DFIELDSOLUTIONS

Security

GlossaryEncryption at rest

Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.

The other half of 'encrypt everything': TLS protects data moving between systems, encryption at rest protects it sitting still — a stolen laptop, a leaked S3 bucket, a backup drive in a taxi. Modern databases and cloud storage offer it nearly free; the real question is rarely whether but who holds the keys.

Key management is where the security actually lives: keys in a managed vault (KMS), rotated, access-logged. An encrypted database whose key sits in the same repository's config file is a locked safe with the combination taped to it.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain