If you use a Mac daily, store work documents, personal photos, financial data, or company information, you probably already have a login password and think that's enough. The reality is that, without encryption, anyone who gains physical access to your computer can read your hard drive as if it were a simple USB flash drive.even if I don't know your user password.
That's where FileVault comes in, Apple's encryption technology for macOS. FileVault protects the contents of your hard drive or SSD so that they can only be decrypted by entering the correct password or using a recovery key.Let's take a look at exactly what it is, how it works on different types of Macs, and how you can activate it step by step without getting confused, taking full advantage of its security potential.
What is FileVault on Mac and why is it so important?
FileVault is, in short, a full disk encryption system built into macOSIt uses the Advanced Encryption Standard (AES), the same type of technology used by government and businesses to protect particularly sensitive information.
In practice, this means that All data stored on the disk is saved in an unreadable form without the correct key.Even if someone steals your Mac, removes the hard drive, and connects it to another computer, all they will see is encrypted data, impossible to interpret without the password or recovery key.
Historically, FileVault has been in macOS (formerly Mac OS X) since very old versions, such as 10.3, and has evolved over time. Modern versions of FileVault encrypt the entire boot disk, not just the startup folder., offering a much more comprehensive level of protection than in its earlier iterations.
Regarding encryption strength, macOS typically uses 128-bit AES for FileVault, which It provides a very high level of security, sufficient for the vast majority of users and businesses.For an attacker, breaking this encryption by brute force is, in practice, unfeasible.
Therefore, FileVault is specifically geared towards users who handle confidential information: freelancers with financial data, professionals who carry client documents, companies with mobile laptops, or anyone who simply doesn't want their data exposed in case of theft or loss.
How FileVault works depending on the type of Mac you have
One of the key points when understanding FileVault today is distinguishing between the different types of Macs based on their security hardware. It doesn't behave exactly the same on a Mac with an Apple chip (M1, M2, etc.) or a T2 security chip as it does on an older Mac without these chips..
Mac with Apple chip (M1, M2, etc.) or T2 security chip
If your Mac is relatively recent and has an M-series (Apple Silicon) chip or includes the T2 security chip (present in many Intel models of recent years), Storage encryption is already automatically enabled at the hardware levelThese chips integrate an encryption engine that encrypts the disk's contents at all times, regardless of whether you activate FileVault or not.
So what is FileVault used for in these cases? On these Macs, Activating FileVault adds an extra layer of security by linking that hardware encryption to your user password and/or a recovery key.This way, no one can decrypt the content unless they enter the correct password when starting or unlocking the device.
Additionally, by enabling FileVault on these models, Other security measures are automatically reinforcedFor example, the system will require a password when exiting sleep or the screensaver, and secure boot management is integrated with that encryption to minimize the chances of unauthorized access.
Mac without an Apple chip or T2 chip
On older Macs that don't have an Apple chip or a T2 chip, Encryption is not enabled by default.On these devices, if you do not manually enable FileVault, your data is stored on the hard drive or SSD in a readable form (except for the usual macOS permission protections, which are insufficient against direct physical access to the disk).
Therefore, on this type of Mac, Activating FileVault is essential if you want your data to be truly encrypted.When you do this, macOS initiates a conversion process that encrypts all the contents of the startup disk, a task that can take anywhere from several hours to considerably longer, depending on the size and speed of the drive.
What FileVault protects and what it doesn't.

FileVault is designed primarily for Prevent a third party from accessing your data if they cannot log in to your session and do not have your credentials.Its strength lies in the scenario of theft or loss of the equipment, or when someone tries to access it by removing the disk and connecting it to another machine.
When FileVault is active, the disk contents are encrypted “at rest”This means that all stored information is encrypted while the computer is turned off or locked. As soon as you enter your password and the system starts up, macOS decrypts the data it needs to function on the fly and re-encrypts it when saving.
It must be clear, however, that FileVault does not replace other security measuresIf your session is open and you leave your Mac unattended without automatic locks, someone with physical access could use it as if they were you, because at that point the disk is already decrypted for the system.
Therefore, alongside encryption, it is advisable to combine A good policy of locking the system upon waking from sleep or after a certain period of inactivity, and the use of strong passwordsFileVault is a key piece, but it's part of a set of measures.
Real advantages of activating FileVault
Beyond the theory, it's logical to ask what concrete benefits FileVault brings to everyday life. The first major advantage is that, if your Mac is stolen or lost, your data becomes virtually inaccessible to anyone. that you do not have the password or recovery key.
Imagine carrying your business's accounting numbers, internal reports, customer data, or unpublished projects on your laptop. Without encryption, a thief could remove the disk, connect it to another computer, and browse through it with relative ease.With FileVault, you'll end up with a completely encrypted disk, with no realistic possibility of recovering the information.
Another advantage is that Encryption helps comply with internal company policies and legal data protection requirementsIn corporate or educational environments, it is common for IT departments to require disk encryption for all laptops, precisely to mitigate risks in case of loss.
Additionally, on recent Macs with an Apple or T2 chip, The impact on performance is usually very low, practically imperceptible to most users.The hardware is optimized for real-time encryption and decryption, so the system continues to run smoothly.
Finally, FileVault reinforces other layers of system security. When enabled, macOS hardens how it handles login, unlocking after sleep, and certain secure boot parameters.further reducing the chances of unauthorized access.
Disadvantages and limitations of FileVault
Although FileVault is highly recommended, it's not a magic wand without drawbacks. Its main historical disadvantage has been... the potential impact on performance, especially on older Macs or those with mechanical hard drivesBecause the system has to constantly encrypt and decrypt data when reading and writing, a slight slowdown may occur.
On modern systems with fast SSDs and hardware encryption, this impact is much less noticeable, but On older machines, you might notice that certain disk operations are somewhat slower.It won't make the Mac unusable, but it's something to keep in mind.
Another major disadvantage is that, If you lose your login password and associated recovery key, accessing your data becomes impossible.That's precisely what encryption is for: no one, not even Apple, will be able to access your drive without the proper credentials.
For this reason, it is crucial Save the recovery key in a safe and memorable place.But never next to your Mac. You can use a password manager, save it in an encrypted document, or write it down on paper and keep it in a discreet place.
As for why FileVault isn't enabled by default on all Macs, several factors are involved: Compatibility with different user scenarios, potential performance effects on older equipment, and the need to clearly explain the implications of losing the keyApple prefers that the user (or the company) make the informed decision to activate it.
Typical use cases where FileVault makes a difference
There are profiles for which FileVault is almost mandatory. If you work with your company's financial information on a Mac laptop that you frequently take out of the officeHaving an unencrypted hard drive is an unnecessary risk. A simple lapse in attention on a train or in a café could result in a serious data breach.
Another classic case: professionals who handle customer data, medical records, legal documents, research projects, or confidential designsDisk encryption is an essential component for complying with confidentiality obligations and data protection regulations.
Even as a private user, If you keep private photos, personal documents, copies of ID cards, contracts, or any file that you wouldn't want circulatingFileVault gives you peace of mind knowing that if your Mac falls into the wrong hands, your content will remain protected.
It is also very useful in teams that share workspaces, such as laptops used by students in residences, coworking spaces or shared officesIn these contexts, the risk of theft or loss is greater, and encryption is especially recommended.
Requirements to activate FileVault on your Mac

Before you start activating FileVault, it's a good idea to be clear about what you need. The main requirement is to have a user account with administrator privileges on the Macsince only an administrator can turn boot disk encryption on or off.
Furthermore, it is highly advisable that, Before starting the encryption process, make sure you have a recent backup of your data.For example, with Time Machine or another backup tool like Carbon Copy Cloner (CCC). This isn't because FileVault is unstable, but because any large-scale disk operation always carries some risk.
Another important point: During the disk conversion process to encryption, it is recommended to keep your Mac plugged into a power source.Especially on laptops. This will prevent the process from pausing or being interrupted due to a sudden shutdown.
In some cases, especially if you're preparing an external drive with encrypted boot capability, you'll need format the volume correctly (for example, in APFS if your Mac has a T2 chip or Apple Silicon) before launching encryption with FileVault or from the Finder.
How to activate FileVault step by step on your Mac's hard drive
The basic setup of FileVault is fairly straightforward, although the menu text might seem intimidating at first. Everything is done from System Preferences (or System Settings in recent versions of macOS), in the security section.
In classic versions of macOS, the usual path is: System Preferences → Security and Privacy → “FileVault” tabIn newer macOS, the path may vary slightly, but there is always a section dedicated to disk encryption.
Once in that section, you'll see if FileVault is enabled or disabled. To modify it, you will first need to click on the padlock in the bottom corner and enter your administrator password.Without this step, the system will not let you change the settings.
When you click the button to activate FileVault, the wizard will ask you to Choose how you want to be able to unlock the drive if you forget your login passwordThis is where two main recovery systems come into play.
Once you accept the settings, macOS will begin encrypting the contents of your startup disk. The process can take quite a while, depending on the capacity and type of unit.You can continue using your computer in the meantime, although you'll notice slightly increased disk activity. It's not essential to wait until it finishes before restarting, but it's best not to interrupt it abruptly.
Choose recovery method: iCloud or recovery key
One of the most delicate moments when activating FileVault is deciding how you will be able to access the disk if you forget your password. macOS offers you at least two options: use your iCloud account or generate a recovery key.
The “iCloud account and password” option is the most convenient for many users. If you already use iCloud or plan to set it up, you can allow your iCloud account to be used to unlock the encrypted drive. in case of emergency. This way you don't have to worry about storing another long key separately.
The alternative is to use a “Recovery Key”. In this case, the system It generates a unique string of letters and numbers that acts as a master key to decrypt the disk.This key is shown only once during setup, and you must write it down very carefully.
It is vital that Store that recovery key in a location separate from your Mac and sufficiently secure.It could be in a password manager, in an encrypted document on another device, or even on a well-protected piece of paper. The important thing is that it's not lost, but also that it's not easily accessible.
In business or educational settings, it is common for the organization itself manages an institutional recovery keyThus, if an employee forgets their password, the IT department can unlock the computer without losing the information, while at the same time maintaining a high level of control over corporate data.
Using FileVault with other users on the same Mac
When an administrator activates FileVault on a Mac with multiple user accounts, Each user who has FileVault enabled on their account will be able to boot the Mac and log in with their own password.In other words, the disk is decrypted when one of those authorized users enters their credentials at startup.
If there is an account on that Mac that does not have FileVault enabled, That user will not be able to boot the Mac and unlock the disk on their own.In that scenario, someone who has FileVault enabled must log in first; then, without restarting, that user can log out and the other user can log in normally.
This way of working guarantees that Only expressly authorized accounts can unlock the encrypted diskIt's important to review which users have this privilege, especially if you share the Mac with other people or use it in a family environment with multiple accounts.
FileVault and backups: using it with Carbon Copy Cloner (CCC)
Disk encryption doesn't end on the primary Mac: It's also a good idea to encrypt your backups, especially if they're on external drives that get moved around.Tools like Carbon Copy Cloner (CCC) allow you to work with volumes protected by FileVault, in both HFS+ and APFS.
If you want to create a bootable and encrypted backup with FileVaultThere is a recommended procedure. First, format the destination volume following CCC's instructions, without marking it as encrypted boot. If your Mac has a T2 chip, it is recommended to use APFS.
Then, you use CCC to clone your current boot disk to the unencrypted destination volumeOn systems prior to macOS Mojave, it's usually necessary to create a Recovery volume on that disk (CCC includes an option for this), and to do so you must be logged in with an administrator account. On modern APFS volumes, this step is usually unnecessary.
Next, in System Preferences, select the backup disk as your boot disk and restart from it. Once booted from this cloned volume, You activate FileVault from the Security and Privacy panel to encrypt the backup disk.
Once FileVault has been activated (you don't need to wait for the encryption to finish completely), you can return to the Boot Disk panel, Select your primary volume as your boot disk again and restartAfter that, all you have to do is configure CCC to perform regular backups to that already encrypted volume.
Advanced aspects and precautions when encrypting backups
There are some advanced details to consider when You activate encryption on a backup disk that is initially unencryptedWhile the volume is being converted to encrypted, the data is being overwritten, and at the end of the process, in principle there should be no accessible trace of the unencrypted information left.
However, there are nuances. For example, On SSD drives, if you deleted files before activating encryptionThe SSD itself may have discarded some unencrypted data blocks (due to its own internal wear management). In a highly technical scenario, an expert might be able to recover some of that residual data.
Similarly, If the encryption process is interrupted or fails for any reason, some of the data could potentially be recovered.If these assumptions are unacceptable to you due to the sensitivity of your information, you can choose not to include your most sensitive data in the first backup to that disk or follow a secure data deletion protocol.
The idea would be to exclude certain directories in the first cloning, Boot from the backup disk, activate FileVault on it, and once encrypted, run the backup task again. including all data. In this way, any file copied while the volume is already being encrypted will be stored encrypted from the very beginning.
If your backup doesn't need to be bootable (you just want an encrypted external drive to store data), the procedure is even simplerSimply right-click on the volume in the Finder and choose the option to encrypt the volume. However, in macOS High Sierra and later, enabling encryption this way on an HFS+ volume will likely cause the system to automatically convert it to APFS.
Practical recommendations and common problems during encryption
During the process of converting to an encrypted disk, especially on macOS Catalina, Some users have observed that encryption remains paused indefinitely if the Mac is unplugged. halfway there. Although it doesn't always happen, it's a frequent enough behavior to warrant taking precautions.
To avoid headaches, it is recommended to Leave the Mac plugged into the power outlet during the entire conversionEspecially if the volume being encrypted is a large backup. If you see that the system indicates that encryption is paused, leave it connected and logged in, ideally overnight.
macOS doesn't offer a very user-friendly way to view detailed encryption progress, but You can use the Terminal app and run commands like “diskutil apfs list” or “diskutil cs list” (depending on whether the volume is APFS or HFS+) to check the internal status of the conversion.
In some cases, Encryption is only reinstated after logging in with an administrator account on the main system.If you notice that the conversion has gotten stuck, try booting from your normal disk, logging in as an administrator, and leaving the computer running for a while with the backup disk connected.
As a general rule, Do not abruptly disconnect external drives while they are being encrypted.And don't force system shutdowns if you can avoid them. Although the process is designed to be robust, any unexpected interruption increases the likelihood that something won't finish cleanly.
Ultimately, activating and using FileVault adds a very strong barrier against unauthorized access, both on your primary Mac and your backups. With a good backup, a well-guarded recovery key, and some patience during encryption, you can achieve a very high level of data protection without overcomplicating things..