Secure Disk for BitLocker

Go beyond basic Microsoft BitLocker with pre-boot authentication that requires more than just a PIN.
NIS2-ready with next-level disk encryption featuring multi-factor pre-boot authentication.

CryptoPro Secure Disk Administrationsoberfläche mit PBA-Einstellungen, einschließlich Sprache, Tastaturbelegung, Bildschirmauslösung und Authentifizierungsmethoden für Benutzername/Passwort und Smartcard-Anmeldung
Why do we need Secure Disk for BitLocker?

BitLocker without Secure Disk is hacked in 43 seconds

With the introduction of Microsoft BitLocker and full-disk encryption including the operating system, pre-boot authentication—not the Windows log-on screen—is the most critical technology for endpoint security and integrity.

However, Microsoft BitLocker with TPM and without a PIN—as is common practice in many companies—can be cracked in no time and fails to meet regulatory and cyber insurance requirements. Official Microsoft documentation therefore advises against TPM-only configurations (read more here). Contrary to Microsoft's assessment that hacking TPM-only requires an experienced hacker with significant time, the record time we have encountered is 43 seconds.

Using it with a PIN is an administrative and user-experience nightmare, which inevitably leads to new security vulnerabilities. Furthermore, Microsoft BitLocker is not natively multi-factor capable.

Secure Disk addresses these gaps with multi-factor capable single sign-on pre-boot authentication.

The highlights are:

  • High user acceptance through single sign-on for AD & Entra ID
  • Multi-factor authentication with Microsoft Authenticator integration
  • Easy compliance with legal requirements without operational restrictions
  • Software deployment despite active BitLocker encryption and pre-boot authentication

Who is Secure Disk for?

Secure Disk is essential for any company that wants to use Microsoft BitLocker as more than just a facade, and especially for companies subject to NIS2 that need to implement multi-factor authentication for their pre-boot process.

See how TPM-Only gets hacked in 43 seconds:

That's why you need SecureDisk to securely encrypt your hard drives. The video clearly explains how BitLocker and TPM work and how the hack works.

Before we can show you videos, we need to let you know that when you watch the videos, data may be sent to the provider.

Benefits

The pre-boot authentication, that enables multi-factor

Security without operational restrictions

Single sign-on, straightforward MFA, simple help desk procedures for password recovery, and software distribution despite pre-boot authentication ensure high levels of acceptance among users and administrators.

Easy compliance with legal requirements

Secure hard disk and operating system encryption with MFA is required by various regulations (GDPR, BaFin, KRITIS, etc.)

User-friendly MFA

MFA without Secure Disk: BitLocker PIN + Entra ID password

MFA with Secure Disk: Entra ID password + MFA, e.g., using Microsoft Authenticator

Disk encryption even without BitLocker

The Secure Disk Enterprise version features its own 256-bit AES crypto engine, allowing it to be used on Windows operating systems that do not include BitLocker.

Get a no-obligation consultation now

You could certainly wait a while to implement truly secure disk encryption, but threats won't wait for you.

Here is why: Let’s talk Secure Disk. We offer clear recommendations, robust implementation, and proven procedures.

Services

Your trusted partner for multi-factor pre-boot authentication

As a partner, we implement the benefits of Secure Disk for you so that you can use its full potential and enjoy rapid implementation.

Secure Disk Trial, Setup, and Licensing
Design & implementation of system hardening
Managed system hardening
In action

This is what secure disk encryption looks like – without an extra PIN

Features
  • Centralized management of all settings

  • Offline Challenge/Response HelpDesk

  • Software deployment despite BitLocker

  • Separation of roles: IT admin and security admin

  • InPlace upgrade compatibility

  • Benefits
  • Hardened BitLocker without effort

  • Significant reduction in effort compared to lost PIN

  • More worry-free protection with InPlace upgrades

  • comparison

    Secure Disk keeps your data simply secure

    Without Secure Disk

    BitLocker as a mere facade

    Unsafe or cumbersome

    Extra PINs for users, often leading to sticky notes with passwords

    No MFA during pre-boot authentication

    Hard disk encryption from questionable providers

    With Secure Disk

  • True BitLocker protection without the administrative and user headaches

  • Single sign-on (SSO) for users

  • NIS2 compliance via MFA during pre-boot authentication

  • High user acceptance for secure hard disk encryption

  • Hard disk encryption made in Germany

  • Free endpoint security check

    Rotes Schild mit einem Vorhängeschloss-Symbol in der Mitte, das Sicherheit und Schutz darstellt.

    Companies with best-practice endpoint management are demonstrably better protected. With the free Endpoint Security Check, you can find out how well your devices are protected.

    90%

    All successful ransomware attacks originate from poorly and unmanaged devices

    11x

    Higher probability of cyber attacks on > 20% unmanaged or poorly managed devices

    Learn more
    Case studies

    How companies benefit from our partnership

    01
    MECM+system hardening @ textile manuf.

    Managed MECM and system hardening for manufacturers of innovative textiles

    Manufacturing industry
    |
    >2,500
    staffs

    Challenge:

    • Small IT team needs specialized support to operate MECM
    • The team had recognized the importance of standard system hardening, but could not guarantee it themselves

    The solution:

    • Managed service for MECM with managed UEM and trouble shooting for international locations
    • Adapting the CIS standard to an individual environment
    • Regular system hardening as a service in accordance with CIS standards
    01
    Intune+system hardening @ game developer

    Intune Deployment and Managed Service Plus System Hardening for Game Developers

    Game development
    |
    >100
    staffs

    Challenge:

    • Customer was dissatisfied with the speed and expertise of the old service provider
    • Intune should be introduced and cyber security significantly improved

    The solution:

    • From the 1st Intune workshop to implementation and long-term support
    • Establishment and regular updates of security baselines,
    • Microsoft Defender for Endpoint Implementation and Managed Service
    • SOFTTAILOR as a new go-to partner
    01
    Patch Management @ Law Firm

    Patch Management as a Service for law firm

    Professional Services
    |
    >500
    staffs

    Challenge:

    • Customer wants to migrate to Intune
    • High importance of cybersecurity in a very sensitive environment
    • More than 200 applications must always be patched

    The solution:

    • Managed service for partially automated continuous updating of applications
    • Close integration into the vulnerability management process
    • Migrate software packages to Microsoft Intune
    01
    Software packaging @ Energy provider

    Application packaging aaS for energy suppliers

    energy supply
    |
    >1,500
    staffs

    Challenge:

    • Restructuring should separate the IT department and infrastructure from the existing
    • New IT department is being streamlined
    • The company is therefore unable to manage 350 applications itself

    The solution:

    • Application packaging aaSin close coordination with the internal IT department
    • Provision of a customer portal to view status
    • Considering high safety requirements
    Let's talk Endpoint

    The fastest path to effective BitLocker protection

    Secure and productive endpoints in three steps.
    Learn what you need to do and how to get to more structure and secure and productive endpoints in the shortest possible way.
    1
    Get in touch

    Get in touch with us below for a short, no-obligation initial consultation.

    2
    Initial consultation

    During the initial consultation, we will discuss your requirements and determine whether Secure Disk is the right solution for you.

    3
    Free trial


    We are launching the free trial period together, during which you will see that Secure Disk for BitLocker is an investment that will pay off for your organization as well.

    blog

    Expert Insights To Go: Our Newest Blog Posts

    Always a step ahead!

    We send IT decision makers and endpoint administrators hand-curated news, technical insights and practical tips about endpoint management & security that are not available anywhere else.