Full disk encryption protects data at rest, which means it keeps the drive unreadable when the device is powered off or in the wrong hands. It does not protect data that is already available to an authenticated session. If someone finds an unlocked laptop, they may still access files and applications unless additional controls, such as session locking and file-level protection, are in place.
Why full disk encryption helps at rest, not in an active session
full disk encryption is designed to protect the contents of storage when the device is powered off, locked before boot, or otherwise inaccessible to an attacker. Once a user is authenticated and the operating system has decrypted the drive, the protection boundary shifts. At that point, the device is relying on session state, local access controls, and the strength of the lock screen, not on the disk encryption layer.
What changes when the laptop is already logged in
The key distinction is whether the attacker must defeat encryption or only take over an existing session. If the laptop is logged in and unlocked, the data is already available to any person with physical access to the keyboard, screen, or active session. In practical terms, full disk encryption does not prevent someone from opening files, reading cached content, using signed-in applications, or taking advantage of any trusted session that is still alive.
That is why device theft and “walk-up” access are different threat states. A stolen powered-off laptop forces the attacker to confront encryption and, ideally, a strong pre-boot or login credential. A left-open laptop instead presents a live trust context that the encryption layer does not interrupt.
Which controls close the gap left by disk encryption
To reduce exposure after login, organisations need controls that act above the storage layer. Session locking, short idle timeouts, reauthentication for sensitive actions, file- or app-level protection, and remote wipe or revoke capabilities all help limit what an attacker can do with an already-accessible endpoint. This is where local access control and session hygiene matter more than the strength of the encryption key alone.
File-level encryption or protected containers can add another boundary for especially sensitive material, because they can stay inaccessible even if the device itself is currently unlocked. The right mix depends on how much data remains reachable through a live session and whether the device is expected to be used in public or unattended environments.
Risk and Threat Considerations
Lost or stolen laptops are often high-impact because the attacker may get both the device and any authenticated access that was left open. Full disk encryption reduces the chance that offline theft becomes an immediate data breach, but it does not stop opportunistic abuse of an active session, cached credentials, or open applications.
Failure mechanism: The encryption control is bypassed in practice when the operating system has already unlocked the drive and the user session remains active, leaving data reachable through the running environment rather than the storage layer.
Impact: An attacker with physical access may be able to read files, access internal systems, or pivot through authenticated applications before any lock, timeout, or remote response occurs.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle matters because active sessions remain usable after disk unlock. |
| AC-11 — Session Lock | Session locking is the direct control that limits access after a user leaves the device logged in. | |
| Recommendation — Shorten session lifetime and rotate or revoke credentials when a device is lost or left unlocked. Enforce automatic session locking after brief inactivity on portable endpoints. | ||
| ISO/IEC 27001:2022 | A.8.24 — Use of cryptography | Full disk encryption is a cryptographic protection for data at rest, not active session access. |
| Recommendation — Apply cryptographic protection to stored data while pairing it with separate session controls. | ||
| NIST CSF 2.0 | PR.AA-05 — Authenticator Management | The issue turns on whether authenticated access can continue after the device is unattended. |
| Recommendation — Limit authenticated access duration and require reauthentication for sensitive actions. | ||
Practitioner Guidance
What to verify: Confirm that unattended devices lock quickly enough to beat realistic theft or “briefly left behind” scenarios. The important question is not whether full disk encryption is enabled, but whether the session becomes unusable before an opportunistic attacker can interact with it.
What good looks like: A lost powered-off laptop should be unreadable, while a left-open laptop should lock fast enough that access requires a fresh credential or strong reauthentication. Sensitive apps should not remain fully usable just because the desktop is still in memory.
Practitioner takeaway: Treat disk encryption as a theft-at-rest control, and treat session locking, reauthentication, and file-level protection as the controls that actually reduce exposure after login.
Related resources from NHI Mgmt Group
- Why does full-disk encryption create less risk for lost or stolen devices than unencrypted storage?
- Why does full disk encryption reduce the impact of lost or stolen Macs?
- Why does MDM reduce the risk of lost or stolen devices creating a breach?
- When does full disk encryption reduce risk, and when do organisations still need additional controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org