CYBER WELFARE

Protect your Digital Privacy

Impact of unencrypted data

A device without encryption is not a device protected by a password: it is an archive with a door. The password governs normal access; the drive, removed and connected elsewhere, does not know it.

This post looks at what a device really holds, and what becomes reachable when the archive is not encrypted.

It expands on the recommendation encrypting your personal devices.

What a device holds

Before the impacts, an inventory. The amount of information on a computer or a phone is nearly always more than its owner expects.

CategoryWhat it includes
DocumentsWork, personal, tax and health files
Archived mailYears of correspondence, often downloaded locally
Photos and videosPersonal and family images, photographed documents
Saved credentialsPasswords stored in the browser and in apps
Active sessionsTokens giving access to services
HistoryBrowsing, searches, recent files
Backups of other devicesThe computer often holds the phone’s copy
Keys and certificatesAccess to company systems
Third parties’ dataClients, colleagues, family

Rows four and five carry the greatest immediate impact: credentials saved in the browser are in the clear on an unencrypted drive, and active sessions allow accounts to be entered without knowing them.

The seventh is the most underestimated: a computer serving as the archive for a phone’s backups holds both devices.

1. Confidentiality: complete access

A practical example

An unencrypted laptop is stolen. It has a strong sign-in password.

What the incident looks like

The password protects the system’s startup. It does not protect the drive, which can be removed and connected to another computer like any external storage.

At that point everything listed above is readable with nothing to get past. No skill is needed: it is the same operation used to recover data from a broken computer, and it is documented everywhere.

There is also a simpler route: starting the computer from external media, which bypasses the installed system and gives access to the drive.

With an encrypted drive, both routes produce the same result: unreadable data.

What to watch for

There is nothing: it is a condition, not an event. You check once and you know.

What to do

Check the state of encryption, which on computers is often off. And, where possible, reduce what the device keeps locally: mail read through the browser rather than downloaded in full reduces the exposed archive without taking anything from daily use.

2. Integrity: the silent modification

A less considered aspect and in some contexts more serious than reading.

A practical example

A device left unattended for a few hours — in a hotel room, in an office, during an inspection.

What the incident looks like

On an unencrypted archive it is possible not only to read but to write: to add a program that starts with the system, change a configuration, replace a file.

The device comes back to its owner apparently identical, and keeps working normally — with one difference that cannot be seen.

Encryption prevents that scenario because without the key nothing meaningful can be written into the archive.

It is the scenario specifically concerning anybody travelling with work devices, and the reason many organisations require encryption on laptops.

What to do

Encryption on, and — in the contexts that call for it — the device switched off, not just locked, when left unattended.

3. Availability: the other side of the coin

Here encryption has a cost, and it should be said honestly.

An encrypted archive with no recovery key is unrecoverable. If the code gets forgotten, if an update goes wrong, if the component holding the keys fails, the data is lost for good — for the owner too.

It is not a defect: it is correct behaviour. If there were a way to recover without the key, there would be one for anybody else as well.

SituationWith encryptionWithout encryption
TheftData protectedData reachable
A drive failureRecovery hard or impossibleRecovery often possible
A forgotten codeData lost without the keyAccess recoverable
DisposalSafeIt needs a careful wipe

The third row is why the recovery key is not a detail: it is what separates a protection from a trap.

AspectImpact of unencrypted data
ConfidentialityVery high: complete access to the archive
IntegrityHigh: the possibility of undetectable modification
AvailabilityEncryption introduces a risk, managed by the recovery key

The three states of a device

It is the distinction that decides everything, and it is worth fixing.

StateWhere the keys areThe data is
Switched offNot loadedUnreadable
LockedPartly removedLargely unreadable
On and unlockedIn memoryIn the clear

The third row is this recommendation’s limit, and it needs understanding properly: on an open device, encryption offers no protection at all. The keys are loaded because they are needed to make it work.

Two practical consequences follow:

Encryption and screen locking are the same defence in two parts. One makes the data unreadable, the other decides for how long it stays that way.

In risky contexts, switching off beats locking. A device that is off is in the state of maximum protection; one asleep keeps the keys in memory.

The case of external media

They deserve a mention because they are the most neglected point.

External drives, sticks and memory cards often hold complete copies of documents and backups. And they are, by size and use, the objects most easily lost.

MediumFrequency of lossTypical content
A USB stickHighWork documents, presentations
An external driveMediumComplete backups, photo archives
A memory cardHighPhotos, videos
The drive of a retired computerMediumYears of content, all of it

The last row describes a silent scenario: a computer sold or disposed of without a careful wipe. On an encrypted drive the problem does not arise; on an unencrypted one, a quick format is not enough.

Why a computer exposes more than a phone

A useful comparison, because people’s attention is nearly always on the phone while the greater risk is elsewhere.

AspectPhoneComputer
Encryption as standardYes, on recent modelsOften not
Isolation between applicationsStrongWeak
Saved credentialsIn the system keychainOften in the browser
Archived documentsFewMany, and for years
Mail downloaded locallyRarelyOften, the whole history
Backups of other devicesNoOften yes
Ease of removing the driveHardSimple

The right-hand column describes a device holding far more and protecting far less.

The paradox is that the perception of risk is inverted: people worry about the phone, which is the device best protected as standard, and overlook the laptop — which holds years of documents, the complete mail archive, the browser’s credentials and, often, the phone’s backup itself.

Hence this unit’s operational priority: if you have time to check one device, check the computer.

The exposure that lasts years: retired devices

A case involving no loss but producing the same exposure, and one almost nobody considers.

A replaced phone, a retired laptop, an external drive no longer used: they still hold all the content from the period when they were active.

DestinationWhat happens
ResoldThe content passes to a stranger
Given awayIt passes to somebody you know
Taken to a recycling pointIt passes into a chain you do not control
Left in a drawerIt stays reachable by whoever enters the house
Repaired or traded inIt passes to a commercial intermediary

On an encrypted device, none of these rows is a problem: a reset is enough, and even an imperfect wipe leaves unreadable data.

On an unencrypted one, a quick format is not enough: the data stays recoverable with common tools, and that is why anybody disposing of devices professionally uses specific wiping procedures.

The fourth row is the most frequent and the one nobody talks about: household drawers hold a remarkable number of old phones, each with photos, messages and accounts from a few years ago. They are not an immediate risk, but they are a forgotten archive — and in the event of a burglary, they are also the easiest haul.

A practical note for anybody with old, unencrypted devices they want to be rid of: the simplest route is not to wipe, it is to encrypt now and then reset. Turning encryption on makes what is there unreadable, and the reset afterwards removes the key.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that the sign-in password does not protect the drive
SkillsTelling the three device states apart and what they mean
Secure BehaviourSwitching off in risky contexts; encrypting external media

Reference level: FL2 — Beginner.

Summary

  • The password protects access to the system; the drive, removed, does not know it.
  • Saved credentials and active sessions are the most immediate exposure.
  • The data is unreadable when off and when locked, in the clear on an open device.
  • Encryption introduces a risk of being unrecoverable: the recovery key manages it.

One thing to do today. Check whether your computer is encrypted. If you do not know, it probably is not — and that is the most useful piece of information this unit can give you.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.