Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Hardening and Configuration Review5 services in this practice area

Harden the Tiers that Hold Your Data

Database and Web Server Configuration Review

We review your database and web server configurations against CIS Benchmarks and vendor guides. You learn where authentication, encryption and access settings fall short, and how to close the gaps without downtime.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Databases and web servers sit closest to your data, yet they often run with default accounts, weak TLS and loose permissions. This review reads the configuration of your database engines and web servers, compares it to the matching CIS Benchmark and vendor hardening guide, and checks the settings that protect your data: authentication, encryption in transit, access control and logging. We validate a small number of findings safely so you know what is real, then hand you a runbook to harden each tier.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Database and Web Server Configuration engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx. Activities: Inventory database engines, versions and hosting locations; Inventory web servers and reverse proxies in scope; Select the matching CIS Benchmark per engine and server; Agree which instances allow safe active validation. Hands over Tier Inventory and Baseline Selection. Phase 2, Evidence and Config Collection. We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports. Activities: Export database instance parameters and startup settings; List database logins, roles and object-level grants; Collect Apache, Nginx and IIS configuration files and modules; Record TLS certificate, protocol and cipher settings per endpoint. Hands over Tier Configuration Evidence Set. Phase 3, Benchmark Comparison. We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides. Activities: Run CIS-CAT Pro against each database and web server; Run Nessus database compliance policies where supported; Map failed checks to CIS control numbers per engine; Score each instance against its benchmark. Hands over CIS Benchmark Scorecard Per Instance. Phase 4, Manual Review and Safe Validation. We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate. Activities: Check for default accounts, shared logins and weak SQL authentication; Review TLS ciphers and protocols with testssl.sh; Scan web servers with Nikto for exposed files and headers; Run read-only sqlmap checks on agreed endpoints; Verify audit logging captures privileged database activity. Hands over TLS and Access-Control Assessment. Phase 5, Prioritised Findings. Findings are ranked by exposure to your data, with affected instances listed so remediation is precise. Activities: Rank findings by how close they sit to sensitive data; Name the affected instances and endpoints per finding; Separate settings changeable live from those needing a restart; Walk the database and platform owners through the results. Hands over Database and Web Server Findings Report. Phase 6, Remediation and Re-Check. We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved. Activities: Write hardening steps per engine with exact parameter values; Provide tested TLS configuration blocks for each server type; Advise on sequencing changes around maintenance windows; Re-run the benchmark and TLS checks and reissue the grades. Hands over Hardening Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.

What Happens In This Phase

  • Inventory database engines, versions and hosting locations
  • Inventory web servers and reverse proxies in scope
  • Select the matching CIS Benchmark per engine and server
  • Agree which instances allow safe active validation

The Handover

Tier Inventory and Baseline Selection

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We list the database engines and web servers in scope and select the matching CIS Benchmark, such as CIS Microsoft SQL Server, Apache or Nginx.

    OutputTier Inventory and Baseline Selection

    Activities

    • Inventory database engines, versions and hosting locations
    • Inventory web servers and reverse proxies in scope
    • Select the matching CIS Benchmark per engine and server
    • Agree which instances allow safe active validation
  2. 02

    Evidence and Config Collection

    We gather configuration files, parameters and access settings as read-only evidence, using DBeaver and server config exports.

    OutputTier Configuration Evidence Set

    Activities

    • Export database instance parameters and startup settings
    • List database logins, roles and object-level grants
    • Collect Apache, Nginx and IIS configuration files and modules
    • Record TLS certificate, protocol and cipher settings per endpoint
  3. 03

    Benchmark Comparison

    We run CIS-CAT Pro against each tier and map results to CIS controls and vendor hardening guides.

    OutputCIS Benchmark Scorecard Per Instance

    Activities

    • Run CIS-CAT Pro against each database and web server
    • Run Nessus database compliance policies where supported
    • Map failed checks to CIS control numbers per engine
    • Score each instance against its benchmark
  4. 04

    Manual Review and Safe Validation

    We review authentication, encryption, permissions and logging by hand, then safely validate exposure with Nikto, testssl.sh and read-only sqlmap checks where appropriate.

    OutputTLS and Access-Control Assessment

    Activities

    • Check for default accounts, shared logins and weak SQL authentication
    • Review TLS ciphers and protocols with testssl.sh
    • Scan web servers with Nikto for exposed files and headers
    • Run read-only sqlmap checks on agreed endpoints
    • Verify audit logging captures privileged database activity
  5. 05

    Prioritised Findings

    Findings are ranked by exposure to your data, with affected instances listed so remediation is precise.

    OutputDatabase and Web Server Findings Report

    Activities

    • Rank findings by how close they sit to sensitive data
    • Name the affected instances and endpoints per finding
    • Separate settings changeable live from those needing a restart
    • Walk the database and platform owners through the results
  6. 06

    Remediation and Re-Check

    We provide hardening guidance per engine and server, then re-check to confirm the settings and TLS grades have improved.

    OutputHardening Runbook and Re-Check Report

    Activities

    • Write hardening steps per engine with exact parameter values
    • Provide tested TLS configuration blocks for each server type
    • Advise on sequencing changes around maintenance windows
    • Re-run the benchmark and TLS checks and reissue the grades

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Database and Web Server Configuration scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: CIS-CAT Pro, sqlmap (read-only validation), Nikto, testssl.sh, Qualys SSL Labs, DBeaver, Nessus (database compliance), web server config parsers. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Microsoft SQL Server Benchmark, CIS Oracle, MySQL and PostgreSQL Benchmarks, CIS Apache HTTP Server Benchmark, CIS Nginx Benchmark, DISA Database and Web Server STIGs, NIST SP 800-53, Vendor hardening guides.

What We Run

8 tools

  • CIS-CAT Pro
  • sqlmap (read-only validation)
  • Nikto
  • testssl.sh
  • Qualys SSL Labs
  • DBeaver
  • Nessus (database compliance)
  • web server config parsers

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

7 standards

  • CISMicrosoft SQL Server
  • CISOracle, MySQL and PostgreSQL
  • CISApache HTTP Server
  • CISNginx
  • DISASTIGsDatabase
  • NIST SP 800-53
  • VENDORHardening Guides
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Database and web server findings report
  • CIS benchmark scorecard per instance
  • TLS and access-control assessment
  • Hardening runbook
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Will your testing affect production databases?

No. We work from read-only configuration and evidence. Any active validation is limited, agreed in advance, and non-destructive.

Which databases and web servers do you cover?

Common engines including SQL Server, Oracle, MySQL and PostgreSQL, and servers including Apache, Nginx and IIS, each against its CIS Benchmark.

Do you check TLS configuration too?

Yes. We grade your encryption in transit with testssl.sh and SSL Labs so weak protocols and ciphers are surfaced and fixed.