Since there are usually significant costs to encrypting production databases, such as CPU utilization, many organizations choose to focus on other security controls. Data encryption is just one of many security controls at play in a scenario such as this and the security team has to carefully pick their battles to avoid just being completely ignored as the "say no to everything" guys.
For example, if done right, you need to decrypt with some form of passcode/system on boot, etc, etc. But once "unlocked" the system has access to the data, and usually the hackers come in via the "live" system.
Things like backups are usually encrypted but not always, but the number of incidents of people stealing physical media is pretty low compared to ransomware/remote hacks.