This is the shortest guide in the whole series, for a precise reason: on phones there is almost nothing to do, and on computers it is a single setting.
The only step requiring attention — and it comes first — is keeping the recovery key.
It puts into practice the recommendation encrypting your personal devices.
Step 0 — The recovery key, before anything else
It has to be said at the start because it is the only way this recommendation can cause harm.
What it is. A code, usually long, generated when encryption gets turned on. It serves to unlock the archive when the normal method does not work — an update that went wrong, a fault, a forgotten code.
Why it is indispensable. Without it, in those situations, the data is lost for good. No support service can recover it: it is encryption working correctly.
Where to keep it:
| Place | Suitable? | Why |
|---|---|---|
| In the account linked to the device | Yes | It is the default option, and it works |
| In your password vault | Yes | If it is reachable from another device |
| Printed, kept at home | Yes | Simple and independent of everything |
| On another device | Yes | As long as it is not the one it protects |
| On the same device | No | Unreachable exactly when needed |
| Not saved at all | No | It is the greatest risk in this unit |
The best combination: in the account and printed. Two independent copies, neither of which depends on the device.
Step 1 — The phone
On iPhone and iPad: encryption is on automatically if you have set an unlock code. There is nothing to turn on.
To check: Settings → Face ID/Touch ID & Passcode. At the bottom of the screen you find the indication about data protection.
On Android: on devices from recent years encryption is on as standard. Check in Settings → Security, where you typically find an entry about encryption or data protection.
An important point for both: encryption is as strong as the code protecting it. A four-digit passcode weakens the whole protection, because that is the attackable point. Six digits or more, or an alphanumeric code, is the right choice.
Step 2 — The computer
This is where the work concentrates, because this is where it is often off.
On Windows
Check first: Settings → Privacy & security → Device encryption. If the entry exists and is on, you are done.
If it is off: turn it on from that screen. The system will ask where to save the recovery key: the linked account is the simplest and most reliable option.
If the entry does not appear: it depends on the system’s edition and the computer’s characteristics. The professional editions offer a fuller tool, reachable from the drive’s settings. On some home computers the function is not available: in that case reliable alternative tools exist, but they take more care.
On macOS
Check: System Settings → Privacy & Security → look for the disk encryption entry.
If it is off: turn it on from there. The system will ask how you want to be able to recover access, offering the linked account or a key to keep.
The first encryption takes time — from a few minutes to a few hours, depending on the size of the drive — but the computer stays usable during the process.
On Linux
Disk encryption is normally set up at installation, with an option in the guided procedure. Adding it afterwards is possible but complex: if the system is already installed without it, the simplest route is reinstalling with encryption on.
Step 3 — External media
It is the most neglected part and one of the most useful, because sticks and external drives are the objects most easily lost.
On Windows: right-click the drive and look for the option to turn encryption on. Here too a recovery key gets generated, to be kept.
On macOS: from the drive’s context menu it can be encrypted, or formatted as an encrypted volume. Careful: formatting erases the content, so the data has to be copied elsewhere first.
A simpler alternative for anybody who only has to protect a few documents: creating a password-protected compressed archive. It is less robust than full encryption, but it is immediate and works on every system.
Step 4 — The final check
It is worth making an explicit check instead of assuming.
| Device | How to check |
|---|---|
| Phone | Security settings, the data protection entry |
| A Windows computer | Settings → Privacy & security → Device encryption |
| A macOS computer | System Settings → Privacy & Security |
| An external drive | The icon shows a padlock, or the system asks for the password when connected |
The simplest test for external media: disconnect it and reconnect it. If it asks for a password, it is encrypted.
What to do afterwards
Three points of care completing the recommendation.
Strengthen the unlock code. Encryption is as strong as that code. If it is four digits, lengthening it is the quickest way to improve the protection of the whole device.
Turn on the device-finding function. It allows a device to be located, locked and wiped remotely. It is complementary to encryption: the first protects the data, the second gives you options if the device disappears.
Check the backups. Encryption increases the risk of definitive loss in the event of a fault. A regular backup — itself encrypted — is the countermeasure.
The most frequent objections
“It slows the computer down.” On devices from recent years encryption is handled by dedicated hardware components and the effect on performance is not perceptible. On very old computers there can be an impact, generally contained.
“If I forget the password I lose everything.” True, and it is exactly why step 0 comes before all the others. With the recovery key kept, the risk is managed.
“I have nothing important.” The archive holds saved credentials, active sessions, mail, photos and — almost always — other people’s data. It is nearly always more than you remember.
“My phone already has a code.” The code protects normal access. On most recent phones it also enables encryption, but on computers they are two separate things: the sign-in password encrypts nothing.
“It is complicated.” It is two clicks on both systems. The part requiring attention is where to save the key, and that is another two minutes.
“I have a company computer, the company takes care of it.” Often true, and it is one of the reasons organisations require it. A check is still worth it: the entry in the settings tells you in thirty seconds, and knowing how the device you use every day is configured is useful anyway.
“The first encryption takes hours.” On a computer, yes, if the drive is large, but it stays usable during the process: you can keep working. On recent phones the operation was already done at first switch-on.
Backups: the part that completes encryption
It has to be addressed because it is the point where this recommendation most often gets undone.
The problem. Encrypting the computer and keeping the backups in the clear on an external drive means protecting one copy and leaving the other reachable. And the backup drive holds exactly the same things.
What to do, depending on where you keep the backups:
| Where | What to check |
|---|---|
| An external drive | That it is encrypted: turned on from the drive’s properties |
| A cloud service | That the account has a strong password and a second factor |
| Another computer at home | That it too is encrypted |
| A network device | That it offers encryption, and turning it on |
The second row deserves a clarification: the protection of a backup in the cloud is not your device’s encryption, it is the security of that account. They are two distinct defences, and the first does not cover the second.
One last check, as important as the others. Encryption increases the risk of definitive loss in the event of a fault or a forgotten code. A regular backup is the countermeasure, and it is why this recommendation and good backup practice go together.
If one sentence were to stay: encrypt the device, and encrypt the copy too.
A particular case: old devices to be disposed of
If you have phones or computers at home no longer used and not encrypted, they still hold all the content from the period they were active.
The simplest procedure, and more effective than a wipe:
- Switch the device on and turn encryption on, if it supports it. The operation makes what is there unreadable.
- Then perform a factory reset. The reset removes the key, and with it any possibility of recovery.
- If the device does not support encryption, and it holds data you care about, the route is a careful wipe with dedicated tools — or, for a drive that will not be reused, physical destruction.
Before proceeding, two checks worth making:
- Disconnect the device from your accounts. A device still associated can cause complications for the new owner and stays in your list of linked devices.
- Remove the memory cards, which often stay inside and are untouched by a reset.
For an external drive or stick you want to reuse: formatting it as an encrypted volume is quicker and safer than any wipe, because from that moment everything written to it is already protected.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Checking the state and turning encryption on across every device |
| Secure Behaviour | Keeping the recovery key before needing it |
| Awareness | Knowing that encryption is as strong as the unlock code |
Reference level: FL2 — Beginner. The step to FL3 comes when it includes external media and the key kept in two places.
Summary
- Step 0 is the recovery key: without it, the protection can become a trap.
- On phones it is nearly always already on; on computers often not.
- Encryption is as strong as the code: four digits weaken everything.
- External drives and sticks are the most neglected point and the easiest to lose.
One thing to do today. Open your computer’s security settings and check whether encryption is on. If it is not, turning it on and saving the key takes five minutes — and it completely changes what losing that computer would mean.
Related content
- Encrypting your personal devices — the recommendation this guide comes from
- How device encryption works — why the recovery key exists
- Signs encryption is not enabled — how to check with certainty
- Impact of unencrypted data — what is at stake
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



