other systems.
- Lock or disable the device through the endpoint management stack if the device is still online.
- Wipe corporate data or perform a remote wipe where policy and tooling allow it.
- Invalidate active sessions, refresh tokens, API keys, VPN sessions, and other credentials that could still work from the lost device.
- Rotate any secrets that may have been stored locally, especially if the device held sync clients, browser sessions, or cached administrative access.
Where the device also represented access to collaboration tools or cloud services, the breach patterns in NHI and AI agent compromises show why stolen credentials and long-lived trust are often more damaging than the device itself.
What Good Response Looks Like in Practice
The best response is a short, coordinated sequence with clear ownership. Endpoint, identity, and service owners should be able to act in parallel, because waiting for one team to finish before the next begins creates avoidable exposure.
Use the device’s trust relationship as the decision point. If it can still reach corporate resources, treat it as a credential and session containment event. If the device was only a personal productivity endpoint with no corporate trust material, response can be narrower. The higher the privilege on the device, the faster and broader the containment should be.
For teams that want a clear source for incident handling discipline, the FIRST incident response standards are a useful reference for coordination and escalation. When the lost device could expose sensitive sessions or tokens, RFC 9449 on OAuth 2.0 DPoP is a reminder that sender-constrained tokens reduce replay value if the device is ever compromised.
Risk and Threat Considerations
A lost or stolen device is risky because modern endpoints often carry active trust, not just stored files. An attacker may not need full disk access if the device already holds authenticated browser sessions, cached tokens, or saved secrets that can be reused before expiry.
Failure mechanism: The device remains trusted long enough for someone else to use it, replay sessions, or extract credentials from local storage, sync clients, or connected apps.
Impact: The event can expand from a hardware loss into account takeover, data exposure, lateral movement, or unauthorized transactions, especially when privileged or long-lived access is present.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Lost-device response hinges on revoking tokens, sessions, and cached credentials. |
| AC-20 — Use of External Information Systems | A stolen company device is an external-use exposure that can extend beyond the endpoint. | |
| IR-4 — Incident Handling | The question is about first-response containment to a security incident. | |
| Recommendation — Rotate exposed authenticators and invalidate sessions tied to the lost device. Restrict and revoke external access paths that the lost device could still use. Trigger incident handling to contain the device and coordinate response actions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions Management | The answer focuses on revoking device trust and access before abuse occurs. |
| RS.MA-01 — Response Planning and Execution | Immediate containment and coordinated action are the core response need. | |
| Recommendation — Revoke and reissue access permissions tied to the lost device immediately. Execute the device-loss response playbook and coordinate containment across teams. | ||
| OWASP Non-Human Identity Top 10 | NHI-07 — Long-Lived Secrets | Lost devices often expose cached or long-lived credentials that remain usable. |
| NHI-01 — Improper Offboarding | A lost device requires rapid trust removal similar to offboarding exposure. | |
| Recommendation — Replace long-lived secrets that may have been accessible on the device. Remove device-linked access immediately and confirm all trust has been withdrawn. | ||
Practitioner Guidance
What to prioritise: Revoke anything that can still authenticate before spending time on recovery logistics or blame analysis. If the device had access to mail, VPN, cloud consoles, source control, or admin tools, treat those sessions as exposed until proven otherwise.
What to verify: Confirm whether remote lock, wipe, and session revocation actually succeeded, and verify that high-risk accounts were forced through reauthentication or token invalidation. If the device was unmanaged or offline, assume the containment window is worse and broaden the reset scope.
Practitioner takeaway: The first job is not to find the device, it is to remove its remaining authority before someone else can use it.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org