Navigation

Get in touch
Logo
News

Encryption / Disk encryption

Device lost. Protect the data.

A lost laptop must not become open access to your stored business data. With DiskEncrypt and a matching device and recovery concept, we protect the workstations of small businesses as well as large device fleets. Our offering covers regular business use and, separately, the approved editions for VS-NfD, EU or NATO RESTRICTED. As the exclusive EMEA distributor, we take care of procurement, installation, customer-specific integration, maintenance and Level 1-3 support.

Services in detail
black and gray computer motherboard — illustrative image
Disk encryption

Analysis, integration and documented handover

Utimaco / OTOKO®

Encryption from the product to ongoing operation.

Exclusive EMEA distributor for DiskEncrypt and u.trust LAN Crypt. Your partner for custom adaptations, installation, commissioning, maintenance and Level 1-3 support.

Disk encryption

DiskEncrypt

Protect stored data on company devices against unauthorized reading. OTOKO® supplies DiskEncrypt and handles the integration of authentication, key management, device rollout and recovery.

For small businesses, midsize companies and enterprises: standard deployment and separate editions for classified information. We align licensing, user scope and support with your organization.

Approved edition: version 9.10 · VS-NfD
Vendor
Utimaco IS GmbH
BSI approval
BSI-VSA-10717 · up to VS-NfD
Approved on
02/15/2025
Valid until
02/29/2028
Entry as of
02/15/2025
EU
RESTREINT UE/EU RESTRICTED · 03/10/2025
NATO
NATO RESTRICTED · 02/15/2025

These details apply to the versions named and their respective deployment and operating conditions. Customer-specific modifications and changes are reviewed for their effect on the scope of approval before implementation. BSI list of approved products.

Your brief for OTOKO®

Disk encryption: what we take on for you.

The work packages are derived from your current situation. Your team knows the agreed scope, the required involvement and the results that should be available at handover.

Standard or approved edition

We determine protection needs, the number of users and the operational requirements. You receive a suitable selection for regular business use or a separately reviewed, approved edition. Product, version and included services are specified in detail in the quote.

Your result

A transparent proposal covering configuration, rollout and ongoing support.

Assess devices and operating states

Hardware, operating systems, external storage media and mobile use are recorded. Together, we define which data and states must be protected and how encryption works together with your existing device management.

Your result

A device and requirements matrix for product selection.

Secure authentication and keys

The selected setup combines authentication, key management and the required administration. Where pre-boot authentication is planned, it is incorporated into the operating process, including deputy and outage scenarios.

Your result

A documented authentication and administration concept.

Test recovery and maintenance

Lost credentials, hardware replacement and changes to the device base must remain manageable. A pilot tests the intended recovery paths and maintenance steps before the solution is rolled out to further devices.

Your result

A tested recovery procedure and maintenance guidelines.

Organize rollout and evidence

Rollout waves, responsibilities and inventory evidence are planned. For classified information, we check the specific approval, including version, platform and operating conditions, before production use.

Your result

A rollout plan and documented configuration of the devices included.

Planning & implementation

Disk encryption in everyday project work.

Disk encryption also belongs in everyday office life

Field service, remote work and business travel regularly take corporate devices out of the controlled office environment. These devices hold not only deliberately saved documents but also local working files and application data. We record which devices, storage media and operating states need to be protected. From this, we develop a suitable rollout concept for regular business use. Whether an approved configuration is additionally required is decided by the information processed and your deployment requirements, not by the size of your company.

A few laptops or several thousand endpoints

For small teams, an easy-to-understand sign-in, a named administrator and reliably documented emergency access are central. In larger organizations, we plan rollout groups, software distribution, different device profiles and collaboration with the service desk. A pilot tests representative hardware, updates and recovery before further groups follow. Device changes, repairs and staff departures also receive a defined process. This way, the project does not end with encryption that is switched on just once.

Putting the protection of powered-off devices in perspective

Disk encryption is aimed in particular at preventing the reading of stored data without the required authorization, for example after the loss of a device or storage medium. Its effectiveness depends on the specific setup and the device state. That is why we consider the intended use, including sign-in, shutdown and resume. Selection must not be based on an encryption algorithm alone: key management and the actual permitted operation are equally part of the assessment.

After a successful sign-in, the operating system and authorized applications can access data. Disk encryption then does not automatically prevent malware, abusive actions by a signed-in user or data loss through other channels. File and folder encryption can address additional protection requirements; however, it follows a different permission model. Together, we determine which combination is needed. This gives your company a clear scope of protection and avoids the assumption that an encrypted storage medium eliminates every risk at the workstation.

Clarify recovery before the broad rollout

Rolling out encryption affects the device’s lifecycle. Planning covers new employees, changed roles, lost credentials, repairs and decommissioning. Recovery must be available without undermining the intended access controls. For this, owners, identity verification and approvals are defined. A technically available recovery key alone is not yet a usable procedure. It must be clear who may use it, under what conditions and how this process remains traceable.

In the pilot, the intended devices and maintenance steps are tested together with encryption. This includes changes to hardware or system configuration relevant to the project and collaboration with existing management procedures. The results determine the rollout plan and the necessary briefing. For ongoing operation, inventory information, open exceptions and responsibilities are documented. This makes it possible to later identify which devices were actually included in the scope of protection and where a deliberate decision is still required.

An approved configuration, not a generic security label

DiskEncrypt version 9.10 from Utimaco IS GmbH is approved under BSI-VSA-10717 up to VS-NfD. The approval, issued on February 15, 2025, is valid until February 29, 2028, with a status date of February 15, 2025. The entry names RESTREINT UE/EU RESTRICTED as of March 10, 2025, and NATO RESTRICTED as of February 15, 2025. These details apply to the product version named and its permitted use. Before the rollout, we match the specific hardware, platform and configuration against the associated documentation and coordinate deployment with your responsible parties.

For military clients, additional requirements may apply to premises, devices, access and the personnel deployed. A required Ü3 is a requirement relating to the individual, not evidence of a product’s technical suitability. The project therefore separates personnel clearances from the selection of encryption and the approval of the environment. We plan these interfaces with you; this does not imply a blanket claim that every OTOKO® service or every team member is approved for every classified environment.

From EMEA distribution to Level 1-3 support

As the exclusive EMEA distributor for DiskEncrypt, OTOKO® combines delivery of the solution with technical implementation at your organization. We handle customer-specific adaptations and modifications, installation and commissioning. First, we determine which systems and workflows are to be connected, which functions are needed and who will administer the solution afterward. This results in an agreed implementation scope, a pilot and a rollout plan. Modifications are documented and assessed against the respective approval: the approval of the original version does not automatically apply to every modified setup.

After commissioning, maintenance and Level 1-3 support remain part of our offering. Level 1 handles structured intake and initial triage, Level 2 the in-depth analysis of configuration and integration, Level 3 the resolution of complex technical root causes and the required coordination with the vendor. Support scope, availability, response times and permitted remote access are agreed to fit the project. In classified environments, we take the permitted access and communication channels into account. Maintenance changes are assessed and tested in a traceable way and put into operation through the agreed approvals.

Illustrative project scenario

Example: mobile devices with elevated protection needs

A company wants to use laptops for sensitive project work. In the pilot, sign-in, device states, hardware replacement and recovery are tested. Only afterward do rollout waves follow with documented responsibilities and, if required, a confirmed, permitted product configuration.

Before you start

Questions about Disk encryption.

Is this solution intended only for VS-NfD or large organizations?

No. Our offering also covers regular business use, from small businesses through midsize companies to enterprises. We size the solution according to your data, users and workflows. VS-NfD, EU or NATO requirements are considered separately and apply only to the specific version and configuration for which they are documented.

Does disk encryption replace file and folder encryption?

No. Disk encryption protects the storage medium in the intended state. File and folder encryption can provide additional access protection at the content level. Which combination fits is derived from your data pathways and requirements.

Which approvals apply to DiskEncrypt 9.10?

The BSI-VSA-10717 entry names VS-NfD, RESTREINT UE/EU RESTRICTED and NATO RESTRICTED. The national approval, issued on February 15, 2025, is valid until February 29, 2028. The associated deployment and operating conditions remain decisive; these details cannot be applied as a blanket rule to other versions or customer-specific modifications.

How do authorized people access their data after a device failure?

A predefined recovery procedure governs prerequisites, identity verification, approval and execution. The agreed process is tested on the intended devices.

Can we continue using existing devices?

Your existing hardware and system configuration are checked against the chosen solution. For approved use cases, specific requirements may apply; a blanket approval for every existing device is not possible.

Does OTOKO® also provide adaptations, maintenance and support?

Yes. As the exclusive EMEA distributor, we offer customer-specific adaptations and modifications as well as installation, commissioning, maintenance and Level 1-3 support. Scope of services and service hours are agreed. For approved use cases, we review the effect on the scope of approval before making changes; a vendor approval does not automatically cover every modification.

Related services

Go to the cybersecurity overview

Disk encryption with OTOKO®

Describe your project. We will clarify the right starting point.

Tell us your use case, the approximate number of devices or users and the desired scope of protection. We discuss standard editions and special requirements separately and plan procurement, rollout and support to fit your organization.

Discuss Disk encryption

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.