I mostly just see "not even encrypted" by way of password stores and PII though — stuff no employee or CFO is ever going to need to visually examine — and those we have a lot of best practices to fall back on about keeping always encrypted all the time.