Field Guide to AI, Security and Cybercrime

Full-Disk Encryption: Turn It On Before You Need It

The encryption built into your laptop costs nothing. Its real failure points are the recovery key and the sleeping lid.

Field Guide to AI, Security and Cybercrime·Abdolmadjid Masoomi·4 October 2026·7 min read

A lost or stolen laptop is a data breach only if its drive is unencrypted. Full-disk encryption is built into Windows, macOS and Linux and costs nothing to use. What actually goes wrong is a lost recovery key, or a laptop left asleep instead of shut down when it leaves your control.

A stolen laptop is a hardware problem or a data breach

You think of a lost laptop as lost hardware. The hardware is the cheap part. The expensive part is everything on the drive, and without encryption that belongs to whoever is holding the machine. They do not need your password. They can take the drive out, connect it to another computer and read it like a USB stick: documents, local email, browser profiles, saved sessions, the work folder you synced last week.

This is not an advanced attack. It is what anyone does with a found laptop who is curious, and it is the first thing anyone does who is not merely curious. Your login screen protects the operating system, not the disk. A login password on an unencrypted drive is a lock on the front door of a house with no walls.

Full-disk encryption changes what the thief has. The drive becomes scrambled data that only turns back into files when the right password or key is supplied at start-up. The laptop is still gone. The breach is not.

What full-disk encryption protects, and what it does not

Full-disk encryption protects data at rest on the device: when the machine is switched off, and, depending on the system, when it is locked before the keys are loaded. Its job is the lost bag, the stolen car, the laptop left in a taxi, the repair shop you never quite trusted, and the old machine you sold without wiping.

It is just as important to know where it stops.

  • A running, unlocked machine is decrypted. If you walk away from an unlocked laptop in a café, the encryption is doing nothing for you at that moment. Screen lock matters as much as the encryption itself.
  • Malware runs after you have unlocked the disk. Encryption is not an antivirus. Anything running as you can read what you can read.
  • Copies elsewhere are not covered. Files synced to cloud storage, attached to email or copied to a USB stick live under different rules. This is why a service saying "encrypted at rest" tells you less than it sounds; the question is always who can decrypt it, which is the argument in why "encrypted at rest" is the weakest claim on the page.
  • It is not tamper-proofing. Someone with repeated, unobserved access to the machine can try to interfere with it so that it captures your password the next time you type it. Encryption protects the data on a device that has left your hands; it does not make a device that came back to you trustworthy.

Turning it on: Windows, macOS and Linux

Every major operating system includes full-disk encryption. You do not need to buy anything.

On Windows, the tool is BitLocker, included in the Pro, Enterprise and Education editions. Many devices running Windows Home offer a simpler feature called device encryption instead, found under Settings, then Privacy and security. On BitLocker editions, search the Start menu for "Manage BitLocker". To check the state of every drive from an administrator command prompt, run manage-bde -status; the line that matters is whether protection is on.

On macOS, the feature is FileVault, under System Settings, then Privacy and Security. Turning it on asks you to choose how you will get back in if you forget your password: by letting your Apple account unlock the disk, or by writing down a recovery key that only you hold.

On Linux, encryption is normally chosen during installation, usually as LUKS. Most installers offer it as a checkbox, and it is far easier to tick it then than to add it afterwards, which in practice means backing up and reinstalling. To check an existing system, lsblk -f lists your partitions, and an encrypted one shows the type crypto_LUKS.

Encrypting an existing drive happens in the background and can take a while on a full disk. Plug the laptop in and keep working.

The recovery key decides who can read your data

When you turn encryption on, you get a recovery key: a long code that unlocks the drive if your password is forgotten, or if a firmware update or hardware change makes the machine ask for it. This is the single most important object in the whole arrangement, because whoever holds it holds the data.

That cuts both ways. Lose the key and forget the password, and the data is gone. There is no back door, and that is the point. Store the key where a laptop thief would not also get it: printed and kept with your important papers, or in a password manager you can open from your phone, never in the laptop bag.

If you let your Microsoft or Apple account save the key, anyone who takes over that account can unlock your stolen laptop's disk. This is a convenience, but it makes the security of your drive depend on the security of that online account. Protect that account with a strong sign-in method. The general rule, set out in who holds the key, is that key custody, not the cipher, decides who can read the data.

If the machine is managed by your employer, the key is almost certainly held by the organisation. That is normal, and it means your employer can unlock that disk.

Sleep is not shut down

Closing the lid usually puts a laptop to sleep, and a sleeping laptop has already unlocked its drive. The keys are in memory so that the machine can wake instantly. Someone who takes a sleeping laptop is attacking a machine whose encryption is already open, protected only by the screen lock and whatever stands between memory and a determined attacker.

A full shutdown clears the keys. The next start-up demands the password or key again, and the drive is protected the way you assumed it was.

So make shut-down the habit whenever the laptop is about to leave your control: before a flight, before a border, before it goes in the boot of a car or into a hotel room safe. The same reasoning applies to phones, and preparing your devices for a border crossing covers the rest of that situation. If a device does go missing, the order of the first actions matters, and the first thirty minutes after a phone is stolen applies almost unchanged to a laptop.

A short checklist

  1. Check. Confirm encryption is on for every laptop you use, including the old one in the cupboard that still syncs your email.
  2. Turn it on where it is off, and let it finish.
  3. Find the recovery key. Decide deliberately whether it lives in your online account or only with you, and store a copy away from the laptop.
  4. Know how to use it. Look up your system's recovery screen once while nothing is wrong.
  5. Shut down, do not sleep, when the laptop is in transit or out of your sight.
  6. Wipe before you sell. On an encrypted drive, a factory reset that destroys the key leaves the old data unreadable, which is the cleanest way to hand a machine on.

Questions people ask

Does full-disk encryption slow a laptop down?

Not noticeably on a modern machine. Current processors include instructions that speed up the encryption used by these tools, and the work happens as data is read and written. You will not feel it in normal use.

Can my employer recover my laptop if I forget the password?

If the laptop is managed by your employer, almost certainly, because the recovery key is usually stored centrally. On a personal machine, only whoever holds the recovery key can, and if you chose to keep it yourself and lost it, nobody can.

Does encryption protect me if I am hacked while using the laptop?

No. Once you have unlocked the machine, the drive is readable by anything running under your account, including malware. Full-disk encryption protects against loss and theft of the device, not against attacks on a running system.

My laptop with encryption was stolen. What now?

Use your device-finding service to lock or erase it if you can. Then sign out of its sessions from your accounts and change the passwords that were saved in its browser, starting with email. The files on the drive are protected if it was shut down; sessions that were open may not be.

Close

Full-disk encryption is the rare control that is free, already installed, and invisible once switched on. What it asks of you is not cryptography but custody: know where the recovery key is, choose who else holds it, and shut the machine down when it leaves your hands. Do that, and a stolen laptop costs you a laptop.

Questions people ask

Does full-disk encryption slow a laptop down?

Not noticeably on a modern machine. Current processors include instructions that speed up the encryption used by these tools, and the work happens as data is read and written. You will not feel it in normal use.

Can my employer recover my laptop if I forget the password?

If the laptop is managed by your employer, almost certainly, because the recovery key is usually stored centrally. On a personal machine, only whoever holds the recovery key can, and if you chose to keep it yourself and lost it, nobody can.

Does encryption protect me if I am hacked while using the laptop?

No. Once you have unlocked the machine, the drive is readable by anything running under your account, including malware. Full-disk encryption protects against loss and theft of the device, not against attacks on a running system.

My laptop with encryption was stolen. What now?

Use your device-finding service to lock or erase it if you can. Then sign out of its sessions from your accounts and change the passwords that were saved in its browser, starting with email. The files on the drive are protected if it was shut down; sessions that were open may not be.

Ask NEXUS about this article

Get an AI-powered summary, key points, or follow-up questions about Full-Disk Encryption: Turn It On Before You Need It, grounded in the essay content and the broader corpus.