CYBER WELFARE

Protect your Digital Privacy

Consequences of losing an unencrypted device

Losing a device is a common event. It happens on a train, in a taxi, at the gym, at an airport — and it happens to everybody, sooner or later.

What changes radically is not the event, but what it leads to. With encryption on, the consequence is the loss of an object. Without it, the consequence is everything that object held, for a length of time nobody can predict.

It expands on the recommendation encrypting your personal devices.

The two days compared

Before the categories, the concrete picture — because in this unit the difference is so stark that it is worth seeing whole.

The device was encrypted. You block the cards if there were any in the wallet, report the loss, use the device-finding function, and — if you do not get it back — wipe the data remotely for safety. You pick the work up again on another device from your backups. The inconvenience is replacing the hardware and a few lost hours.

The device was not encrypted. All of the above, plus: changing the passwords of every service with saved credentials; revoking the active sessions; checking the sign-ins of recent days; working out which documents were on it; telling the people whose data was on the device; and — in a professional setting — assessing the reporting obligations. The inconvenience lasts weeks, and an uncertainty remains that never closes.

The difference is not one of degree: it is one of kind.

1. The financial consequences

ItemWith encryptionWithout encryption
Replacing the deviceYesYes
Unsaved work lostLittle, if there is a backupLittle, if there is a backup
Fraudulent use of accountsNoPossible
Time to restoreHoursWeeks
Professional costsNonePossible

The row about time weighs most and nobody counts it: working out which services had saved credentials, changing them one by one, checking the sign-ins. That is days.

2. The professional consequences

Clients’ data

If the device held documents, correspondence or client data, the exposure concerns people who took no part in the choice.

In many professional contexts there are notification obligations with defined deadlines, triggered when third parties’ personal data turns out to be exposed. An encrypted device substantially changes the assessment, because the data is not reachable; an unencrypted one does not.

This is not legal advice — for that you need somebody qualified to give it — but it is the practical reason why many organisations require encryption on mobile devices: not to protect the employee, but to be able to say with certainty what happened.

Access to company systems

A work laptop typically holds credentials, certificates and active sessions towards the organisation’s systems. On an unencrypted device, whoever finds it has a way in.

The impossible reconstruction

The question that always arrives — “what exactly was on that device?” — almost never has a precise answer. Nobody keeps an inventory of what is on their computer.

With encryption the question does not arise. Without it, the absence of an answer is itself a problem, because it prevents a perimeter being stated.

3. The relational consequences

The people whose data was on the device. Contacts, photos, conversations, shared documents: they concern family, friends, colleagues. They have to be told, and it is a difficult conversation because there is nothing they can do.

Personal photos. It is the aspect people fear most, often more than the financial loss. An unencrypted device exposes the whole photo archive.

Other people’s correspondence. The messages received contain other people’s words, said in confidence.

4. The psychological consequences

They are particularly marked here, and worth recognising.

The intrusion into private life. A personal device holds a person’s life in concentrated form. Knowing somebody could scroll through it produces discomfort out of proportion to the financial damage, and it is entirely legitimate.

Uncertainty with no end. You will never know whether the device was simply resold — the likeliest outcome — or whether somebody looked through its content. That question has no answer, and it is the most wearing part.

Guilt. “I should have turned it on.” It is worth being clear: on computers encryption is not on from the factory, and nobody says so at the point of purchase. Not having turned on something you did not know you had to turn on is not negligence.

What helps. The concrete actions: remote wiping, changing credentials, checking sign-ins. They give back control in a situation that takes a great deal of it away.

And, for the future, checking the other devices — which is how an unpleasant episode produces at least one benefit.

What to do if it has already happened

In order, and without waiting.

  1. Use the device-finding function. Every main system offers one, and it also allows the device to be locked and a message shown.
  2. Report the loss if it happened somewhere with a lost property service, and report the theft if it was one.
  3. Change your main email’s password, which is the recovery key to everything else.
  4. Revoke the active sessions on every main service: it is what closes the already authenticated access.
  5. Change the credentials saved in the browser, starting with financial services.
  6. Wipe the data remotely once it is clear the device is not coming back.
  7. Tell the people involved, personally and professionally.
  8. Check the sign-ins over the following days, with alerts on.
  9. Block the SIM with your operator, if the device held one: it can be used to receive verification codes.
  10. Mark the device as lost in the list of devices linked to your accounts: some services allow it to be flagged, revoking every future access.

Point 4 is the one most often skipped and it counts for more than changing the password: active sessions keep working even after the password has been changed, on many services.

Which consequences close and which do not

ConsequenceCan it be closed?
Active sessions on the lost deviceYes, by revoking them
Future access to accountsYes, by changing the credentials
Data on the deviceYes, with a remote wipe — if it is reachable
The device itselfReplaceable
Documents already copiedNo
Personal photos seenNo
Third parties’ data exposedNo, but it has to be communicated
The uncertainty about what happenedNo

The first four rows close within hours, and they are the only part where immediate action changes anything.

The others do not close. And here the difference with encryption is stark: with encryption on, the lower rows simply do not exist. There are no copied documents, no photos seen, no third parties’ data exposed — and so there is not even the uncertainty.

That is why, in this unit more than any other, the preventive measure does not reduce the damage: it removes it.

Why preparing beforehand pays

A lost device is a confused situation: you are away from home, you have little time, and you have often lost the very tool you would use to check things.

Three preparations that make that moment manageable:

The device-finding function on, across every device. It has to be enabled beforehand: afterwards it cannot be.

A second device or an alternative way in to your accounts. If the only way into your email is the phone you lost, the situation becomes far harder.

The second factor’s recovery codes, kept off the device. They are what allows you back into your accounts when the authenticator app was on the lost device.

The third point is what stops most people: the second factor protects, and if the factor was only on that device, it protects against you too.

Why this scenario concerns everybody

It is worth closing with a consideration setting this unit apart from the others in the series.

The other recommendations concern events that can happen: a compromised password, an unauthorised sign-in, a fake network. They are probable, but not certain.

Losing a device, by contrast, happens to almost everybody, sooner or later. It requires no adversary, it requires no particular mistake, it does not depend on skill. A moment of distraction on a busy day is enough.

EventDoes it need an adversary?Lifetime probability
A password compromised in a breachNoHigh
Successful phishingYesMedium
An unauthorised sign-inYesMedium
A device lost or stolenNoVery high

The last row is the only one where the event depends on nobody wanting to harm you. It is statistics, not threat.

And that changes how to look at the recommendation: it is not a defence against somebody, it is preparation for something that happens. Like leaving a copy of your house keys with a neighbour: it is not there to defend you from anybody, it is there because sooner or later you get locked out.

It is also why, of all the measures in Phase 1, this is the one with the best ratio of effort — five minutes, once — to the probability of actually being needed.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that the difference between the two scenarios is one of kind, not degree
SkillsKnowing the correct order of actions after a loss
Secure BehaviourChecking encryption before it is needed

Reference level: FL2 — Beginner.

Summary

  • With encryption the consequence is the loss of an object; without it, everything it held.
  • The most underestimated cost is time: weeks of checks and credential changes.
  • In a professional setting encryption changes the assessment of what has to be reported.
  • Revoking active sessions counts more than changing the password.

One thing to do today. Check now whether your computer is encrypted. It is the one action in this unit that has to be done beforehand and not afterwards — because afterwards it is of no use at all.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.