As mentioned the device can't be remotely locked or erase if the lost\stolen phone has it's SIM removed. As always you should at least enforce a basic password policy (via BES I.T Policy) so the devices automatically lock after 10 minutes (I set our users to 2 minutes). This way if a device was lost and the SIM was removed the device would automatically erase after the password was entered incorrectly 10 times. Whilst users are getting use to password you can set Allow Outgoing Calls While Locked to Yes as they will only need to unlock the device to access email, calendar etc (e.g. It will operate as a normal phone without unlocking).