Additional resource for the lesson “Data Encryption: Already On, Worth Understanding” — Online Security course
Data encryption sounds like something you would have to set up. On a modern phone it is already running, tied to your unlock code. Knowing that changes what you do about the devices and drives where it is not.
A. Why this matters
Backup protects you from losing data. Encryption protects you from someone else reading it. They solve different problems and are worth having together.
The useful starting point is that much of this is already done. Modern phones encrypt their storage by default, and the key is derived from your unlock code. Recent laptops often do too, though not always, and not always with encryption switched on.
The key idea: if your device is encrypted, your unlock code is the encryption key. That is the real reason a longer code matters — it is protecting the data, not just the screen.
B. Key concepts
Six ideas, starting with what is already true.
Encryption
Transforming data so it can only be read with the right key. Without the key, it is unreadable rather than merely inaccessible.
Why it matters to you: This is the difference between a locked device and an encrypted one. A locked device might be opened another way; an encrypted one, without the key, has nothing readable to open.
Your unlock code is the key
On an encrypted phone or laptop, the code you type derives the key that decrypts the storage.
Why it matters to you: This connects two lessons that usually sit apart. The passcode resource is also, without saying so, a lesson about encryption strength.
Full disk encryption
The whole storage is encrypted rather than selected files.
Why it matters to you: Default on modern phones. On computers it is BitLocker on Windows and FileVault on macOS — often available and not always enabled. Worth checking.
Encrypted backups
The backup copy is encrypted too, whether on an external drive or in the cloud.
Why it matters to you: An unencrypted external drive in a drawer is a copy of everything, readable by anyone who picks it up. This is the most commonly overlooked gap.
End-to-end encryption in the cloud
Some services encrypt your files so that only you hold the key, and the provider cannot read them.
Why it matters to you: Worth knowing the distinction: most mainstream cloud storage encrypts in transit and at rest but can read your files. Whether that matters depends on what you store.
The recovery key
The code that recovers an encrypted device if you forget the password.
Why it matters to you: Every system generates one. Saving it somewhere safe is essential — encryption without a recovery route is how people lose data to their own protection.
C. A practical example: a laptop and a drawer
A laptop is stolen from a car. On it: work documents, photographs, saved browser sessions.
Without encryption
The password prevents signing in. It does not prevent removing the drive and reading it on another computer, which requires no special skill and takes minutes.
With encryption
The same drive, read elsewhere, contains nothing legible. The laptop is a financial loss and nothing more.
The drawer
In the same house is the external backup drive holding a copy of all the same files. If it is not encrypted, everything protected on the laptop is available there instead.
This is the gap worth closing: people encrypt the device they carry and leave the complete copy of it unencrypted at home.
D. Try it yourself: three checks
Twenty minutes across your devices.
Step 1 — Confirm your phone
- Modern iPhones and Android phones encrypt by default when a passcode is set.
- No passcode means no encryption. This is the connection between the two lessons.
Step 2 — Check your computer
- Windows: is BitLocker on? Some editions and devices have it, some do not.
- macOS: is FileVault on? It is offered at setup and often declined.
- If it is available and off, turning it on is a background operation you can start and forget.
Step 3 — Save the recovery key
- Whatever you enable will produce one.
- Save it somewhere that is not the encrypted device — printed, or in a password manager you can reach elsewhere.
Step 4 — Encrypt the backup drive
- Both Windows and macOS can encrypt an external drive.
- This is usually the largest gap and takes one setting.
Step 3 deserves emphasis. Encryption without a saved recovery key has locked people out of their own data more often than it has protected them from anyone else.
E. Videos, articles and further resources
Independent and institutional sources in English.
EFF — Keeping your data safe
The clearest independent explanation of device encryption and what it does and does not protect.
https://ssd.eff.org/module/keeping-your-data-safe
NCSC (UK) — Backing up your data
Backup and encryption belong together; this covers the other half.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/always-back-up-your-most-important-data
NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
FTC — Online privacy and security
Consumer-facing advice on protecting your identity, securing your home network and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security
CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
NCSC (UK) — Responding to a ransomware attack
What ransomware does and why a working backup is the thing that decides the outcome.
https://www.ncsc.gov.uk/section/respond-recover/ransomware-attack
Links checked in August 2026. For enabling encryption on your specific system, Microsoft and Apple document BitLocker and FileVault directly.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits at level FL3 on the Skills pillar. The concept is simple; the value is in checking what is actually enabled.
Skills
- Checking whether a device is encrypted.
- Enabling full disk encryption and storing the recovery key safely.
- Encrypting an external backup drive.
For professionals and organizations
- Requiring encryption on any device holding company data, and managing recovery keys centrally.
Awareness
- Understanding that the unlock code is the encryption key.
- Recognising that an unencrypted backup undoes an encrypted device.
- Knowing the difference between encrypted at rest and end-to-end encrypted.
For future instructors and ambassadors
- Connecting this to the passcode lesson explicitly. It is the moment where a longer code stops feeling arbitrary.
Secure Behavior
- Keeping a strong device code, because it protects the data and not only the screen.
- Encrypting backup drives as well as devices.
- Storing recovery keys somewhere independent of the encrypted device.
For organizations
- Treating a lost unencrypted device as a data breach, which in most jurisdictions it is.
G. Questions to sit with
- Is your laptop encrypted? Do you know how to check?
- Is your backup drive encrypted, or is it a readable copy of everything?
- Where is your recovery key? Could you reach it if the device would not start?
- Does the length of your device passcode look different now that it is also the encryption key?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database that relate to protecting data at rest.
The device
- R5 — A six-digit PIN at minimum, since it derives the encryption key.
- MS4 — An alphanumeric passcode of 8 characters or more where the device holds sensitive data.
- R7 — A short screen lock timeout, because encryption protects a locked device rather than an unlocked one.
The copies
- R19 — Keep periodic backups, and encrypt them.
- R2 — Store the recovery key in a password manager reachable from another device.
- R6 — Keep systems updated, since encryption depends on the software implementing it.
Minimum commitment: The unencrypted backup drive is the most common gap, and it takes one setting to close.
In short
- Your phone is almost certainly already encrypted, and your passcode is the key.
- Laptop encryption is often available and not always enabled — check.
- An unencrypted backup drive undoes an encrypted device.
- Save the recovery key somewhere other than the encrypted device.
Related resources in this course
The other half of protecting your data:
- Data Backup: The Only Protection That Works Afterwards
- Phone Passcode Security: Choosing the Right Unlock Method
- Device Lock: The Barrier Everything Else Sits Behind
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply