Increase your SQL Server Security!
The Problem
From our experience, the SQL Servers we encounter haven’t been set up and configured with security in mind. SQL Server’s default settings are strong but not necessarily the most secure; as an example, an essential principle in a good security model is “the principle of least privilege” where you only grant the bare minimum of permissions needed to perform the work. Often this is not implemented across database and application security models. With GDPR and other regulatory data security factors also coming into play, organisations need to ensure that their database platform is as secure as possible.
Our SQL Server Hardening Process
We will look at your SQL Server’s security configuration compare against an industry benchmark and then work with you and your applications teams to work out what actions can be taken to “harden” the SQL Server as much as possible. Reducing the attack surface area, encrypting data where needed and design a security model for your users and your applications built on the principle of least privilege. Our security hardening process uses a simple ABC approach:
A. Analyse and Design
We have developed a series of scripts which we can run against your SQL Server to obtain critical information about its security configuration and assess whether that aligns with best practice. These scripts focus on several key areas listed below.
- Installation Version, CU and Service Pack Levels – we will ensure that they the most recent patch levels are applied and check that SQL Server has a dedicated
- Surface Area Reduction – We will examine whether you have features enabled which are not required. A feature not being used potentially poses a security risk. Minimising the ‘attack’ surface area reduces the target for a potential hacker.
- We’ll examine how your Servers are configured for authentication and authorisation, identifying who has SysAdmin rights, whether any of your databases have orphaned users, whether the services accounts are set to best practice and, where a SQL login exists, ensure that password policies are applied.
- We’ll examine how your SQL Server log is configured and check whether it is capturing the correct information to identify a potential security breach.
- We’ll identify databases that have been encrypted or could benefit from encryption and ensure that we choose an appropriate encryption algorithm.
B. Build and Execute
With our analysis complete, we can work with your DBAs and Application Developers and any other key stakeholders to implement the changes required to the configuration of your SQL environment to secure the database, while minimising effects on your applications.
C. Manage
If an organisation is struggling with security, whether its keeping patch levels up to date, keeping control of access, following the principle of least privilege or just enhancing database security in general, we can help. If your organisation has a full-time DBA, this will likely fall to them. In which case we are happy to hand over all the work we have done. If you have DBA in another data platform technology or staff member who will be responsible for the data platform afterwards, we can help with any training needs they may have. If you don’t have a full-time DBA or dedicated resource to help manage the data platform security, then you can engage and utilise our data platform managed service offering, and we handle your data platform for you which will include undertaking periodic performance reviews, patching, ensuring back-ups have been successful, ensuring that security is in place and conducting regular maintenance. Alternatively, you can engage with us with using a “pay as you go” support service, whereby you call off support time, as and when you need help.
Talk to us for free today