Skip to content
BCN-T1-DAT-003Tier 1 · CriticalData Protection

Unencrypted Sensitive Data at Rest

Regulated or business-critical data stored without encryption on systems exposed to compromise.

Remediation SLA
48 hours
Tier
1 · Critical
Domain
Data
Escalation
CISO and executive sponsor notified at 48 hours

What this finding is

Databases, volumes, snapshots, or backups holding regulated or business-critical data are stored without encryption at rest. Beacon reserves Tier 1 for the case where the unencrypted store sits on a system with a realistic compromise path — an internet-facing host, a shared platform, or a backup replicated to third-party infrastructure.

Why it is Tier 1

Encryption at rest is the control that determines whether a compromise is an incident or a notifiable breach. Snapshots and backups are copied far more widely than their source systems and routinely outlive the security controls that protected the original, which means an unencrypted snapshot exposes data long after the primary system is decommissioned. Most breach-notification regimes offer a safe harbour for properly encrypted data, so this control has direct financial consequence.

Most common misclassification

This is the finding most often misplaced between tiers. Tier 1 requires a realistic compromise path to the unencrypted store; where data is encrypted but the algorithm or key management does not meet the regulatory standard, the correct classification is BCN-T2-DAT-001.

How to detect it

  1. 1Inventory every storage volume, database instance, and snapshot, and report encryption state — snapshots are the most commonly missed category.
  2. 2Verify that encryption is enabled with a customer-managed or provider-managed key as policy requires, rather than merely that a flag is set.
  3. 3Check backup destinations and any replication targets separately; encryption at source does not imply encryption at the replica.
  4. 4Trace where regulated data is exported — reporting extracts, data-warehouse loads, and analytics copies frequently land in unencrypted stores.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Enable encryption on the highest-sensitivity store first; for engines that cannot encrypt in place, plan an encrypted replica and cut over.
  2. 2Re-encrypt existing snapshots by copying them into encrypted equivalents, then delete the unencrypted originals — creating the new copy alone does not close the finding.
  3. 3Move key material into a managed KMS with access policies separate from the data plane, so that database compromise does not yield keys.
  4. 4Enable encryption-by-default at account level so new resources inherit it without relying on the creator.
  5. 5Record the encryption state and key custodian in the data inventory, since regulators ask for evidence rather than assertion.

How to verify the fix

Every store and snapshot holding regulated data reports encryption enabled with the correct key, unencrypted originals are confirmed deleted, and account-level default encryption is active.

Mappings

Attacker techniques

  • T1530Data from Cloud Storage
  • T1005Data from Local System

Weakness

  • CWE-311Missing Encryption of Sensitive Data

Compliance mappings

  • PCI DSS v4.0
    3.5.1 — PAN rendered unreadable
  • HIPAA
    §164.312(a)(2)(iv) — encryption and decryption
  • GDPR
    Art. 32(1)(a) — encryption of personal data
  • ISO/IEC 27001:2022
    A.8.24 — use of cryptography

Tools that surface this

PROWLERCloudsploitScoutSuiteNessus