Critical Security Incident: Stolen Device Intake & Response Protocol

1. Section 1: Employee Profile, Device Identification & Geospatial Incident Metadata

This section captures the affected employee's identity, the compromised asset's technical specifications, and precise geospatial-temporal metadata surrounding the theft incident. Accuracy is critical for forensic analysis and insurance claims.

 

Employee Full Legal Name

Employee Unique Identifier

Employee Department/Division

Employee Job Role Title

Employee Primary Contact Number

Employee Alternative Contact Number

Employee Corporate Email Address

Employee Personal Email Address (for recovery coordination)

Employee Work Arrangement at Time of Incident

 

Provide detailed travel itinerary: cities, hotels, transportation modes

 

Customer/Client Organization Name

 

Co-working Space Name and Address

 

Describe public location context: venue name, address, time spent

 

Device Asset Specification & Identification Matrix

 

Compromised Asset Inventory

Device Category

Manufacturer

Model Name/Number

Serial Number (Primary ID)

Corporate Asset Tag (Barcode)

MAC Address (Wi-Fi)

MAC Address (Ethernet/Bluetooth)

IMEI (for cellular devices)

Device Issue Date to Employee

Operating System & Version

A
B
C
D
E
F
G
H
I
J
1
Laptop
Dell Inc.
Latitude 7420
SN-8X4T9P2
AST-2023-8472
A4:CF:12:8B:3D:E1
N/A
N/A
5/15/2023
Windows 11 Enterprise 22H2
2
 
 
 
 
 
 
 
 
 
 
3
 
 
 
 
 
 
 
 
 
 
4
 
 
 
 
 
 
 
 
 
 
5
 
 
 
 
 
 
 
 
 
 
6
 
 
 
 
 
 
 
 
 
 
7
 
 
 
 
 
 
 
 
 
 
8
 
 
 
 
 
 
 
 
 
 
9
 
 
 
 
 
 
 
 
 
 
10
 
 
 
 
 
 
 
 
 
 

Exact Date and Time Theft Discovered (Employee Local Time)

Employee Time Zone at Discovery

Last Confirmed Physical Possession (Date/Time)

Theft Location Physical Address or GPS Coordinates

Is the theft location the employee's designated remote work address?

Detailed Description of Location Environment

Was the device connected to corporate VPN at time of theft or last known session?

 

Last Known VPN IP Address

 

Explain network connectivity status and last known corporate network access

Was the device domain-joined or Azure AD joined?

 

Domain Name or Azure AD Tenant ID

2. Section 2: Law Enforcement Engagement & Forensic Loss Circumstances Documentation

This section documents official law enforcement engagement and reconstructs the circumstances of loss to support investigation, insurance claims, and potential recovery efforts.

 

Has a formal police report been filed with local law enforcement?

 

Police Report/Crime Reference Number

 

Explain why police report was not filed and planned next steps

Law Enforcement Agency Name

Precinct/Station Address

Investigating Officer Name and Badge Number

Officer Contact Information (Email/Phone)

Date and Time Police Report Filed

Upload Official Police Report Document (PDF/Scan)

Choose a file or drop it here
 

Upload Photo of Police Report Receipt or Acknowledgment

Choose a file or drop it here

Theft Incident Classification

 

Was the vehicle corporate-owned or personal?

 

Describe the 'Other' classification in detail

Estimated Date and Time of Theft (if different from discovery)

Employee Activity at Time of Incident (select all applicable)

Were there any witnesses to the theft or suspicious activity?

 

Witness Details: Name, Contact, Statement Summary

Was CCTV or surveillance footage available at the location?

 

CCTV Details: Camera locations, retention period, contact for footage retrieval

Was the device stored in a locked container (safe, lockbox, trunk) when stolen?

 

Describe container type and locking mechanism

 

Explain why device was not secured in locked container

Assess the physical security of the theft location environment

Detailed Narrative of Events Leading to Loss

Was any other corporate or personal property stolen simultaneously?

3. Section 3: Remote Wipe Command Execution & Digital Access Token Revocation Protocol Checklist

This section verifies execution of remote data destruction commands and comprehensive revocation of all digital access credentials to prevent unauthorized network or data access.

 

Has a remote wipe command been initiated via Mobile Device Management (MDM)?

 

MDM Remote Wipe Status

 

Command Initiation Timestamp

 

Command Sent Timestamp

 

Wipe Confirmation Timestamp

 

Error Details and Failure Reason

 

Explain why MDM wipe was not initiated and alternative mitigation steps

Was the device enrolled in Microsoft Intune, Jamf Pro, or other MDM platform?

 

MDM Platform Name and Version

Was the device configured with 'Find My Device' (Apple) or 'Find My Device' (Android/Windows)?

 

Provide tracking status and last known location if available

 

Access Token and Credential Revocation Matrix

 

Digital Access Revocation Checklist

Revocation Action Completed

Access Type

Revocation Timestamp

Performed By (Initials)

Notes/Confirmation Details

A
B
C
D
E
1
Corporate VPN Access
1/15/2024, 2:30 PM
JS
Disabled in FortiGate, session killed
2
Corporate Email Account
1/15/2024, 2:32 PM
JS
All tokens revoked
3
Single Sign-On (SSO) Sessions
1/15/2024, 2:35 PM
JS
Okta sessions terminated globally
4
Cloud Storage Sync (OneDrive/Box)
 
 
 
5
Source Code Repository Access
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Have all active directory sessions been terminated across all domain controllers?

Were any privileged/administrative credentials cached or stored on the device?

 

List all privileged accounts and immediate containment actions taken

Was a remote lock command sent to prevent device boot or access?

 

Lock Command Reference ID

Has the device been flagged in asset management system as 'Stolen - Security Incident'?

Has the SIM card (if applicable) been deactivated with mobile carrier?

 

Carrier Name and Deactivation Reference

Additional Digital Containment Measures Implemented

4. Section 4: Data Classification Sensitivity Assessment & Proprietary Information Exposure Audit

This section conducts a rigorous audit of data sensitivity levels stored on or accessible from the compromised device to quantify breach severity and determine regulatory notification obligations.

 

Official Corporate Data Classification Level of Device

 

Describe specific confidential data categories present

 

Describe specific restricted data categories present

 

Describe specific top secret data categories present

Was the device protected with Full Disk Encryption (FDE) at time of theft?

 

Encryption Standard and Algorithm

 

Justification for lack of encryption and immediate risk mitigation

Was the device powered on or in sleep/hibernation mode when stolen?

 

Was the user logged in and session unlocked?

 

Describe session state and potential data exposure risk

Select all categories of sensitive data potentially stored on or accessible via the device

Did the device have offline/local copies of cloud-synced files?

 

Which cloud storage services had offline copies?

Were any cached credentials stored on the device?

 

Was the device configured with auto-save or recent documents cache?

 

Describe applications with auto-save and potential data remnants

Last Successful Cloud Backup or Sync Timestamp

Was any data actively being transferred or synced at time of theft?

 

Describe data transfer context and potential interception risk

 

Data Exposure Risk Assessment Matrix

 

Rate the potential exposure severity for each data category (1=Minimal, 5=Catastrophic)

Customer PII Exposure

Employee PII Exposure

Financial Data Exposure

Intellectual Property Theft

Credential Compromise Risk

Regulatory Non-Compliance Risk

Does this incident potentially trigger regulatory breach notification requirements?

 

Select potentially applicable regulatory frameworks

Estimated Volume of Sensitive Records Potentially Compromised

Has a preliminary data inventory been conducted from backup logs?

 

Upload Data Inventory Analysis Report

Choose a file or drop it here
 

5. Section 5: Information Security Officer & IT Service Desk Lead Joint Clearance Sign-Off

This final section requires dual-authority verification from Information Security and IT Service Management leadership to confirm all required containment, documentation, and escalation actions have been satisfactorily completed before incident closure.

Information Security Officer (ISO) Verification Checklist

 

ISO Security Controls Validation

Control Verified

Security Control Item

Verification Method

Verified By (Name/Role)

Verification Timestamp

A
B
C
D
E
1
Remote wipe command issued and confirmed
MDM console log review
InfoSec Team
1/15/2024, 3:45 PM
2
All access tokens revoked globally
Identity platform audit
InfoSec Team
1/15/2024, 4:00 PM
3
Data sensitivity assessment completed
Review of Sections 1-4
InfoSec Team
1/15/2024, 4:30 PM
4
Regulatory breach evaluation conducted
 
 
 
5
Forensic image obtained (if applicable)
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Does the ISO recommend escalation to executive leadership or legal counsel?

 

Escalation Rationale and Recommended Actions

 

IT Service Desk Lead Operational Closure Validation

 

IT Service Desk Operational Verification

Task Completed

Operational Task

Completion Evidence

Completed By (Initials)

Completion Timestamp

A
B
C
D
E
1
Employee issued temporary replacement device
Asset tag RT-2024-001
TK
1/16/2024, 9:00 AM
2
User account security hardening completed
MFA re-enrollment
TK
1/16/2024, 9:15 AM
3
Incident ticket fully documented
Ticket #INC-2024-0847 updated
TK
1/16/2024, 10:00 AM
4
Insurance claim initiated
 
 
 
5
Asset management system updated
 
 
 
6
 
 
 
 
7
 
 
 
 
8
 
 
 
 
9
 
 
 
 
10
 
 
 
 

Has the employee been provided with security awareness retraining?

 

Training Module Completed and Date

 

Schedule and plan for mandatory security retraining

Has a replacement device been provisioned to the employee?

 

Replacement Device Asset Tag

 

Explain delay and estimated provisioning timeline

Information Security Officer Digital Signature

Information Security Officer Name (Printed)

Information Security Officer Title

Information Security Officer Sign-off Timestamp

IT Service Desk Lead Digital Signature

IT Service Desk Lead Name (Printed)

IT Service Desk Lead Title

IT Service Desk Lead Sign-off Timestamp

Do both authorizing officers approve incident closure?

Final Incident Summary and Lessons Learned Recommendations

Should this incident be included in quarterly security metrics and board reporting?

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.