Hardening · 10 July 2026 · 4 min read
BitLocker and automatic updates: secure your Windows machines in an hour
A lost laptop without encryption is a data breach. How to turn on BitLocker, where to store the recovery key, and how to make sure Windows updates itself.
ClearSecurity Vision
Two mundane risks account for a surprisingly large share of incidents at small companies: the lost or stolen laptop with unencrypted data on it, and the out-of-date computer an attacker walks through using a vulnerability that was published — and fixed — months earlier. Both close with tools Windows already ships: BitLocker for encryption and Windows Update for patching.
Without encryption, whoever finds the laptop can pull the disk and read everything: contracts, customer data, saved passwords. With BitLocker on, the disk is unreadable without the key — the loss stays a hardware expense instead of a reportable data breach.
What you need
- Windows 10 or 11 Pro (the Home edition doesn’t have full BitLocker — it has “device encryption”, a simplified variant, and only when signed in with a Microsoft account)
- Administrator rights on the machine
- A TPM chip — present on virtually any computer from recent years
- 15–20 minutes per machine; the encryption itself then runs in the background
Step 1: turn on BitLocker
- Press Start and search for “Manage BitLocker” (or Control Panel → BitLocker Drive Encryption).
- On drive C:, click Turn on BitLocker.
- The recovery key — the step that matters most, see the next section. Decide where you save it before moving on.
- When asked how much to encrypt: on a new machine choose Encrypt used disk space only (faster); on one that’s been in use for a while choose Encrypt entire drive — traces of deleted files can remain on disk.
- Leave Run BitLocker system check ticked, restart, and let encryption run in the background — you can work normally in the meantime.
Step 2: the recovery key, stored somewhere safe
If the motherboard fails or Windows detects a suspicious change, it will ask for the 48-digit recovery key. Without it, the data is gone for good — that is precisely the point of encryption.
Simple rules:
- Save it to the company’s Microsoft/Entra ID account (the option in the wizard) or printed, in the office safe.
- Never as a file on the same laptop or on a USB stick kept in the laptop bag — that’s taping the key to the door.
- If you manage several machines, keep a register: which machine, where its key is, who has access.
Step 3: automatic updates
- Open Settings → Windows Update and make sure no updates have been sitting there for weeks. Install everything outstanding.
- Under Advanced options, enable Receive updates for other Microsoft products and leave automatic restarts on.
- Set Active hours to match the working day, so restarts happen outside it — that removes the main reason people postpone updates.
- Don’t forget the browser — it’s the most exposed application. Chrome and Edge update themselves, but only if the browser gets restarted now and then; the window that “has been open for three weeks” is running the version from three weeks ago.
More than 10–15 machines? Per-computer manual setup stops scaling — the natural next step is central management (Microsoft Intune or equivalent), where encryption and updates become policies applied automatically.
Verify the result
- Open a terminal as administrator and run
manage-bde -status. For drive C: you should see Percentage Encrypted: 100% and Protection On. - Confirm you can actually find the recovery key where you saved it — now, not during an emergency.
- In Settings → Windows Update, check the date of the last update: it shouldn’t be older than a month.
Common mistakes
- The recovery key saved on the desktop. Surprisingly common. If the disk is encrypted, the file can’t be read exactly when you need it; if the laptop is stolen, the thief gets the key next to the door.
- “I’ll install updates manually, when I have time.” You never have time; meanwhile, published vulnerabilities have public exploits. Automatic or not at all.
- Only the laptops, not the USB sticks. Data leaves the company on USB drives too. For sticks and external disks there’s BitLocker To Go — same menu, same procedure.
- Encryption on, record-keeping zero. With 20 machines and no key register, the first hardware failure becomes a lost day.
If you’re wondering what the alternative costs, we did the maths in what a security incident really costs.
Under NIS2? Data encryption and vulnerability management both appear among the law’s minimum measures.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.