Administration
I lost my phone with the session open
What to do in the first ten minutes, and in what order.
A lost phone or laptop with an open session is not a catastrophe if you act fast, and very much is if it waits until Monday. These are the steps, in the order that matters.
The first ten minutes
- 1
Close that device's session
From somewhere else. First, because it cuts access instantly.
- 2
Change the password
If the device had it saved, closing the session is not enough.
- 3
Check the second factor
If the lost phone **was** the second factor, replace it before anything else.
- 4
And tell an administrator
Even if it is your own phone: some decisions are not yours to take.
Important
The third step trips many people up. If the lost phone was also the one receiving codes, changing the password without solving that can lock you out of your own account. That is why it is checked before touching anything else.
Afterwards, calmly
| What | What for |
|---|---|
| Review the last few hours of activity | To know whether anyone got in, and to what |
| Check the device list | Remove any you no longer use |
| Check the associated email account | It is the back door to almost everything |
| And decide whether anyone else must be told | If third-party data was accessed, there may be an obligation |
Watch out
The last row is not theoretical. If someone accessed documentation containing third-party personal data, assessing whether to notify has short deadlines. That decision is not taken by whoever lost the phone: it is taken by an administrator, which is why the internal alert is step four and not the last.
What stops it being serious
With those four, a lost phone is a problem of replacing a phone, not a security problem.
Worth knowing
Everything done from that device is in the activity log, with timestamps. That is what lets you answer afterwards what was actually seen, instead of assuming the worst or the best.
›Do I lose my work if I close the session?
No: what was uploaded and signed lives in the organisation, not on the phone.
›What if it turns up the next day?
You log in as normal. Closing the session breaks nothing.
›Must I report it if nothing sensitive was there?
Report it anyway; an administrator decides, and that decision is best recorded.
A real case
The situation
Someone loses their work phone on a Friday afternoon with the session open.
What you do
- Closes that device's session from a computer
- Checks the second factor did not depend on the lost phone
- Tells the administrator
What you get
Access is cut within minutes and activity is reviewed calmly on Monday.
The situation
A phone is lost with the session open.
What you do
- Closes the sessions from another device
What you get
Access is cut within minutes.
The situation
The second factor was on that phone.
What you do
- Recovers access with the administrator
What you get
The account comes back without switching security off.
The situation
Reporting is delayed out of embarrassment.
What you do
- Reports it as soon as it happens
What you get
The risk window closes sooner.
The situation
Nobody knows what could have been seen from that phone.
What you do
- Checks that session's log
What you get
The scope becomes known.
The situation
The phone is recovered and the matter is considered closed.
What you do
- Changes the credentials anyway
What you get
The risk does not stay open.
This article answers
- lost my phone with my account logged in
- work laptop stolen
- log out of a lost device
- what to do if i lose my work phone