BNW1X6 marked IC being held with tweezers and removed from a computer circuit board using hot air
An integrated circuit marked BNW1X6 is being held with precision tweezers while a hot air rework station heats the solder connections for removal from a computer circuit board. This repair image is an independent work sample and is not an illustration of the educational subject discussed below.

Understanding Used-Space Encryption

Encrypting a Drive Can Mean Two Different Things

Drive encryption is often described as though the process has only one possible form. Turn encryption on, wait while the entire disk is processed, and eventually every sector becomes encrypted.

That is one approach, but it is not the only one.

BitLocker introduced the ability to encrypt only the portions of a volume that are currently being used. Instead of immediately processing every available sector, including space where the filesystem presently stores no active data, encryption can concentrate on occupied areas and then protect new information as it is written later.

Empty Space Changes the Amount of Work

A newly prepared one-terabyte drive may contain very little actual data. Encrypting every sector requires processing the entire capacity, while used-space encryption can initially concentrate on the much smaller portion that contains active information.

Full-Volume Encryption Processes Used and Unused Space

With full-volume encryption, BitLocker processes the entire volume. Areas containing files are encrypted, but so is free space that the filesystem currently considers unused.

This approach can require considerable time on a large drive because the amount of work is related to the size of the volume rather than merely the amount of information stored on it.

A mostly empty drive therefore does not necessarily finish quickly. If the entire volume is being encrypted, its unused capacity still has to be processed.

Full Encryption

The entire volume is processed, including sectors containing active data and areas currently identified as free space.

Used-Space Encryption

Existing occupied space is encrypted first, while previously unused areas are protected as new information is written to them.

Used-Space Encryption Can Finish Much Faster

Consider a newly installed drive with hundreds of gigabytes of capacity but only a small operating-system installation stored on it. Processing the complete capacity can involve far more work than processing the information that actually exists.

Used-space encryption avoids that initial requirement. BitLocker can encrypt the occupied portions and allow the remaining free areas to be handled as they become used.

The difference can be particularly significant during computer deployment, when a freshly prepared volume contains little or no previous user information.

Drive Size and Stored Data Are Different Measurements

A large disk can contain very little information. Used-space encryption bases much of the initial workload on occupied storage rather than requiring every available sector to be processed immediately.

New Data Is Encrypted as It Is Written

Leaving currently unused sectors outside the initial encryption pass does not mean future files are intentionally stored there without protection.

As new information is written into previously unused areas of a BitLocker-protected volume, that information is encrypted. The protected portion of the drive therefore grows naturally with the data stored on it.

This allows the system to avoid processing empty capacity in advance while still protecting new active information when it appears.

Unused Does Not Mean Permanently Unencrypted

Used-space encryption postpones work on free areas until those areas are needed. Once new data is written there, BitLocker encrypts that information as part of normal protected storage operation.

The Meaning of Free Space Requires Care

A filesystem calling an area free does not necessarily mean that the physical sectors have never contained information.

When a file is deleted, the filesystem can mark its occupied space as available for reuse without immediately erasing every byte that previously belonged to the file. Until that space is overwritten, remnants of old information may remain physically recoverable.

This creates an important distinction between a genuinely new drive and an existing drive that has already held sensitive information.

Deleted Data Can Exist Inside Free Space

Used-space encryption is most straightforward on new or securely prepared storage. On a previously used volume, areas reported as free can still contain remnants of deleted unencrypted files until those sectors are overwritten.

A Fresh Drive and a Reused Drive Have Different Histories

Imagine two identical drives. Both currently contain the same amount of active data and report the same amount of free space.

The first drive was freshly prepared and has never stored anything else. Its free areas may never have contained meaningful user information.

The second drive previously held years of documents, photographs, temporary files, application data, and other information that was later deleted. Although the filesystem now describes those sectors as available, remnants of the old data can remain until overwritten.

Filesystem free space describes what can be reused. It does not provide a historical record proving that the underlying sectors never contained data.

Full Encryption Can Address Existing Free-Space Remnants

Processing the entire volume has an important consequence on previously used storage. Areas that the filesystem considers free are also included in the encryption operation.

That distinction matters when a drive has a history of storing unencrypted sensitive information. Used-space encryption protects active information and future writes, but previously deleted remnants located in untouched free areas present a different consideration.

The correct choice therefore depends partly on whether the storage is new or has already been used.

Which Method Is Better?

Neither choice can be judged only by speed. A newly prepared drive and a previously used drive present different security conditions. The history of the storage and the protection requirements should influence the encryption method.

Protecting a Drive Before Windows Is Fully Installed Saves Time

A newly prepared computer provides an ideal situation for used-space encryption because very little information has been written to the destination volume.

BitLocker can be prepared during deployment before the full operating-system installation is complete. When only used space needs to be processed, the initial encryption stage can finish quickly because the formatted destination contains little data.

The operating system and subsequent information can then be written into storage that is already operating under the BitLocker encryption process.

Timing Changes the Workload

Enabling encryption before a drive becomes filled with applications and user data can require much less initial processing than waiting until the same volume contains hundreds of gigabytes of information.

Encryption and Activation Are Not Exactly the Same State

A volume can be prepared for BitLocker encryption during deployment before its final secure key protector has been established.

This creates an important distinction. Data on the volume may already be encrypted while the BitLocker configuration is still waiting for the protection mechanism that will control normal access.

Encryption describes what has happened to the stored information. Protection also depends on how the encryption key is secured and released.

Encrypted Data Still Needs Protected Keys

Cryptography cannot provide meaningful access control if the key needed to decrypt the information is left openly available. The method used to protect and release that key is therefore an essential part of drive encryption.

The Encryption Key Must Be Available at the Right Time

An operating-system drive presents a special challenge. Windows needs access to encrypted files in order to start, but simply storing an unprotected decryption key beside those files would undermine the purpose of encryption.

A Trusted Platform Module can participate in protecting key material and releasing it when the system satisfies the expected startup conditions. Other BitLocker configurations can incorporate additional authentication such as a PIN or startup key.

This separates two related concepts: encrypting the contents of the drive and controlling access to the key that makes those contents readable.

Encrypted Volume

Stored information is transformed so that the raw contents are not ordinarily readable without the appropriate cryptographic key.

Key Protector

A protection mechanism controls how the key required to unlock the encrypted volume can become available.

Recovery Method

An alternate recovery mechanism provides a way to regain access when the normal unlocking process cannot be completed.

BitLocker Protects Information Without Removing It

Encryption and secure erasure solve different problems.

Encryption is intended to make stored information unreadable without the appropriate key. The files still exist and remain usable when the authorized system unlocks the volume.

Erasure attempts to eliminate recoverable information altogether. A drive being prepared for disposal therefore presents a different problem from a drive that will remain in service but needs protection against unauthorized access.

Ask What the Storage Will Be Used For Next

A computer that will continue operating normally, a drive being reassigned to another user, and storage being permanently discarded have different security requirements. Encryption should not automatically be treated as a substitute for every form of data sanitization.

Encryption Does Not Prevent Ordinary Data Loss

BitLocker protects confidentiality. It does not prevent a drive from failing, a filesystem from becoming damaged, or a user from deleting an important file.

In fact, encryption makes preservation of recovery information especially important. If the normal unlocking mechanism becomes unavailable and no usable recovery method exists, encrypted data can remain inaccessible even when the physical storage itself is readable.

Backup and encryption therefore serve different purposes. Encryption protects information from unauthorized access. Backup provides another copy when the working information is lost or damaged.

Encryption Is Not a Backup

An encrypted drive can fail just like an unencrypted one. Important information still needs independent backup, and recovery credentials should be preserved separately from the storage they may be needed to unlock.

The Filesystem and Encryption Layer See the Drive Differently

The filesystem understands files, directories, allocated regions, and free space. Drive encryption operates at a lower storage level, protecting the sectors used to hold that information.

Used-space encryption relies on knowledge about which areas are currently occupied so that the initial encryption process can avoid unnecessary work on untouched free capacity.

This relationship explains why the filesystem’s history matters. A sector marked free today may have contained a deleted file yesterday, even though it no longer belongs to any active file.

Logical Status and Physical Contents Are Not the Same

The filesystem can declare a sector available for reuse while remnants of its previous contents remain physically present. Understanding that difference is essential when evaluating encryption and data-recovery behavior.

Faster Encryption Came From Avoiding Unnecessary Initial Work

Used-space encryption did not make cryptography itself dramatically faster. The major improvement came from reducing how much storage needed to be processed at the beginning.

On a new or lightly occupied drive, that difference can be enormous. Instead of encrypting hundreds of gigabytes of unused capacity, the system can protect the relatively small amount of information already present and encrypt additional areas as they become occupied.

That makes drive encryption easier to incorporate into system deployment without requiring a long initial wait merely because the physical disk has a large capacity.

The Right Encryption Method Depends on What Happened Before

The choice between used-space and full-volume encryption demonstrates why storage security cannot be understood from a single checkbox.

A fresh volume with no previous sensitive information can benefit greatly from used-space encryption because there may be little reason to spend time processing untouched empty capacity. A reused volume can present a different concern because free sectors may still contain remnants of data written before encryption was enabled.

The larger lesson is that storage has a history. Filesystems can forget that a deleted file existed while the physical media may continue holding portions of it. Effective encryption planning therefore considers not only what data exists now, but also what may have existed on the drive before protection began.