An encrypted USB memory stick protects your data by scrambling it on the device itself, so that losing the stick stops being a reportable incident and becomes an inconvenience instead. This guide covers the difference between software and hardware encryption, where a standard encrypted stick still leaves you exposed, and when a secure form factor is the better answer for an industrial or regulated application.
What actually makes a memory stick encrypted
Encryption converts the files on the device into unreadable data that only opens with the correct key or password. Lose an encrypted stick and the finder holds a lump of plastic. Lose an unencrypted one and they hold your files.
That is the whole idea, and it is worth being precise about where the encryption lives, because the two approaches behave very differently in the field.
Software encryption is applied by the computer. BitLocker on Windows is the familiar example, built into the operating system since Windows Vista and strengthened in Windows 10. It works, it costs nothing, and it takes a few minutes to apply depending on capacity and whether you encrypt the used space or the entire drive. It also generates a 48 digit recovery key that needs storing somewhere safe, because it opens the drive too.
Hardware encryption is applied by the device. The controller inside the stick encrypts everything written to it, with no software to install and nothing for the user to remember. Products such as the Flexxon FxLocker use AES-XTS 256-bit encryption and authorise access with a password, and because the work happens on the drive they run on Windows, macOS and Linux without an installer. On a locked down industrial PC where you cannot install anything, that difference decides the specification on its own.
| Software encryption | Hardware encryption | |
|---|---|---|
| Where the encryption happens | On the host computer | On the device controller |
| Relies on the user remembering | Yes | No |
| Works on a locked down machine | Often not, install rights needed | Yes, no installation |
| Cross platform | Varies by operating system | Typically Windows, macOS and Linux |
| Protects if the stick is later reused elsewhere | Only if reapplied | Always |
Michael recommends. If you are relying on staff to encrypt sticks themselves, assume the rate is lower than you have been told. Buy the encryption in hardware and the question of whether anybody remembered stops being a question.
The cost of getting this wrong is not theoretical
The Information Commissioner’s Office has been fining UK organisations over unencrypted removable media for years. In October 2018 it fined Heathrow Airport Limited £120,000 after an employee lost a memory stick that a member of the public found, took to a library and read. The device held 76 folders and more than a thousand files, and it was neither encrypted nor password protected. The full decision notice sits on the ICO website.
Two details from that case are worth carrying into your own specification. The employee had not set out to leak anything, and the organisation already had a policy telling staff to use encrypted devices. Neither fact helped, because the policy was not enforced by the hardware.
Most designs that end up in an incident report were specified sensibly with commercial parts by people doing their jobs properly. The fix is rarely a stricter policy. It is usually a device that cannot be used the wrong way.
Where encryption alone still leaves you exposed
Encryption protects the data on the stick. It does nothing about the port you plug it into.
That is the gap most security reviews miss. A standard USB receptacle accepts any device anybody happens to be holding, which is why USB has stayed such a reliable route into otherwise well defended networks. Mandiant reported a threefold rise in attacks using compromised USB drives across the first half of 2023, and the pattern has not gone away since. One widely reported case involved a European hospital, where an employee returned from a conference, plugged in a drive picked up along the way, and spread malware across the network.
The risk runs the other way too. A member of staff takes a document home on a stick, the file picks up an infection on a home machine, and the stick carries it back through the front door the next morning.
Even the cable can be the attack surface. Modern connectors carry data as well as power, so a tampered lead or a public charging point can move files and firmware in both directions. The NCSC publishes practical guidance on removable media and device security that is worth reading alongside your own policy.
Some organisations respond by banning removable media outright. IBM did exactly that in 2018, moving to a zero tolerance policy on USB sticks and SD cards across the company, and reporting at the time noted how disruptive that was going to be given how deeply the habit was embedded. Bans are hard to hold. The alternative is to keep removable memory and change what can physically be inserted.
Controlling the port, not just the file
If your equipment is in the field, on a production line, in a vehicle or in a hospital, the strongest control available is a memory device that a standard USB stick cannot mate with.
Datakey RUGGEDrive tokens give you USB or SD functionality behind a proprietary form factor. Your memory port will not accept a consumer stick, so nobody can walk up to your equipment and copy the configuration data, and nobody can introduce a file from a home laptop. If one of your tokens is lost, the finder almost certainly has nothing to read it with.
Datakey tokens are in service with NATO member armed forces, and we can talk through the detail under NDA.
The mechanical side matters as much as the security side.
- Receptacles rated for 50,000 insertion cycles, against roughly 1,500 for a typical USB connector and 10,000 for SD
- IP67 rated panel mount options for outdoor, dusty and wash down environments
- A sealed token designed for shock, vibration and temperature extremes rather than a shirt pocket
Where the job is authentication rather than bulk data, Datakey CryptoAuthentication tokens handle the transfer of keys, certificates, passwords and configuration files for systems that need cyber robust removable memory. And where the requirement is classified or restricted material, the Kobra VS range adds two factor authentication to hardware encrypted USB drives and SSDs, manufactured in Germany.
Michael recommends. Ask for the receptacle drawing before you commit to an enclosure design, not after. Panel cut out and rear clearance are what catch people out at the prototype stage, and they are trivial to solve at the sketch stage. Sending us the operating environment and who will be handling the device tells us more than a part number does.
Which option suits which job
| If your situation is | The usual answer |
|---|---|
| Office data leaving the building occasionally | Hardware encrypted USB such as FxLocker |
| Classified or restricted material, defence and government | Two factor authenticated encrypted drive, Kobra VS |
| Equipment in the field where anybody could reach the port | Proprietary form factor token, Datakey RUGGEDrive |
| Transferring keys, certificates or configuration files | CryptoAuthentication token |
| Harsh environment, wash down or outdoor panel | IP67 rated receptacle with a rugged token |
None of these rule each other out. Plenty of customers run an encrypted USB estate for office use and a token based system inside the product itself.
Making it stick once the hardware arrives
Good hardware fails quietly when the process around it is vague. A few habits are worth building in from the start.
- Decide who is allowed to hold a device, and write it down somewhere people actually read
- Keep an inventory of issued devices, so a missing one is noticed the same week rather than the same quarter
- Keep spares, so nobody borrows an unsecured stick because the secure one is in a drawer somewhere
- Keep firmware current, in the same rhythm as the rest of your maintenance
- Test the recovery path occasionally, because a recovery key nobody has ever used is a theory rather than a plan
- Brief new starters on why the device is different, not just on the password
That last one carries more weight than it looks. People follow a rule they understand and route around one they do not.
Frequently asked questions
Is BitLocker enough on its own? For low sensitivity office data on managed Windows machines, often yes. It falls down where users have to remember to apply it, where machines run macOS or Linux, or where the receiving computer is locked down. Hardware encryption removes all three problems.
Does AES-256 mean my data can never be recovered by anyone? It means recovery is not realistically achievable for an opportunist who finds the device. Treat it as excellent protection against loss and theft rather than an absolute guarantee, and match the standard to the sensitivity of the material. Where classification levels are involved, the approval on the product matters more than the algorithm name.
Can I retrofit a secure token into an existing product? Frequently, yes, though the receptacle needs a panel cut out and clearance behind it. Send us the enclosure drawing and we will tell you honestly whether it fits or whether you are better off waiting for the next revision.
What happens if a user loses a token? The data is protected by the encryption, and with a proprietary form factor the finder is very unlikely to own anything that can read it. You revoke the device in your inventory and issue a replacement, which is why keeping spares matters.
Can an encrypted stick be part of a recovery plan? Yes, and it is one of the few jobs where removable media still beats the cloud. If the network is down or the servers are unreachable, a hardware encrypted drive holding current configuration files and recovery material gets you moving without waiting for access to be restored. Keep it current, keep it in your inventory, and test occasionally that you can actually open it.
How long will the part stay available? Longer than most commercial memory. Long term supply commitments with our manufacturing partners are the reason customers with ten and fifteen year product lifecycles come to us, because a memory change part way through means requalification.
Talk it through before you specify
Every one of these decisions gets easier once somebody who has specified the part before looks at your actual application. Tell us the operating environment, who handles the device and what the data is worth if it walks out of the building, and we will tell you which of these routes fits.
Get in touch with the Nexus team for a straight answer, or request a memory sample if you would rather put one in your hand first. Nexus has been supplying secure industrial memory since 1987, and is the appointed partner for Datakey and Flexxon across the UK, Ireland and the DACH region.