ClearSecurity VISION
EN / RO
← All articles

Hardening · 10 July 2026 · 4 min read

BitLocker and automatic updates: secure your Windows machines in an hour

A lost laptop without encryption is a data breach. How to turn on BitLocker, where to store the recovery key, and how to make sure Windows updates itself.

ClearSecurity Vision

Two mundane risks account for a surprisingly large share of incidents at small companies: the lost or stolen laptop with unencrypted data on it, and the out-of-date computer an attacker walks through using a vulnerability that was published — and fixed — months earlier. Both close with tools Windows already ships: BitLocker for encryption and Windows Update for patching.

Without encryption, whoever finds the laptop can pull the disk and read everything: contracts, customer data, saved passwords. With BitLocker on, the disk is unreadable without the key — the loss stays a hardware expense instead of a reportable data breach.

What you need

  • Windows 10 or 11 Pro (the Home edition doesn’t have full BitLocker — it has “device encryption”, a simplified variant, and only when signed in with a Microsoft account)
  • Administrator rights on the machine
  • A TPM chip — present on virtually any computer from recent years
  • 15–20 minutes per machine; the encryption itself then runs in the background

Step 1: turn on BitLocker

  1. Press Start and search for “Manage BitLocker” (or Control Panel → BitLocker Drive Encryption).
  2. On drive C:, click Turn on BitLocker.
  3. The recovery key — the step that matters most, see the next section. Decide where you save it before moving on.
  4. When asked how much to encrypt: on a new machine choose Encrypt used disk space only (faster); on one that’s been in use for a while choose Encrypt entire drive — traces of deleted files can remain on disk.
  5. Leave Run BitLocker system check ticked, restart, and let encryption run in the background — you can work normally in the meantime.

Step 2: the recovery key, stored somewhere safe

If the motherboard fails or Windows detects a suspicious change, it will ask for the 48-digit recovery key. Without it, the data is gone for good — that is precisely the point of encryption.

Simple rules:

  • Save it to the company’s Microsoft/Entra ID account (the option in the wizard) or printed, in the office safe.
  • Never as a file on the same laptop or on a USB stick kept in the laptop bag — that’s taping the key to the door.
  • If you manage several machines, keep a register: which machine, where its key is, who has access.

Step 3: automatic updates

  1. Open Settings → Windows Update and make sure no updates have been sitting there for weeks. Install everything outstanding.
  2. Under Advanced options, enable Receive updates for other Microsoft products and leave automatic restarts on.
  3. Set Active hours to match the working day, so restarts happen outside it — that removes the main reason people postpone updates.
  4. Don’t forget the browser — it’s the most exposed application. Chrome and Edge update themselves, but only if the browser gets restarted now and then; the window that “has been open for three weeks” is running the version from three weeks ago.

More than 10–15 machines? Per-computer manual setup stops scaling — the natural next step is central management (Microsoft Intune or equivalent), where encryption and updates become policies applied automatically.

Verify the result

  1. Open a terminal as administrator and run manage-bde -status. For drive C: you should see Percentage Encrypted: 100% and Protection On.
  2. Confirm you can actually find the recovery key where you saved it — now, not during an emergency.
  3. In Settings → Windows Update, check the date of the last update: it shouldn’t be older than a month.

Common mistakes

  • The recovery key saved on the desktop. Surprisingly common. If the disk is encrypted, the file can’t be read exactly when you need it; if the laptop is stolen, the thief gets the key next to the door.
  • “I’ll install updates manually, when I have time.” You never have time; meanwhile, published vulnerabilities have public exploits. Automatic or not at all.
  • Only the laptops, not the USB sticks. Data leaves the company on USB drives too. For sticks and external disks there’s BitLocker To Go — same menu, same procedure.
  • Encryption on, record-keeping zero. With 20 machines and no key register, the first hardware failure becomes a lost day.

If you’re wondering what the alternative costs, we did the maths in what a security incident really costs.


Under NIS2? Data encryption and vulnerability management both appear among the law’s minimum measures.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.