Service · Cybersecurity

Database security

Your accounting package, online shop and booking system look nothing alike on screen, but underneath each one sits a database, and that is what an attacker is really after. Take an accountancy practice whose accounting software runs on SQL Server: the built-in sa login still has the password set on installation day, and port 1433 was opened to the internet for a remote employee and never closed again. Or a WooCommerce store whose MySQL dumps pile up in a publicly reachable folder on the web server. In both cases the application appears perfectly healthy; the problem lives one layer down. Database security deals with that layer. Who can connect, with what rights and from where? Is the data encrypted at rest and in transit? Are there backups, and more importantly, can they actually be restored? We work with Microsoft SQL Server, MySQL, MariaDB and PostgreSQL, whether on your own servers or in the cloud. For packaged software, every change is agreed with your software partner beforehand and carried out remotely without disrupting your operations.

No shared logins
separate identities for apps, admins and reporting
No open ports
the database stays off the internet
Encrypted
on disk, on the wire and in backups
Restore drills
regularly, not just backup jobs

What the work covers in practice

We cover Microsoft SQL Server, MySQL, MariaDB and PostgreSQL, on premises or on Azure, AWS and European providers. Changes to databases behind packaged software are cleared with the vendor or your software partner first.

Agree the scope with the engineer who will do the work

Logins and rights

A dedicated login for each application limited to what it needs, personal logins for administrators and read-only access for reporting tools. Built-in accounts such as sa and root are disabled or tightly guarded.

Network reach

Only the servers that need the database can talk to it. Remote staff connect through a VPN or the application server, never straight to the database port.

Encryption

Transparent data encryption or full-disk encryption, TLS between application and database, encrypted backups, with keys held separately and documented.

Access logging

Logins, permission changes and reads of sensitive tables such as payroll, customer ledgers or patient records are recorded, and the logs are kept somewhere a database admin cannot quietly erase them.

Patching

Security and cumulative updates for the database engine follow a schedule, checked against the versions your packaged software supports. Engines past end of support get a migration plan.

Backups and restores

Backups are stored out of reach of ordinary users and the web server, ideally immutable. Restore steps are written down and have been tried.

How we approach the job, from first call to handover

Databases carry the whole business, so nothing changes without a backup, agreement and a route back.

01

Inventory

Which database servers exist, on which versions, serving which applications, with which logins? A forgotten test copy or remnant of retired software usually turns up.

02

Assessment

Configuration, logins, network exposure, encryption and backups are compared with CIS recommendations and vendor guidance, and findings are ranked by risk.

03

Changes

Agreed with your software partner and applied remotely in a maintenance window, each preceded by a full backup.

04

Restore test

A backup is restored into an isolated environment and we confirm the application opens and the data is complete. Time taken and steps are documented.

A backup nobody has restored is only a hope. Ransomware crews go after backups early, and the next discovery is often that nobody knows how to bring a database back. A regular restore drill is the cheapest and most neglected part of database security.

Frequently asked questions

We do not touch the schema, the tables or the way the application account works. Our changes stay at the level of server settings, admin logins, network access, encryption and backups. Even so, each step is shared with your software partner in advance, and some items, such as the application account's rights, must not change without their sign-off.

On shared hosting with limited access, we can still improve credentials, backup locations and the application's connection settings. On a virtual or dedicated server, the full scope applies. We confirm which situation you are in during the first review.

When scoped properly the overhead is small. We record access to sensitive tables and permission changes rather than every query, watch performance during the first weeks and narrow the scope if needed.

If it is out of support, yes, because new vulnerabilities will not be fixed. In the meantime we restrict network access further and tighten logging. The real fix is an upgrade; we agree a compatible target version with your software partner and plan the move.

Secure the layer underneath your applications

Tell us which databases you run and where they are hosted. We will share the obvious risks and a review plan.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.