Disk encryption protects a laptop that has been lost or stolen. It does almost nothing for a laptop that is switched on and logged in, and confusing the two is how it ends up carrying more weight than it can hold.
The short answer
Disk encryption, often called full disk encryption or FDE, encrypts an entire drive so its contents are unreadable without the key. On a managed fleet it is enforced centrally through BitLocker on Windows and FileVault on macOS, with recovery keys escrowed by the organisation. Its threat model is physical: a device that leaves the building in someone else’s hands.
That narrow scope is the whole point of the control, and also the source of every misunderstanding about it.
On this page
Disk encryption in three states
Whether the control is doing anything depends entirely on the state of the machine at the moment something goes wrong.
Encryption without screen lock is half a control
A stolen laptop is far more often taken from a desk or a cafe table than from a locked cupboard, which means it is frequently taken awake. Disk encryption only engages once the machine reaches a powered-off or locked state, so a short screen lock timeout and a requirement for credentials on wake are what actually make the control operate in the real theft scenario. Auditors increasingly sample both together for this reason.
Disk encryption and encryption at rest
Related, frequently conflated on questionnaires, and answering one when asked about the other is a common way to stall a review.
| Disk encryption | Encryption at rest | |
|---|---|---|
| What it covers | The whole volume on a physical machine | Data in databases, object storage, backups and snapshots |
| Threat it addresses | Physical loss or theft of the device | Unauthorised access to stored data in infrastructure |
| Where it runs | Laptops, desktops, servers | Cloud services and managed storage |
| Who enforces it | The endpoint agent and OS | Cloud provider configuration and application design |
| Typical evidence | Fleet coverage report showing encryption on per device | Configuration state for each store, plus key handling |
A buyer asking whether you encrypt customer data at rest is asking about your infrastructure. A buyer asking whether employee laptops are encrypted is asking about disk encryption. Both appear on most security questionnaires, usually in different sections.
What auditors actually check
| What they ask for | Why it fails |
|---|---|
| Fleet coverage report | A handful of devices show as unencrypted, usually contractor or older machines nobody enrolled |
| Recovery key escrow | Keys sit with individual users rather than the organisation, so the company cannot recover its own data |
| Enforcement mechanism | Encryption was enabled by hand at setup and there is nothing preventing a user turning it off |
| Screen lock policy | Set to a length that means a stolen machine is almost always taken unlocked |
| Exception list | Exceptions exist with no owner, no expiry and no record of who approved them |
| Decommissioning evidence | No record of what happened to drives in devices that left the fleet |
Coverage is the recurring theme. Enabling disk encryption is trivial; proving that every in-scope device has it on, that nobody can switch it off, and that the organisation holds the recovery keys, is the part that takes work and the part that gets sampled.
Where frameworks require disk encryption
| Framework | What it expects |
|---|---|
| PCI DSS | Cardholder data rendered unreadable wherever stored, with documented key management |
| ISO 27001 | Annex A controls for use of cryptography, storage media and endpoint devices |
| SOC 2 | Protection of data on endpoints, evidenced as operating throughout the observation window |
| HIPAA | Encryption as an addressable specification, meaning implement it or document why not |
| DPDP Act | Reasonable security safeguards over personal data, including on the devices holding it |
| RBI and SEBI frameworks | Encryption of sensitive data on endpoints for regulated entities, with central enforcement |
Several breach notification regimes also treat encryption as a mitigating factor. A lost device that was encrypted, with keys held separately, is a materially different disclosure conversation from a lost device that was not.
How Osto handles disk encryption
Disk encryption is enforced from the same agent as the rest of the endpoint stack, alongside antimalware and application control, device control and screen lock policy. Because screen lock sits in the same policy set, the gap described above closes as one configuration rather than two teams agreeing on a standard.
Coverage reporting is the output that matters. Every enrolled device shows encryption state in one view, so the answer to an auditor or a buyer is a report rather than a spreadsheet somebody maintains by hand. That evidence maps into SOC 2, ISO 27001 and PCI DSS from one control set and feeds the GRC evidence base directly.
Platform walkthrough
Coverage you can hand to an auditor
Encryption and screen lock enforced from the same agent that runs antimalware, device control and file access policy, with fleet coverage in one view. One owner, one dashboard.
Book a demoFleet coverage reporting · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is disk encryption?
Encryption of an entire drive so its contents are unreadable without the key. It is implemented through BitLocker on Windows and FileVault on macOS, and on a managed fleet it is enforced centrally with recovery keys held by the organisation rather than the user.
Does disk encryption protect against malware or ransomware?
No. On a running, logged-in machine files decrypt transparently, so software with access to the operating system sees plaintext. Disk encryption addresses physical loss and theft. Malware is the job of endpoint protection and EDR.
What is the difference between disk encryption and encryption at rest?
Disk encryption covers the whole volume on a physical machine and addresses device theft. Encryption at rest covers data held in databases, object storage and backups, and addresses unauthorised access within infrastructure. Questionnaires ask about both, usually in different sections.
Do we need it if the laptop has a strong password?
Yes. Without encryption, the drive can be removed and read on another machine, where the original password is irrelevant. The password protects the running session. Encryption protects the storage itself.
What evidence do auditors want?
A fleet coverage report showing encryption state per device, proof that it is centrally enforced rather than manually enabled, evidence that recovery keys are escrowed by the organisation, screen lock policy, and an exception list with owners and expiry dates.

