An IS auditor reviewing a company's encryption practices finds that sensitive data at rest is encrypted using a symmetric key stored in the same database as the data.What is the PRIMARY concern?