> Similar to encryption in transit, practicing data encryption at rest—using standards like AES-256—will ensure that stored data is not accessible to any application or user unless they present the decryption key.
A lot of people seem to have the attitude "Oh, my DB is in Amazon RDS, and they say everything is encrypted, so I'm good". However, if your DB creds get hacked, they can still read all the info in your DB.
What should really be required is a tokenization or app-side encryption scheme, ideally using something like AWS or GCP KMS so that all decryption requests are logged and monitored, for any even remotely sensitive data that is saved to the DB. That can also make it much easier for developers, because it's safe to give out read-only user access if you're sure they can't read any sensitive private data.