Back
Database Management

Reliable database management for modern, high-performance systems.

Back
Data Modernisation

Reliable database management for modern, high-performance systems.

Back
Data Engineering

Reliable database management for modern, high-performance systems.

Back
Analytics & Intelligence

Reliable database management for modern, high-performance systems.

Back
Data Strategy Consulting

Reliable database management for modern, high-performance systems.

How Geopits helped an enterprise client close critical gaps in SQL Server security

20

Security Findings Identified and Prioritized by Risk

12

High-Severity Issues Requiring Immediate Action

7

Sysadmin-Level Accounts Reviewed for Least Privilege

0 of 3

Core Encryption Controls (Data at Rest, Data in Transit, Backups) Active at Time of Audit
Company Info
Company
Samsonite
About
Global leader in travel luggage, bags, and accessories. Industry: Enterprise reporting and business intelligence
Industry
Enterprise reporting and business intelligence
Tech Used
Microsoft SQL Server

About

Samsonite

The client runs a SQL Server environment supporting enterprise reporting and business intelligence workloads, with the reporting application layer hosted alongside the database on the same server. 

Business Challenges

The environment had grown without a periodic security review, leaving default configurations and legacy access in place well past their original justification.

Weak authentication controls

Mixed-mode authentication was enabled alongside an active, unrenamed default administrator login, widening the door to credential-based attacks.

Excessive standing privilege

Multiple accounts, including several service accounts, held full administrative rights on the server beyond what their function required.

Limited visibility into activity

No audit specifications were configured, and successful logins, permission changes, and data modifications were going unrecorded.

Unencrypted data at rest and in transit

Data was encrypted neither at rest nor in transit, and backup files carried no encryption or offline copy.

Delayed patch cadence

The instance was several cumulative updates behind current, with no formal process for testing and deploying patches.

Project Objectives

Geopits scoped the engagement to give the client's team a prioritized, risk-ranked path to closing every identified gap without disrupting a live reporting environment.

Key Goals:

  • Establish least-privilege access across authentication, server roles, and host-level administration 
  • Close encryption gaps across data at rest, data in transit, and backup files 
  • Build sustainable logging, patching, and access-review processes the client's team can run going forward

Solution Provided by Geopits

Geopits ran the assessment as a structured, four-part engagement covering identity, data protection, monitoring, and patch posture.

Authentication & Privilege Audit

Reviewed authentication mode, default account exposure, and administrative role membership across SQL logins, Windows logins, and service accounts.

Encryption & Data Protection Assessment

Evaluated encryption at rest, in-transit encryption, data masking, and backup encryption practices against current standards.

Auditing & Patch Review

Assessed audit configuration, login logging scope, and patch level against the latest available cumulative update.

Prioritized Remediation Roadmap

Delivered a risk-ranked action plan covering authentication, privilege, encryption, auditing, and patching, sequenced for safe rollout on a production system.

Capabilities
Before
After
Authentication mode
Mixed mode with an active default administrator login
Windows Authentication only, default login disabled or renamed
Administrative privilege
Multiple accounts, including service accounts, holding full administrative rights
Limited to essential accounts, managed through directory groups
Network exposure
Default listening port, application connections over the public network
Non-standard port, private network connections only
Encryption coverage
No encryption at rest, in transit, or on backups
Encryption enforced across all three, backups using a strong algorithm
Auditing scope
Failed logins only, no formal audit specifications
Full audit coverage of logins, permission changes, and data modifications

Key outcomes

12 high-severity issues prioritized

Covering authentication, privilege, network exposure, encryption, and backup security, sequenced into a risk-ranked remediation plan.

7 administrative accounts reviewed

Including SQL logins, Windows logins, and Windows service accounts, each assessed against least-privilege requirements and right-sized accordingly.

Zero of three core encryption controls active

Data at rest, data in transit, and backup files were all found unencrypted at the time of assessment, now addressed in the remediation roadmap.

Patch level gap identified

The instance was found running behind the latest cumulative update, with no formal testing or deployment process in place to keep pace going forward.

Conclusion

The assessment gave the client's team a clear, risk-ranked view of where its SQL Server environment stood: which accounts held more access than they needed, where encryption was missing, and where visibility into activity was absent. Geopits is now working with the team to close these gaps in a sequence that protects the live reporting environment throughout. 

Ready to Transform Your Data?

Geopits works alongside your team as a strategic partner, starting with stabilizing your current databases, then modernizing your data infrastructure, and ultimately helping you unlock the full potential of AI.

170

Happy Clients so far

2100+

Databases Managed

142+

Successful Migrations

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
New