Immediate actions.
IMMEDIATELY
Wipe it remotely, if possible Report it, if stolen
THEN, FROM A CLEAN DEVICE
Change the password on every account it accessed Start with email End all active sessions on those accounts
SECOND FACTOR
If the device held your authentication application, reset two-factor on affected accounts using your recovery codes
THAT IS WHY THEY ARE STORED SEPARATELY
ACCOUNTS TO PRIORITISE
Email Banking and payments Domain registrar and hosting Anything holding customer data
THEN
Remove the device from trusted-device lists Check for activity you did not perform Check for rules or changes made
IF IT HELD BUSINESS DATA
Establish what, and whether obligations follow.
Take advice if personal data was involved.
RECORD
What happened, when, and what you did.
AFTERWARDS
Review whether encryption and locks were enabled.
If they were, the position is far better than if not.