Your devices
Probably, if it is recent — and this changed recently enough that most advice is wrong.
Windows 11 has switched device encryption on by default since version 24H2, including Home edition, on clean installs. It did not before.
macOS 26 enables FileVault during setup when you sign in with an Apple Account.
Two gaps remain, and they are the ones that matter. Machines upgraded in place from older Windows versions are often still unencrypted. And a PC set up with a local account only can end up encrypted with no recovery key saved anywhere, which is its own kind of disaster.
Backups are the part that is genuinely still exposed. An iPhone backup made through Finder is not encrypted unless you tick the box. iCloud Backup is not end-to-end encrypted unless you turn on Advanced Data Protection, which is off by default.
On Windows, search for Device encryption or BitLocker in Settings and confirm it is on and that a recovery key is saved somewhere you can reach. On a Mac, System Settings, Privacy and Security, FileVault.
Then check the backup. On iPhone through Finder, tick Encrypt local backup. For iCloud, look for Advanced Data Protection and understand that turning it on means Apple cannot recover your data if you lose your keys.
If the machine holds client or patient records and you cannot tell whether it is encrypted, that is worth an hour with someone who can check properly, including whether the recovery key exists.
A · Verified
Checked 6 Sep 2026 · Review by Mar 2027
Microsoft BitLocker and device encryption documentation, updated August 2026, read directly. Apple's macOS 26 enterprise release notes for the FileVault setup behaviour. iCloud Backup and Advanced Data Protection behaviour from Apple's own support documentation.
Every correction we have made is published. Nobody pays us.