Failure to properly protect sensitive data can be difficult to recognize during application development. The database management system is just one part of an application, however. This session will explore ways in which databases can be compromised to expose sensitive information and help database administrators and applications developers take a risk-based approach to protecting their data.