Guides → Data & destruction

Is drive encryption enough when you dispose of a laptop?

· 5 min read

If every laptop in the business runs BitLocker or FileVault, it's reasonable to ask whether disposal still needs any care at all. The honest answer is that encryption does a lot of the work, but it isn't a method of disposal on its own, and relying on it that way leaves gaps.

What full-disk encryption protects against

BitLocker on Windows, FileVault on macOS and the encryption built into modern phones all scramble everything written to the drive using a key. Without the key, the data on the drive is unreadable. That's enormously valuable while a device is in use. If a laptop is lost on a train while switched off, the finder has an expensive paperweight rather than your client files.

It also matters for data protection law. When deciding how serious a lost device is, the ICO takes into account whether the data on it was protected by strong encryption. A lost encrypted laptop is a very different conversation from a lost unencrypted one.

NAND flash memory chip
Exhibit 01Encrypted or not, the data physically sits in chips like this onePhoto: maushammer, CC BY 2.0

Where the protection runs out

1. The key has to live somewhere

Most business BitLocker deployments keep the key in the laptop's TPM chip and unlock the drive automatically at start-up. That's convenient, but it means that when the device boots, the drive decrypts itself before anyone logs in. From then on, the data is protected by the Windows login and the security of the TPM rather than by the encryption alone. That's usually strong, but it's a different and weaker guarantee than "the data is unreadable".

2. Recovery keys exist on purpose

Every well-run deployment escrows recovery keys in Active Directory, Entra ID, an MDM platform or a password manager, so IT can get into a machine when something goes wrong. That's good practice, but it means the data remains recoverable by anyone who can reach those keys, for as long as they're kept. If a disposed-of laptop's recovery key is still sitting in your directory, the data on that laptop isn't gone. It's locked, and you still hold the key.

3. Not every device is actually encrypted

Encryption policy and encryption reality drift apart. There are machines built before the policy, ones where encryption was suspended for a firmware update and never resumed, desktops nobody thought to include, and loose drives pulled from servers. At disposal time, "we encrypt everything" needs to be true for every individual serial number, not just for the policy document.

4. Hardware encryption has had real flaws

Self-encrypting drives do the encryption inside the drive's own controller. In 2018, researchers at Radboud University showed that several widely sold SSDs with hardware encryption had implementation flaws, and on some of them the data could be recovered without the password. The vendors issued fixes and Windows changed its defaults. The lesson is that encryption is only as good as its implementation, and from the outside you usually can't verify the implementation.

Cryptographic erase: when encryption is the sanitisation

There's a legitimate technique built on all this. If a drive encrypts everything it stores, destroying the key, securely and in every place it exists, leaves the data permanently unreadable. NIST 800-88 recognises this cryptographic erase as a Purge technique, provided it's properly implemented. It's how phones are made safe by a factory reset, and it's why modern SSDs can be sanitised in seconds with a firmware command.

It works well as part of a process: run with tooling that confirms the command succeeded, records the drive's serial number, and is backed by deleting any escrowed copies of the key. What it can't give you is certainty about firmware you can't inspect. For that reason, the usual guidance is to use cryptographic erase for devices going back into service and physical destruction for high-sensitivity media at end of life.

Encryption at disposal: a checklist

  1. Confirm each device's encryption status by serial number, rather than assuming it from policy.
  2. Don't boot machines to "check them over" before disposal, because booting unlocks TPM-protected drives.
  3. Record which recovery keys belong to which serials, and delete them once destruction is certified.
  4. Sanitise or destroy the media anyway, with evidence per serial.

The sensible position

Treat encryption as the reason a lost laptop isn't a disaster, and as a helpful extra layer while devices are in transit to disposal. Don't treat it as the disposal itself. The media still needs sanitising or destroying with a method matched to its type (see degaussing, shredding or wiping), and the certificate should list each serial, so the recovery keys can be retired with confidence.

Encrypted fleet due for replacement? We never boot devices on collection, so TPM-protected drives stay locked all the way to destruction.

Talk to us

→ Next step

Ready to clear the cupboard?

Most collections are free. Tell us roughly what you have and where it is, and we'll come back with a date.