Trust me, I've been there. Well, on the fringes, at least.

The only way it works for end-users (e.g. reasonably un-teched senior executives) is if it is part of a secure PC package - which brings up issues of key management. And then they don't see the point in picking individual files to encrypt. The downside is not that encrypting the whole disk needs to be pretty fast but you need a personnel structure for managing supervisor passwords in case they forget their own or have hardware problems.

In other words, it has to be managed by the same people who already manage encrypting services in IT. Or the end-users will quickly find it Too Hard To Do.

Wade.