---
title: 'Disk encryption'
url: 'https://triplepoint.org.uk/security/devices/disk-encryption'
markdown: 'https://triplepoint.org.uk/security/devices/disk-encryption.md'
date: '2026-09-28'
description: 'Disk encryption for UK businesses. Encrypt Windows and Mac drives with centrally managed recovery keys, so a lost or stolen laptop does not become a data breach.'
---

# Disk encryption

The riskLaptops get left on trains, taken from cars and lost in airports. If the drive isn't encrypted, whoever ends up with it can read everything on it: customer records, emails and saved passwords.

A lost unencrypted laptop holding personal data may also have to be reported to the ICO as a data breach. An encrypted one usually doesn't turn into a breach at all.

 What it does- Switches on and manages the encryption already built into Windows (BitLocker) and macOS (FileVault)
- Recovery keys kept securely in the cloud console, so a locked-out user can be helped back in quickly
- Applied by policy, so new devices are encrypted without anyone having to remember
- Shows which devices are encrypted and which aren't, so you can prove it when asked
- The Windows agent installs with the standard device protection installer

 Who it's forAny business whose laptops leave the office, which today is most of them. It's especially worth having if you hold personal data, if your cyber insurer asks about encryption, or if you're working towards ISO 27001.

 How we supply itBy default we supply the licence and you (or your IT provider) deploy it. If you'd rather hand the whole job to us, we can configure and install it for you at our standard day rate — scoped and agreed with you up front, and invoiced separately.

 What's under the hood**Sophos Device Encryption** — manages Windows BitLocker and macOS FileVault from Sophos Fusion rather than adding an encryption engine of its own, so it uses what's already built into your devices.

 Questions Doesn't Windows already do this?+Windows and macOS include the encryption itself. What's usually missing is a way to switch it on consistently, keep the recovery keys somewhere safe, and see at a glance which devices are protected. That's what this adds.

 What if someone gets locked out?+An administrator can look up that device's recovery key in the console and get them back in.

 Does it encrypt USB sticks?+No. It covers the device's own drives. USB sticks and other removable devices can be controlled separately through device protection.

 Will staff notice any difference?+Very little. Once a drive is encrypted, people sign in and work as normal.

[← Back to Protect your devices](https://triplepoint.org.uk/security/devices)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Disk%20encryption) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Device and server protection](https://triplepoint.org.uk/security/devices.md)
- Previous: [Server & cloud workload protection](https://triplepoint.org.uk/security/devices/server-protection.md)
- Next: [Mobile device management](https://triplepoint.org.uk/security/devices/mobile-devices.md)
