You always get people screaming about 'it should have been encrypted!' when there's a leak without understanding what encryption can and can't do in principle and in practice (it most certainly isn't a synonym for 'secure' or 'safe').
Whenever someone says "But it should have been encrypted!" about things like configs on a server, I ask them how they'd implement that in practice.
PoC or GTFO.
I think you'll find it's a bit harder to do than you expect.
Encryption turns your data confidentiality problem into a key management problem.