Service · Cybersecurity

Database security

A database gathers everything the company knows into one place, in the format that is easiest of all to copy. Even so it is often guarded less carefully than the application in front of it: careful roles and profiles in the software, and underneath a single all-powerful account whose password is known to the previous IT person, the current maintainer and the firm that installed the ERP six years ago.

Shared admin
the account we switch off
1433
a port with no business facing the internet
TDE
encryption of the database files
Backups
encrypted and immutable

Where this service reaches

Three questions cover the subject: who can connect, what they are allowed to do, and whether a trace remains. We work with SQL Server, PostgreSQL, MySQL and MariaDB, on physical servers, on a VPS or in the cloud.

Put your scope to an engineer

Accounts

A named account for each administrator and a restricted account for each application. The all-powerful account is disabled or locked in a vault, with a written procedure for the rare occasions it must come out.

Network isolation

Direct connections from user workstations are closed, and exposure to the internet should not exist at all. The application talks to the database; people talk to the application.

Access auditing

Sign-ins, permission changes and above all bulk reads. Pulling the whole orders table cannot pass without leaving a trace somebody can read the next morning.

Encryption

Transparent encryption of the data files, encrypted application connections, and encryption of every backup file, including the ones produced by hand just before an upgrade.

Test datasets

Anonymised copies for developers and testers. Checking a new report needs neither real names nor real addresses nor real bank details.

Engine patching

A regular routine for applying security fixes to the engine, tried on a copy before anything touches production.

The way an engagement runs

Changes to a production database happen in a window agreed with you and, where the software vendor has its own requirements, with them as well.

01

Review

Who connects, from where and with which rights. Forgotten accounts nearly always turn up: a consultant from years back, an application retired two summers ago.

02

Tidying access

Unnecessary network paths closed, one account created per administrator, and passwords shared between several people withdrawn.

03

Auditing and encryption

Logging switched on, then encryption applied to the data and to the backup archive alike.

04

Proof

We check that a bulk read really does leave a trace and that restoring from an encrypted backup actually works, with a stopwatch running.

A backup is a database too, just watched less closely. Hand-made export files often sit on a network share half the company can open, unencrypted and with no record of who read them. Whoever holds the copy holds the data, however carefully the server itself has been hardened.

Questions and answers

We first try to reproduce it on an anonymised dataset, which is enough in most cases. If not, access to production is named, time-limited, read-only and logged, and it closes itself at the agreed deadline.

That depends on the version and edition installed. Recent versions offer it more widely than they used to, so we look at your licence before recommending anything. On an older engine we go through disk and backup encryption instead, or plan an upgrade.

Ask which operations actually require it. In almost every case a narrower account will do, or the full account is opened for the length of an upgrade with the password changed at the end of the session. We can hold that technical conversation on your behalf.

At the rhythm set in your backup plan, and always after a significant version change. The test means bringing the database up in a separate environment and starting the application on it, not confirming that a file exists and is roughly the right size.

Who holds the keys to your database?

Tell us which engines run your applications and where they are hosted. We will propose the scope of a first review.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.