A device without encryption is not a device protected by a password: it is an archive with a door. The password governs normal access; the drive, removed and connected elsewhere, does not know it.
This post looks at what a device really holds, and what becomes reachable when the archive is not encrypted.
It expands on the recommendation encrypting your personal devices.
What a device holds
Before the impacts, an inventory. The amount of information on a computer or a phone is nearly always more than its owner expects.
| Category | What it includes |
|---|---|
| Documents | Work, personal, tax and health files |
| Archived mail | Years of correspondence, often downloaded locally |
| Photos and videos | Personal and family images, photographed documents |
| Saved credentials | Passwords stored in the browser and in apps |
| Active sessions | Tokens giving access to services |
| History | Browsing, searches, recent files |
| Backups of other devices | The computer often holds the phone’s copy |
| Keys and certificates | Access to company systems |
| Third parties’ data | Clients, colleagues, family |
Rows four and five carry the greatest immediate impact: credentials saved in the browser are in the clear on an unencrypted drive, and active sessions allow accounts to be entered without knowing them.
The seventh is the most underestimated: a computer serving as the archive for a phone’s backups holds both devices.
1. Confidentiality: complete access
A practical example
An unencrypted laptop is stolen. It has a strong sign-in password.
What the incident looks like
The password protects the system’s startup. It does not protect the drive, which can be removed and connected to another computer like any external storage.
At that point everything listed above is readable with nothing to get past. No skill is needed: it is the same operation used to recover data from a broken computer, and it is documented everywhere.
There is also a simpler route: starting the computer from external media, which bypasses the installed system and gives access to the drive.
With an encrypted drive, both routes produce the same result: unreadable data.
What to watch for
There is nothing: it is a condition, not an event. You check once and you know.
What to do
Check the state of encryption, which on computers is often off. And, where possible, reduce what the device keeps locally: mail read through the browser rather than downloaded in full reduces the exposed archive without taking anything from daily use.
2. Integrity: the silent modification
A less considered aspect and in some contexts more serious than reading.
A practical example
A device left unattended for a few hours — in a hotel room, in an office, during an inspection.
What the incident looks like
On an unencrypted archive it is possible not only to read but to write: to add a program that starts with the system, change a configuration, replace a file.
The device comes back to its owner apparently identical, and keeps working normally — with one difference that cannot be seen.
Encryption prevents that scenario because without the key nothing meaningful can be written into the archive.
It is the scenario specifically concerning anybody travelling with work devices, and the reason many organisations require encryption on laptops.
What to do
Encryption on, and — in the contexts that call for it — the device switched off, not just locked, when left unattended.
3. Availability: the other side of the coin
Here encryption has a cost, and it should be said honestly.
An encrypted archive with no recovery key is unrecoverable. If the code gets forgotten, if an update goes wrong, if the component holding the keys fails, the data is lost for good — for the owner too.
It is not a defect: it is correct behaviour. If there were a way to recover without the key, there would be one for anybody else as well.
| Situation | With encryption | Without encryption |
|---|---|---|
| Theft | Data protected | Data reachable |
| A drive failure | Recovery hard or impossible | Recovery often possible |
| A forgotten code | Data lost without the key | Access recoverable |
| Disposal | Safe | It needs a careful wipe |
The third row is why the recovery key is not a detail: it is what separates a protection from a trap.
| Aspect | Impact of unencrypted data |
|---|---|
| Confidentiality | Very high: complete access to the archive |
| Integrity | High: the possibility of undetectable modification |
| Availability | Encryption introduces a risk, managed by the recovery key |
The three states of a device
It is the distinction that decides everything, and it is worth fixing.
| State | Where the keys are | The data is |
|---|---|---|
| Switched off | Not loaded | Unreadable |
| Locked | Partly removed | Largely unreadable |
| On and unlocked | In memory | In the clear |
The third row is this recommendation’s limit, and it needs understanding properly: on an open device, encryption offers no protection at all. The keys are loaded because they are needed to make it work.
Two practical consequences follow:
Encryption and screen locking are the same defence in two parts. One makes the data unreadable, the other decides for how long it stays that way.
In risky contexts, switching off beats locking. A device that is off is in the state of maximum protection; one asleep keeps the keys in memory.
The case of external media
They deserve a mention because they are the most neglected point.
External drives, sticks and memory cards often hold complete copies of documents and backups. And they are, by size and use, the objects most easily lost.
| Medium | Frequency of loss | Typical content |
|---|---|---|
| A USB stick | High | Work documents, presentations |
| An external drive | Medium | Complete backups, photo archives |
| A memory card | High | Photos, videos |
| The drive of a retired computer | Medium | Years of content, all of it |
The last row describes a silent scenario: a computer sold or disposed of without a careful wipe. On an encrypted drive the problem does not arise; on an unencrypted one, a quick format is not enough.
Why a computer exposes more than a phone
A useful comparison, because people’s attention is nearly always on the phone while the greater risk is elsewhere.
| Aspect | Phone | Computer |
|---|---|---|
| Encryption as standard | Yes, on recent models | Often not |
| Isolation between applications | Strong | Weak |
| Saved credentials | In the system keychain | Often in the browser |
| Archived documents | Few | Many, and for years |
| Mail downloaded locally | Rarely | Often, the whole history |
| Backups of other devices | No | Often yes |
| Ease of removing the drive | Hard | Simple |
The right-hand column describes a device holding far more and protecting far less.
The paradox is that the perception of risk is inverted: people worry about the phone, which is the device best protected as standard, and overlook the laptop — which holds years of documents, the complete mail archive, the browser’s credentials and, often, the phone’s backup itself.
Hence this unit’s operational priority: if you have time to check one device, check the computer.
The exposure that lasts years: retired devices
A case involving no loss but producing the same exposure, and one almost nobody considers.
A replaced phone, a retired laptop, an external drive no longer used: they still hold all the content from the period when they were active.
| Destination | What happens |
|---|---|
| Resold | The content passes to a stranger |
| Given away | It passes to somebody you know |
| Taken to a recycling point | It passes into a chain you do not control |
| Left in a drawer | It stays reachable by whoever enters the house |
| Repaired or traded in | It passes to a commercial intermediary |
On an encrypted device, none of these rows is a problem: a reset is enough, and even an imperfect wipe leaves unreadable data.
On an unencrypted one, a quick format is not enough: the data stays recoverable with common tools, and that is why anybody disposing of devices professionally uses specific wiping procedures.
The fourth row is the most frequent and the one nobody talks about: household drawers hold a remarkable number of old phones, each with photos, messages and accounts from a few years ago. They are not an immediate risk, but they are a forgotten archive — and in the event of a burglary, they are also the easiest haul.
A practical note for anybody with old, unencrypted devices they want to be rid of: the simplest route is not to wipe, it is to encrypt now and then reset. Turning encryption on makes what is there unreadable, and the reset afterwards removes the key.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that the sign-in password does not protect the drive |
| Skills | Telling the three device states apart and what they mean |
| Secure Behaviour | Switching off in risky contexts; encrypting external media |
Reference level: FL2 — Beginner.
Summary
- The password protects access to the system; the drive, removed, does not know it.
- Saved credentials and active sessions are the most immediate exposure.
- The data is unreadable when off and when locked, in the clear on an open device.
- Encryption introduces a risk of being unrecoverable: the recovery key manages it.
One thing to do today. Check whether your computer is encrypted. If you do not know, it probably is not — and that is the most useful piece of information this unit can give you.
Related content
- Encrypting your personal devices — the recommendation this expands on
- Consequences of losing an unencrypted device — the concrete effects
- How device encryption works — why the states count
- How to turn on device encryption — what to do, in practice
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



