- Using SSL/TLS encryption for data transfer
- Storing data in plaintext format
- Disabling encryption for improved performance
- Sharing encryption keys with third-party vendors