Who this is for / when to use it
Use this if a device you use for Cornell work is lost or stolen — a laptop, phone, or tablet, whether it's a JCB-managed machine or your personal device. Act quickly: the sooner you report it and lock down your account, the less anyone can do with it.
If your device is only misplaced and you think it's nearby, check the usual spots first — but don't wait long. The steps below are ordered by urgency.
Do these first, in order
1. If it was stolen, report it to the police
Report the theft to the police with jurisdiction where it happened — Cornell Police (CUPD) if it was on campus, otherwise the local police department where it went missing. If it's a Cornell-owned device, always report it to CUPD as well, even if the theft happened off campus and you've already filed with local police.
Contact CUPD at:
For a Cornell-owned, managed computer (one running managed endpoint security), Cornell's IT Security Office can sometimes see whether it has connected to the campus network. This generally isn't possible for a personal phone or tablet, even one you use for work. Either way, ITSO is not permitted to share that information with you directly — the request has to come through CUPD.
2. Change your NetID password
Assume anyone holding your device could reach anything you were signed in to. Change your NetID password now, from another device, at the Manage Your NetID page → Change your Password. Choose a strong, unique passphrase (see Create a Strong Passphrase).
Important if the lost device was a JCB-managed Windows laptop: if you still have it or expect to recover it, changing your NetID password while the laptop is offline means the laptop keeps expecting your old password until it next reaches the Cornell network or CU VPN. For a device that's truly gone, change the password anyway — securing your account is what matters. After a change you'll re-sign-in to Cornell services; see What Happens After a NetID Password Change.
While you're in your account, it's a good time to confirm you have a NetID recovery email set, and to check that your email forwarding and signature haven't been tampered with.
3. Report a Cornell-owned device to JCB IT
If the lost device is Cornell-owned (JCB-managed), contact JCB IT as soon as you've reported the theft — the fastest way is to email the Helpdesk (below), who will bring in our security team. We're an active part of the response, not just a bystander: for a Cornell-owned device, JCB IT reports the incident to Cornell's IT Security Office (ITSO) and works with them on your behalf, so you don't have to field ITSO's technical questions yourself. We'll also confirm the device was encrypted, verify its most recent CrashPlan backup, take appropriate action on the managed device, and help start a replacement.
When you reach out, it helps to have as much of this on hand as you can — but don't delay reporting to track it all down; we'll capture the rest with you:
- The name of the device (for a Cornell-managed machine, that's all we need to look it up).
- Roughly when and where you last had it, and whether it was powered on and signed in.
- What kind of Cornell information was stored on the device itself — for example student records (FERPA), personal data (PII), financial data, or research data. Focus on data saved locally on the machine, not information you only accessed through cloud services like Box, OneDrive, or email (that data isn't sitting on the device).
- Any police report number from step 1.
Gathering these lets us complete our internal intake and align with what ITSO will ask.
4. Personal device? Report it to the IT Security Office yourself
If the lost device is your personal phone, tablet, or computer that you used for Cornell work, report it as a security incident directly — this is required by university policy. Email itsecurity@cornell.edu and copy itrequests@business.cornell.edu with what happened, when, and what Cornell information was on the device — that way both Cornell IT Security and JCB IT are informed. Also mention if your NetID password may be exposed — for example, if the device was signed in when it was lost, you had your password saved in a browser, or you'd recently entered it after clicking a suspicious link. ITSO will advise whether to reset it.
Good to know
- Encryption is your safety net. JCB-managed laptops are encrypted, so a locked, lost device is far less of a data risk than one that was unlocked and signed in when it went missing. This is exactly why device encryption is required.
- Report even if you're not sure it's “stolen.” A device that you are unable to locate quickly should be treated as lost — reporting early helps protect your account and university data.
- Personal devices count too — follow the personal-device reporting steps above.
Common problems
- “I can't change my password — it's already been changed.” Someone may have changed it, or the Security Office may have scrambled it to stop abuse. Contact the IT Service Desk to reset it (you'll need to prove your identity).
- “I found the device after I reported it.” Good — let CUPD and JCB IT know. If you changed your NetID password, a managed Windows laptop will re-sync once it's back on the Cornell network or CU VPN; if it doesn't, contact the Helpdesk (itrequests@business.cornell.edu) and we'll help you get it re-synced.
- “Do I need to email IT Security myself?” For a Cornell-owned (JCB-managed) device, no — once you've reported it to JCB IT, we make the report to Cornell's IT Security Office and handle their questions for you. For a personal device you used for Cornell work, yes — that report is required by policy and it's yours to make (step 4).
More information
For more on securing your accounts and devices, see Cornell's IT Security & Policy site. Reporting security incidents is required under Policy 5.4.2, Reporting Electronic Security Incidents.
Still stuck?
If you need help locking down your account or replacing a JCB device, contact JCB IT and we'll walk through it with you.
Still need help? Contact the Cornell SC Johnson College of Business Helpdesk at itrequests@business.cornell.edu.
[edited via Jane by rtm25 on 2026-09-03 18:37 UTC]