In February 2007, the UK's Financial Services Authority fined Nationwide Building Society £980,000. The trigger was a laptop stolen from an employee's home during a burglary the previous August. The regulator's complaint was not that a laptop had been stolen — burglaries happen — but that the society had taken weeks to grasp that the machine held customer information, and had no adequate controls to prevent the situation in the first place. That fine captured the shape of laptop theft data loss in the mid-2000s exactly. The device was rarely the point. The point was that organizations had spent a decade putting corporate data on portable machines without deciding what would happen when one of them walked out of the building.
Why Laptops Dominated the Breach Statistics
For several years running, stolen and lost laptops led the published tallies of data loss incidents. Three things explain it. Mobility outran controls. Laptop deployment accelerated through the early 2000s while the management tooling to govern those machines lagged badly behind. Configuration was often whatever the reseller shipped. Data lived locally by design. Bandwidth and thin-client limitations meant analysts genuinely needed local copies of large datasets. Extracts from finance, HR and CRM systems sat on hard drives because that was the only practical way to work with them. Physical loss is countable. An intrusion could run undetected for eighteen months, as TJX discovered. A stolen laptop produces a police report, an insurance claim and a specific date. Breach statistics of the era over-represented physical loss partly because physical loss was the category organizations could actually detect. The canonical incident had already happened: in May 2006, a laptop and external drive containing records on roughly 26.5 million US veterans were stolen from an employee's home. The equipment was recovered, the litigation was not cheap, and the case established that a single misplaced device could become a national news story.
The Numbers Behind the Cliche
The most useful data arrived slightly later, when Ponemon Institute began pricing the problem properly. Its cost of a lost laptop study put the average total cost of a single lost business laptop at $49,246. The composition of that figure is the part worth remembering:
- Data breach costs accounted for around 80% of the total.
- Replacement hardware accounted for about 2%.
- Encrypted laptops cost an average of $37,443; unencrypted ones $56,165 — a difference of roughly $20,000 per incident attributable to a control that was already commercially available. A follow-up European study found that 275 organizations had collectively lost tens of thousands of laptops in a single year, with an aggregate value running into the billions of euros once data exposure was priced in. Put plainly: the hardware was never the loss. The hardware was the receipt.
The Encryption Was Already There
This is what makes the period instructive rather than merely historical. Full disk encryption was not an emerging technology in 2007. It was a purchasable product with an obvious business case. Microsoft shipped BitLocker with the Enterprise and Ultimate editions of Windows Vista, released to businesses at the end of 2006. Apple had shipped FileVault years earlier. The independent market was consolidating fast — Check Point bought the parent of endpoint encryption vendor Pointsec early in 2007, and McAfee acquired SafeBoot later the same year, both deals reflecting exactly where enterprise buyers were spending. Adoption lagged anyway, for reasons that remain recognisable:
- IT teams feared key escrow failures and permanently locked-out executives more than they feared theft.
- Encryption on the hardware of the era carried a real performance penalty on machines already considered slow.
- Hardware fleets were mixed, and the enterprise SKUs that included BitLocker were not what most organizations had bought.
- Nobody owned the decision. It sat between IT operations, risk and finance, and stayed there.
The Regulation That Actually Changed Behaviour
What finally moved the market was not a security argument. It was a notification exemption. California's breach notification law, and the wave of state statutes that copied it, generally did not require notification where the exposed data was encrypted. That converted encryption from a control with abstract benefits into a control with a specific, quantifiable one: encrypt the disk, avoid the letter to 200,000 customers, the call centre, the credit monitoring and the news coverage. The same logic appears in later frameworks. GDPR allows organizations to skip individual notification where data was rendered unintelligible to unauthorised parties, typically through encryption. Nineteen years of policy design have essentially reaffirmed the 2007 lesson: encryption is cheap, and notification is not.
What Replaced Laptop Theft
Device encryption is now largely a solved problem. It ships on by default on modern laptops, management platforms can attest to its state, and remote wipe is standard. The risk moved, as risk does. Today's equivalent of the stolen laptop is the stolen session. Infostealer malware harvests browser-stored credentials and authentication tokens from unmanaged and personal devices, and those tokens open the SaaS platforms where the data now lives. Nobody has to steal the hardware, because the hardware no longer holds anything interesting — the access does. The structural parallel is exact. In 2007, organizations put data on portable devices without deciding how to protect it. Today they put access on personal devices without deciding how to govern it.
What an Endpoint Review Should Cover Now
- Verify encryption state, do not assume policy. Report on actual device attestation, including contractor and BYOD machines.
- Test recovery key escrow before you need it. A control you cannot recover from is an outage waiting for a bad week.
- Gate access on device enrolment, so unmanaged machines cannot reach sensitive SaaS applications.
- Minimise local data. Bulk extracts to laptops are still routine in finance and HR, and still the largest exposure per device.
- Move to phishing-resistant, device-bound credentials to break the token-theft chain.
- Write and rehearse a lost-device runbook that produces regulator-grade evidence within hours, not weeks — the failing that cost Nationwide most of its fine.
Common Questions
Was laptop theft really the leading cause of data breaches?
It led the published incident counts for several years in the mid-2000s. That reflects both genuine exposure and the fact that physical loss was detectable, while network intrusions frequently were not.
How much does full disk encryption reduce breach cost?
Ponemon's study found encrypted laptops cost roughly $20,000 less per incident than unencrypted ones, driven almost entirely by avoided data breach consequences rather than hardware or productivity savings.
Is device encryption sufficient today?
No. It protects data at rest on a powered-down device. It does nothing against credential theft, malicious browser extensions or session hijacking, which is where most endpoint-originating compromise now begins.
What should a mid-market company check first?
Whether encryption is actually enabled on every device with access to company data — including personal machines — and whether anyone can produce that evidence on request. The answer is frequently no on both counts.
Endpoint Encryption Review — Outpace audits real device state rather than written policy: encryption coverage, recovery key custody, unmanaged device access, and whether your lost-device process would satisfy a regulator in 72 hours.
