Encryption at Rest - Securing Data on Disk
About 2 min read
Encryption at rest is a technique that protects data stored in storage by encrypting it. Even if data stored on a hard disk, SSD, or cloud storage is physically stolen or accessed without authorization, its contents cannot be read unless the encryption key is also compromised. As of 2026, the major cloud storage services (Amazon S3, Azure Storage, Google Cloud Storage) apply encryption at rest by default, and it is a standard measure for corporate compliance requirements. It is a concept that pairs with encryption in transit.
Real-World Use Cases
For example, an employee's laptop might be stolen while on a business trip. If full-disk encryption such as BitLocker is enabled, the contents cannot be extracted without the encryption key even if the disk is removed and read directly. Under Japan's Act on the Protection of Personal Information, a leak of personal data to which measures such as advanced encryption have been applied is excluded from the situations that must be reported to the Personal Information Protection Commission (Article 7 of the Enforcement Rules), so whether the data was encrypted changes how heavy the follow-up response becomes.
Methods of Encryption at Rest
Full-disk encryption (FDE) encrypts the entire disk, with BitLocker (Windows) and FileVault (macOS) being representative examples. File-level encryption encrypts individual files or folders. Database encryption protects data within a database using methods such as TDE (Transparent Data Encryption). In cloud environments, server-side encryption using AWS KMS or Azure Key Vault is standard.
The Difference from Encryption in Transit
Whereas encryption at rest protects data on storage, encryption in transit (such as SSL/TLS) protects data flowing over the network. For example, a password sent over HTTPS is encrypted during transmission, but when it is stored in the server's database it remains in plaintext unless encryption at rest is in place. Complete data protection requires both. The basics of encryption explains the relationship between the two in detail.
Relation to Passwords
Decrypting encrypted storage requires a password or an encryption key. Using a sufficiently long random password as the disk encryption passphrase strengthens protection even against physical theft. Managing the encryption key is also important, because losing the key makes the data inaccessible. Portable devices always carry a risk of loss or theft, so keeping full-disk encryption enabled is a basic step alongside cloud storage security.
Was this article helpful?