When an executive phone goes missing, the first objective is containment—not immediate erasure. Confirm the device and account, use the official locate-and-lock service, notify the corporate security route, contact the carrier, protect high-value identities and preserve evidence. Erase only when recovery is unlikely or policy requires it, because erasure can end location visibility and destroy useful evidence.
Do not confront a suspected thief. If a location appears unsafe, give it to law enforcement or venue security.
The 30-minute runbook
| Time | Action | Purpose | Evidence to retain |
|---|---|---|---|
| 0–3 min | Reconstruct last confirmed use; call once if appropriate | Distinguish misplaced from likely stolen | Time, place, route, witnesses |
| 3–7 min | Use Apple Find My or Android Find Hub from a trusted device | Locate, ring and mark lost/lock | Screenshot of status and location time |
| 7–10 min | Notify corporate IT/security and venue | Trigger managed-device and physical recovery processes | Incident/ticket number |
| 10–15 min | Contact carrier; protect number and SIM/eSIM | Reduce account and port-out risk | Case number and representative |
| 15–20 min | Suspend payments and review high-value accounts | Contain financial and identity exposure | Actions and timestamps |
| 20–25 min | Revoke sessions or change credentials in risk order | Stop active access without creating lockout chaos | Account action log |
| 25–30 min | Decide recover/hold/erase with IT or policy | Preserve recovery when reasonable; erase when necessary | Decision owner and rationale |
Minute 0–3: establish facts
Use another device to call the phone once if that is safe and appropriate. Check the last physical handover: aircraft seat, security tray, car, meeting room, restaurant or hotel safe. Ask a companion to retrace the route while one person controls the digital response.
Record the device model, phone number, serial/IMEI if available, case description and last confirmed time. Do not publish the full identifier or location on social media.
Minute 3–7: locate and lock
Apple’s Find My guidance lets owners locate a device and use Lost Mode. Apple explains that Lost Mode can display a contact message and suspend applicable payment cards. It must have been enabled before loss.
Google’s Find Hub instructions allow owners to find, mark lost, secure or erase supported Android devices. Google notes that erasing permanently deletes device data and location will no longer be available in Find Hub.
Use only the official domain or app. A phishing message claiming “your lost phone was found” may try to steal the account password and remove activation protections. Do not follow a link from an unsolicited SMS; navigate independently.
Add a neutral recovery message with an alternate contact that does not expose the owner’s role, itinerary or home address. Keep the device associated with the account while recovery remains realistic.
Minute 7–10: trigger organisational response
For a managed phone, corporate security or IT can assess mobile-device-management status, revoke work tokens, mark the device non-compliant and preserve logs. The executive should not improvise around this process.
Notify venue security or the airline with the exact location and time. Obtain a case number. If theft is likely, make a police report according to local requirements and insurer instructions.
Minute 10–15: protect the telephone number
The number may receive calls, messages and account-recovery codes. Contact the carrier through its official support channel. Ask it to suspend or transfer service safely and apply account protections against unauthorised SIM change or number porting.
Do not cancel the number blindly if the locate service or recovery process depends on connectivity. Coordinate carrier action with IT and the device platform. The correct sequence varies by device, eSIM/SIM configuration and threat.
Google recommends setting a SIM PIN before loss and documents theft-protection features in its Android data-theft guidance. Preparation is part of the response: recovery codes and a second trusted device should exist before travel.
Minute 15–20: payments and identity
Check mobile wallets, banking apps, corporate approvals, password managers, authenticator apps, email and messaging. Suspend cards through the wallet or issuer when required. Look for alerts showing attempted sign-in, password reset, SIM change or payment.
Prioritise the accounts that can reset other accounts: primary email, identity provider, password manager and carrier. Then protect finance, corporate systems and messaging. Avoid changing every password at once without a plan; you can lock yourself out and destroy the clean recovery route.
Minute 20–25: revoke sessions in order
From a trusted device, inspect active sessions and sign out the missing phone where the platform allows. For a Google account, the company provides lost-device account steps, including sign-out and password actions.
Use an incident log:
exact UTC/local time;
account or service;
action taken;
confirmation/reference;
person responsible;
follow-up required.
This avoids duplicate changes and supports later investigation.
Minute 25–30: decide whether to erase
Remote erase is appropriate when policy requires it, sensitive data exposure is unacceptable or recovery is no longer realistic. It may remove the ability to locate the device. Discuss the decision with corporate security where possible and document who authorised it.
If the phone is merely in an aircraft seat pocket and the airline has confirmed possession, keeping Lost Mode active may be more useful than erasing. If the device is moving through an unfamiliar location after theft, containment may outweigh recovery.
Preparation card for the travel wallet
Before the next trip, keep a secure offline record of:
official Find My/Find Hub access route;
device serial/IMEI and insurer reference;
carrier fraud/loss number;
corporate security contact;
recovery codes stored separately;
payment issuer contacts;
approved spare-device procedure.
Never store the account password beside this card. The goal is resilient access, not a complete compromise kit.
For authentication resilience, use the passkey, authenticator and hardware-key travel plan. For broader confidential-device selection, see the business-phone decision framework.
The operating principle
Locate and lock first, escalate early, protect the number and identity, then erase by policy and evidence. A calm thirty-minute sequence preserves more options than a panicked password spree—and gives the organisation a record of what happened.
Within 24 hours, reconcile the incident: confirm the final device state, review account alerts, replace or recover the SIM safely, update the asset register, notify the insurer if required and preserve the timeline. If the phone returns, do not resume normal use immediately; have the organisation or owner check for unexpected configuration, account and physical changes first.




