A work Mac is missing. What should you do first?
A calm first-response guide for a missing work Mac: report it, check available controls, review account access and preserve useful records.

What should I do if a work Mac is lost or stolen?
Tell the person responsible for security immediately and record when and where the Mac was last seen. Use your approved lost-device process, including Apple’s Find My options if they were enabled. Review account access from a trusted device and preserve the facts needed to assess what company or client information may be affected.
Make the first message useful
You reach the office and the laptop bag is not with you. The first useful action is to tell the right person, even while you check where it might be. Do not wait until the end of the day to avoid embarrassment. Early information gives the business more time to protect access and help you recover.
Share the device identity, last known location, approximate time and whether it was locked, asleep or in use. Name the client projects and important accounts you were working with. Keep the account factual. “The Mac was locked when I left the train” is more useful than “I think everything should be fine”. Record what remains uncertain.
Use the controls already set up
Apple’s Find My can help locate or protect a missing Mac when the required setup was in place beforehand. Follow Apple’s current instructions and your company’s approved process. If company device management provides additional controls, let the authorised person use them. Do not assume a missing device is online or that a remote action has completed.
Treat a command being requested and a command being confirmed as different states. Before an irreversible erase, consider recovery, evidence and company policy with the responsible person. If theft is suspected, use the relevant police reporting route; do not attempt to recover the device from someone yourself. Keep the serial number and report reference available.
Keep the first response orderly
- Report
Who, which Mac, when and where?
- Protect
Use approved device and account controls.
- Assess
Record evidence, decisions and confirmations.
Example workflow.
Review the access the Mac carried
From a trusted device, identify the accounts, sessions and credentials that may need attention. Prioritise business email, administrative access and sensitive client services. Use each provider’s process for ending sessions or changing access. Do not assume changing one password signs the missing Mac out of every service or cancels every separate API key.
For a developer or AI-heavy team, include tools connected to repositories, deployments and external services. Identify which credentials were stored or usable on the missing device without copying their values into incident notes. Follow the incident owner’s decisions about revocation and replacement, and check whether changes affect scheduled work or other people using shared access.
Separate protection facts from conclusions
A recent record of FileVault and screen-lock settings can help establish what was enabled on an assessed Mac. It cannot prove that nobody saw an unlocked screen, accessed a live session or copied information before the loss. Keep the device’s last observed state and its observation time together, especially if it has been offline.
Work out what information may be involved and which clients or other parties need to be consulted under your agreements and applicable requirements. Use appropriate incident or legal advice where needed. Avoid announcing either a confirmed breach or “no risk” before the facts support it. Keep a timeline of reports, decisions, actions and confirmations.
Use the incident to improve the ordinary routine
Once the immediate situation is handled, restore work from a trusted backup or replacement device through your normal process. Check what made the response easier and what was missing: current device records, recovery information, a contact route or a tested backup. Give each improvement an owner so it becomes part of the business rather than a forgotten lesson.
Cybee’s device records show the last assessed security state. Its training prepares people to report a lost Mac. It is not a substitute for Apple’s location service or your backup system. Keep those responsibilities distinct. The best time to agree who does what is before the next bag goes missing.
What to remember
- Report early and record facts, including what is uncertain.
- Verify remote actions and review accounts separately.
- A previous security record informs the assessment; it does not prove no data was accessed.
Sources and further reading
Product scope and provider guidance can change. Check the linked source for your own setup.
Put it to work.
Continue with a practical guide or see how cybee helps with the work.