This unit is different from every other in the series, and it is worth saying at once: there are no signs to recognise.
An unencrypted device behaves exactly like an encrypted one. There is no clue, no symptom, nothing flagging it. It is a silent condition — and it stays one until something happens that makes it relevant, at which point it is too late.
What you can do, and what this post describes, is check it. It is a thirty-second operation, and it has to be done explicitly.
It expands on the recommendation encrypting your personal devices.
The direct check
It is the only reliable way. There are no shortcuts and there is nothing to deduce.
| Device | Where to look | What to look for |
|---|---|---|
| iPhone / iPad | Settings → Face ID/Touch ID & Passcode | The indication about data protection at the bottom |
| Android | Settings → Security | An entry about encryption or data protection |
| Windows | Settings → Privacy & security | The entry about device encryption |
| macOS | System Settings → Privacy & Security | The state of disk encryption |
| An external drive | Disconnect it and reconnect it | If it asks for a password, it is encrypted |
The last row is the simplest test in this unit: encrypted media always ask for something when connected. If it opens straight away, it is not.
The indirect clues
They do not replace the check, but they orient your expectation.
The device is recent and has an unlock code. On phones from recent years this is enough for encryption to be on. On computers it is not enough: the sign-in password and encryption are two separate things.
The computer starts without asking anything before the operating system. On some encrypted configurations a credential is requested at startup. It is not a reliable criterion, though, because many modern implementations do not do it.
The computer was updated from an earlier version. Encryption does not always get turned on during an update: often it stays as it was.
The device was reset. A reset can restore the configuration, and the check has to be redone.
The computer is an inexpensive or a few-years-old model. Some configurations do not offer the function as standard.
The computer is a company one. In many organisations encryption is imposed centrally, so it is likely to be on. “Likely” is not “verified”, though, and the settings screen answers in thirty seconds.
The device was set up by somebody else. A computer prepared by a family member or a shop follows the choices of whoever configured it, which often favour simplicity.
None of these clues is conclusive. They are reasons to check, not answers.
The moments to redo the check
Since there are no signs, the only alternative is tying the check to a few events.
| Event | Why |
|---|---|
| A new device | It is the moment the option gets offered and skipped |
| A reset or a reinstallation | The configuration may have gone back to default |
| A major system update | Rare, but worth a check |
| A change of drive | A new drive inherits nothing |
| Before a trip | It is the moment the protection counts most |
| Before selling or disposing | It changes how it has to be wiped |
| A new external drive | It is never encrypted out of the box |
The last two rows carry a practical note: an encrypted device is far simpler to retire safely, because even an imperfect wipe leaves unreadable data.
What is NOT a sign
| What | Why it indicates nothing |
|---|---|
| The computer asks for a password at startup | That is the user’s password, not encryption |
| The phone has face recognition | It concerns unlocking, not the archive |
| The device is fast | Modern encryption does not slow things down |
| The device is slow | The causes are elsewhere |
| I have never seen a recovery key | Possible on a device encrypted out of the box |
| The external drive opens straight away | This one is a sign: it is not encrypted |
The first row is the most widespread misunderstanding, and it is worth insisting: on a computer, the sign-in password encrypts nothing. It protects the session, not the archive — and the drive, once removed, does not know it.
The sign concerning the recovery key
There is a check going beyond the state of encryption, and it is just as important.
Do I know where my recovery key is?
If the answer is no, the situation is ambivalent: the data is protected from others, and potentially from you as well. In the event of a startup problem, there would be no way to recover it.
How to check:
- In the account linked to the device: look in the devices section for the entry about recovery keys;
- In your password vault: if you saved it there, search by the device’s name;
- Among your printed documents, if that was the route you chose.
If you do not find it in any of these places, most systems allow a new one to be generated from the encryption settings. It is a two-minute operation, and it closes the only serious risk in this recommendation.
What to do after the check
If encryption is on and the key is safe: you are done. It is one of the few recommendations in this series needing no maintenance.
If encryption is on but you do not know where the key is: generate a new one and keep it in two independent places.
If encryption is not on: turn it on. The procedure is in this unit’s practical guide, and it takes two clicks plus keeping the key.
If the device does not support it: consider reliable alternative tools, or — for anybody with limited needs — at least encrypt the folder holding important documents with a password-protected archive.
If the device is old and you will not use it again: turn encryption on before retiring it anyway, then perform a reset. It is the quickest and safest way to make what it holds unreadable, and it needs no dedicated wiping tools.
The device inventory: the complete check
Since the check has to be done explicitly, it is worth doing it once across everything rather than piecemeal.
The devices to include, in order of priority:
| # | Device | Why |
|---|---|---|
| 1 | The main computer | Often not encrypted, and it holds more |
| 2 | The laptop you take out | The highest probability of loss |
| 3 | The backup drive | It holds a copy of everything |
| 4 | The phone | Usually already encrypted, but check it |
| 5 | Sticks and external drives | Never encrypted out of the box |
| 6 | The tablet | Often forgotten |
| 7 | The desktop computer at home | Less exposed, but it holds a lot |
| 8 | Retired devices still in the house | They still hold everything |
The last row is the one almost nobody considers: an old phone or an old laptop in a drawer still holds the data from when it was in use. If it was not encrypted, that content is reachable by anybody who comes into possession of the object — including the person you will give or sell it to.
For retired devices the solution is twofold: if they were encrypted, a reset is enough; if they were not, a careful wipe is needed, or — if the device will not be reused — the physical destruction of the drive.
Once the inventory is done, maintenance comes down to one check when a new device arrives.
The other checks accompanying this one
Since checking encryption takes thirty seconds, it is worth doing it together with three others sitting in the same screens and forgotten in the same way.
The strength of the unlock code. Encryption is as strong as that code. If it is four digits, or a date, lengthening it is the quickest way to strengthen the whole protection without touching anything else.
The device-finding function. It allows a device to be located, locked and wiped remotely. It has to be turned on beforehand: after a loss it cannot be. It is complementary to encryption — the first makes the data unreadable, the second gives you options.
The second factor’s recovery codes. If the authenticator app is on the device you might lose, those codes are the only way back into your accounts. They have to be kept off that device.
The state of your backups. Encryption increases the risk of definitive loss in the event of a fault: a regular backup is the countermeasure, and it should itself be encrypted.
| Check | Where | Time |
|---|---|---|
| Encryption on | The security settings | 30 seconds |
| A strong code | The same screen | 1 minute |
| The device-finding function | The account settings | 30 seconds |
| Recovery codes | Account security | 2 minutes |
| An encrypted backup | The drive’s properties | 1 minute |
Five minutes in all, once. They are the five things that, together, decide what losing a device will mean — and none of them can be done afterwards.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that it is a silent condition, with no signs |
| Skills | Checking the state with certainty instead of deducing it |
| Secure Behaviour | Tying the check to recurring events |
Reference level: FL2 — Beginner.
Summary
- There are no signs: an unencrypted device behaves like an encrypted one.
- The only route is the direct check, which takes thirty seconds.
- The sign-in password is not encryption: on computers they are two separate things.
- The second check, just as important: do I know where the recovery key is?
One thing to do today. Connect an external drive or a stick you use for documents. If it opens without asking anything, it is not encrypted — and it is probably the medium you are most likely to lose.
Related content
- Encrypting your personal devices — the recommendation this expands on
- How to turn on device encryption — what to do if the check comes back negative
- How device encryption works — why there are no visible signs
- Impact of unencrypted data — what is at stake
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



