A company's serverless website utilizes an unencrypted Amazon S3 bucket as the origin for a CloudFront distribution. The solutions architect must implement encryption for existing and future S3 objects with minimal effort. What is the most efficient approach?