CYBER WELFARE

Protect your Digital Privacy

Encrypt your personal devices: the protection that acts afterwards

Every earlier recommendation exists to stop something happening. This one does something different: it makes sure that, when it happens, it does not count.

A lost or stolen device is an event no skill entirely prevents. Encryption decides whether that event is the loss of an object or the loss of everything the object held.

What this recommendation says

Recommendation R18 establishes that you should check data encryption is on across every device, and understand when it protects and when it does not.

Encryption turns stored data into a form that is unreadable without the correct key. On a device, that key is tied to the unlock code.

What it is not. It is not a program to install. On recent phones and tablets it is on by default; on computers often not, and that is where action is needed.

What it does not protect — and it should be said at once. Encryption protects a device that is switched off or locked. It does not protect a device that is on and unlocked: in that state the keys are in memory and the data is in the clear. It is why this recommendation depends entirely on the one about screen locking.

Scope. Phone, tablet, computer, and — a frequently forgotten point — external drives and USB sticks.

Why it matters

BenefitWhy it counts
It turns a theft into a hardware problemYou lose an object, not the data
It protects if the drive is removedExtracting an encrypted drive achieves nothing
It makes disposal safeA retired device exposes nothing
It protects third parties’ dataClients’, colleagues’, family members’ documents
It needs no maintenanceYou turn it on once and it always works
It does not slow daily useEncryption is handled by dedicated hardware

The last row removes the most common objection: on devices from recent years encryption has no perceptible cost in performance, because it is carried out by components designed for it.

The third row deserves a practical note: reselling or disposing of an encrypted device is far safer, because even an imperfect wipe leaves only unreadable data.

A concrete example

Helen has her bag stolen with her work laptop inside. The computer was switched off.

Whoever takes it can switch it on, format it and resell the hardware. They cannot read anything: without the password there is no way to reach the data, not even by removing the drive and connecting it elsewhere.

Helen loses an object and a few hours of unsaved work. No document leaves, no client has to be told, no report has to be made.

The same theft, with an unencrypted computer, would have meant complete access to all the content: documents, archived mail, credentials saved in the browser, client data.

The difference between the two scenarios is a setting turned on months earlier.

When to apply it

  • When setting up a new device. On computers it is the moment the option gets offered and often skipped.
  • On every laptop, which are the devices most likely to be lost.
  • Before a trip, when the exposure increases.
  • On external drives and USB sticks holding documents.
  • Before selling or disposing of a device.
  • On devices used for work, where the data is not only yours.
  • After a reset, because encryption does not always stay on.

How to apply it

  1. Check the current state. Do not assume it is on: on recent phones it is, on computers often not.
  2. On a phone: look in the security settings for the entry about encryption. If the device has an unlock code set, on recent systems the encryption is on.
  3. On Windows: check whether device encryption is on in the privacy and security settings. The professional editions offer a fuller tool.
  4. On macOS: System Settings → Privacy & Security → look for the disk encryption entry and turn it on if it is off.
  5. On Linux: encryption is normally set up at installation; adding it afterwards is more complex.
  6. Keep the recovery key. It is the most important step and the most neglected: without it, a startup problem makes the data unrecoverable even for you.
  7. Encrypt external drives too. Every system offers this, and they are the media most easily lost.

Common mistakes to avoid

  • Assuming it is on. On computers it often is not, and nothing flags it.
  • Not keeping the recovery key, or keeping it on the same device it protects.
  • Using a weak unlock code. Encryption is as strong as the key protecting it: a four-digit passcode weakens everything else.
  • Thinking it protects a device that is on. It does not, and it is the most important misunderstanding in this unit.
  • Overlooking external drives and sticks. They often hold complete copies of documents.
  • Confusing device encryption with message encryption. They are different things: the first protects data at rest, the second data in transit.
  • Not redoing the check after a reset.

The recovery key: the step not to skip

It deserves a section because it is the point where this recommendation can turn against you.

If something goes wrong — a problematic update, a fault, a forgotten code — encrypted data is unrecoverable without the recovery key. No support service can help: it is encryption working correctly, not a defect.

Where to keep it:

PlaceSuitable?
In the account linked to the deviceYes, it is the default option
In your password vaultYes, if it is on another device
Printed and kept at homeYes, simple and effective
On the same deviceNo: unreachable exactly when needed
In a file on the desktopNo
Never saved at allNo: it is the greatest risk in this unit

It is worth doing before you need the key, because at the moment it is needed the device does not start.

What encryption protects and what it does not

Since the main misunderstanding concerns precisely this, the boundaries are worth setting out in full.

SituationProtected?
A device stolen switched offYes, completely
A device stolen lockedYes, largely
A drive removed and connected elsewhereYes, completely
A computer started from an external stickYes, completely
A device retired or resoldYes
A device stolen on and unlockedNo
A device asleepNo: the keys are in memory
A backup on an unencrypted external driveNo
Data synced to the cloudNo: it depends on the service
Data in transit over the internetNo: connection encryption protects that

The last four rows are the limits to know.

The row about sleep is the most surprising: a laptop that is closed but not switched off keeps the keys in memory. It is often treated as equivalent to switched off, and it is not.

The row about backups is the one that most often undoes the whole recommendation: encrypting the computer and leaving the backup drive in the clear means protecting one copy and not the other.

The link with the other recommendations

This unit closes Phase 1, and it is the point where the sequence can be seen whole.

RecommendationWhat it doesWhen it acts
Unique passwords, a vault, a second factorThey prevent access to accountsBefore
Updates, permissions, networksThey reduce the opportunitiesBefore
Screen lockingIt closes the window of exposureDuring
Login alertsThey shorten the time to discoveryDuring
EncryptionIt makes what was taken uselessAfterwards

It is the only measure in the series sitting in the third column, and that makes it complementary to all the others rather than an alternative.

And it has a property none of the others has: it requires nothing of you at the moment it is needed. The others depend on behaviour — checking, recognising, reacting. Encryption works even while you do not know it is working.

How this connects to the Cyber Welfare Framework

PillarHow it contributes
AwarenessUnderstanding that it protects a locked device, not an open one
SkillsChecking the state and keeping the recovery key
Secure BehaviourSwitching the device off when it is left unattended for a long time

Digital maturity levels.

  • FL1 — Basic. The encryption state is unknown, there is no recovery key.
  • FL2 — Beginner. Encryption checked and on for the main device.
  • FL3 — Autonomous. On across every device, the key kept somewhere safe and separate.
  • FL4 — Skilled. External drives encrypted; you know the device has to be switched off, not just locked, in risky situations.
  • FL5 — Expert-Guide. You help others check it — particularly on computers, where it is often off.

R18 closes the circle with R5 and R7: the unlock code protects access, the automatic lock decides when, encryption makes getting around them pointless.

How to check you are applying it correctly

  1. Can I say for certain whether my computer is encrypted?
  2. Where is the recovery key, and could I reach it if the device would not start?
  3. Is the external drive holding my backups encrypted?

Quick checklist

  • ☐ Encryption checked on the phone
  • ☐ Encryption checked and on for the computer
  • ☐ The recovery key kept somewhere separate and reachable
  • ☐ A strong unlock code (not four digits)
  • ☐ External drives and sticks holding documents encrypted
  • ☐ I know the protection applies with the device off or locked
  • ☐ The check redone after the last reset

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

Encryption is the only recommendation in this series that prevents nothing. It acts afterwards, and it turns a serious event into an inconvenience.

It costs one setting, it slows nothing, and it needs no maintenance. The only step requiring attention is the recovery key, which has to be kept before it is needed.

And one thing should be kept in mind above all: it protects a device that is switched off or locked. On one that is on and open, the protection is suspended — and it is why this recommendation and the one on screen locking hold each other up.

Something to think about. If your computer disappeared right now, could you say for certain whether whoever finds it can read your files?

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.