A laptop holds personal documents, work projects, correspondence, passwords and access to your accounts. If it is lost or stolen, the device itself can be replaced. It is much worse if a stranger gets access to the data.
This guide explains which measures really protect the data on a laptop, what each of them can and cannot do, and how to combine them.
Why a Windows password is not enough
A Windows password only protects signing in to Windows. It does not protect the files on the disk:
- the disk can be removed and connected to another computer;
- the laptop can be booted from a USB stick with another operating system;
- if the UEFI (BIOS) settings have no password, anyone can change the boot order.
In all these cases Windows does not start, so its password makes no difference. Reliable protection has three parts: a UEFI password, a boot password and data encryption.
1. UEFI (BIOS) password and no booting from USB
This first step is free. In the laptop’s UEFI (BIOS) settings:
- set an administrator (supervisor) password;
- disable booting from USB and other external devices, or put the internal disk first in the boot order;
- keep Secure Boot turned on.
Without the UEFI password nobody can change these settings, and booting the laptop from a USB stick becomes much harder.
2. A password before the operating system starts
Disk Password Protection asks for a password before the operating system starts:
- Windows will not boot without the correct password;
- the password is required even when the disk is booted in another computer, and even after the program has been uninstalled;
- in stealth mode no password screen is shown, and the computer looks frozen;
- individual partitions can be hidden: Windows and other programs will not see them until you remove the protection with the password;
- BIOS and UEFI, MBR and GPT disks, and Windows x86, x64 and ARM64 are supported, and the UEFI modules are signed with the Microsoft UEFI CA 2023 certificate.
It is important to understand what Disk Password Protection does not do. It does not encrypt data. If the laptop is booted from a USB stick, the password prompt does not appear, and hidden partitions can be found with data recovery tools. That is why a boot password should be combined with a UEFI password (step 1) and with encryption (step 3).
3. Data encryption
Encryption protects the data itself. Without the password or key, the contents of the disk look like random bytes, even when the disk is connected to another computer.
BitLocker
- built into Windows Pro, Enterprise and Education;
- encrypts the system disk and is fast;
- Windows Home has a simplified “Device encryption”, but only on compatible computers and with almost no settings;
- save the recovery key: without it you can lose access to the data after a hardware change or a firmware update.
VeraCrypt
A free, open-source program that can also encrypt the system disk. It is harder to set up, and beginners can easily make mistakes.
Cryptic Disk
Cryptic Disk encrypts data partitions, external drives, USB sticks and container files:
- transparent encryption: you mount an encrypted disk with the password and then use it like any other disk;
- hidden volumes inside encrypted ones, when you need to hide the very fact that the data exists;
- key files and security tokens instead of a password or together with it;
- hardware AES acceleration, so encryption hardly slows your work down;
- portable mode: the program runs without installation and leaves no traces in the system.
Cryptic Disk does not encrypt the system partition. It is more convenient to keep important data on a separate partition or in a container, and to encrypt the system disk with BitLocker if needed.
How to combine them
This setup works for most laptops:
- a UEFI (BIOS) password and no booting from USB;
- Disk Password Protection for the boot password and hidden partitions;
- BitLocker for the system disk and Cryptic Disk for data partitions, external drives and containers.
Short checklist
- Set a UEFI (BIOS) password and disable booting from external devices.
- Turn on a boot password.
- Encrypt the disks and containers with important data.
- Keep the BitLocker recovery key and a backup of the Cryptic Disk encryption key in a safe place, but not on this laptop.
- Use different long passwords.
- When travelling, shut the laptop down completely instead of putting it to sleep: in sleep mode the encrypted disks stay mounted and the encryption keys stay in memory.
Summary
No single measure stops every threat. A UEFI password keeps others out of the boot settings. Disk Password Protection stops the system from starting without the password and hides partitions. And encryption with Cryptic Disk or BitLocker protects the data even if the disk ends up in someone else’s hands.