Harden the Tiers that Hold Your Data
Database and Web Server Configuration Review
We review your database and web server configurations against CIS Benchmarks and vendor guides. You learn where authentication, encryption and access settings fall short, and how to close the gaps without downtime.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Databases and web servers sit closest to your data, yet they often run with default accounts, weak TLS and loose permissions. This review reads the configuration of your database engines and web servers, compares it to the matching CIS Benchmark and vendor hardening guide, and checks the settings that protect your data: authentication, encryption in transit, access control and logging. We validate a small number of findings safely so you know what is real, then hand you a runbook to harden each tier.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Database and Web Server Configuration engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx. Activities: Inventory database engines, versions and hosting locations; Inventory web servers and reverse proxies in scope; Select the matching CIS Benchmark per engine and server; Agree which instances allow safe active validation. Hands over Tier Inventory and Baseline Selection. Phase 2, Evidence and Config Collection. We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports. Activities: Export database instance parameters and startup settings; List database logins, roles and object-level grants; Collect Apache, Nginx and IIS configuration files and modules; Record TLS certificate, protocol and cipher settings per endpoint. Hands over Tier Configuration Evidence Set. Phase 3, Benchmark Comparison. We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides. Activities: Run CIS-CAT Pro against each database and web server; Run Nessus database compliance policies where supported; Map failed checks to CIS control numbers per engine; Score each instance against its benchmark. Hands over CIS Benchmark Scorecard Per Instance. Phase 4, Manual Review and Safe Validation. We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate. Activities: Check for default accounts, shared logins and weak SQL authentication; Review TLS ciphers and protocols with testssl.sh; Scan web servers with Nikto for exposed files and headers; Run read-only sqlmap checks on agreed endpoints; Verify audit logging captures privileged database activity. Hands over TLS and Access-Control Assessment. Phase 5, Prioritised Findings. Findings are ranked by exposure to your data, with affected instances listed so remediation is precise. Activities: Rank findings by how close they sit to sensitive data; Name the affected instances and endpoints per finding; Separate settings changeable live from those needing a restart; Walk the database and platform owners through the results. Hands over Database and Web Server Findings Report. Phase 6, Remediation and Re-Check. We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved. Activities: Write hardening steps per engine with exact parameter values; Provide tested TLS configuration blocks for each server type; Advise on sequencing changes around maintenance windows; Re-run the benchmark and TLS checks and reissue the grades. Hands over Hardening Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
What Happens In This Phase
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
The Handover
Tier Inventory and Baseline Selection
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
What Happens In This Phase
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
The Handover
Tier Inventory and Baseline Selection
The next phase starts from this.
- 01
Scoping and Baseline Selection
We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.
OutputTier Inventory and Baseline SelectionActivities
- Inventory database engines, versions and hosting locations
- Inventory web servers and reverse proxies in scope
- Select the matching CIS Benchmark per engine and server
- Agree which instances allow safe active validation
- 02
Evidence and Config Collection
We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports.
OutputTier Configuration Evidence SetActivities
- Export database instance parameters and startup settings
- List database logins, roles and object-level grants
- Collect Apache, Nginx and IIS configuration files and modules
- Record TLS certificate, protocol and cipher settings per endpoint
- 03
Benchmark Comparison
We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides.
OutputCIS Benchmark Scorecard Per InstanceActivities
- Run CIS-CAT Pro against each database and web server
- Run Nessus database compliance policies where supported
- Map failed checks to CIS control numbers per engine
- Score each instance against its benchmark
- 04
Manual Review and Safe Validation
We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate.
OutputTLS and Access-Control AssessmentActivities
- Check for default accounts, shared logins and weak SQL authentication
- Review TLS ciphers and protocols with testssl.sh
- Scan web servers with Nikto for exposed files and headers
- Run read-only sqlmap checks on agreed endpoints
- Verify audit logging captures privileged database activity
- 05
Prioritised Findings
Findings are ranked by exposure to your data, with affected instances listed so remediation is precise.
OutputDatabase and Web Server Findings ReportActivities
- Rank findings by how close they sit to sensitive data
- Name the affected instances and endpoints per finding
- Separate settings changeable live from those needing a restart
- Walk the database and platform owners through the results
- 06
Remediation and Re-Check
We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved.
OutputHardening Runbook and Re-Check ReportActivities
- Write hardening steps per engine with exact parameter values
- Provide tested TLS configuration blocks for each server type
- Advise on sequencing changes around maintenance windows
- Re-run the benchmark and TLS checks and reissue the grades
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Database and Web Server Configuration scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: CIS-CAT Pro, sqlmap (read-only validation), Nikto, testssl.sh, Qualys SSL Labs, DBeaver, Nessus (database compliance), web server config parsers. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Microsoft SQL Server Benchmark, CIS Oracle, MySQL and PostgreSQL Benchmarks, CIS Apache HTTP Server Benchmark, CIS Nginx Benchmark, DISA Database and Web Server STIGs, NIST SP 800-53, Vendor hardening guides.
What We Run
8 tools
- testssl.sh
- web server config parsers
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
7 standards
- CIS
- CIS
- CIS
- CIS
- DISADatabase
- VENDOR
Deliverables
What You Receive
- Database and web server findings report
- CIS benchmark scorecard per instance
- TLS and access-control assessment
- Hardening runbook
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Will your testing affect production databases?
No. We work from read-only configuration and evidence. Any active validation is limited, agreed in advance, and non-destructive.
Which databases and web servers do you cover?
Common engines including SQL Server, Oracle, MySQL and PostgreSQL, and servers including Apache, Nginx and IIS, each against its CIS Benchmark.
Do you check TLS configuration too?
Yes. We grade your encryption in transit with testssl.sh and SSL Labs so weak protocols and ciphers are surfaced and fixed.
Keep Moving Through Hardening and Configuration Review
Service 5 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths