Your laptop is gone. Maybe it was stolen from a car, held by police during an investigation, damaged by water or locked after a failed update. The cause matters, but the first business problem is the same. One device may contain the only working copy of client files, passwords, invoices, contracts and the notes that explain what needs to happen tomorrow.
A business laptop emergency plan gives you a calm sequence to follow. It protects the information already on the device, restores essential work and helps you avoid panicked decisions that create a second problem.
Table of Contents
Decide What Kind of Incident You Have
Start by writing down what happened, when you last controlled the laptop and who may have it now. Keep facts separate from assumptions.
A stolen laptop calls for account security, an insurance report and possibly a police report.
A failed drive calls for technical recovery.
A device seized under legal authority raises questions about the warrant, the accounts that remain accessible and what you should say or do next. A laptop held by a former employee may involve company property, employment records and access rights.
Do not use a remote-wipe command until you understand the situation. Erasing a stolen device may be sensible after files are backed up and access is secured. Erasing a device connected to a dispute or investigation can destroy records that need to be preserved. Pause long enough to classify the event.
Protect access before replacing hardware
The laptop is replaceable. The access attached to it may be harder to recover.
From a separate trusted device, change the password for the primary business email account. Email often controls password resets for every other service. Then review active sessions and sign out the missing laptop where the provider allows it.
Work through the accounts that could move money, expose client information or publish under the company’s name:
● Banking, payment and bookkeeping services
● Cloud storage and document platforms
● Password manager and authenticator accounts
● Website hosting, domain and ecommerce tools
● Customer relationship and email-marketing systems
● Social media, advertising and marketplace accounts
Start with the highest-risk accounts instead of changing passwords in alphabetical order. Record each completed action in an incident log. That log prevents duplicate work when another team member joins the response.
If the laptop stored passkeys, recovery codes or an authenticator app, use the provider’s recovery process to register a new trusted device. Avoid sending codes through a channel that was open on the missing computer.
Map The Work That Must Continue Today
List the tasks that would cause immediate harm if missed. Payroll, client deadlines, order fulfilment, scheduled advertising, tax payments and customer support usually matter more than recreating a perfect desktop.
Assign each task to a person and a working device. Give temporary access with the narrowest permissions needed. If a contractor only needs to answer support tickets, they do not need administrator control of the whole workspace.
Tell the team where the temporary source of truth will live. It might be a shared task board or a dated document. During an incident, people often create parallel lists and then lose track of which one is current. Pick one.
Restore From a Backup You Understand
A useful backup has three qualities. It is recent enough to matter, separate from the missing device and tested well enough that you know how to restore it.
The National Institute of Standards and Technology has long advised small businesses to keep protected backups apart from the main network. That separation matters when the incident involves ransomware, account compromise or physical loss.
Before restoring everything, identify the minimum folders and applications needed for urgent work. Recover those first. Check the date of the backup and compare it with your incident timeline. A backup made after a suspicious file appeared may carry the same problem onto the replacement computer.
If the cause is unknown, ask a qualified technician to examine the replacement environment before connecting restored data. Keep the original backup unchanged and work from a copy. This preserves a clean fallback if the first recovery attempt fails.
Preserve Business Records Without Creating New Copies Everywhere
Founders often respond to fear by downloading every file to several personal devices. That can scatter confidential records across computers with weaker security.
Create one controlled preservation folder with restricted access. Save contracts, invoices, communications, access logs and incident notes that relate to the missing laptop. Keep original file names and dates where possible. Record where each item came from.
Do not edit an original document to add an explanation. Put the explanation in the incident log. If a message thread matters, preserve the whole thread rather than a cropped screenshot that removes context.
Check whether your contracts, privacy policy or industry rules require notice to clients or another party.
A missing laptop is not automatically a data breach. The answer depends on what information was stored, whether it was encrypted, who obtained the device and whether access occurred. Get advice before making a public statement that cannot be withdrawn.
Respond Carefully When Law Enforcement Has the Device
If officers seized the laptop, ask for a copy of the warrant, receipt or property record you are entitled to receive. Note the agency, officer, date, location and devices taken. Do not physically interfere with the search or tell an employee to hide, erase or move records.
You can protect the business while legal questions are reviewed. Secure unrelated accounts, activate the continuity plan and preserve copies that remain lawfully available. Avoid changing or deleting records connected to the investigation.
The scope of a search, access to business data and communication with investigators require case-specific advice. A lawyer who handles criminal defense can review the documents, identify deadlines and explain which response steps protect your rights without disrupting lawful process.
Choose one person to communicate with counsel and one to manage business operations. Combining those roles can work in a tiny company, but the person should still keep legal questions and recovery tasks in separate notes.
Give Staff a Short Script
Employees need enough information to work safely. They rarely need every detail.
A useful internal message states that the laptop is unavailable, tells staff which accounts or files they should avoid, identifies the temporary workflow and names the person handling questions. It should also warn against speculation on social media or in client conversations.
If someone receives a call or email about the incident, they should record the caller’s name, organisation, contact information and request. They should avoid guessing or promising a response time. Route the message to the named incident lead.
For clients, plain language is best. Explain any service impact, the temporary contact method and the next update time. Share confirmed facts. If there is no reason to believe client data was exposed, do not imply that it was.
Rebuild Access With Fewer Single Points of Failure
The replacement laptop should not recreate the same risk. Give every critical service at least two controlled recovery paths. This might mean two trusted administrators, securely stored recovery codes and a business-owned email address that does not depend on one founder’s personal account.
Use a password manager with business recovery features. Encrypt laptops and mobile devices. Turn on automatic screen locking and install system updates. Keep an asset list with the device serial number, assigned user and encryption status.
Separate personal and business profiles. A founder who uses one browser profile for family email, banking, client work and website administration makes both recovery and investigation harder.
Review permissions while rebuilding. Former contractors, unused integrations and duplicate administrator accounts can be removed. The incident creates a reason to clean access that grew casually over time.
Write the One-Page Plan Now
Your finished plan should fit on one page and remain available away from the primary laptop.
Include the following in your plan:
● The incident lead and backup decision-maker
● The order for securing critical accounts
● Backup locations and restoration owner
● Device, insurer and technical-support details
● Legal and regulatory contacts
● A staff message template
● The five business tasks that must continue
Test the plan twice a year. Ask one team member to pretend the founder’s laptop is unavailable and recover a harmless sample folder, enter the website dashboard and locate the account-recovery codes. A plan that only one person can follow still depends on one person.
Also print a contact card for the person who may discover the incident first. Include the incident lead, technical support, insurer, lawyer and the place where the offline plan is stored. Keep one copy at the office and one with a manager. A response plan is useful only if somebody can find it while the device is unavailable.
The first hour after a laptop disappears should feel procedural. Secure access, preserve records, keep essential work moving and get the right advice for the cause. That sequence turns a missing device from a company-wide panic into a problem the business already knows how to handle.










