When a work laptop is left in a taxi or a phone is lifted from a bag, the first reaction is usually about the money: the cost of replacing the hardware. That is the smallest part of what has actually been lost. A modern work device is a key to a business's data and accounts - the files stored on it, the email logged in on it, the saved passwords, the access to cloud systems that stays connected in the background. Whoever ends up with the device potentially ends up with all of that. The right way to think about a lost or stolen device is not as a hardware expense but as a possible data breach, and how bad a breach it becomes depends almost entirely on decisions made before it went missing.
The exposure is broad because devices accumulate access. A laptop holds documents that may include customer details, financial records, contracts and internal information. Browsers and apps stay logged in, so the person holding the device may reach email, banking, and business systems without needing to know a single password. Saved credentials can unlock still more. For a small business this is exactly the kind of data whose exposure causes real harm - to customers whose information it holds, to the business's obligations under data-protection rules, and to its reputation. A single misplaced device can put more sensitive information at risk than most owners realise is sitting on it, precisely because it is convenient for it to be there.
The two protections that change the outcome are both things you switch on ahead of time and then forget about. The first is device encryption, which scrambles the contents of the storage so that they are unreadable without the login - meaning that a thief who has the physical device still cannot get at the data on it. Modern computers and phones offer this and it is often available at no cost; the difference it makes is the difference between a lost gadget and a lost filing cabinet full of records. The second is the ability to remotely lock or erase a device that has gone missing, so that even the access it carries can be cut off from a distance once you know it is gone. Together they turn a stolen device from an emergency into an expensive nuisance.
The practical posture is to assume any portable device will eventually be lost or stolen and to prepare for that as a certainty rather than a possibility. That means encryption switched on for every device that touches business data, a screen lock that actually engages, remote-wipe capability set up before it is needed rather than scrambled for afterwards, and not storing more sensitive data on portable devices than the work genuinely requires. It also means having a plan for what to do in the first hour after a device disappears - which accounts to secure, what to wipe - so the response is quick rather than paralysed. Handled this way, losing a laptop costs the price of a laptop. Handled carelessly, it can cost far more than the business ever spent on the device in the first place.