A company laptop walks out the door every day at five o’clock. It rides home in a backseat, sits in a cup-holder at the coffee shop, gets tossed in checked luggage, and waits in a hotel room while the owner goes to dinner. Most of those laptops come back. Some do not. The ones that do not are the moment that decides whether your business has a lost-hardware problem or a full-blown data breach.
Encryption is the single setting that flips one of those into the other. With it on, a stolen drive is mathematically unreadable. Without it, the drive can be pulled out, plugged into another computer, and read like a USB stick. The strange part is that most small business owners assume their laptops are encrypted because the IT person said so once, the laptops came from a name-brand vendor, or BitLocker sounds like something Windows turns on by default. None of those assumptions hold up in the field.
This article walks through what an unencrypted laptop actually exposes, how full-disk encryption works in plain English, how to turn it on across every device your team carries, and what should happen in the first hour after a laptop is reported missing.
Why Does An Unencrypted Laptop Matter For A Small Business?
The risk on a small business laptop is not abstract. It is the same files that get opened on that screen during a normal workweek: customer records, tax returns, payroll files, contracts, banking logins saved in the browser, the local cache of email, Quickbooks data files, screenshots of insurance policies, photos of driver’s licenses sent by a vendor, a folder of HR documents the office manager keeps on the desktop. None of that is meant to leave the building. All of it does, every night, on a hard drive that goes wherever the laptop goes.
What Actually Happens When An Unencrypted Drive Walks Out
Without encryption, every file on the drive is stored in plain blocks. A Windows login password is not protection. Someone with the physical laptop can pull the drive in under a minute with a small screwdriver, plug it into a docking cradle, and read every file with no password challenge at all. They can also boot the laptop from a USB stick into a separate operating system and browse the drive without touching the user account. Both techniques are documented in public forums and walked through in YouTube videos for hobbyists. They do not require a professional thief, a clean room, or any special skill.
What The Breach Notification Laws Care About
All fifty states have a breach notification law, and most of them carve out an explicit safe harbor for data that was encrypted when it was lost or stolen. Florida’s Information Protection Act, for example, only counts a breach as a breach if the lost data was not encrypted, redacted, or otherwise unreadable. HIPAA treats encrypted devices as a presumption against breach reporting. The FTC Safeguards Rule lists encryption of customer information at rest as one of the required controls for financial institutions, accountants, and tax pros. Cyber insurance carriers ask whether laptops are encrypted on the renewal questionnaire, and the policy premium reflects the answer. None of that math works in your favor if a laptop is lost and nobody can prove the drive was encrypted at the time.
The Quiet Cost That Adds Up After A Lost Device
Lost-hardware research from the Ponemon Institute has held steady for years: the average cost of a lost laptop runs to tens of thousands of dollars once you add forensic review, customer notification, credit monitoring offers, regulator inquiries, and the staff hours spent rebuilding trust. Encryption does not eliminate that math, but it shifts the curve dramatically. A laptop that was encrypted is treated as recoverable hardware, not the long tail of a small business data breach that ends with sending letters to every customer whose record might have been on the device.
What Does Encryption Actually Do For The Data On A Laptop?
Full-disk encryption is the version that matters for a business laptop. It scrambles every block of the drive using a strong cipher and a key that lives in the laptop’s Trusted Platform Module, the TPM chip on the motherboard. When the laptop is powered off, the contents of the drive are mathematically unreadable. There is no shortcut. Without the key, the data is noise.
How The Login Step Fits In
When the laptop powers on, the TPM checks that nothing in the boot path has been tampered with, then releases the key. Windows or macOS finishes loading, and the user’s normal login screen appears. From that point on the user does not see anything different. The laptop runs at full speed, opens files normally, and connects to the network the way it always has. The encryption is doing its work silently underneath everything.
What Encryption Does Not Protect Against
Encryption is not a defense against a malware infection on a running laptop, a phished password that hands over the user’s account, or a logged-in laptop that gets stolen while the owner is in the bathroom of the coffee shop. The drive is unlocked the entire time the user is signed in. That is why encryption sits next to, not instead of, the rest of the security stack: strong authentication, modern threat detection on the endpoint devices that already run on every desk in the office, screen-lock timeouts measured in minutes, and a remote wipe capability for the worst case.
BitLocker, FileVault, And What Each One Needs
On Windows, full-disk encryption is called BitLocker. It is included in Windows 10 Pro, Windows 11 Pro, and the Enterprise editions. It is not included in Home editions, which means a laptop running Windows Home cannot be encrypted with BitLocker without changing the operating system edition first. On a Mac, encryption is called FileVault. It is included in every modern version of macOS, and the prompt to turn it on appears the first time a user sets up the machine, although it is easy to click past. The underlying cryptography on both platforms is strong enough to be accepted by federal agencies. The challenge is not the technology. It is the discipline of making sure every laptop in the company actually has it switched on.
How Do You Turn Encryption On Across Every Company Laptop?
The rollout is straightforward as a project, but only when the steps happen in the right order. The mistake most small businesses make is enabling encryption one laptop at a time, in a hurry, without escrowing the recovery key. That is the version where, six months later, a laptop reboots into BitLocker recovery mode after a Windows update and nobody can find the key.
Build A Real Inventory Of Every Laptop First
The inventory is the foundation. Every laptop the company owns or expects an employee to use for work needs a row: serial number, model, Windows or macOS edition, current user, encryption status, and recovery key location. Most small offices discover during this step that the inventory in their head is missing a few laptops, that two machines are running Home editions that need to be upgraded, and that one or two devices have never been logged into the corporate identity system. None of those gaps are fixable until they are visible.
Decide Where The Recovery Keys Live
Every encrypted laptop generates a recovery key. That key is the get-out-of-jail card when the TPM glitches, when a firmware update goes sideways, or when an employee forgets their Windows password. The right place to store recovery keys is the company’s identity provider: Microsoft Entra ID, the modern name for what used to be Azure AD, can hold the keys for every laptop joined to it, and an admin can look up the key in seconds. The wrong place is a spreadsheet on the office manager’s desktop. If recovery keys are not escrowed somewhere central before encryption is turned on, the rollout itself becomes the next outage.
Push Encryption Through Policy, Not One Laptop At A Time
Microsoft Intune, included in Microsoft 365 Business Premium, can require BitLocker on every enrolled Windows laptop, capture the recovery key into Entra ID, and report which devices are still non-compliant. Apple Business Manager and a mobile device management platform do the same job for Macs with FileVault. Pushing encryption through policy means the next laptop bought, the next laptop reimaged, and the next new hire’s machine all start encrypted on day one, with the recovery key already in the right vault. It also means the IT provider can produce a single report that lists encryption status for every device, which is the answer most cyber insurance questionnaires actually want.
Bake Encryption Into The Deployment Workflow
Once policy is in place, every new laptop should be encrypted at the workbench before it lands on a desk. Encryption status should be part of the joiner-mover-leaver workflow that brings each new hire onto the network properly, alongside the user account, MFA enrollment, mailbox provisioning, and the standard application set. By the time the laptop is handed to the employee, encryption is already on, the recovery key is already in Entra ID, and the asset register already shows compliant.
What Should Happen The Moment A Company Laptop Goes Missing?
The first hour after a laptop is reported lost or stolen is the hour that matters. The decisions made in that window determine whether the incident becomes a quick replacement order or a regulator-facing notification project. The script below is what a well-run small business runs through.
Confirm The Encryption Status From The Register, Not From Memory
The asset register, not the user’s recollection, is what gets quoted on the incident report. Look up the device serial, confirm it shows encryption enabled, and pull the timestamp on when the policy was last verified. If the register is missing or out of date, the incident has to be treated as worst-case until proven otherwise, which is the painful version. This is exactly why the inventory step from the rollout matters so much.
Trigger Remote Wipe And Revoke Sessions
Intune, Jamf, or whichever device management platform the company uses can send a remote wipe command that fires the next time the laptop checks in to the internet. While that is going out, the IT provider should revoke the user’s active session tokens, force a password reset, and disable any single-sign-on session that could still be alive on the missing device. The faster these run, the smaller the window an attacker has to log in even if they manage to bypass encryption.
Trigger The Written Response, File The Police Report, And Notify The Carrier
A lost laptop is an incident, and a small business with a written response for when a device goes missing or gets stolen handles the next steps from a checklist rather than from panic. The checklist includes filing a police report for stolen devices, notifying the cyber insurance carrier within the policy’s required window, and documenting what data was on the device and when. That documentation is the evidence packet that supports the encryption safe harbor under state breach laws, so it has to be written down at the time, not reconstructed weeks later.
Frequently Asked Questions
Is BitLocker Really Free, Or Is There A Hidden Cost?
BitLocker is included in Windows 10 Pro, Windows 11 Pro, and the Enterprise editions at no extra license cost. It is not included in Windows Home. A small business that bought laptops with Home editions to save fifty dollars apiece will need to upgrade those machines to a Pro edition before BitLocker can run, and that upgrade is the only direct cost. The bigger cost most companies hit is the management tooling, since pushing BitLocker policy and escrowing recovery keys cleanly is a Microsoft 365 Business Premium or higher feature.
What Is The Difference Between BitLocker And FileVault?
BitLocker is the Windows full-disk encryption feature, and FileVault is the macOS equivalent. The cryptography is comparable on both. The differences are operational. BitLocker integrates with Microsoft Entra ID and Intune for centralized policy and key escrow. FileVault integrates with Apple Business Manager and a mobile device management platform such as Jamf or Kandji. A mixed environment with both Macs and PCs needs both, which is normal and well supported.
Does Encryption Slow Down A Laptop?
On any laptop bought in the last several years, no, not in a way users notice. Modern Intel and AMD processors include hardware acceleration for AES, the cipher both BitLocker and FileVault use. Apple silicon chips have the same acceleration. The performance hit on day-to-day work is in the low single digits and is not visible during normal use. The exception is very old hardware with a slow spinning hard drive, which was already painful before encryption.
What About The Data On USB Drives And External Drives?
BitLocker To Go encrypts USB sticks and external drives on Windows. The same Intune policy that requires BitLocker on the laptop drive can also require BitLocker To Go on any removable media plugged into the device. On Macs, FileVault does not extend to external drives by default, so external drives used for business data should be encrypted separately, either with Apple’s Disk Utility or with hardware-encrypted drives. A small business that ships customer data on a USB stick to a vendor should make sure that stick is encrypted before it leaves the office.
If A Laptop Is Encrypted, Do We Still Have To Notify Customers When It Goes Missing?
Probably not, but the answer depends on the state and the industry. Most state breach notification laws and federal regulations such as HIPAA treat encrypted data as out of scope for notification, provided the encryption key was not lost along with the device and the encryption meets the standard the regulator specifies. That last clause is why documenting the encryption status, the cipher, and the key escrow at the time of the incident matters so much. Talk to the company’s legal counsel and cyber insurance carrier within the policy window, even when the device is known to be encrypted.
Can A Managed IT Provider See Encryption Status Across Every Laptop At Once?
Yes, that visibility is one of the practical reasons to centralize device management. Intune, Jamf, and the rest of the major device management platforms produce a single report showing every enrolled laptop, its encryption status, the date the policy was last evaluated, and where the recovery key is stored. A managed IT provider should be able to send that report on request, and if they cannot, that gap is itself the answer to the question of whether the program is healthy.
Does Encryption Protect A Logged-In Laptop That Someone Walks Off With Mid-Session?
No. While the laptop is powered on and the user is signed in, the drive is unlocked and the encryption is doing nothing to keep an opportunistic thief out of the data. That is why screen-lock timeouts measured in a few minutes, MFA on the account, and remote wipe capability are part of the same control set. Encryption protects the drive when the laptop is off or has been restarted. The other controls cover the gap when it is on.
Where Should You Start?
The fastest way to find out where the company stands is to ask for a written report listing every company laptop, its operating system edition, whether encryption is enabled, where the recovery key is escrowed, and the date the policy was last evaluated. If that report does not exist, building it is the first job, and the answers it surfaces become the rollout plan. O&O Systems handles that inventory, encryption rollout, and ongoing reporting for small businesses across the Treasure Coast as part of a hardware deployment and lifecycle program that ships every laptop encrypted before it lands on the desk, so the next missing laptop is a hardware replacement story and not a breach notification one.