---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Lost Equipment workflow template

# Security Incident Lost Equipment workflow template {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The Security Incident - Lost Equipment - Template allows you to perform a series of
tasks designed to handle lost equipment.

## Before you begin

Role required: sn_si.write

## About this task

The workflow is triggered when the Category in a security
incident is set to Equipment loss. This action causes a
response task to be created for the first activity in the workflow.
Figure 1. Equipment loss

## Procedure

1. Open the security incident for the equipment loss, or [create a new security incident](https://servicenow-prod.fluidtopics.net/hRLl9dw7~RuP3HDYtHJlEg "In addition to automatic methods for creating security incidents, you can create them manually, as needed.").
2. In Category, select Equipment loss.
3. Save the record.
4. Scroll down and open the Response Tasks related list.  
   The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the flow to end.{#si-lost-equip-template__table_s33_4ls_kbb__entry__3}

   | Response task | Action | Results |
   |-|-|-|
   | Did the equipment contain sensitive data? | Determine whether the equipment associated with this security incident contained any sensitive or confidential information. In the task, select Yes or No in Outcome as appropriate. | If you select Yes the Was the data encrypted? task is executed. If you select No, the flow ends. |
   | Was the data encrypted? | Determine if the sensitive data on the lost device was encrypted. In the task, select Yes or No in Outcome as appropriate. | If you select Yes, the Remote wipe created? response task is executed. If you select No, the Create potential data loss incidentresponse task is executed. |
   | Create potential data loss incident | Perform the steps necessary to create a potential data loss incident. After you have finished, set the state of the task to Complete or Incomplete as appropriate. | The Remote wipe created? response task is executed. |
   | Remote wipe created? | Perform the steps necessary to execute a remote wipe of the lost equipment. In the task, select Yes or No in Outcome as appropriate. | The Legal process - Disclosure required task is executed . |
   | Legal process - Disclosure required? | Perform the steps to satisfy the legal requirements of this analysis. Select Yes if a legal disclosure is required, Noif it is not. | The Lessons learned meeting task is executed. |
   | PR process | Perform the steps necessary to satisfy the PR requirements of this analysis. After you have finished, set the state of the task to Complete or Incomplete as appropriate. | The Set state to review task is executed. |
   | Set state to review | No action is necessary. | The State of the security incident is changed automatically to Review. |
   | Lessons learned meeting | Conduct a lessons learned meeting to triage the work performed for this lost equipment incident. After you have finished, set the state of the task to Complete or Incomplete as appropriate. | The flow ends. |
   [Table 1. Response tasks in Lost Equipment Template]

   {#si-lost-equip-template__table_s33_4ls_kbb}
**Related tasks**   

* [Security Incident Confidential Data Exposure workflow template](https://servicenow-prod.fluidtopics.net/nFKIzAO87NmEaSmbOlfnBg "The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.")
* [Security Incident Denial of Service workflow template](https://servicenow-prod.fluidtopics.net/sSSFVstKld_nT4PbN6Uzjg "The Security Incident - Denial of Service - Template allows you to perform a series of tasks designed to handle Denial of Service (DOS) attacks.")
* [Security Incident Malicious Software workflow template](https://servicenow-prod.fluidtopics.net/_VPjlhZMzho3MBg~FSE80g "The Security Incident - Malicious Software - Template allows you to perform a series of tasks designed to handle malicious software on your network.")
* [Security Incident Phishing workflow template](https://servicenow-prod.fluidtopics.net/e_fMyDIGgjuYycuEtZKEoQ "The Security Incident - Phishing - Template allows you to perform a series of tasks designed to handle spear phishing emails on your network.")
* [Security Incident Policy Violation workflow template](https://servicenow-prod.fluidtopics.net/jj5HhCQ9g6WokjWDIbe7KA "The Security Incident - Policy Violation - Template allows you to perform a series of tasks designed to handle security policy violations.")
* [Security Incident Reconnaissance workflow template](https://servicenow-prod.fluidtopics.net/p70N3CfQJ5HFRTywU7oo5w "Reconnaissance is usually a preliminary step toward a further attack seeking to exploit a device or system. The Security Incident - Reconnaissance - Template allows you to perform a series of tasks designed to handle reconnaissance on your network.")
* [Security Incident Rogue Server or Service workflow template](https://servicenow-prod.fluidtopics.net/hM7_g1Qwyg8kNe8Np56Yqw "The Security Incident - Rogue Server or Service - Template allows you to perform a series of tasks designed to handle activity from rogue servers or services affecting your network.")
* [Security Incident Spam workflow template](https://servicenow-prod.fluidtopics.net/DxsjNHaxoerxIv4_~sTNyg "The Security Incident - Spam - Template allows you to perform a series of tasks designed to handle email spam on your network.")
* [Security Incident Unauthorized Access workflow template](https://servicenow-prod.fluidtopics.net/NFoUZQBaMzTmVEgwQDQ14w "The Security Incident - Unauthorized Access - Template allows you to perform a series of tasks designed to handle unauthorized access to your network.")
* [Security Incident Web/BBS Defacement workflow template](https://servicenow-prod.fluidtopics.net/UoGVdQA3r7wkoF40RpZgBw "The Security Incident - Web/BBS Defacement - Template allows you to perform a series of tasks designed to handle vandalism directed against one of your organization's BBS or web sites.")

