Yep. Very first thing I do when setting up a work machine is enable full-disk encryption, both to protect company assets from theft, and protect any sensitive material from prying coworkers/management.
Same here. It amazes me that this is not more common.
I wonder if doing this, just the action of choosing to encrypt, would be held up as sufficient grounds for the company to investigate your activity, or even possibly regarded immediately as criminal or potentially criminal. I can see a lot of companies coming up with extremely irrational policies that say that any attempt to encrypt anything is inherently not allowed.
What? I don’t just encrypt my desktop, I encrypt all the servers too, for the same reason.