A contractor’s engagement ends on a Friday. IT deactivates the account that afternoon. Jamf still shows the MacBook enrolled, checked in, compliant. On paper, offboarding is done.
Nobody has the device. Nobody has a record that it was ever sent back. That gap is not a future risk you need to plan for. It already exists, on a machine you can no longer see, in the hands of someone who no longer works for you.
The 71% Is Already in Your Inventory
A 2022 Capterra survey of nearly 300 HR professionals found that 71% had at least one departing employee fail to return company-owned equipment like a laptop or phone. Hybrid and remote workers were 17% more likely to keep the hardware than on-site staff. The average value walking out the door was close to $2,000 per person.
Read that as a present-tense fact about your own organization, because it almost certainly is. If you have offboarded remote employees in the last year, some of those devices did not come back. You may not know which ones. That is the actual problem: not the loss, but the not-knowing.
High-turnover roles turn a one-time survey stat into a standing condition. Contractors, seasonal staff, RTO-driven exits, and performance-managed departures churn through your fleet several times faster than tenured FTEs. Each exit is another device, another account closure, another spreadsheet row that says “recovered” without any evidence behind the word. Volume is the multiplier. The more people you cycle, the more devices sit in the gap between “account disabled” and “hardware confirmed in hand.”
Account Closed Is Not a Security Control
Deactivating a user is an administrative record. It says you revoked access on your side. It says nothing about the physical device.
A laptop is not a cost-center line item. It is an access vector. Cached credentials, saved sessions, downloaded files, local copies of customer data, VPN certificates that outlive the SSO revocation by longer than anyone assumes. The 2025 IBM Cost of a Data Breach report put the average US breach at $10.22 million, the highest in the world and an all-time high, up 9% from the prior year even as the global average fell. Insider-connected incidents sit near the top of that range because the person already knows where the valuable data lives.
The $2,000 hardware figure is the part that shows up in a budget. It is the least of it. The exposure is the machine’s continued ability to reach into your environment after the person holding it has a reason to be unhappy. You closed the account. You did not close the risk. Those are different actions, and only one of them is documented.
A Spreadsheet Is Not a Chain of Custody
Here is the specific, proximate version of the problem. Your SOC 2 auditor asks for a chain-of-custody record for the 14 devices returned in Q3. You have a spreadsheet with dates, a few tracking numbers, and an email thread where someone confirmed a laptop “should be on its way.”
That is not a chain of custody. It is a collection of intentions. A chain of custody documents who had the device, when it changed hands, and how each transfer was verified, from the employee’s last day to the moment the wiped machine is confirmed back in your control. Dates in a spreadsheet do not establish any of that. They establish that someone typed a date.
The reason this lands harder every quarter is that device recovery has quietly become Step 1 of risk containment. State privacy laws, HIPAA, SOC 2, and government contracting frameworks increasingly treat the endpoint as the first place a breach starts and the first thing you must prove you controlled. Auditors are starting to ask for the recovery record specifically. When the answer is a thread and a hope, the finding writes itself.
What You Can Prove Is the Only Thing That Counts
The uncomfortable reframe is that you are not trying to prevent a hypothetical loss. In a high-turnover operation, some devices are already gone, and more will leave next quarter. That is the baseline, not the exception.
So the question is not whether you will lose devices. It is whether, when someone asks, you can produce a record proving you got the rest of them back. Provable control is the asset here. Not the laptop, and not the deactivated account, but the documented, verifiable trail that shows a device left, moved through known hands, and returned to a known state.
Most organizations discover the difference between having a policy and having proof at the exact moment they can least afford to. Turnover does not wait for you to build the record. It generates the gap first and asks the question later.
You can’t prevent the turnover. You can prove what you recovered.
LaptopReturn documents every device from an employee’s last day to a confirmed wipe, the chain-of-custody record an auditor actually asks for. No contracts, no minimums, and your first return is free.
FAQ
What happens if an employee doesn’t return company equipment? Most companies write off the hardware, but the device is the smaller issue. Until the machine is confirmed back and wiped, it retains cached credentials, saved sessions, and local data, an open access path that outlives the deactivated account.
Is deactivating a user account enough to secure a former employee’s device? No. Deactivation revokes access on your side and documents nothing about the physical machine. VPN certificates and cached sessions can outlive SSO revocation, so a closed account and a controlled device are two different things, and only one of them is proven.
How do companies recover laptops from remote or contract employees? The reliable pattern is a prepaid, tracked return kit sent to the departing employee, with each hand-off logged from last day to confirmed wipe, a chain of custody rather than a spreadsheet of dates and hopeful email threads.
What does a chain-of-custody record need to show for a compliance audit? Who held the device, when it changed hands, how each transfer was verified, and the final wiped state, an unbroken, verifiable trail. Dates in a spreadsheet establish that someone typed a date, not that the device was controlled.