Encryption at Rest as the 2026 Default

Most clouds now offer encryption-by-default. The remaining configuration to enforce and verify.

Default-on encryption

Default-on encryption removes the per-resource decision entirely. The team configures the account once, and every resource provisioned afterwards inherits the encrypted-by-default setting.

Verifying encryption

Default-on does not verify itself. Config rules and quarterly audits catch the rare cases where a resource slips past the default or a manual override turns it off.

KMS for sensitive data

KMS handles the high-sensitivity tier. Customer-managed keys grant the team explicit control over rotation, access policy, and per-tenant blast-radius scoping.

Why default-on matters

Default-on is a multiplier on every later security investment. The cost is near zero and the cleanup it removes is endless.