Somebody smashes a car window in a parking lot and takes the bag off the back seat. Your laptop is in it. That is a bad afternoon and an insurance claim. Whether it becomes anything worse depends on choices you made weeks earlier, on a quiet evening, when nothing was wrong.

The goal is simple: make a stolen device a hardware loss and nothing else. A thief gets a machine worth a few hundred dollars on a resale site and nothing at all from the inside of it. That is achievable with settings you already own and have probably never opened. Here is the short list, then what to do in the first hour.

Encryption Is the Whole Ballgame

Most people do not know this. Without encryption, your login password protects almost nothing. A thief does not have to guess it. They can pull the drive out, or start the computer from a different disk, and read your files directly. The password guards the front door. The files themselves sit there in plain form.

Full disk encryption scrambles everything on the drive so it is unreadable without the key. Apple describes FileVault as “an extra layer of security by keeping someone from decrypting or getting access to your data without entering your login password.” Microsoft describes Device Encryption as a feature “that enables BitLocker encryption automatically for the Operating System drive and fixed drives.” Same idea from both: without the key, the drive is noise.

  • Encryption is only as strong as your login password. If the password is short and obvious, the encryption politely opens for whoever guesses it. These are one control, not two.
  • The recovery key is not optional paperwork. Apple is blunt: if you turn on FileVault, forget your login password, cannot reset it, and also forget your recovery key, “you won’t be able to log in, and your files and settings will be lost forever.” Microsoft attaches a recovery key to the account you signed in with. Know where yours is.

How to Confirm It Is Actually On

Do not assume. Plenty of computers ship with encryption available but not switched on. Check today, and check every laptop in the house.

  • On a Mac. Open System Settings and look in the privacy and security area for FileVault. If it is off, turn it on and store the recovery key somewhere that is not the Mac.
  • On Windows. Open the Settings app and look in the privacy and security area for device encryption or BitLocker. Microsoft’s documentation notes the status shows there as a simple toggle.
  • Watch for the local account trap. Microsoft is specific: Device Encryption turns on automatically when you sign in with a Microsoft account or a work or school account, and “if you’re using a local account, Device Encryption isn’t turned on automatically.” Plenty of people who set up with a local account are quietly unencrypted.
  • Phones and tablets are usually fine. Modern phones encrypt by default once you set a passcode. The catch is the passcode. A four digit code you picked a decade ago is the weak link.
  • Encrypt the backup drive too. It holds a copy of everything. Both operating systems support that for removable drives.

A Real Password and a Screen That Locks Itself

Most laptop thefts are opportunistic. The device gets taken while it is awake, on a coffee shop table or a passenger seat, still logged in. Encryption does nothing for a machine that is already unlocked.

  • Use a login password you would not be embarrassed by. Long beats complicated. Three or four unrelated words are easy to type and hard to guess. Skip family names and birth years.
  • Set the screen to lock itself quickly. In your display or lock screen settings, check how long the machine waits before sleeping and whether a password is required on wake. Five minutes is reasonable. Many defaults are much longer, or never.
  • Learn the manual lock. Every operating system has a shortcut that locks the screen instantly. Use it every time you stand up. It becomes reflex in about a week.
  • Turn off automatic login. If your computer boots straight to the desktop with no prompt, the encryption is effectively decorative.

Set Up Find My Before You Need It

You cannot enable device tracking after the device is gone. Apple’s guidance for a lost or stolen Mac splits into two lists: what you can do if Find My was already on, and a much shorter list for when it was not.

Set up in advance, Apple describes seeing the device’s approximate location on a map, putting it in a lost mode that prevents access, and erasing it remotely, which Apple notes “deletes all of your data from your Mac.” Windows and Android offer equivalents through your account. Turn on whichever matches, today.

Why the Browser Saving Every Password Makes Theft Worse

This is the part that turns a hardware loss into an identity problem. Every time you click save password in your browser, you deposit another key into a vault that opens automatically whenever the computer is unlocked. Add a browser that stays signed in to your email, and a thief who catches the machine awake needs to crack nothing. They open the browser and walk through your life alphabetically.

  • Move passwords into a real password manager. It locks separately from the computer and needs its own password. Same convenience, one more door.
  • Set it to lock on its own. A manager that never re locks is a browser with extra steps. Set a short timeout.
  • Keep your second factor off that machine. If your login codes come from an app on the stolen laptop, the thief has both halves. A phone app, or better, a hardware key you carry separately, keeps them apart. Our post on what a YubiKey is explains how that works.
  • Clear the saved passwords out of the browser afterward. Importing them into a manager does not remove the originals. Delete them.

The Hour After It Happens

If it happens, work in this order. Speed beats thoroughness in the first hour.

  1. Open your device tracking service from a phone or another computer. Locate it if you can, then mark it lost so it locks.
  2. Change your main account password. Apple advises this to prevent anyone from reaching your cloud data. Do it whether or not tracking was on.
  3. Sign out of all sessions on your email. Anything still logged in on that machine gets kicked out. This is the highest value single step available.
  4. Change the passwords for anything financial. Apple’s guidance says to update other accounts including email, banking, and social media. Start with money.
  5. Erase it remotely once recovery looks unlikely. Wiping immediately ends your ability to track it, so give location a short window unless the data is truly sensitive.
  6. File a police report. Apple advises reporting a lost or stolen device to local law enforcement with the serial number ready. Insurance will want the report number, and so will your employer if it was a work machine. Your serial number lives in your account’s device list and on the original box. Write it down somewhere else today.

The Bottom Line

You cannot do much to prevent a break in. What you can control is what it costs. Encryption on, a real login password, a screen that locks itself, device tracking enabled in advance, and passwords living somewhere better than the browser. That is the whole list, and it takes about twenty minutes.

Do it once and a stolen laptop becomes a story about a broken car window. To go further on the accounts themselves, our comparison of hardware keys, passkeys, and standard multifactor authentication covers which second step holds up.

If you cannot tell whether encryption is on, or you are staring at a recovery key with no idea where to keep it, we are glad to walk you through it. We handle this for businesses across Denton County, and the personal version is the same checklist. Contact us today


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).