LUCIDTextjet - Print logo

SOPHOS Central Device Encryption Corporate

Short Description

Open HTML

What are the key advantages of Sophos Central Device Encryption Corporate?
Central management – All encryption policies run from Sophos Central.
Native encryption – Manages Windows BitLocker and macOS FileVault.
Self service – Users retrieve their own recovery keys online.
Compliance reporting – Shows which devices are encrypted right now.
Secure sharing – Password protects files sent outside the company.
Important note – Removable media and USB sticks stay unmanaged.

Long Description

Open HTML

What is included in Sophos Central Device Encryption Corporate?

BitLocker management – Enforces and monitors BitLocker encryption on Windows computers.
FileVault management – Applies FileVault full disk encryption on managed Macs.
Central key storage – Recovery keys are held encrypted inside Sophos Central.
Self Service Portal – Users recover their own boot volume without a ticket.
Compliance reporting – Shows the current encryption status of every managed device.
Important – Removable media are not managed, including BitLocker To Go.

What are the main benefits of Sophos Central Device Encryption Corporate?

Sophos Central Device Encryption manages the encryption already built into Windows and macOS instead of installing its own encryption engine, and every policy, key and report lives in the web-based Sophos Central console rather than on a server you operate. It is the product Sophos named as the migration path for SafeGuard Enterprise, which reached end of life on 20 July 2023, and it is sold as a standalone subscription that does not require another Sophos endpoint licence.

No key server – No on-premises encryption server or key database to operate.
Fewer helpdesk calls – Locked-out users retrieve recovery keys through the self service portal.
Enforced startup authentication – TPM+PIN, passphrase or USB key instead of TPM only.
Takes over BitLocker – Already encrypted computers are adopted and receive new recovery keys.
Password protected sharing – AES-256 HTML wrapper for files sent outside the company.
Active Directory storage – BitLocker recovery keys can additionally be stored in Active Directory.

Which company size is Sophos Central Device Encryption Corporate suitable for?

Full disk encryption is usually the first data protection control a company can introduce without redesigning its infrastructure, because the encryption itself is already part of Windows and macOS. The table shows where the requirement normally comes from, and where this product is a complete answer rather than a partial one.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector Often
NIS 2 in the European Union Rarely By sector Often
Security questionnaire from large customers ✓ ✓ ✓
Encryption evidence per device Occasional ✓ ✓
This product fits ✓ ✓ Partly

Does Sophos Central Device Encryption Corporate meet the requirements of Swiss cybersecurity legislation?

The revised Information Security Act obliges operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, while most companies outside those sectors have no such duty and are driven instead by customer and insurer requirements. Sophos Central Device Encryption supports the preventive side of that picture: it enforces full disk encryption through policy on Windows and macOS devices and records for every managed device whether encryption is currently active, which is the documentation a company needs when a notebook goes missing. It does not detect attacks, does not generate an incident report and cannot tell you whether data was accessed, so the reporting obligation itself remains a matter of your own processes and, where relevant, of a separate detection product. The practical benefit is narrower but real: a lost device with a documented encryption status is a different case from a lost device whose status nobody can prove. This text is general product information and not legal advice; clarify your own obligations with a qualified adviser.

Does Sophos Central Device Encryption Corporate meet the requirements of European cybersecurity legislation?

No software product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk management measures and software can only support them. NIS 2 names measure categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, and policies on the use of cryptography and encryption. Sophos Central Device Encryption addresses the cryptography and encryption category for data at rest on employee devices, and it supplies asset-level evidence by reporting the encryption state of each managed endpoint. It does not cover incident handling, backup and continuity, supplier risk, vulnerability management or multi-factor authentication, and each of those needs its own product and documented process. Whether an organisation falls under NIS 2 at all depends on its sector and size as defined at directive level.

Does Sophos Central Device Encryption Corporate help with security questionnaires from large customers?

Yes, for the data-at-rest block of a questionnaire, and only for that block. It answers whether company notebooks are encrypted, whether encryption is enforced centrally rather than left to the user, which algorithm is used (XTS-AES 256-bit on Windows and XTS-AES 128-bit on macOS according to the Sophos datasheet), whether startup authentication is required, and how recovery keys are stored and who may access them: encrypted in Sophos Central, retrievable only by the HelpDesk, Admin and SuperAdmin roles, and not exportable. It does not answer the questions on malware protection, detection and response, patch status, multi-factor authentication, backup, mobile devices, removable media control or log retention, and it produces no evidence for any of them. If your questionnaire fails on those points, the cheaper route is usually to add the matching Sophos Central products to the same console rather than introducing a second vendor, because the reporting then comes from one place and the reviewer sees one consistent set of evidence.

Best antivirus? Why Windows Defender alone is not enough
Explains where the protection built into Windows reaches its limits and which gaps a customer questionnaire is likely to probe.

Which limitations should you know before buying?

Removable media are outside the scope: you can still encrypt a USB stick with BitLocker To Go, but Sophos Central neither manages it nor stores its recovery key, and it does not appear in the encryption status view. There is no file or folder encryption either, because Sophos ended the SafeGuard Enterprise line in July 2023 and stated that it would not replace the file encryption modules, so files leaving a device are covered only by the password-protected HTML sharing function. Coverage is Windows and macOS; Linux is not part of Device Encryption, BitLocker Network Unlock can coexist but cannot be configured from Sophos Central, and Windows partitions created with Boot Camp are unsupported. Recovery keys cannot be exported from Sophos Central by design, and in the Self Service Portal users can only recover the boot volume, so recovering a data volume stays an administrator task. We found no feature restricted to particular countries; the regional decision that matters is the Sophos Central data region, which is selected when the account is created and determines the AWS region in which your recovery keys are held.

Data loss is expensive: How backups help you avoid outages
Shows why encryption protects confidentiality but not availability, and which backup approach covers the remaining risk.

Frequently asked questions about Sophos Central Device Encryption Corporate

Does full disk encryption replace endpoint protection?

No. Full disk encryption protects data on a device that is lost, stolen or disposed of, while the drive is powered down and locked. Once a user has signed in, the volume is unlocked and malware sees ordinary files, so malware protection and detection remain separate products.

Test: Best antivirus programs for Windows
Compares the current Windows antivirus options and helps you decide what belongs next to device encryption.

Which volumes can be encrypted?

System volumes and fixed data volumes. From Central Device Encryption 1.4 onwards you can choose to encrypt system volumes only and leave data volumes untouched, and volumes of 64 MB or less are ignored.

Can we migrate from SafeGuard Enterprise without decrypting the disks?

With SafeGuard Enterprise 8 and later you can uninstall the BitLocker module without decrypting the volumes and then manage the same machines from Sophos Central. Once the Central policy applies, the recovery key is renewed and sent to Sophos Central. Devices running SafeGuard's own full disk encryption must be decrypted during removal of the client before Central Device Encryption takes over.

 

Meta Description

Manages BitLocker and FileVault full disk encryption from Sophos Central, with self-service recovery keys. Removable media is not managed.

Keywords

Sophos Central Device Encryption, Sophos, Sophos Central, SafeGuard Enterprise, device encryption, full disk encryption, bitlocker management, filevault management, recovery key management

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree