Overview
SQL Server Security Assessment multi-server sample
The picture shows the header section of a SQL Server Security Assessment Summary-Report for multiple SQL Servers.
SQL Server Security Assessment multi-server sample
SQL Server Security Assessment server report
SQL Server Security Assessment technical report
Identify real SQL Server security risks - not merely failed checklist items
Sarpedon Quality Lab provides independent security and resilience assessments for Microsoft SQL Server workloads running on Amazon EC2, Amazon RDS for SQL Server, and connected hybrid environments. The assessment is designed and led by Andreas Wolter, a former Microsoft Program Manager for SQL Server and Azure SQL Security with more than 25 years of SQL Server experience and Microsoft Certified Solutions Master credentials.
Generic vulnerability scanners and benchmark reviews often examine individual settings without determining how identity, permissions, configuration, auditing, encryption, linked servers, and operational practices interact. Our methodology focuses on risks that could actually be exploited in the assessed environment, including excessive privileges, hidden elevation paths, lateral-movement opportunities, unsafe trust relationships, legacy authentication, auditability gaps, and weaknesses in cryptographic and recovery controls.
Critical questions the assessment answers
- Who has powerful access to critical SQL Server systems?
- Are there hidden paths to elevated privileges?
- Could the available audit evidence support an investigation?
- Are systems exposed through configuration, legacy access, or weak boundaries?
- Have backup, recovery, and resilience assumptions been properly validated?
- Which risks should be addressed first?
Assessment levels
-
Standard - Approximately 90 proprietary checks: Covers identity context, database configuration, privilege boundaries, in-transit encryption, NTLM deprecation exposure, and legacy weak-encryption discovery. Includes structured executive and technical reporting, a remote Q&A session, and access to an optional Delta-Check re-assessment.
-
Premium - Approximately 120 proprietary checks: Extends coverage to operating-system and backup controls where applicable, SQL Server Audit design and configuration, forensic readiness, log analysis, sensitive-data discovery, and operational security baselines. Includes comprehensive executive and technical reports, prioritized remediation guidance, and a remote Q&A session. Guidance for establishing or improving SQL Server Audit is included; implementation support can be added to the agreed scope.
-
White Glove - More than 140 proprietary checks: Includes a NIST-aligned cryptographic assessment and post-quantum readiness review. The engagement is personally conducted on-site by Andreas Wolter and includes comprehensive executive and technical reporting and one Delta-Check re-assessment.
The number of SQL Server instances, applicable checks, delivery approach, schedule, and final deliverables are agreed with the customer and documented in the AWS Marketplace private offer.
Evidence-backed findings and remediation guidance
Each finding is classified as PASS, OBSERVE, WARNING, or FAIL and includes:
- Supporting technical evidence
- A plain-language explanation of the risk
- Concrete remediation guidance
- An estimated level of implementation effort
- Relevant dependencies and contributing conditions
Attack-path-oriented analysis shows how individual permissions and configuration conditions can combine to create meaningful risk. The reports help technical teams understand what must change and help security and business leaders determine which risks require attention first.
The assessment can support internal reviews and initiatives aligned with CIS Benchmarks, NIST, ISO 27001, PCI DSS, and HIPAA, but it is not a compliance certification. The optional Delta-Check verifies selected remediation work and documents how the assessed risk has changed.
Typical use cases
- First comprehensive security review of an established SQL Server environment
- Review of an environment previously assessed only through vulnerability scans, benchmarks, or general audits
- Audit and compliance preparation
- Ransomware-readiness reviews
- Cloud migration planning
- Acquisition due diligence
- Incident follow-up
- Privileged-access reviews
- Review of inherited or long-running SQL Server estates
Delivery and engagement model
The assessment uses customer-approved, read-only evidence collection. No persistent agent or additional AWS infrastructure is deployed unless explicitly included in the agreed scope.
Before purchase, Sarpedon Quality Lab and the customer confirm the target environment, AWS deployment model, number of SQL Server instances, assessment level, delivery approach, schedule, and deliverables. The final scope and price are documented in an AWS Marketplace private offer.
Highlights
- Led by a former Microsoft Data Platform Security Program Manager with more than 25 years of SQL Server expertise and Microsoft Certified Solutions Master credentials
- Identifies hidden privilege-escalation paths, lateral movement opportunities, audit gaps, and architectural risks across SQL Server on Amazon EC2, Amazon RDS for SQL Server, and hybrid environments
- Delivers evidence-backed executive and technical reports with prioritized findings, concrete remediation guidance, and estimated levels of effort
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Support
Vendor support
For pre-purchase questions, scoping, and assessment-level selection, contact Sarpedon Quality Lab at:
https://sarpedonqualitylab.us/contact/
Sarpedon Quality Lab responds to Marketplace inquiries within two business days. After acceptance of a private offer, onboarding instructions and next steps are provided within two business days unless the private offer specifies another schedule.
Standard, Premium, and White Glove engagements include a remote Q&A session covering findings and remediation guidance. White Glove engagements also include personal on-site participation by lead architect Andreas Wolter as defined in the private offer. Questions concerning delivery, reports, remediation roadmaps, or refund requests can be submitted through the support URL above.
Software associated with this service



