Problem overview
Reacting to a lost or stolen device can often happen too late. This automation helps IT teams proactively plan for such scenarios, ensuring sensitive data stays protected while gathering valuable device intelligence.
This automation is a cross-platform solution designed for Windows, macOS, and Linux devices. It can be triggered manually or by applying a “Lost” or “Stolen” tag to the device in Level. Upon activation, the automation gathers key intelligence such as device location, ARP tables, and other critical data points.
Once intel is collected, the automation pauses and waits for approval before proceeding to the next phase. With approval, the device initiates a secure erase process, removing as much data as possible before attempting a system restart.
Use cases
- Mitigating the risk of data breaches from lost or stolen devices.
- Ensuring compliance with data protection regulations by securely wiping devices.
- Proactively managing device security for a remote or distributed workforce.
Recommendations
- Best Practices: Test this automation in a controlled environment to understand its execution fully.
- Getting Started: Tag a test device with “Lost” or “Stolen” to see how the automation gathers intel.
- Testing Instructions: Use non-production devices for initial testing to prevent accidental data loss.
- Required Changes: Customize the intel-gathering scripts to align with your organization’s specific needs.