Hardware Security
- FileVault Encryption for Mac Computers (macOS)
- Securing Your Mobile Device
- Personal Device Security for Medium- to High-Risk Work
FileVault Encryption for Mac Computers (macOS)
Mac computers include FileVault, a built-in encryption system that secures all data at rest using AES-XTS encryption.
How It Works
On Apple Silicon and T2 Macs:
- FileVault uses Data Protection Class C with a volume key
- Encryption leverages the Secure Enclave and AES engine hardware
- User credentials required at boot after enabling FileVault
Important: On older Macs (pre-T2), non-original internal storage, or external drives: Files created before enabling FileVault aren't encrypted and may be recoverable with forensic tools.
Internal Storage Security
FileVault Enabled
When FileVault is on, volumes remain encrypted even if the physical drive is removed. Without valid credentials or a recovery key, the data is inaccessible.
Encryption covers:
- macOS 10.15: Both system and data volumes
- macOS 11+: Data volume (system volume protected by signed system volume feature)
Key Management Apple Silicon and T2 Macs use a hierarchical key system that:
- Requires user password for decryption
- Protects against brute-force attacks on removed storage
- Enables instant secure data wiping
- Allows password changes without full reencryption
All key operations occur within the Secure Enclave—encryption keys never reach the CPU. Each APFS volume has a volume encryption key (VEK) that encrypts contents and metadata. The VEK is wrapped by a key encryption key (KEK), which is protected by both the user password and hardware UID.
FileVault Disabled
Even without FileVault, Apple Silicon and T2 Macs still encrypt volumes—but the VEK is protected only by the hardware UID. Enabling FileVault later is instant (data already encrypted) and adds an anti-replay mechanism to prevent the old hardware-only key from being used.
Secure Deletion
Deleting a volume triggers the Secure Enclave to securely erase its VEK, preventing future access. Additionally, all VEKs are wrapped with a media key. Erasing the media key (via MDM commands, for example) makes the volume cryptographically inaccessible.
External Storage
Removable drives don't use Secure Enclave capabilities—they're encrypted the same way as Intel Macs without T2 chips.
Securing Your Mobile Device
Most of us use our personal phones for work, and that's okay. But it creates real security questions: What happens if your phone is lost or stolen? Who can see your work data? What if your org needs to manage your device? There's no single right answer, and the right approach depends on your role, your organization, and the sensitivity of what you're working with.
If you work with confidential data like client records, legal documents, source information, immigration files, or donor details, the stakes are higher and some of these steps move from "good idea" to "essential."
1. Lock Your Device
A strong lock screen is your first line of defense if your phone is lost, stolen, or handed to someone else.
- Use a PIN of at least 6 digits or a strong alphanumeric passcode. Avoid patterns and 4-digit PINs.
- Face ID and fingerprint unlock are convenient and secure but not sufficient on their own. Always require a passcode as the fallback.
- Set your screen to lock automatically after no more than 1–2 minutes of inactivity.
- Enable "Erase data after failed attempts" if you carry particularly sensitive information.
Higher-sensitivity roles: Consider disabling biometric unlock entirely and using a strong passcode only, particularly especially for border crossings or high-risk situations. Border agents can legally compel biometric unlock in ways they cannot compel a passcode.
2. Review App Permissions
Apps routinely request access to your location, contacts, camera, and microphone, often more than they need.
- Go through your app permissions periodically: Settings → Privacy (iPhone) or Settings → Apps (Android).
- Revoke location access for apps that don't need it. Choose "While Using" rather than "Always" where possible.
- Disable microphone and camera access for apps that have no clear need for it.
- Uninstall apps you no longer use. Dormant apps can still collect data.
Work accounts specifically: Be thoughtful about which apps have access to your work email or calendar. A personal productivity app like Asana or Trello connected to your work Google account could expose more than you intend.
3. Keep a Boundary Between Work and Personal Data
When your personal phone is also your work phone, data can mix in ways that are hard to untangle. A few strategies help keep things separate:
- Use your work email account (e.g., Google Workspace) through a dedicated app (like the the Gmail app) rather than the Mail app, which combines personal and work inboxes.
- Android work profiles: Some organizations use MDM tools (see section 4) to set up a dedicated work profile — a separate section on your phone for work apps. This keeps work data isolated even if your personal apps are compromised.
- Avoid storing work documents in personal cloud storage (personal Google Drive, iCloud, Dropbox). Use your organization's designated storage (Google Workspace, Tresorit, or another approved service).
- Use a dedicated secure messaging app like Signal for sensitive conversations, rather than SMS or personal messaging platforms.
4. Mobile Device Management (MDM)
MDM software allows an organization to remotely manage devices, enforcing security policies, pushing updates, and wiping a lost or stolen device. If your organization uses MDM (such as Jamf, Microsoft Intune, or Google Endpoint), they may ask to install a profile on your personal device.
What MDM can do on your device:
- Enforce passcode requirements and encryption
- Remotely wipe the device if it's lost or stolen
- Require software updates
- Limit or monitor work-related apps and data
MDM profiles give your organization visibility into and control over the portions of your device covered by the profile. Before installing, ask your IT contact exactly what the profile can see and do.
If installing MDM on a personal device feels like too much of an intrusion, it's worth discussing with your organization whether they can provide a dedicated work device instead.
5. Keep Your Phone Updated
Software updates patch security vulnerabilities. An unpatched phone, even one with a good passcode, can be compromised through known holes in the device's software.
- Enable automatic OS updates on your phone.
- Update your apps regularly, or enable automatic app updates.
- Don't ignore "your software is out of date" warnings! These often address active vulnerabilities.
Personal Device Security for Medium- to High-Risk Work
A personal device isn't set up the way a work laptop is. Nobody's checked that it's locked down, up to date, or free of other apps and accounts mixed in with work stuff. You can't turn it into a full company laptop that's not realistic. What you can do is either keep the sensitive work in a separate, protected space on the device that can be wiped if needed, or avoid putting it on the device at all.
The basics
| Control | What it means | Why it matters |
|---|---|---|
| Encryption | Turn on full-disk encryption (BitLocker on Windows, FileVault on Mac) and ensure it's on | Phones and laptops don't always come encrypted by default |
| Screen lock | Auto-lock after 5 minutes or less, with a PIN/password or fingerprint/face unlock | Stops someone from just picking up an unlocked device and looking through it |
| Keep devices and browsers updated | Turn on automatic updates | Most break-ins happen through known holes that a software update would close |
| Two-factor login | Require a second step (code, key, or app approval) to log in anywhere sensitive | A stolen password alone shouldn't be enough to get into anything important |
| Separate work space | Use a work profile or separate browser profile that keeps work stuff separate from personal photos, texts, apps | Lets the work data get wiped without touching anything personal on the device |
| No random file syncing | Don't let personal Dropbox, personal Google Drive, etc. touch work files | Keeps sensitive files from quietly ending up in the wrong place |
| Remote wipe | Make sure the work data can be wiped remotely if the device is lost, using Google Workspace, MS 365 or another service | Losing a device only becomes a real problem if the data on it is still readable |
Quick test: if your device were lost tonight, could whoever found it get into sensitive records, passwords, or personal info? If yes, it needs all of the above before it's used for work.
Putting it into practice
New staff: A new staffer's device should meet the basics above before it's allowed anywhere near sensitive work. Check that encryption is on and the software is current.
Handling the data: For medium-risk work, a separate work profile with some basic restrictions (no copying files out, no plugging in random USB drives) is usually enough. For high-risk work, it's better if the sensitive data never lands on the device at all. Access it through a browser-based tool or remote desktop instead.
By how sensitive the work is:
| Medium-risk work | High-risk work | |
|---|---|---|
| Where the data lives | In a separate work space on the device | Nowhere on the device - accessed remotely only |
| Copying or downloading files | Restricted | Not allowed |
| Staying logged in | Fine day-to-day, re-verify for sensitive actions | Log back in often |
If a device is lost, stolen, or acting weird
Wipe the work data remotely right away. Cut off that device's access and log it out everywhere. Look back through recent activity on the account for anything unusual. Report it right away.