Insights

Your Stolen Laptop Isn’t as Locked as You Think

 
A laptop goes missing. Left in a cab, lifted from a bag at the airport, gone from a coffee shop table while someone stepped away. The reassuring thing everyone says is the same: it’s fine, the drive is encrypted.

Until this week, on a lot of machines, that reassurance was thinner than it sounded.

On Patch Tuesday, Microsoft disclosed a flaw in BitLocker, the encryption built into Windows, tracked as CVE-2026-50661. Someone holding the device can reach the data on it without the password. No account, no network, nothing typed at a sign-in. Just the laptop in their hands. It was made public before the fix was ready, and a working exploit is already circulating, dropped by a researcher who has now pulled the same move two months running.

Here is why it lands harder than a medium-severity score suggests. Forrester found that lost and stolen devices sit behind about one in six breaches, and that only seven percent of security leaders count it among their real worries. The comfort is the exposure. “It’s encrypted” carries a lot of quiet weight in a lot of heads, and this is the stretch where that assumption slipped.

The fix is worth doing now. Install this week’s update. And on any device carrying something you would not want read aloud, tie the encryption to the machine’s hardware chip and require a startup PIN, so the data needs something a thief cannot pick up with the laptop.

The safest laptop to lose is the one that asks for something you never wrote down.

NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.