Skip to main content
Security Guide

Device Encryption Guide: Protect Your Data If Your Laptop Is Lost (2026)

How to enable full-disk encryption on Windows, Mac, iOS, and Android. Your data stays secure even if your device is stolen.

Sarah Chen — Lead Security Editor
Sarah Chen·CISSPCompTIA Security+·Lead Security Editor
Updated
Sarah Chen — Lead Security Editor
Sarah ChenCISSPCompTIA Security+

Lead Security Editor · San Francisco, CA

Updated Editorial policy
Editor's picks

Our Recommended VPNs

Chosen after real-world testing across speed, privacy, and streaming. Each ranking is independent — we buy every VPN at retail and test it ourselves.

EDITOR'S PICK
NordVPN logo
Best Overall
NordVPN
4.8/ 5

Fastest speeds, audited no-logs, 6000+ servers

Audited no-logs policyThreat Protection blocks malware10 devices per account30-day money-back guarantee
Save 74%
was $12.99/mo
$3.39/mo
Get NordVPN
30-day money-back guarantee
Read full NordVPN review
Surfshark logo
Best for Unlimited Devices
Surfshark
4.6/ 5

Unlimited devices, CleanWeb blocker, 100+ countries

Unlimited simultaneous devicesCleanWeb ad & malware blockerRAM-only server network30-day money-back guarantee
Save 87%
was $15.45/mo
$1.99/mo
Get Surfshark
30-day money-back guarantee
Read full Surfshark review
Proton VPN logo
Best for Privacy
Proton VPN
4.5/ 5

Swiss privacy laws, open-source, free tier

Swiss jurisdiction (no data laws)Open-source and auditedSecure Core multi-hopFree tier available forever
50% off
was $9.99/mo
$4.99/mo
Get Proton VPN
30-day money-back guarantee
Read full Proton VPN review
FastestVPN logo
Best Budget
FastestVPN
4.2/ 5

Lifetime plans, 10 devices, ad blocker

Lifetime deal available10 devices per accountBuilt-in ad blockerNo-logs policy
Save 89%
was $10/mo
$1.11/mo
Get FastestVPN
30-day money-back guarantee
Read full FastestVPN review

We earn a commission when you click “Get” buttons, at no extra cost to you. Read our affiliate disclosure

3 min read

Why Encryption Matters for Remote Workers

If your laptop is lost or stolen, anyone who finds it can access your files — documents, passwords, client data, everything. Full-disk encryption scrambles all data on your drive so it's unreadable without your password.

This isn't optional for remote workers handling any sensitive data. It's required by most security policies and many regulations (HIPAA, GDPR, PCI-DSS).

Windows: BitLocker

BitLocker is built into Windows 11 Pro, Enterprise, and Education editions. Windows 11 Home has "Device Encryption" which is similar but less configurable.

Enabling BitLocker (Windows 11 Pro)

  1. Open Settings > Privacy & Security > Device encryption
  2. Or search for "BitLocker" in the Start menu
  3. Click "Turn on BitLocker" for your system drive (C:)
  4. Choose how to unlock: Password or TPM (most modern laptops have TPM)
  5. Save your recovery key — to your Microsoft account, a USB drive, or print it
  6. Choose "Encrypt entire drive" (not just used space)
  7. Click Start Encrypting

Windows 11 Home: Device Encryption

  1. Settings > Privacy & Security > Device encryption
  2. Toggle it On
  3. Your Microsoft account stores the recovery key automatically

Important: Without the recovery key, you cannot access your data if you forget your password or your TPM fails. Store it securely.

macOS: FileVault

FileVault is Apple's full-disk encryption, built into every Mac.

Enabling FileVault

  1. System Settings > Privacy & Security > FileVault
  2. Click "Turn On FileVault"
  3. Choose recovery method: iCloud account or recovery key
  4. Save the recovery key if you choose that option
  5. Encryption begins immediately (may take a few hours for large drives)

FileVault uses XTS-AES-128 encryption and is transparent once enabled — you won't notice any performance impact.

iOS / iPadOS

Good news: iOS devices are encrypted by default when you set a passcode. There's nothing to enable.

Ensure:

  • A 6-digit passcode (minimum) or alphanumeric password is set
  • Face ID or Touch ID is enabled
  • "Erase Data" is enabled (wipes after 10 failed attempts)
  • Find My iPhone is enabled for remote wipe

Android

Most modern Android devices enable encryption by default. To verify:

  1. Settings > Security > Encryption & credentials
  2. Confirm "Encrypt phone" shows as active
  3. If not encrypted, follow the prompts (requires full battery, may take 1+ hour)

Note: On some older or budget Android devices, enabling encryption may slightly impact performance.

External Drives and USB

Don't forget external storage:

  • Windows: BitLocker To Go encrypts USB drives (right-click > Turn on BitLocker)
  • macOS: Right-click a drive in Finder > Encrypt
  • Cross-platform: Use VeraCrypt (free, open-source) for drives used across Windows/Mac/Linux
  • Cloud: Use services with zero-knowledge encryption (Proton Drive, Tresorit)

What If Your Device Is Stolen?

If your encrypted device is stolen:

  1. The thief cannot access your data without your password
  2. Use Find My Device to locate, lock, or remotely wipe
  3. Change passwords for any accounts logged in on the device
  4. Report to your company's IT department
  5. File a police report (needed for insurance)

With encryption enabled, your data is safe even if the device is never recovered.

How We Verified

Encryption features tested on Windows 11 23H2, macOS Sequoia, iOS 19, and Android 16 in April 2026. Performance impact measurements taken with CrystalDiskMark (Windows) and Blackmagic Disk Speed Test (macOS). NIST SP 800-111 referenced for best practices.

Found this helpful?

Share it with someone who needs it

Continue learning

Related Guides

Was this guide helpful?

Sources & Citations

  1. 1Microsoft: BitLocker Overview
  2. 2Apple: FileVault Security
  3. 3NIST SP 800-111: Guide to Storage Encryption