Hi there,
Have you ever had something stolen from you? It's a horrible feeling of invasion. I'm fortunate that the most expensive thing I've had stolen from me was a pair of sunglasses lifted out of the side pocket of my backpack while riding the subway. That, and my data.
When a company loses someone's data, it's almost always sensitive and meaningful information that affects you, me, and people all over the world. People's lives are impacted when their information is stolen. Trust is broken. Reputations are damaged.
But often, organizations treat all of the data they hold like it's just bits and bytes and like the only consequence of poor protection is the prospect of hassles and headaches.
It's insane to me that more organizations haven't embraced the obvious solution: application-layer encryption (ALE). If you could choose between a hack resulting in a massive leak of the personal information of your customers versus a large bag of unimportant data mixed with encrypted data that the attackers don't have the means to decrypt, what would you choose?
Application-layer encryption has many uses, and in our most recent blog we discuss How to Neutralize Toxic Data In Custom Fields. Read the blog to learn more about this common pattern in cloud applications and how to reduce the risks inherent in custom fields.