We encrypted the most sensitive user data in the database even though no regulation required it. The product collected detailed family and personal histories, nothing legally protected, so most teams would have stored it in plain text. We didn't. Building protection in early cost days. Retrofitting after a breach would cost weeks, plus the trust you don't get back.
