Insecure storage of sensitive information

Overview

Sensitive information such as tokens, secrets and passwords should never be stored in the database.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
41%24%
arrow down16%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
2 years6 months
arrow down73%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconUse of EncryptioniconA07:2021 – Identification and Authentication Failuresicon