You can remotely lock any MDM managed device, this was possible 10 years ago and you need zero development. iCloud lock even brought this to the consumer space.
It is clear that non-tech people wrote this. Any company device I used in the last 10 years was always encrypted and could be remotely locked to not boot.
Additionally most bigger companies will have "security" software like Crowdstrike on all devices which is basically a backdoor.