Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What happens when organisations skip encryption and secure…
Cyber Security

What happens when organisations skip encryption and secure backup planning for sensitive data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Cyber Security

Without encryption and reliable backups, a breach or loss event can become both a confidentiality problem and an availability problem. Sensitive data may be exposed in transit or at rest, and recovery can be slow, incomplete, or impossible. Those failures amplify operational disruption, increase remediation cost, and make regulatory response much harder.

How Missing Encryption Turns a Data Loss Event into Exposure

Encryption changes the failure mode of sensitive data. If a file, backup, database export, or transport path is compromised without encryption, the attacker or unintended recipient can read the content directly. That matters most for records with long-term value, such as customer data, credentials, regulated personal data, financial records, and internal operational data.

Unencrypted data is also harder to contain once copied. If storage media, snapshots, archives, or backup sets are exposed, the organisation may have no practical way to limit disclosure after the fact. Strong handling of sensitive data normally pairs NIST SP 800-53 Rev 5 Security and Privacy Controls with encryption, access control, and auditability so the data remains protected even when a surrounding control fails.

Encryption does not prevent every breach, but it narrows the blast radius. With good key management and protected backups, a stolen copy may be useless to the attacker, while the organisation still has a usable recovery path. That is why key handling and storage design matter as much as the encryption algorithm itself, and why NIST SP 800-57 Key Management is directly relevant to the protection of encrypted data.

Why Backup Planning Is Part of Security, Not Just Recovery

Backups are the difference between a recoverable incident and a prolonged outage. If the organisation loses production data through ransomware, deletion, corruption, or platform failure and the backups are missing, outdated, or unusable, the incident becomes an availability crisis as well as a security event. In practice, the question is not whether backups exist, but whether they can restore the right data within the required time.

Secure backup planning has to cover more than copy frequency. Teams need to think about retention, immutability, offline or isolated copies, restore testing, and whether the backup set includes everything required to rebuild the service. If backups are encrypted but the keys are unavailable, or the restore process is never tested, the organisation still faces the same outcome: slow recovery, data loss, and business interruption.

Good recovery design is also a governance issue because it determines whether the organisation can meet operational commitments after an incident. Controls in NIST Cybersecurity Framework 2.0 emphasise not only protection, but recovery and resilience, which is exactly where secure backup planning belongs.

What Gets Worse When Encryption and Backups Fail Together

The most damaging cases occur when confidentiality and availability fail at the same time. A compromise that exposes sensitive data can also destroy or encrypt the only viable backups, leaving the organisation with both disclosure and downtime. That combination increases regulatory pressure, complicates incident response, and forces leaders to choose between delayed restoration and rebuilding from partial data.

The operational consequence is often wider than the original data set. Systems that depend on the affected records may fail downstream, manual workarounds may introduce errors, and customer-facing processes may stall. If the data includes identity material, payment data, or regulated personal information, the recovery burden expands into legal, contractual, and notification obligations as well.

Cloud and distributed environments make this more visible because backup copies, replicas, and archives may live across multiple services and administrative boundaries. NIST Privacy Framework is relevant here because data handling, minimisation, and retention choices affect how much exposure a lost or copied backup can create.

Risk and Threat Considerations

Skipping encryption and backup planning increases both attacker payoff and failure impact. Attackers look for unencrypted stores because they can read or exfiltrate data immediately, and they target weak backup design because it removes the organisation’s recovery option after encryption, deletion, or sabotage.

Failure mechanism: Sensitive data remains readable in transit, at rest, or inside backup media, while weak backup design leaves no trusted restore path after breach, ransomware, corruption, or accidental deletion.

Impact: The organisation may face direct disclosure, extended outage, failed recovery, higher remediation cost, and a much harder legal or regulatory response because it cannot prove protection or restore integrity quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-57 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SC-28 — Protection of Information at RestSensitive data at rest needs encryption to limit breach exposure.
CP-9 — System BackupBackup planning is central to recoverability after loss, corruption, or ransomware.
Recommendation — Encrypt sensitive data at rest and protect backup media and archives. Maintain and test backups that support timely recovery of critical data.
NIST SP 800-57Key lifecycle management — Key LifecycleEncrypted data depends on protected keys and recoverable key lifecycle handling.
Recommendation — Manage encryption keys so backup recovery remains possible after an incident.
NIST CSF 2.0PR.DS-01 — Data-at-Rest ProtectionProtecting stored sensitive data directly addresses the confidentiality risk in the question.
RC.RP-01 — Recovery Plan ExecutionReliable backup planning supports restoration after loss or ransomware.
Recommendation — Apply data-at-rest protection to sensitive information and backup copies. Test recovery procedures so critical data can be restored under pressure.
ISO/IEC 27001:2022A.8.13 — Information BackupThe subject directly concerns backup planning and restore capability for sensitive data.
A.8.24 — Use of CryptographyEncryption is the central control for reducing disclosure risk in transit and at rest.
Recommendation — Define backup frequency, protection, and restore testing for sensitive data. Use cryptography to protect sensitive data and related backup copies.

Practitioner Guidance

What to prioritise: Treat encryption, key protection, and backup recoverability as one control family. If any one of the three is missing, the overall protection story is incomplete.

What to verify: Confirm that sensitive data is encrypted in transit and at rest, that backup copies are protected with separate access boundaries, and that at least one restore path has been tested against a realistic outage scenario.

Common mistake: Assuming that “we have backups” means “we can recover.” A backup that cannot be restored, or a restore that depends on unavailable keys or broken permissions, is not a reliable control.

Practitioner takeaway: The real objective is not simply to store copies, but to preserve confidentiality while keeping a proven path to restoration when the primary system, keys, or data are lost.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org