The timeline was reconstructed in full. Laptop stolen at 8:40 PM on 6 May. Reported to IT at 9:12 AM on 7 May, logged as a lost asset, remote wipe issued to a device that never reconnected. Drive read on 9 May. Bank-change email sent on 20 May. Redirected payment run on 29 May. Breach awareness established at 10:41 AM on 29 May — the moment the supplier’s call reached the finance manager. The breach was reported at 4:30 PM the same day.
Twenty-three days between the breach and the moment anyone inside knew to start the clock.
This is what the investigation found. Not as background. As verdict.
No one owned the alarm.
A breach has to be raised the moment it happens — not whenever someone eventually connects the dots. The laptop left the building on 6 May. The company became aware on 29 May. In between, the theft lived entirely inside an IT ticket: lost asset, wipe, replace, close. No one was assigned to ask whether a data breach had just occurred.
No one owned the data.
There was no named person responsible for what personal and financial data left the building on a device — no one whose job it was to ask why a two-year payment master and a customer ledger were living on a laptop that travelled through airports. So the question never got asked, and the habit was never governed.
Nothing guarded the door.
The laptop had a login password and no disk encryption. The export files were unencrypted. There was no log of who pulled the vendor master, or when. The one control that would have made the whole theft harmless — encryption that turns a stolen drive into noise — was never switched on.
In the UAE, data protection rules now apply, and the consequences for a breach are no longer hypothetical.
The investigators’ conclusion was the same one that appeared in the reports before it: the person who lost the laptop was not the problem. The absence of any system around that moment was.
Karim did everything a careful finance professional does. He checked his payments twice. He refused to work on a frozen screen. He reported the theft the next morning. He kept his files tidy and close.
That was the problem — because nothing around him was built to make any of it safe.
The 3-step protocol the investigators recommended:
1. Encrypt every device — and treat a lost one as a breach. Full-disk encryption on every laptop and phone, so a stolen drive is unreadable. And a named person who, the moment a device goes missing, asks what data was on it — and starts the breach protocol, not just the replacement order.
2. Govern data at rest. A clear rule on what data may be held offline and for how long — no unencrypted exports of payment or customer masters onto local machines. If it has to travel, it travels encrypted, and it’s deleted when the trip ends.
3. Train the people who touch the data. Not a policy handout. Training built around what finance, procurement and operations staff actually do every day — offline copies, device handling, bank-change requests — and what UAE data protection law requires in those specific moments.
Karim still works there. He knows what to do now. Does your team?
If your organisation needs to close this gap — the training exists, built for exactly this.
training.cybernym.io/login/?tab=demo
Cybernym.io — Cyber Instincts. Built, Not Taught.