Ensure that 'OS and Data' disks are encrypted with Customer Managed Key (CMK)
Encrypting the IaaS VM's OS disk (boot volume), Data disks (non-boot volume) ensures that the entire content is fully unrecoverable without a key and thus protects the volume from unwarranted reads. CMK is superior encryption although requires additional planning.
Updated 7 months ago