Hey everyone,
I was doing some late-night reading on incident response frameworks and stumbled across this documentation on building a Data Neutralization Strategy.
It got me thinking, are we all just relying way too heavily on the basic remote wipe command when a device goes missing?
I manage a fleet of about 400 devices (a messy mix of corporate-owned and BYOD). My current strategy for a lost device is basically just panicking, hitting the wipe command from our MDM, and praying it connects to the internet before the thief gets into the local files. But the article talks about neutralization as a layered framework rather than just a single action.
How are you guys handling this in the wild? What happens if the device is immediately thrown into airplane mode or a Faraday bag? I want to build a strategy that doesn’t just rely on an all-or-nothing wipe command.