You are standing at a hotel front desk in a city you flew into three hours ago, patting your shoulder where the laptop bag should be. The car pulled away eight minutes ago. The app says the driver is already two miles east and has picked somebody else up. Your laptop is in that back seat, in a black bag that looks like every other black bag on earth.

What happens next splits into two very different stories, and which one you get was decided weeks ago by settings that were either turned on or were not. In the first story you file a report, order a replacement, and are back to work by lunch tomorrow. In the second you are on the phone with an attorney, drafting letters, and explaining to a customer in Flower Mound why their files were riding around in the back of a stranger’s sedan. The gap between those two stories is not luck. It is about twenty minutes of configuration.

Quick note before we go further. This article touches on notification laws, and it is general information rather than legal advice. Your specific obligations depend on your industry, your contracts, and the kind of data you hold, so bring an attorney into that conversation.

What Actually Decides How Bad This Is

Two questions determine everything. Was the drive encrypted, and was the machine actually shut down or locked when it left your hands. Almost every other detail is noise next to those two.

Full disk encryption means the entire contents of the drive are scrambled and stay that way until someone supplies the right key. Somebody can unscrew the case, pull the drive out, and plug it into another computer, and what they get back is static. The files are physically there and completely useless. The laptop becomes worth exactly what a used laptop is worth, and nothing more.

Encryption Turns A Data Breach Into A Hardware Loss

This is not just a comfortable feeling. It shows up in the actual rules.

Texas defines a breach of system security in Chapter 521 of the Business and Commerce Code as the unauthorized acquisition of computerized data, and it specifically includes encrypted data when the person accessing it holds the key needed to decrypt it. Read that from the other direction and the logic is clear. Encrypted data with the key still safely in your possession is not the same event as a folder of readable customer records walking out the door.

Healthcare says it even more directly. The U.S. Department of Health and Human Services, the agency known as HHS, runs the breach notification rule under HIPAA, the federal health privacy law. Its guidance identifies encryption as a way to render health information unusable, unreadable, and indecipherable, and states that organizations that secure information as specified are relieved from providing notifications following a breach of that information.

So the practical difference between the two stories at the front desk is this. In one, you have a purchase order and an insurance claim. In the other, you have a legal obligation, a set of letters to write, and a conversation with every client whose data was on that machine. Same stolen laptop. Different setting.

Turning It On Properly, On Windows And On Mac

  • Windows Pro and above get BitLocker. BitLocker is Microsoft’s full volume encryption feature, and it is included in the Pro, Enterprise, and Education editions of Windows. On business machines this is what you want, because it can be managed centrally and the recovery keys can be stored where your IT team can find them.
  • Windows Home gets Device Encryption, with a catch. Microsoft turns Device Encryption on automatically on qualifying hardware, which sounds like the problem is solved. But its own documentation explains that the drive starts out protected by what it calls a clear key, and only becomes genuinely protected once the recovery key gets backed up to a Microsoft account, to Entra ID, or to Active Directory. A machine signed in with only a local account can sit there looking encrypted in the Settings screen while offering far less protection than you assume. Go check the ones your team is actually carrying.
  • Macs encrypt by default, but FileVault is still the switch that matters. Apple says that on a Mac with Apple silicon or a T2 security chip, the data is encrypted automatically. It also says that turning on FileVault is what keeps someone from decrypting or accessing your data without entering your login password. The hardware locks the door. FileVault is what makes the key yours.
  • Put the recovery keys somewhere that is not the laptop. Apple’s warning is unusually blunt about this. Forget the login password, lose the recovery key, and your files are gone permanently. Store recovery keys in your password manager or with your IT provider. A sticky note in the laptop bag defeats the entire exercise.

Sleep Is Not Off

Here is the part that gets glossed over in most advice, and it is the difference between encryption that works and encryption that just makes you feel better.

Full disk encryption protects data at rest. At rest means powered off. When a laptop is asleep with the lid closed, it is not at rest. The decryption key is still held in memory, and the machine is one trackpad wiggle away from a login screen. If nothing on that machine requires a password to wake it, that trackpad wiggle lands the finder directly on your desktop, encryption and all.

  • Require a password immediately on wake. Not after five minutes, not after fifteen. Immediately. This is one checkbox on both operating systems and it is the single highest value setting in this article.
  • Set a short screen lock timeout. A couple of minutes of idle time is plenty. It is briefly annoying at your desk and enormously valuable in an airport lounge.
  • Actually shut down for long stretches. Before a checked bag, before a long car ride, before anything where the laptop will be out of your sight for hours. A powered-off encrypted laptop is genuinely just an object.
  • Use a real login password. That password is what protects the decryption key. A four digit PIN on a machine holding client data is not a serious answer.

Remote Wipe Is The Second Layer, Not The First

Remote wipe is the feature everybody asks about first. Find My on Apple devices, Find My Device on Android, and management tools like Microsoft Intune for a fleet of Windows machines all let you send a command that erases a device you no longer have.

It is worth having, and it has one honest limitation. A remote wipe only executes when the device connects to the internet and receives the command. Somebody who never powers the machine on, or who pulls the drive out and reads it in another computer, never gets that message. Encryption does not care. It protects the data whether or not the laptop ever phones home again. Set up both, but understand which one is doing the heavy lifting.

One more thing about wipe that people underrate. The most valuable emergency action is usually not erasing the disk. It is signing the device out of your accounts. Your logged-in browser sessions to email, file storage, and your customer database are live access that does not need your password at all. Revoking those sessions from Microsoft 365 or Google Workspace takes a minute and closes the door that actually matters.

The First Hour

  1. Mark it lost and try to locate it. Lost mode on Apple and Android devices locks the screen and displays a contact message. Plenty of laptops and phones come back from rideshare drivers who simply want to return them.
  2. Revoke the sessions. Sign that device out of every business account from your admin console or your own account settings. Do this before you do anything else technical.
  3. Change the passwords that lived in the browser. Anything saved in the browser’s own password feature should be considered exposed. This is also a good argument for not using it.
  4. Issue the remote wipe. Then leave it queued. If the machine ever comes online, the command runs.
  5. Write down what was on it. Not from memory a week later. Now, while it is fresh. This list is what your attorney and your insurance carrier will ask for first.
  6. Tell your IT provider and your insurer. Both are far more useful in hour one than in day three.

The Bottom Line

Laptops get left behind. It happens to careful people in every business in Denton County, usually at the end of a long travel day when the brain is running on fumes. You cannot prevent it reliably, so the goal is to make it boring. Encrypt the drive, lock the screen on wake, keep the recovery key somewhere else, and set up remote wipe as backup. Do those four things and a stolen laptop costs you the price of a laptop.

And again, since this touches legal ground. The above is general information, not legal advice. Talk to an attorney about what your specific business is required to do.

If you are not certain whether every machine in your company is actually encrypted, that is a fair thing to be unsure about, and it is a short project to fix. We can audit it, turn on what is missing, and get the recovery keys stored where you can find them. Reach out at https://harrisonward.com/contact/.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).