How to Secure Company Laptops When Employees Leave

How to Secure Company Laptops When Employees Leave

How do you secure company laptops when employees leave? Do it in the right order, and do it before the goodbye party. The classic failure isn't the exit itself — it's the gap between exit and device return. A software company client once heard "it's in my car" from a departing senior developer for nine weeks. When the laptop finally came back, the drive had been factory-reset, and credentials that had been stored on it had already been used to log into the development environment. The lesson cost them a scramble with the client whose code sat on that machine. Here is the sequence I walk clients through.

How to secure company laptops when employees leave: order matters

Revoke before you collect. Credential revocation — cloud apps, VPN, email, development environments — happens the moment departure is confirmed, not when the device arrives. The laptop is secondary: a device with dead credentials is a box of parts; a device with live credentials is a remote-control session for a departing employee. In the developer's case, the nine-week delay wouldn't have mattered if the account had been closed on day one.

The device collection process

Assign one owner per device, and make collection a tracked step, not a hope. At a client in financial services, unreturned devices were 30 percent of their asset list at any given time — until the process changed: the exit checklist now includes a device-return confirmation with a date, and the manager signs off before final pay is processed. Unreturned devices went from a quiet norm to an exception that someone owns.

Remote wipe is the backstop, not the plan

Remote wipe protects you when collection fails, but it erases evidence and data you might need. Sequence it carefully: back up what the company needs first, preserve logs for legal, then wipe. And wipe the right thing — one client erased a departed employee's machine only to realize the backup had been configured to that same device. Test your backup-and-wipe flow quarterly with a sacrificial device.

Wipe properly before redeployment

A factory reset is not a secure wipe. Use the platform's verified erase: Windows recovery reset with data erasure, or FileVault rekeying on Mac — and never redeploy a device that still has a user profile on it. A client found a predecessor employee's personal files and a saved password vault on a "cleaned" laptop being issued to a new hire. Secure erase before redeployment is a compliance event in its own right.

Track the asset, not just the exit

The asset inventory should be the single source of truth: who holds which serial number, when it was assigned, when it's due back. When a laptop doesn't return, the inventory tells you before the department does. Pair it with the departure list: every termination triggers a device check-in ticket automatically. One client closed a three-year hole this way — 40 devices returned that had been written off as lost.

The manager's checklist

The weakest link in laptop recovery is usually the manager, not the IT team. A client's managers forgot to chase devices because nobody told them it was their job. Give each manager a one-page exit checklist: confirm access revoked, set a device return date, verify the data handover, sign off before final pay. The client's return rate went from 70 percent to 96 percent in two quarters after a half-day training and a laminated checklist on every manager's wall. The process only works when the people closest to the departure own a step.

The small print that matters

Put the return obligation in writing in the employee handbook, define a grace period, and decide in advance what happens with expenses and final pay if a device isn't returned. The policy shouldn't be punitive; it should be predictable. Predictable policies are enforceable, and enforceable policies get devices back.

Handover: don't let the data die with the departure

Before wiping, confirm the handover: the departing employee's working files reviewed, transferred, and acknowledged by the successor. One client lost two weeks of project work because the file transfer was assumed rather than verified. A fifteen-minute handover checklist saves the company from both directions of failure — leaked data on one side, lost data on the other.

How many company laptops are currently unaccounted for at your company — and on which of them do live credentials still exist? If you can't answer in one screen, your exit process has a hole. For visibility into what happens on those machines before they come back, WorkAuditor is cloud-based employee monitoring software for Windows and Mac that logs file and application activity. Find out more at https://www.workauditor.com.