Harden the Tiers that Hold Your Data
Database and Web Server Configuration Review
We review your database and web server configurations against CIS Benchmarks and vendor guides. You learn where authentication, encryption and access settings fall short, and how to close the gaps without downtime.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Databases and web servers sit closest to your data, yet they often run with default accounts, weak TLS and loose permissions. This review reads the configuration of your database engines and web servers, compares it to the matching CIS Benchmark and vendor hardening guide, and checks the settings that protect your data: authentication, encryption in transit, access control and logging. We validate a small number of findings safely so you know what is real, then hand you a runbook to harden each tier.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Database and Web Server Configuration engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx. Activities: Inventory database engines, versions and hosting locations; Inventory web servers and reverse proxies in scope; Select the matching CIS Benchmark per engine and server; Agree which instances allow safe active validation. Hands over Tier Inventory and Baseline Selection. Phase 2, Evidence and Config Collection. We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports. Activities: Export database instance parameters and startup settings; List database logins, roles and object-level grants; Collect Apache, Nginx and IIS configuration files and modules; Record TLS certificate, protocol and cipher settings per endpoint. Hands over Tier Configuration Evidence Set. Phase 3, Benchmark Comparison. We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides. Activities: Run CIS-CAT Pro against each database and web server; Run Nessus database compliance policies where supported; Map failed checks to CIS control numbers per engine; Score each instance against its benchmark. Hands over CIS Benchmark Scorecard Per Instance. Phase 4, Manual Review and Safe Validation. We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate. Activities: Check for default accounts, shared logins and weak SQL authentication; Review TLS ciphers and protocols with testssl.sh; Scan web servers with Nikto for exposed files and headers; Run read-only sqlmap checks on agreed endpoints; Verify audit logging captures privileged database activity. Hands over TLS and Access-Control Assessment. Phase 5, Prioritised Findings. Findings are ranked by exposure to your data, with affected instances listed so remediation is precise. Activities: Rank findings by how close they sit to sensitive data; Name the affected instances and endpoints per finding; Separate settings changeable live from those needing a restart; Walk the database and platform owners through the results. Hands over Database and Web Server Findings Report. Phase 6, Remediation and Re-Check. We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved. Activities: Write hardening steps per engine with exact parameter values; Provide tested TLS configuration blocks for each server type; Advise on sequencing changes around maintenance windows; Re-run the benchmark and TLS checks and reissue the grades. Hands over Hardening Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
What Happens In This Phase
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
The Handover
Tier Inventory and Baseline Selection
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
What Happens In This Phase
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
The Handover
Tier Inventory and Baseline Selection
The next phase starts from this.
- 01
Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
OutputTier Inventory and Baseline SelectionActivities
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
- 02
Evidence and Config Collection
We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports.
OutputTier Configuration Evidence SetActivities
- Export database instance parameters and startup settings
- List database logins, roles and object-level grants
- Collect Apache, Nginx and IIS configuration files and modules
- Record TLS certificate, protocol and cipher settings per endpoint
- 03
Benchmark Comparison
We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides.
OutputCIS Benchmark Scorecard Per InstanceActivities
- Run CIS-CAT Pro against each database and web server
- Run Nessus database compliance policies where supported
- Map failed checks to CIS control numbers per engine
- Score each instance against its benchmark
- 04
Manual Review and Safe Validation
We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate.
OutputTLS and Access-Control AssessmentActivities
- Check for default accounts, shared logins and weak SQL authentication
- Review TLS ciphers and protocols with testssl.sh
- Scan web servers with Nikto for exposed files and headers
- Run read-only sqlmap checks on agreed endpoints
- Verify audit logging captures privileged database activity
- 05
Prioritised Findings
Findings are ranked by exposure to your data, with affected instances listed so remediation is precise.
OutputDatabase and Web Server Findings ReportActivities
- Rank findings by how close they sit to sensitive data
- Name the affected instances and endpoints per finding
- Separate settings changeable live from those needing a restart
- Walk the database and platform owners through the results
- 06
Remediation and Re-Check
We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved.
OutputHardening Runbook and Re-Check ReportActivities
- Write hardening steps per engine with exact parameter values
- Provide tested TLS configuration blocks for each server type
- Advise on sequencing changes around maintenance windows
- Re-run the benchmark and TLS checks and reissue the grades
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Database and Web Server Configuration scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: CIS-CAT Pro, sqlmap (read-only validation), Nikto, testssl.sh, Qualys SSL Labs, DBeaver, Nessus (database compliance), web server config parsers. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Microsoft SQL Server Benchmark, CIS Oracle, MySQL and PostgreSQL Benchmarks, CIS Apache HTTP Server Benchmark, CIS Nginx Benchmark, DISA Database and Web Server STIGs, NIST SP 800-53, Vendor hardening guides.
What We Run
8 tools
- CIS-CAT Pro
- sqlmap (read-only validation)
- Nikto
- testssl.sh
- Qualys SSL Labs
- DBeaver
- Nessus (database compliance)
- web server config parsers
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
7 standards
- CISMicrosoft SQL Server
- CISOracle, MySQL and PostgreSQL
- CISApache HTTP Server
- CISNginx
- DISASTIGsDatabase
- NIST SP 800-53
- VENDORHardening Guides
Deliverables
What You Receive
- Database and web server findings report
- CIS benchmark scorecard per instance
- TLS and access-control assessment
- Hardening runbook
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Which database engines and web servers does this review cover, and what happens if we run something unusual?
The review covers the common engines and servers that have a published hardening baseline: SQL Server, Oracle, MySQL and PostgreSQL on the database side, and Apache, Nginx and IIS on the web side, each measured against its matching CIS Benchmark. Scoping is where the edge cases get settled. During the 30-45 minute scoping call we inventory the engines, versions and hosting locations you actually run, including the reverse proxies that are easy to forget, and we say plainly which of them have a published benchmark and which do not. Where an engine has none, we do not pretend otherwise: we review it against the vendor hardening guide and the relevant NIST SP 800-53 controls instead, and the report records which baseline was used for that instance. You receive a written scope naming the instances included, with a timeline and a fixed price, before work begins.
What exactly is examined inside a database or web server, and what is left out?
Five things drive the review: authentication, encryption in transit, access control, logging, and management interfaces that should not be reachable. On the database side that means default and shared accounts, weak SQL authentication modes, the object-level grants held by service logins, and whether audit logging captures privileged activity rather than only failed logins. On the web side it means TLS protocols and ciphers per endpoint, exposed configuration files, status and admin handlers left open, and modules loaded for no reason. What is left out: we read configuration, so we do not audit your key custody and rotation processes, and we do not read the data itself. Encryption at rest sits outside the scope of this review as well. Those questions belong in a compliance engagement rather than a hardening review, and we will say so at scoping.
Can you run this against production, and how do you avoid causing an outage?
Yes, and the reason is that the bulk of the work is read-only. One phase exists purely to collect evidence: parameters, startup settings, logins, roles, grants, configuration files and certificate details are exported as read-only evidence, which places no more load on an instance than a monitoring query does. Active checks are the narrow exception. Benchmark scanning, TLS grading and the read-only sqlmap validation run against the instances you nominated during scoping, at times you choose, and nothing in that set is destructive. Which instances allow safe active validation is agreed in the first phase, before anyone connects. Findings are reproduced by hand and carry proof of concept, so you are not chasing a scanner's guess during a maintenance window. The findings phase also separates the settings you can change live from those that need a restart, so remediation is sequenced around your maintenance windows rather than ours.
How do the findings turn into evidence we can hand an auditor?
The artefact auditors ask for is the CIS benchmark scorecard per instance, and you receive one for each database and web server in scope. It names the instance, the baseline it was measured against, which checks passed and failed, and the CIS control number behind each failure. That is what makes it usable as evidence for a configuration-baseline control, rather than a screenshot somebody took once and filed. The same single pass is graded against the DISA STIGs and NIST SP 800-53 as well, so you are not funding the work again per framework. The re-check at the end matters as much as the first scan: a scorecard showing a failure closed and re-verified is stronger evidence than a remediation ticket marked done. If the wider control programme is what you are building, our ISO 27001 and PCI DSS services carry that side.
Where does this review stop and application penetration testing begin?
This review examines how the tiers are configured; application testing examines what your code does with them. The line is easiest to see through an example. If a web server exposes a directory listing, negotiates TLS 1.0, or a database service account holds write access to tables it only reads from, those are configuration findings and they belong here. If a search field concatenates user input into a query and returns another tenant's rows, that is an application flaw and it belongs in a penetration test, even though the damage lands in the same database. The read-only sqlmap checks in phase four sit deliberately on the configuration side of that line: they confirm exposure on endpoints you nominated, and they are not a substitute for testing the application. Our Web Application penetration testing service covers that, and the two pair well in one window.
Keep Moving Through Hardening and Configuration Review
Service 5 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths