Companies plan to take extensive actions in the next 12 months to address a broad concern for sensitive data being unprotected in use at the application layer. Only 24% of companies are employing techniques that protect data in the applications they control. Encryption, data masking, security audit logging, and tokenization were among top solutions listed by respondents. Cryptographic key management as the highest challenge in applying data protection in applications was ‘generating and storing cryptographic keys securely’ 98% cite using Hardware Security Modules to support encryption in applications.
Source: https://www.helpnetsecurity.com/2021/05/20/application-level-data-protection/