Full-disk encryption protects a powered-off device best
Disk encryption is at its strongest when the machine is off, and considerably weaker once it is running and unlocked.
A stolen laptop that was suspended rather than shut down, with a key still in memory, is a different proposition from one that was powered off. This is why lock screens, timeouts and hibernation settings are part of whether the encryption actually delivers anything.
More on Endpoint security
- EDR visibility depends on the sensor being aliveSilence is not the same as safety
- Application allowlisting controls execution, not intentThe list checks the name
- Local admin changes the consequence of compromiseOne click, two blast radii
- Device compliance is a snapshot, not permanent healthA tick is a photograph
- USB controls are a system design problemDesign the socket, not the poster
- Patch compliance percentages can hide critical exceptionsWhat the number covers
