How to Encrypt a Shared Folder on a Synology NAS for Privacy
A Synology NAS can hold tax records, family photographs, business documents, client files and device backups in one central location. That convenience also makes access control important: anyone who obtains administrator credentials, removes a drive, or gains access to an unprotected backup may be able to read the data. Encrypting a shared folder adds a strong layer of protection beyond user permissions and login passwords.
This guide explains how to encrypt a shared folder on a Synology NAS for privacy using DiskStation Manager (DSM). It covers preparation, setup, key management, everyday access and the practical limitations that Australian households and businesses should consider before enabling encryption.
What Shared Folder Encryption Protects
Synology shared folder encryption uses AES-256 encryption to protect stored data. When the folder is locked, its contents cannot be read normally, even if someone removes the hard drives and connects them to another computer or Synology system. This is particularly useful for confidential PDFs, identity documents, payroll records, legal files and private photographs.
Encryption applies to the selected shared folder rather than automatically covering every file on the NAS. Other folders, system settings, application databases and some package data may remain unencrypted. A person who can log in to DSM with sufficient privileges may also be able to access a folder while it is unlocked, so encryption should work alongside strong accounts, multi-factor authentication and carefully managed permissions.
It is also important to distinguish encryption at rest from encryption during transfer. Shared folder encryption protects files stored on the NAS. Secure protocols such as HTTPS, SFTP and SMB encryption help protect data moving between the NAS and computers on the network. Using both approaches provides more complete privacy.
Check Your NAS Before Enabling Encryption
Sign in to DSM with an administrator account and open Control Panel > Shared Folder. Before creating an encrypted folder, check the available storage space, the current DSM version and the Synology model’s supported features. The exact wording can differ between DSM releases, and older hardware may handle encryption more slowly than current Plus-series systems.
Encryption can affect performance because the NAS must encrypt and decrypt data as it is written and read. Modern Intel or AMD-based models generally cope well with ordinary documents and media libraries, while entry-level ARM systems may show a larger impact during heavy file transfers. If you are comparing hardware, a NAS hardware reference can help you examine processor, memory and drive specifications before choosing a model.
Plan the folder structure before switching on encryption. A folder containing large video files, active virtual machines or frequently accessed database files may be a poor first test. Begin with a dedicated folder for sensitive documents, then measure transfer speeds and application compatibility before moving additional data.
Create An Encrypted Shared Folder
In DSM, open Control Panel, choose Shared Folder, and select Create. Give the folder a clear name, add an optional description, and continue until DSM displays the encryption option. Select Encrypt this shared folder, then enter a strong encryption key or passphrase. This key is separate from the DSM administrator password and must be treated as the primary credential for opening the folder.
DSM may offer an option to save or download the encryption key file. Accept this option and store the key securely outside the NAS, such as in an encrypted password manager or an offline storage device held in a secure location. Do not leave the only copy in the encrypted folder itself. If the key is lost and the folder is locked, Synology cannot recover the contents for you.
After confirming the settings, DSM creates the folder and applies permissions. Assign access only to the users and groups that require it. Disable broad access for guest accounts, review read-and-write permissions, and avoid giving ordinary users administrative privileges. For a household, this might mean a private folder for identity records rather than placing everything in a shared family folder.
Manage Keys And Mounting Carefully
An encrypted shared folder must be mounted before its files can be used. In DSM’s shared folder controls, an administrator can mount or unmount the folder by supplying the encryption key. When mounted, authorised users can work with files according to their normal permissions. When unmounted, the data becomes inaccessible through file-sharing services and applications.
Some Synology systems can mount encrypted folders automatically after a restart by storing the key in the NAS’s key manager. This is convenient after a power failure, which is common during severe storms or local infrastructure outages, but it reduces protection against someone who gains physical access to a powered-on or automatically restarting NAS. For highly confidential information, manual mounting may provide a better security balance.
Keep a documented key-recovery process. A business should decide who may access the key, where the backup key is stored and how access is transferred if an administrator leaves. A household should ensure that a trusted person can locate the key without placing it in an unprotected text file or beside the NAS. Test the saved key by using it to unlock a separate copy or test folder before relying on it for irreplaceable records.
Understand Backups And Synology Apps
Encryption does not replace a backup. If ransomware deletes files while the encrypted folder is mounted, or a drive fails, encryption will not restore the data. Use the 3-2-1 approach where practical: maintain three copies, on two different types of storage, with at least one copy stored elsewhere. An external USB backup and a reputable cloud destination can complement the NAS.
Check how each Synology application handles encrypted folders. Hyper Backup can back up data, but the backup job’s encryption settings are separate from the source folder’s encryption. Enabling client-side encryption for an off-site backup prevents the storage provider from reading the files, even if the backup destination is compromised. Keep the Hyper Backup password or key in a separate secure location.
Snapshots and replication are useful for recovering earlier versions, but they are not automatically an independent disaster-recovery copy. A snapshot stored on the same volume may be affected by serious storage failure, theft or a destructive administrator action. Test file restoration regularly, including the process of unlocking the source folder and decrypting an off-site backup.
Australian businesses should also consider the Privacy Act 1988 and the Australian Privacy Principles where they apply to personal information. Covered organisations need reasonable steps to protect information from misuse, loss and unauthorised access. Encryption supports that obligation, but it does not by itself guarantee compliance, especially where access policies, retention practices and breach response are weak.
Fit Encryption Into Australian Home And Business Use
Australian households often scan passports, Medicare correspondence, insurance papers and property documents into digital storage. Keeping those files in an encrypted folder can reduce exposure if a NAS is sold, stolen during a house break-in or returned for warranty service. It is still wise to remove old drives securely and follow a documented process before disposing of them.
For a small business in Sydney, Melbourne, Brisbane or Perth, an encrypted folder can separate client material from general team documents. Staff may work remotely over an NBN connection, so DSM accounts should use multi-factor authentication and access should be limited through a VPN or secure reverse-proxy arrangement rather than exposing DSM directly to the internet. Encryption protects stored files, while those network controls reduce the chance of account compromise.
Location and resilience matter as well as privacy. A NAS in a garage or spare room may face heat, dust, flooding or power interruptions. Place it somewhere ventilated and protected, use a UPS where appropriate, and keep an encrypted backup in another location. Businesses should also account for the Australian Notifiable Data Breaches scheme when developing an incident-response plan: if personal information is exposed, encryption status may affect the risk assessment, but it does not remove the need to investigate.
Before encrypting a production folder, create a small test folder and perform the complete cycle: copy files, unmount it, restart the NAS, restore the key, mount it again and recover a file from backup. This confirms that your chosen applications, users and recovery process work as expected. Record the DSM version and key location in a restricted internal document, without writing the actual passphrase in that document.
Open Control Panel > Shared Folder today and start with a small collection of sensitive, non-critical files. Save the encryption key securely, review user permissions, configure an independent backup and test recovery before moving important records. A carefully managed encrypted folder can make a Synology NAS a far safer home or business repository without sacrificing the convenience of centralised storage.