What this protects, and what it doesn't
Protects
- A device that is lost or stolen while switched off: without your password, PIN or recovery key the disk is unreadable.
- Data on a drive that is removed and read in another computer.
- Old devices that you sell or recycle: an encrypted disk whose key is gone is hard to recover from.
Does not protect
- A device that is running and unlocked, or merely asleep. While it is on, the key is in memory and the files are readable to anyone who can use it.
- Copies elsewhere: cloud backups, synced folders, email and messaging servers. Each has its own protection, or none.
- Malware on the device. It runs after you unlock, so it sees what you see.
- An attacker who tampers with the device and gives it back to you (the “evil maid” attack), then captures your password when you next type it.
- Your data, if you lose the password and the recovery key. Nobody, including the vendor, can get it back.
Prerequisites
- A full backup of the device before you start, in case anything goes wrong.
- An administrator account on the computer.
- A safe place for a recovery key that is not the device itself: a password manager, or paper kept somewhere else.
Step by step
-
Windows: Device Encryption or BitLocker
Windows offers two versions of the same technology. Device Encryption works on a wide range of hardware, including Windows Home. BitLocker with full controls is in the Pro, Enterprise and Education editions.
- Device Encryption: open Settings, then Privacy & security, then Device encryption, and turn it on. It needs an administrator account. If you sign in with a Microsoft or work account, Windows may already have turned it on during setup.
- If the option is missing, the hardware may not qualify. Windows needs a usable TPM chip, the Windows Recovery Environment and Secure Boot. System Information, run as administrator, shows the reason under “Device Encryption Support”.
- BitLocker (Pro and above): search the Start menu for Manage BitLocker.
-
Windows: save the recovery key, and check where it already is
In Manage BitLocker, choose Back up your recovery key. You can save it to your Microsoft account, print it, save it as a file, or copy it to a USB drive.
- Never store the key on the encrypted drive, and do not keep the USB stick or the printout with the laptop.
- If Device Encryption turned itself on, the key was uploaded to your Microsoft account. You can see the keys stored there at aka.ms/myrecoverykey.
- Microsoft cannot recreate a lost key.
Decide whether a key held by your account provider fits your threat model. If it does not, keep your own copy and talk to your IT team or read Microsoft's documentation before you remove the online copy.
-
macOS: turn on FileVault and pick a recovery method
Open the Apple menu, then System Settings, then Privacy & Security, then FileVault (you may need to scroll down). Turn it on.
- Macs with Apple silicon or a T2 chip already encrypt their storage. FileVault ties that encryption to your login password, so the disk cannot be read without it.
- Apple's security guide says that on a Mac with macOS 26.4 or later, FileVault is turned on by default and can be turned off. Check that it is still on.
- For the recovery method, you can let your iCloud account unlock the disk, or create a recovery key and not use iCloud. If you choose the key, write it down and keep it away from the Mac.
- If you forget your password and also lose the recovery key, your files are lost for good.
-
Linux: LUKS, chosen at install time
On Linux, full-disk encryption is normally LUKS, set up with
cryptsetup. The simplest way is to tick the disk encryption option in your distribution's installer when you install. Encrypting an existing system in place is possible, but it is an advanced job. Back up first.The LUKS header at the start of the partition holds the key slots. If anything overwrites it and you have no header backup, the data cannot be decrypted. The cryptsetup FAQ recommends keeping a header backup somewhere safe:
cryptsetup luksHeaderBackup --header-backup-file <file> <device>Treat that file like a key. Anyone who has it and an old passphrase can unlock the disk, even if you have since changed the passphrase.
-
Phones: encryption is on; your passcode is what makes it count
- iPhone: Apple's guide says that setting a passcode also turns on data protection, which encrypts the iPhone's data with 256-bit AES. Set one under Settings, then Face ID & Passcode (or Touch ID & Passcode).
- Android: phones that launch with Android 10 or later must use file-based encryption. Most app data sits in credential-encrypted storage, which opens only after you unlock the phone once after it starts.
- On both, use a passcode longer than 4 digits (6 digits at least, or an alphanumeric one). A short code can be guessed.
- A phone that has been unlocked once since it started is more exposed than one that has just been switched on. If the phone may be taken from you, turn it off.
-
Shut down before the device leaves your hands
Encryption protects a device that is switched off. When a laptop is asleep, the key stays in memory and waking it does not ask for the disk key again.
Microsoft's BitLocker guidance for high-risk users:
- Shut down or hibernate the device before it leaves your control.
- Consider requiring a PIN at startup (TPM with PIN) rather than relying on the TPM alone.
Shut down before border crossings, before you check a bag, and at the end of the day. If the device is likely to be seized, power it off.
-
Test that you can recover
Look up your recovery key now, where you stored it, and check that it matches the key ID your device shows. A recovery key you cannot find on the day you need it does the same as no key. Write down which devices are encrypted and where each recovery key is. Keep that list in your password manager, not on the devices.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Storing the recovery key on the encrypted laptop itself, or in a file synced from it.
- Assuming “encrypted” means safe while the laptop is only asleep in a bag.
- Encrypting the laptop but leaving unencrypted backups on an external drive or in a cloud folder.
- Keeping a 4-digit phone PIN because it is quicker.
- Not knowing that the Windows recovery key went to your Microsoft account automatically, which matters if your threat model includes a legal request to the provider.
Going further
Encrypt external drives and backups too (BitLocker To Go on Windows, an encrypted APFS volume on macOS, LUKS on Linux). On Medium or High threat levels, add a startup PIN on Windows, keep the device powered off when you cross borders, and pair encryption with hardware security keys for your accounts.