Case file · 2024 to 2025
A laptop was formatted on the way out. The firm couldn't remotely stop it.
Owning a laptop isn't the same as controlling what's on it. Here is how a data-loss incident during employee offboarding led to an endpoint-security evaluation, and the remote lock, wipe, and visibility controls that came out of it.
- Organization
- Jackson Etti & Edu (law firm), Lagos, Nigeria
- Role
- Head, Information Technology & Data Management
- Incident
- Departing employees, including a Senior Partner, formatted firm-issued laptops before leaving
- Gap exposed
- No remote ability to monitor, lock, or wipe corporate laptops once issued
- Evaluation criteria
- Visibility, control, and data protection
- Selected
- DriveStrike, for remote locate, lock, wipe, and encryption
- The incident
Employees leaving the firm, including a Senior Partner, formatted their firm-issued laptops before their departure. The action destroyed data stored locally on those devices and exposed a real gap in the firm's endpoint-security controls: at the time, the firm had limited ability to remotely monitor, secure, lock, or wipe a corporate laptop once it left the office. Recovering a device, and whatever was on it, depended on the physical laptop coming back and the departing employee's cooperation. The firm owned the device, but it didn't have technical control over the data on it, and that was the real risk.
- The investigation
I evaluated Mobile Device Management and endpoint-security solutions that could give the firm centralized control over its corporate work tools, against three requirements: visibility, knowing where managed devices were and keeping centralized oversight of them; control, the ability to remotely lock or secure a device the moment it became a security risk; and data protection, the ability to remotely wipe corporate data from a device that was lost, stolen, or compromised. DriveStrike matched all three: remote locate, lock, wipe, and encryption for managed devices, built to protect data when a device is lost, stolen, used outside the firm's control, or presents an insider-threat risk, including a departing employee who still has the laptop in hand.
- The solution
I introduced DriveStrike as part of the firm's endpoint-management and data-protection strategy. It gave IT a centralized layer of control over the firm's work tools, one it could act on remotely the moment a device became compromised or presented a data-security risk: a shift from a device-recovery approach to a device-and-data-protection one.
- The controls
- Centralized device visibility: the firm could locate managed devices and see their location history, giving IT ongoing awareness of where corporate laptops actually were.
- Remote lock: a lost, stolen, or compromised device could be locked remotely to block unauthorized access, including in the insider-threat and dismissed-employee scenarios DriveStrike specifically builds the feature for.
- Remote wipe: corporate data could be deleted remotely from a managed device, an additional layer of protection when a laptop couldn't be recovered or was considered compromised.
- Stronger offboarding: where a departing employee could previously format or otherwise manipulate a firm-issued laptop before it was recovered, IT could now retain administrative control over the device through the entire offboarding process, no longer dependent on that employee to protect what was on it.
- The result
The original incident exposed a real weakness: physical possession of a corporate laptop couldn't be treated as sufficient control over corporate data. Introducing DriveStrike closed that gap. Lost or stolen devices could now be acted on remotely instead of relying on recovery alone, offboarding became something IT controlled rather than something it hoped would go well, and the firm moved from a reactive posture on data loss to a proactive endpoint-security model, tying asset management, offboarding, and information security together as one system instead of three separate concerns.
What it shows
Treating a single data-loss incident as a systemic gap rather than a one-off: defining concrete evaluation criteria before choosing a vendor, matching a solution's actual stated capabilities against those criteria rather than a sales pitch, and closing the loop on the process that caused the incident (offboarding) rather than stopping at the technology.
- Endpoint Security
- Mobile Device Management
- DriveStrike
- Data Loss Prevention
- Remote Wipe & Lock
- Employee Offboarding
Open to Head of IT / CIO and IT Security Leadership roles.
Start a conversation