Cybersecurity Glossary
Encryption at Rest
Protecting stored data so that a stolen disk or database file is unreadable.
What Encryption at Rest means
Encryption at rest applies to laptop disks, phone storage, servers, databases, backups and cloud storage. On current devices it is built in and needs only to be switched on and verified. The keys are usually managed by the platform, with recovery keys held by the organisation.
Why Encryption at Rest matters for small businesses and nonprofits
Most data protection regimes treat properly encrypted lost devices very differently from unencrypted ones. Being able to show that a lost laptop was encrypted can be the difference between a note in a log and a notification to every affected person.
What to do about Encryption at Rest
- Verify encryption status centrally rather than trusting that it is on
- Include external drives and removable media in the policy
- Store recovery keys in your management platform, not in a spreadsheet
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.