A lost or stolen phone is stressful at the best of times. When it is a work phone with access to email, files and customer data, it can quickly become a serious data protection incident. The difference between a minor inconvenience and a reportable breach almost always comes down to how prepared you were before it happened. This guide gives you the action plan for the moment one goes missing - and the preparation that makes that moment a non-event.
The immediate action plan
If a work phone goes missing, work through these steps in order. Speed matters - the goal is to close off access before a thief or finder can reach anything.
- Lock or wipe it remotely. If you have Mobile Device Management (MDM), you can lock the device or erase company data instantly from a dashboard. This is the single most important control. Lock first if there is any chance of recovery; wipe if the data risk outweighs the handset.
- Suspend the SIM. Call your provider (or do it through your management portal) to suspend the SIM, preventing call and data fraud and stopping any premium-rate or international abuse on your account.
- Change critical passwords. Reset passwords for accounts the device could reach - starting with email, then any single sign-on or password manager that was unlocked on it.
- Revoke the device's sessions. In Microsoft 365 or your identity system, sign the device out of all active sessions and remove its access, so a saved login cannot be reused.
- Report it. Notify your provider, report the theft to the police if relevant (you will get a crime reference number, useful for insurance), and log it internally.
- Assess the data exposure. Work out exactly what data was reachable and whether it was protected. This determines whether you have a reportable incident.
Keep this list somewhere staff and managers can find it under pressure - ideally inside your company mobile phone policy - so nobody is improvising during the one moment it matters.
A worked example
A field engineer realises at 4pm that their work phone is gone, last seen at a customer site. Because the business runs MDM with enforced encryption and a six-digit passcode:
- At 4:05pm the line manager locks the device remotely and triggers a wipe of the work container.
- At 4:10pm IT revokes the device's Microsoft 365 sessions and suspends the SIM.
- By 4:20pm the engineer has a crime reference number and the loss is logged.
- The data assessment concludes the device was encrypted, passcode-locked and wiped before any access was possible.
Outcome: a replacement handset is provisioned the next morning, the work line is re-enabled to a new device, and there is a documented basis for concluding the risk to individuals was minimal. The same event on an unmanaged, unencrypted phone would have meant a frantic password reset across every system and a genuine question over whether the ICO needed to be told.
When is it a reportable data breach?
Under UK GDPR, if personal data was accessible on the device and you cannot confirm it is safe, you may have to notify the ICO without undue delay and within 72 hours of becoming aware. You must also keep an internal record of the incident even if it is not reportable.
This is exactly why encryption plus remote wipe is so valuable. If you can demonstrate the data was encrypted, the device was locked, and the company data was erased before anyone could access it, the risk to individuals is low - which usually means no notification is required, and in any case a far stronger position if questions are ever asked. Preparation does not just speed up your response; it changes the legal outcome.
Why preparation beats panic
Without preparation, your response is frantic and uncertain - and you may never be sure whether data was exposed. With the right setup, it is calm, quick and defensible:
- Encryption means the data is unreadable without the passcode, even if the storage is removed.
- A strong passcode or biometric lock buys you time and blocks casual access.
- MDM lets you lock or wipe remotely in seconds, from anywhere.
- A documented process means everyone - not just IT - knows exactly what to do.
- An accurate device inventory means you know whose phone it is, what it could reach and what to revoke.
These are the same fundamentals we cover in our mobile security best practices.
Lost vs stolen: does it matter?
For your data-protection response, treat both the same - assume the worst and act immediately. The practical differences are around recovery and reporting: a stolen device warrants a police report and crime reference for insurance and for demonstrating you took it seriously, while a device merely mislaid in the office may be recoverable, so locking (rather than immediately wiping) can be the first move. Either way, the clock on your breach assessment starts the moment you become aware.
Prevention checklist
The best time to prepare for a lost phone is long before one goes missing:
- Enforce device locks and encryption on every work phone, company-owned or BYOD.
- Deploy MDM across the whole fleet so remote lock and wipe is always available.
- Keep an up-to-date inventory of who has which device and what it can access.
- Use conditional access so only enrolled, compliant devices can reach company systems.
- Train staff to report a loss immediately - the first hour is when access can be closed off cleanly.
- Write the action plan into your company mobile phone policy and rehearse it.
Much of this is easier to get right from the start when you buy through a business provider on a managed plan - a point we make in our comparison of the best mobile network for business, where account support and management tooling matter as much as coverage. Get a business mobile quote and we will make sure your fleet arrives secured and ready to manage.
Be ready before it happens
The businesses that handle a lost phone calmly are simply the ones that set it up properly in advance. Our Mobile Products service puts the security and management in place so a lost handset stays a minor event rather than a reportable breach. Get a business mobile quote to protect your business before you need to.
Frequently asked questions
What should I do if a work phone is lost or stolen?
Act fast: remotely lock or wipe the device, suspend the SIM, change critical passwords, revoke its sessions in your identity system, report it to your provider and the police if relevant, and assess exactly what data was exposed. The faster you close off access, the smaller the incident.
Is a lost work phone a data breach?
It can be. Under UK GDPR, if personal data was accessible and you cannot confirm it is safe, you may have to report it to the ICO within 72 hours and must record it internally regardless. If the device was encrypted, locked and wiped before access, the risk - and usually the reporting obligation - is far lower.
How quickly do I have to report a lost-phone data breach?
If it is reportable, you must notify the ICO without undue delay and within 72 hours of becoming aware. That short window is exactly why a prepared, documented response with remote wipe matters so much - you cannot improvise it after the fact.
Can I wipe a lost phone remotely?
Yes, if the device is enrolled in MDM. You can lock it or erase the company data from a dashboard in seconds, from anywhere. On a BYOD device, MDM wipes only the work container, leaving the owner's personal data intact.
How can I prepare for lost or stolen phones?
Enforce device locks and encryption, deploy MDM for remote lock and wipe across the whole fleet, keep an accurate device inventory, use conditional access, and train staff to report losses immediately. Then write it all into your phone policy so the response is automatic.
What if the lost phone was a personal (BYOD) device?
The same urgency applies, because your company data is still on it. With MDM and a BYOD policy in place, you remotely remove the work container and revoke access without touching the owner's personal content - which is why unmanaged BYOD is so risky in this scenario.
Should I report a stolen work phone to the police?
Yes, for a theft - you will get a crime reference number useful for insurance and for demonstrating you treated the incident properly. For a device simply mislaid, focus first on locking and assessing data exposure, and report if it does not turn up.
