Critical Security Incident: Stolen Device Intake & Response Protocol

1. Section 1: Employee Profile, Device Identification & Geospatial Incident Metadata

This section captures the affected employee's identity, the compromised asset's technical specifications, and precise geospatial-temporal metadata surrounding the theft incident. Accuracy is critical for forensic analysis and insurance claims.


Employee Full Legal Name

Employee Unique Identifier

Employee Department/Division

Employee Job Role Title

Employee Primary Contact Number

Employee Alternative Contact Number

Employee Corporate Email Address

Employee Personal Email Address (for recovery coordination)

Employee Work Arrangement at Time of Incident




Device Asset Specification & Identification Matrix


Compromised Asset Inventory

Device Category

Manufacturer

Model Name/Number

Serial Number (Primary ID)

Corporate Asset Tag (Barcode)

MAC Address (Wi-Fi)

MAC Address (Ethernet/Bluetooth)

IMEI (for cellular devices)

Device Issue Date to Employee

Operating System & Version

Laptop
Dell Inc.
Latitude 7420
SN-8X4T9P2
AST-2023-8472
A4:CF:12:8B:3D:E1
N/A
N/A
5/15/2023
Windows 11 Enterprise 22H2
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Exact Date and Time Theft Discovered (Employee Local Time)

Employee Time Zone at Discovery

Last Confirmed Physical Possession (Date/Time)

Theft Location Physical Address or GPS Coordinates

Is the theft location the employee's designated remote work address?

Detailed Description of Location Environment

Was the device connected to corporate VPN at time of theft or last known session?


Was the device domain-joined or Azure AD joined?


2. Section 2: Law Enforcement Engagement & Forensic Loss Circumstances Documentation

This section documents official law enforcement engagement and reconstructs the circumstances of loss to support investigation, insurance claims, and potential recovery efforts.


Has a formal police report been filed with local law enforcement?


Law Enforcement Agency Name

Precinct/Station Address

Investigating Officer Name and Badge Number

Officer Contact Information (Email/Phone)

Date and Time Police Report Filed

Upload Official Police Report Document (PDF/Scan)

Choose a file or drop it here
 

Upload Photo of Police Report Receipt or Acknowledgment

Choose a file or drop it here

Theft Incident Classification


Estimated Date and Time of Theft (if different from discovery)

Employee Activity at Time of Incident (select all applicable)

Were there any witnesses to the theft or suspicious activity?


Was CCTV or surveillance footage available at the location?


Was the device stored in a locked container (safe, lockbox, trunk) when stolen?


Assess the physical security of the theft location environment

Detailed Narrative of Events Leading to Loss

Was any other corporate or personal property stolen simultaneously?

3. Section 3: Remote Wipe Command Execution & Digital Access Token Revocation Protocol Checklist

This section verifies execution of remote data destruction commands and comprehensive revocation of all digital access credentials to prevent unauthorized network or data access.


Has a remote wipe command been initiated via Mobile Device Management (MDM)?




Was the device enrolled in Microsoft Intune, Jamf Pro, or other MDM platform?


Was the device configured with 'Find My Device' (Apple) or 'Find My Device' (Android/Windows)?


Access Token and Credential Revocation Matrix


Digital Access Revocation Checklist

Revocation Action Completed

Access Type

Revocation Timestamp

Performed By (Initials)

Notes/Confirmation Details

Corporate VPN Access
1/15/2024, 2:30 PM
JS
Disabled in FortiGate, session killed
Corporate Email Account
1/15/2024, 2:32 PM
JS
All tokens revoked
Single Sign-On (SSO) Sessions
1/15/2024, 2:35 PM
JS
Okta sessions terminated globally
Cloud Storage Sync (OneDrive/Box)
 
 
 
Source Code Repository Access
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Have all active directory sessions been terminated across all domain controllers?

Were any privileged/administrative credentials cached or stored on the device?


Was a remote lock command sent to prevent device boot or access?


Has the device been flagged in asset management system as 'Stolen - Security Incident'?

Has the SIM card (if applicable) been deactivated with mobile carrier?


Additional Digital Containment Measures Implemented

4. Section 4: Data Classification Sensitivity Assessment & Proprietary Information Exposure Audit

This section conducts a rigorous audit of data sensitivity levels stored on or accessible from the compromised device to quantify breach severity and determine regulatory notification obligations.


Official Corporate Data Classification Level of Device



Was the device protected with Full Disk Encryption (FDE) at time of theft?


Was the device powered on or in sleep/hibernation mode when stolen?


Select all categories of sensitive data potentially stored on or accessible via the device

Did the device have offline/local copies of cloud-synced files?


Were any cached credentials stored on the device?


Was the device configured with auto-save or recent documents cache?


Last Successful Cloud Backup or Sync Timestamp

Was any data actively being transferred or synced at time of theft?


Data Exposure Risk Assessment Matrix


Rate the potential exposure severity for each data category (1=Minimal, 5=Catastrophic)

Customer PII Exposure

Employee PII Exposure

Financial Data Exposure

Intellectual Property Theft

Credential Compromise Risk

Regulatory Non-Compliance Risk

Does this incident potentially trigger regulatory breach notification requirements?


Estimated Volume of Sensitive Records Potentially Compromised

Has a preliminary data inventory been conducted from backup logs?


5. Section 5: Information Security Officer & IT Service Desk Lead Joint Clearance Sign-Off

This final section requires dual-authority verification from Information Security and IT Service Management leadership to confirm all required containment, documentation, and escalation actions have been satisfactorily completed before incident closure.

Information Security Officer (ISO) Verification Checklist


ISO Security Controls Validation

Control Verified

Security Control Item

Verification Method

Verified By (Name/Role)

Verification Timestamp

Remote wipe command issued and confirmed
MDM console log review
InfoSec Team
1/15/2024, 3:45 PM
All access tokens revoked globally
Identity platform audit
InfoSec Team
1/15/2024, 4:00 PM
Data sensitivity assessment completed
Review of Sections 1-4
InfoSec Team
1/15/2024, 4:30 PM
Regulatory breach evaluation conducted
 
 
 
Forensic image obtained (if applicable)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Does the ISO recommend escalation to executive leadership or legal counsel?


IT Service Desk Lead Operational Closure Validation


IT Service Desk Operational Verification

Task Completed

Operational Task

Completion Evidence

Completed By (Initials)

Completion Timestamp

Employee issued temporary replacement device
Asset tag RT-2024-001
TK
1/16/2024, 9:00 AM
User account security hardening completed
MFA re-enrollment
TK
1/16/2024, 9:15 AM
Incident ticket fully documented
Ticket #INC-2024-0847 updated
TK
1/16/2024, 10:00 AM
Insurance claim initiated
 
 
 
Asset management system updated
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Has the employee been provided with security awareness retraining?


Has a replacement device been provisioned to the employee?


Information Security Officer Digital Signature

Information Security Officer Name (Printed)

Information Security Officer Title

Information Security Officer Sign-off Timestamp

IT Service Desk Lead Digital Signature

IT Service Desk Lead Name (Printed)

IT Service Desk Lead Title

IT Service Desk Lead Sign-off Timestamp

Do both authorizing officers approve incident closure?

Final Incident Summary and Lessons Learned Recommendations

Should this incident be included in quarterly security metrics and board reporting?

Editing this form is like giving it a superhero cape—suddenly, it’s faster, stronger, and ready to save the day! 🦸‍♂️💥 Edit this Urgent Incident Intake Form - Stolen Corporate Device Reporting
This template feelin' like it's stuck in neutral? Slam it into overdrive with Zapof! You can build your own super-brainy form that's got more twists and turns than a mountain road rally based on the answers – it's a data demolition derby of fun!
This form is protected by Google reCAPTCHA. Privacy - Terms.
 
Built using Zapof