What are the key advantages of ESET Full Disk Encryption?
Central management – Encryption is deployed and monitored from ESET PROTECT.
Full encryption – System disks, partitions or entire drives are encrypted.
Pre-boot login – An extra password layer before Windows starts.
Mac coverage – Native macOS FileVault is managed from the same console.
Remote recovery – Admins issue recovery passwords for locked-out users.
Important note – No USB, file or email encryption included.
ESET PROTECT integration – Encryption is managed with the same groups, policies and tasks.
Full disk encryption – AES 256 encryption of system disks, partitions or entire drives.
Pre-boot authentication – A password screen shown before Windows begins to load.
macOS FileVault management – Apple native encryption is switched on and monitored remotely.
Central recovery – Administrators issue recovery passwords using the workstation ID.
Important – Removable media, file and email encryption are not included.
ESET Full Disk Encryption is an add-on module for the ESET PROTECT and ESET PROTECT On-Prem consoles that encrypts Windows workstations and manages FileVault on macOS. It has no console of its own, and it can only be bought in addition to a new or existing ESET business subscription.
One console – No separate encryption server has to be installed.
Single-action rollout – Deploy, activate and encrypt a device in one task.
Lost device protection – A stolen laptop stays unreadable without the pre-boot password.
Remote password control – Invalidate, block or wipe the pre-boot login remotely.
Encryption status evidence – Console reports show which devices are actually encrypted.
Low performance cost – Hardware-accelerated AES 256 keeps everyday work responsive.
The deciding factor is not headcount but how many notebooks leave the building and who asks you to prove they are encrypted. A five-person consultancy with five laptops on client sites has the same exposure as a department of a large company.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Central proof of encryption per device | Useful | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partly |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, for example energy and water utilities, listed hospitals, transport companies, data centre operators and cantonal or municipal administrations, and not to every Swiss company. Organisations that are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, including incidents where information was manipulated or extracted. ESET Full Disk Encryption supports two concrete points in that process: the console documents which devices were encrypted at the time of the incident, and an encrypted device that was switched off when it was lost changes how the data outflow has to be assessed, which also matters for a data security breach notification under the Swiss data protection law. What it does not do is detect the attack, build the incident timeline or send anything to BACS, so detection, logging and a written incident process still have to come from your endpoint protection and from your organisation. This text is technical orientation and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No software product makes a company compliant with the NIS 2 Directive, because the directive requires risk management measures and organisational processes rather than a specific tool. NIS 2 names measure categories such as risk analysis and security policies, incident handling, business continuity and backup, supply chain security, access control and asset management, and policies on the use of cryptography and encryption. ESET Full Disk Encryption maps directly onto the cryptography category for data at rest on notebooks and desktops, contributes to access control through pre-boot authentication, and produces per-device encryption status that can be used for asset documentation. It contributes nothing to incident handling, business continuity, backup, supply chain security, vulnerability handling or multi-factor authentication, and it does not cover servers, Linux systems or mobile devices. Because the directive is transposed nationally, the concrete obligations for your entity follow from the implementation that applies to you.
Yes, for the encryption-at-rest questions, and only for those. It answers whether company notebooks and desktops are encrypted, which algorithm is used, whether encryption is enforced centrally rather than left to the user, whether an authentication step exists before the operating system starts, and whether key recovery is handled by an administrator instead of a stored password file. It does not answer questions about USB and removable media encryption, encrypted file exchange with third parties, email encryption, server and database encryption, backup encryption, mobile device encryption or multi-factor authentication, and those are common items on the same questionnaires. If the gap you have to close is removable media, files or email, the cheaper route is usually ESET Endpoint Encryption from the same vendor rather than adding a second encryption vendor, because two encryption agents mean two recovery processes and two sets of evidence for the auditor. If the gaps are broader, such as patch evidence or mail security, a higher ESET PROTECT tier that already contains full disk encryption is normally the better comparison than buying this module separately.
The decisive difference is scope: ESET Full Disk Encryption encrypts the disk and nothing else, while ESET Endpoint Encryption also covers removable media, individual files and folders, Outlook email and encrypted archives. The second difference is where you manage it. ESET Full Disk Encryption lives inside the ESET PROTECT console you already use for endpoint protection, whereas ESET Endpoint Encryption is a standalone product with its own server and console, sold separately and licensed per user rather than per device. ESET Endpoint Encryption is the product that came out of ESET's acquisition of DESlock, so buyers who still search for DESlock will end up there rather than here. The two cannot be installed on the same workstation at the same time.
| Capability | ESET Full Disk Encryption | ESET Endpoint Encryption |
|---|---|---|
| Full disk encryption | ✓ | ✓ |
| Removable media encryption | ✕ | ✓ |
| File and folder encryption | ✕ | ✓ |
| Email and attachment encryption | ✕ | ✓ |
| Managed from ESET PROTECT | ✓ | ✕ |
| Multiple pre-boot user accounts per device | ✕ | ✓ |
| Purchase model | Add-on | Standalone |
ESET Full Disk Encryption cannot be bought on its own: it is an add-on to a new or existing ESET business subscription, and it needs either ESET PROTECT or ESET PROTECT On-Prem to be managed at all. Coverage is limited to Windows and macOS workstations and notebooks; there is no Windows Server, Linux, Android or iOS encryption in this module, which is the limitation that most often triggers a follow-up purchase in mixed environments. On macOS the product does not encrypt with its own engine but switches on and monitors Apple's FileVault, so the feature set there follows what Apple provides. Windows on ARM is not supported, and dual-boot systems and Apple Boot Camp installations are outside the supported scope. Single sign-on between the Windows password and the pre-boot password only works in a Windows domain, so companies without Active Directory should expect users to enter two passwords at start-up.
The user reads the workstation ID from the bottom of the pre-boot login screen and passes it to the administrator, who generates a recovery password in the ESET PROTECT console. If the encryption itself is damaged and password recovery no longer works, the administrator can create a recovery data file that decrypts the drive and removes the pre-boot login.
Not on the same workstation. ESET Full Disk Encryption and ESET Endpoint Encryption cannot be installed on one device at the same time, so a migration between the two means decrypting first and then rolling out the other product.
Yes. ESET Full Disk Encryption is available through ESET's monthly MSP billing model and works with ESET MSP Administrator 2, ESET Business Account and ESET PROTECT Hub, so encryption status for several customer tenants is visible in the same management structure as the endpoint protection.
ESET Full Disk Encryption adds AES 256 disk encryption with pre-boot login on Windows and macOS, managed in the ESET PROTECT console.
ESET Full Disk Encryption, ESET, ESET PROTECT, EFDE, full disk encryption, pre-boot authentication, disk encryption software, central key recovery
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies