Turn on the encryption already built into the operating system, store the recovery key somewhere other than the machine, and confirm it is actually on rather than assuming.

What it changes

Without encryption, a laptop's drive can be removed or booted from another system and read, and your account password does nothing to prevent that.

So a stolen machine is a copy of everything on it: email archives, exported lists, job records, and saved credentials.

With encryption, the drive is unreadable without the key, and a stolen machine is a hardware loss.

That distinction matters practically as well as technically, because assessments of whether a lost device constitutes a reportable breach frequently turn on whether the data was encrypted.

You already have it

The part people do not realise, which is why this is not a purchase decision.

Current versions of both major desktop operating systems include full disk encryption, built in, at no additional cost.

On some machines it is on by default and on others it needs enabling, and there is no reliable way to know which without checking.

Phones and tablets are generally encrypted by default once a passcode is set, which means the gap is usually laptops rather than mobiles.

External drives and memory sticks are the exception and are almost never encrypted unless somebody deliberately did it.

Check whether it is already on

Before anything else, since a proportion of machines are already protected.

Both systems show the status in their security settings, stated plainly as on or off.

Check every machine rather than one, because they will differ: a laptop bought two years ago and one bought last month may well have different defaults.

Do not rely on somebody's recollection that it was set up properly, which is how machines end up unprotected for years.

Write down which machines are encrypted and which are not, and work through the list.

The recovery key

Losing the key means losing the data permanently, which is the one genuine risk this introduces and the reason people avoid encryption. Handled properly it is not a risk at all.

Doing it

The practical process, which is undramatic.

Back up first, because you are about to change something fundamental about the drive and a backup is the sensible precaution.

Turn it on in the security settings and save the recovery key when prompted.

The initial encryption runs in the background and takes anywhere from twenty minutes to a few hours depending on the drive, and the machine remains usable throughout.

Afterwards, performance is effectively unchanged on any machine of the last several years, which is the objection people raise and it has not been true for some time.

Start it before lunch and it will be finished by the afternoon.

A worked example

A firm checked six machines expecting most to be fine.

Two were encrypted, both bought recently with it on by default. Four were not, including the one carried to sites daily and the one belonging to the person who handled invoicing.

Enabling it on all four took an afternoon, most of which was waiting.

The recovery keys went into their password manager, in a shared folder two people could reach.

Eleven months later a laptop was taken from a vehicle.

It held email going back years and several exported spreadsheets. Because the drive was encrypted, the assessment was that the data was not accessible, and the incident was handled as an insurance claim and a replacement rather than as a breach.

The afternoon had been the difference between those two outcomes.

The things people worry about

Three objections, and each has a short answer.

Performance, which is not a meaningful factor on modern hardware and has not been for several years.

Being locked out, which is what the recovery key prevents, and which is a reason to store the key properly rather than to skip encryption.

And repair or recovery difficulty, which is real: a technician cannot recover files from an encrypted drive without the key, so this makes your backups more important rather than less.

That third point is the honest trade-off, and it argues for a working backup routine, which you need anyway.

What it does not protect against

Worth being clear so it is not treated as a general solution.

Encryption protects data at rest on a device that is off or locked. It does nothing while the machine is running and logged in.

Which means it does not help against somebody using an unlocked machine, malware running under your account, a compromised password on a cloud service, or a file emailed to the wrong person.

It pairs with the ordinary measures: a screen lock with a short timeout, a real password on the account, and two-factor on the services that matter.

The screen lock is the one most often disabled for convenience, and it is what makes encryption meaningful on a machine that is carried around.

The counter-case

There is little argument against doing this, and one situation where care is needed.

A business with no backup routine, no password manager, and one person who understands the machines is taking on a real risk of losing data to a forgotten key, and should sort the backups first.

Older hardware running unsupported operating system versions may also lack the feature or handle it poorly, and on a machine old enough for that to apply the more useful decision is replacing it.

Beyond those, this is a free setting that meaningfully changes the consequence of the most likely physical incident a small business faces.

The afternoon

  1. Check every machine's status individually.
  2. Back up before changing anything.
  3. Turn it on in the security settings.
  4. Store the recovery key off the machine.
  5. Confirm two people can reach the keys.
  6. Set a short screen lock timeout.
  7. Do external drives and memory sticks too.

Step one frequently shows that half the machines are already done, which makes the rest a short job.

What is sitting on those drives is covered in email addresses in a spreadsheet on a laptop.


Frequently asked questions

What does encryption actually change?

Without it, a drive can be removed and read regardless of your account password. With it, a stolen machine is a hardware loss rather than a copy of everything on it.

Do I need to buy something?

No. Current versions of both major desktop operating systems include full disk encryption at no cost. On some machines it is on by default, which is why you should check rather than assume.

Where should the recovery key go?

Anywhere other than the machine it unlocks. A password manager is the sensible place; printed and filed is acceptable for a very small business. Never in a file on the encrypted drive.

Will it slow the machine down?

Not meaningfully on hardware of the last several years. That objection was true once and has not been for some time.

What is the real trade-off?

A technician cannot recover files from an encrypted drive without the key, which makes a working backup routine more important rather than less.

What does it not protect against?

Anything while the machine is running and logged in: an unlocked laptop, malware under your account, a compromised cloud password, or a file emailed to the wrong person.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure if your laptops are encrypted?

Check each one individually in the security settings. Half are usually already done, which makes the rest an afternoon.

Start a Conversation