Does someone have a nice guide to do full disk encryption, and other recommendations so that we can at least be a little certain our data isn't being tampered with?
That's if you trust TCG and OPAL, and have an OPAL drive. Windows will use OPAL automatically if available for at least Pro and Enterprise and Server products, I'm not sure about Home. Apple and Linux have software implementations (typically with AES hardware support by the CPU).
If you live in linux-land and assuming bandwidth is not an issue, then it's trivial to move to a VDI solution. See Apache Guacamole for an excellent example of web-enabling remote desktop access.