Jessica Entwistle
July 21 2026
Help Net Security reports that independent research by Milan Brož and colleagues has identified serious security weaknesses in self-encrypting drives (SEDs) that comply with the TCG Opal2 standard. The researchers tested 38 commercially available solid-state drives marketed as providing hardware-based encryption and found multiple implementation flaws that could allow attackers to bypass encryption protections. The drives are widely used in enterprise laptops and workstations, where organisations rely on hardware encryption to protect data at rest without the performance overhead of software-based encryption. Brož, who maintains cryptsetup, the disk encryption tool used across most Linux systems, noted that many of the tested drives failed to implement the Opal2 standard correctly, leaving encrypted data vulnerable to attack.
Many UK organisations have adopted self-encrypting drives as a standard control for protecting data on laptops, particularly for remote workers, field-based staff and executives who travel frequently. The assumption has been that hardware encryption provides strong protection with minimal user or IT involvement. This research challenges that assumption and suggests that organisations may have less protection than they believed. For businesses that have relied on SED technology as their primary data-at-rest protection, this creates a governance and risk management question: how confident can they be that the drives they have deployed actually provide the protection they were purchased to deliver? The research is particularly concerning because many organisations chose SEDs specifically to avoid the complexity and performance impact of software-based encryption solutions such as BitLocker or LUKS. The findings suggest that this trade-off may have introduced risk rather than reducing it. For organisations subject to data protection regulations such as UK GDPR, the effectiveness of encryption controls is not just a technical question but a compliance and accountability issue.
Organisations using self-encrypting drives should review what models are deployed, whether they have been independently tested, and whether software-based encryption such as BitLocker or LUKS should be enabled as an additional layer. Where SEDs are the sole protection for sensitive data, understanding the specific implementation and any known weaknesses is a sensible governance step. IT teams should consult vendor security advisories and independent research to determine whether the drives they have deployed are affected by known implementation flaws. For organisations with large laptop fleets, this may require an audit of hardware models and firmware versions. Where practical, enabling software-based encryption alongside hardware encryption provides defence in depth and reduces reliance on a single control. Organisations should also review their data classification policies to ensure that highly sensitive data is protected by multiple layers of encryption and that the effectiveness of those layers is periodically validated. For new laptop deployments, procurement teams should consider whether software-based encryption is a more reliable and verifiable control than relying solely on hardware encryption claims.
Source: Help Net Security