How to Turn On Full-Disk Encryption (BitLocker and FileVault) for Your Small Business

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

A laptop left in a rental car is an annoyance. A laptop left in a rental car with unencrypted client files, saved browser logins, and a synced mailbox is a reportable incident. The only difference between the two is a setting that takes a few minutes to turn on.

That setting is full-disk encryption, and it is one of the highest-value, lowest-cost protections a small business can deploy. Here is what it does, how to switch it on for Windows and Mac, and the mistakes that leave businesses exposed.

Why disk encryption matters more than you think

Without encryption, anyone can pull the drive out of a laptop, plug it into another computer, and read every file, no password needed. Signing in to Windows or macOS does not prevent that, because the login screen guards the operating system, not the data underneath.

Encryption closes that gap. It is also a legal safety net: under California's data breach notification law, properly encrypted data that is lost generally does not trigger notification duties. Cyber insurers ask about it on renewal, and it appears on most customer security questionnaires and in HIPAA risk reviews. If you want to know what to do in the first hour after a device goes missing, read our lost or stolen laptop checklist.

1. Inventory your devices first

You cannot encrypt a laptop you forgot you own. Start with a simple asset list of every laptop, desktop, and external drive that holds business data, including the owner's personal Mac and the sales rep's old spare. Then check each one:

  • Windows: open Settings, then Privacy & security, then Device encryption (or search for "Manage BitLocker"). It should say the drive is protected.
  • Mac: open System Settings, then Privacy & Security, then FileVault. It should say FileVault is on.

If staff use personal devices for work, your BYOD policy should require encryption too.

2. Turn it on and back up the recovery keys

On Windows 11 Pro, BitLocker uses the computer's TPM chip, so the drive unlocks automatically for the real user and stays locked if moved to another machine. On a Mac, FileVault ties the encryption to the user's password. Both take minutes to enable, and the drive encrypts in the background while people keep working.

The step most people skip is the recovery key. If a motherboard fails or a firmware update trips BitLocker, the device asks for a long recovery key, and without it the data is gone for good. Save keys to a place you control:

  • Windows: back keys up to Microsoft Entra ID or Active Directory, not just a sticky note or the user's own Microsoft account.
  • Mac: escrow the FileVault key through your mobile device management tool or Apple Business Manager setup.

Treat these keys like privileged credentials: limit who can see them and log access.

3. Verify it and make it the default

Encryption that is on for nine of ten laptops is not a policy. Pull a status report monthly, or have your IT provider do it, and flag any device that is off or whose key is not escrowed. Make encryption part of the standard new device setup and the onboarding checklist, and reclaim or wipe devices properly during offboarding.

Remember the limits. Encryption protects a device that is off or locked. It does nothing against malware or stolen passwords on a running machine, so pair it with endpoint detection, multi-factor authentication, and tested backups.

Common mistakes to avoid

  • Encrypting the laptop but not the external USB drive full of client files.
  • Turning on BitLocker without escrowing recovery keys.
  • Running Windows 11 Home and assuming device encryption equals managed BitLocker.
  • Leaving devices on Windows 10 after support ends. See our Windows 10 deadline guide.
  • Skipping the reporting step, so nobody notices the one laptop that never finished encrypting.

The takeaway

Full-disk encryption is a quiet protection: when it works, nothing happens, which is exactly what you want after a laptop goes missing. Inventory your devices, turn on BitLocker and FileVault, escrow every recovery key, and check the status each month. An afternoon of setup can turn your next lost laptop from a breach notification into a replacement purchase.

Frequently asked questions

What is full-disk encryption?

Full-disk encryption scrambles everything stored on a laptop or desktop so it can only be read after the user signs in or supplies a recovery key. If the device is lost or stolen, the thief gets a locked drive instead of readable files.

Is BitLocker included with Windows 11 Pro?

Yes. BitLocker is built into Windows 11 Pro, Enterprise, and Education. Windows 11 Home has a simpler feature called device encryption on supported hardware, but it lacks the central management and key escrow that businesses need, so most small businesses should use Pro.

Does FileVault slow down a Mac?

Not noticeably. Modern Macs encrypt the internal drive in hardware at all times, and FileVault ties that encryption to the user's password. Turning it on is a settings change with no meaningful performance cost.

What happens if I lose the BitLocker recovery key?

If the device cannot start normally and the recovery key is gone, the data is unrecoverable. That is why keys must be backed up to Microsoft Entra ID, Active Directory, or a managed IT system before encryption is considered done.

Does encryption protect me from ransomware or phishing?

No. Encryption protects data on a device that is powered off or locked and in the wrong hands. It does not stop malware or stolen passwords on a running, signed-in machine, so it works alongside endpoint protection, multi-factor authentication, and backups.

Want every laptop encrypted and the keys safely stored?

Ghosxt turns on and verifies BitLocker and FileVault across your devices, escrows the recovery keys, and reports on it every month. You talk directly to the owner. See current pricing or our cybersecurity services.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501