C.W.K.
Stream
Lesson 02 of 05 · published

The Lost-Phone Playbook — First 10 Minutes

~15 min · lost-phone, incident-response, drill

Level 0Greenhorn
0 XP0/53 lessons0/14 achievements
0/100 XP to next level100 XP to go0% complete

Practice this once when nothing is wrong. Drilled, it is a 5-minute drill. Improvised, it is a 2-hour scramble while the threat clock ticks.

The sequence

MinuteActionWhy first
0–1Open laptop, navigate to your bookmarked admin page, click "Revoke All"Cuts every cookie session immediately; cheapest broadest defense
1–2Tailscale admin: find the phone, click "Remove"Phone falls out of the mesh; even SSH (if it had it) stops working
2–4Find My iPhone / Find My Device: lock the phone (don't wipe yet)Lockscreen reduces opportunistic access; wipe eliminates evidence/recovery options
4–61Password / Bitwarden admin: lock all sessions, review autofill eventsVault was the one thing that could log into everything else
6–8Email: revoke any "logged in here" sessions; rotate any password reset email if access is suspectedEmail is the recovery channel for everything else; it's the crown jewel
8–10Critical accounts: GitHub, hosting provider, banking — force re-auth or rotate tokensThese are the ones with real blast radius if compromised

What NOT to do

  • Don't immediately wipe. A wiped phone is unrecoverable for forensics ("what did they actually access before lock?"). Lock first, decide on wipe after.
  • Don't tweet about it from the laptop you just used to revoke. If the attacker is monitoring your social, you've told them the window.
  • Don't change the PIN to something easier "so I can log back in". The PIN is fine; the sessions were the problem.

External links

Exercise

Run the drill: pretend your phone is gone right now. Walk through the 10-minute playbook from start to finish, on a stopwatch. Note where you stumble (logging into Tailscale admin without your phone? Find My slow to load? 1Password 2FA on the phone you 'lost'?). Each stumble is a thing to pre-stage in the next lesson.

Progress

Progress is local-only — sign in to sync across devices.
Spotted a bug or have feedback on this page?Report an Issue

Comments 0

🔔 Reply notifications (sign in)
Sign inPlease sign in to comment.

No comments yet — be the first.