Your Phone Has Been Stolen: the First Hour, in Order
The instinct is to open Find My and watch a dot on a map. It is the wrong first move, and often the least useful one: the device is probably already off or in a signal blocking bag, and while you watch the map, the accounts behind it are what is actually exposed.
The phone is a replaceable object. The accounts it was signed into are not. Here is the order that limits the damage.
The first hour, in order
1. Call your operator and have the SIM blocked. This comes before everything else, and the reason is specific: your number receives the codes that reset your other accounts. A thief with your number can request password resets for services that still send codes by text. Blocking the SIM removes that, and it takes one call.
Ask for a replacement SIM in the same call. You will need your number back to recover most accounts.
2. Sign out of your accounts remotely, starting with the main one. From any other device, open your Google or Apple account security page and revoke the sessions on the missing device. Then your bank app, your email, your password manager.
Changing a password is not enough on its own if the phone holds a session that stays valid. Revoking the device session is what closes it.
3. Only now, lock and locate. Find My iPhone or Find My Device. Mark the phone as lost, which locks it and shows a message with a contact number. Do not go and get it yourself, whatever the map says; a location that appears precise is often a building, not a room, and a stolen phone is not worth what confronting someone costs.
4. Report it, with the IMEI. The police report is what your insurer will ask for, and the IMEI is what identifies the handset. If you did not note it, it is on the box, on your operator’s account page, and in your Google or Apple account.

Why the SIM comes first, and it is not obvious
Most people rank the phone above the SIM card because the phone costs more. For an attacker it is the reverse.
A locked phone is difficult to use. A working SIM in any handset receives your text messages, and text messages are still the recovery channel for a large number of services, including some banks. That is the whole mechanism behind SIM swap fraud, and a stolen phone hands it over without any of the social engineering normally required: see SIM swap attack prevention.
Erase remotely, and the one thing to know first
Both platforms let you wipe the device remotely. It is the right call once you have accepted the phone is gone.
â›” Erasing usually removes the device from your account, and with it the ability to track it. On iPhone, Activation Lock persists after an erase, so the handset stays unusable for a thief, but your own visibility ends. Do the account work in steps 1 and 2 first, then erase; the reverse order leaves you with a wiped phone and live sessions.
Two things to do before it happens
Turn off notification previews on the lock screen. Codes sent by text are readable on a locked phone by default on most configurations, which makes the lock screen a bypass for anything protected by a code. Settings, Notifications, and set previews to when unlocked.
Move your second factor off text messages. An authenticator app or a hardware key does not travel with the SIM. This is the single change that turns a stolen phone from an account emergency into an expensive inconvenience: what is two factor authentication covers which methods survive losing the device.
And note the IMEI somewhere that is not the phone. It takes ten seconds now and it is the number every report will ask for.
What not to bother with
Watching the map for hours. If the dot stops moving in a residential building, that is all you will ever learn from it.
Calling your own number repeatedly. It confirms nothing and it tells whoever has the phone that it matters to someone.
Posting the location publicly. Beyond the personal risk, an address obtained this way is not evidence of anything, and the mistake is on you if it is the wrong one.
If the phone held sensitive documents rather than only accounts, the question becomes what was readable without the passcode, and full disk encryption is the answer that decides it: full disk encryption.