🔒 Free Onsite Hard Drive Shredding · Witnessed Destruction · Greater Phoenix AreaSee Mobile Shredding
ITAD Best Practices7 min readUpdated May 16, 2026

The Remote Work IT Asset Problem: How to Recover Laptops from Employees You'll Never See Again

'We have 200 employees who went remote in 2020. We've had 40 of them leave. We have no idea where 35 of those laptops are.' Here's how to solve the remote work asset problem.

The problem

Here's a scenario we hear constantly from IT managers: "We have 200 employees who went remote in 2020. We've had 40 of them leave the company since then. We have no idea where 35 of those laptops are." This is the remote work IT asset problem, and it's a compliance and security nightmare that most organizations are only now starting to reckon with.

Scale of the problem

The most-cited number in this space comes from a 2022 Iron Mountain survey: roughly 1 in 6 remote-worker laptops issued during the pandemic never made it back to the company that owned them. Other industry surveys put the unreturned rate between 12% and 22% depending on company size and offboarding rigor. For a 1,000-person organization that shifted 60% of its workforce remote, that's something on the order of 100 laptops in the wild — each one carrying SSO tokens, cached email, saved credentials, and whatever local files the employee accumulated over their tenure.

Security risks from unrecovered devices

Three risks compound on every unreturned device. First, data residue: cached email, saved documents, browser-stored credentials, MFA tokens. Second, credential persistence: SSO certificates and VPN keys that may continue to authenticate if account deprovisioning was incomplete. Third, compliance exposure: PHI, PII, cardholder data, or controlled technical data sitting on a drive your organization can't account for. From a regulator's perspective, an unrecovered laptop is functionally identical to a lost laptop, which is functionally identical to a breach.

How a reverse-logistics ITAD program works

The process is straightforward when you have it set up. On offboarding day, HR triggers the ITAD vendor (in our case, an API call into our scheduling system). The vendor ships a serialized return kit — pre-labeled box, tamper-evident bag, prepaid carrier label, simple instructions — directly to the employee's home address. The kit's serial number is pre-bound to the asset tag, so even before it arrives back at our facility we know exactly which laptop is in transit. Pickup is scheduled by the carrier within 48 hours.

When the kit hits our dock, it gets the same chain-of-custody treatment as a corporate pickup: scanned at receiving, asset audit against the manifest, NIST 800-88 sanitization, serialized Certificate of Destruction. The IT team gets one consolidated weekly report showing what was returned, what was sanitized, and what's still outstanding.

When an employee refuses to return equipment

It happens. The most effective lever is the final paycheck — most state employment laws permit withholding a reasonable equivalent of the device value until the asset is returned, if the employee acknowledged the property-return policy in writing at hiring. Second-line tools: certified-mail demand letter from legal, MDM remote wipe (if enrollment is still active), revocation of all credentials, and small-claims court if the asset value justifies it. We've also had clients use a deposit model — a refundable equipment deposit that becomes non-refundable if the device isn't returned within the window.

Preventing the problem going forward

A device return policy belongs in the employee handbook and the offer letter, not in a one-off email at offboarding. The clauses that matter: (1) the device is company property at all times, (2) return is required within a defined window (7 business days is the industry norm), (3) the company will provide a prepaid return kit, (4) failure to return triggers cost recovery and credential revocation, (5) the employee acknowledges they are responsible for the device's condition and data on it until our chain-of-custody scan completes. Get the signature at hiring and the conversation at offboarding is much shorter.

Phoenix ITAD operates nationwide reverse-logistics programs for organizations with distributed workforces. Serialized return kits, scheduled offboarding-day pickup, NAID AAA sanitization, and weekly outstanding-asset reporting. Get a free program quote at phoenixitad.com/contact.

Frequently asked questions

What percentage of remote worker laptops are never recovered?

Industry surveys put the unreturned rate between 12% and 22% for organizations without a structured reverse-logistics program. With prepaid return kits, scheduled pickup windows, and offboarding-day enforcement, that drops below 3%.

What's the legal liability if an employee keeps a company laptop?

The asset itself is recoverable through normal civil channels, but the data exposure is the real liability. If the laptop contained PHI under HIPAA, payment card data under PCI-DSS, or customer financial information under GLBA, the regulator does not care that the employee was terminated — your organization is still on the hook for the breach.

Can you remotely wipe a laptop you can't physically recover?

If MDM (Intune, Jamf, Kandji, Workspace ONE) is enrolled and the device connects to the internet, yes — you can trigger a remote wipe or cryptographic key destruction. If MDM enrollment was never completed or has been removed, you have no remote sanitization path and the data exposure persists until the drive itself is destroyed.

How long should a remote-worker return window be?

7 business days from the offboarding date is the practical sweet spot. Shorter than that and shipping logistics break down; longer than that and return rates drop sharply because the device becomes 'forgotten property' in the employee's mind.

Need Expert ITAD Services?

Get a free quote for certified data destruction, IT asset disposition, and electronics recycling.

Get a Free Quote