How Geopits helped an enterprise client close critical gaps in SQL Server security
20
12
7
0 of 3
About
Samsonite
The client runs a SQL Server environment supporting enterprise reporting and business intelligence workloads, with the reporting application layer hosted alongside the database on the same server.
Business Challenges
The environment had grown without a periodic security review, leaving default configurations and legacy access in place well past their original justification.
Mixed-mode authentication was enabled alongside an active, unrenamed default administrator login, widening the door to credential-based attacks.
Multiple accounts, including several service accounts, held full administrative rights on the server beyond what their function required.
No audit specifications were configured, and successful logins, permission changes, and data modifications were going unrecorded.
Data was encrypted neither at rest nor in transit, and backup files carried no encryption or offline copy.
The instance was several cumulative updates behind current, with no formal process for testing and deploying patches.
Project Objectives
Geopits scoped the engagement to give the client's team a prioritized, risk-ranked path to closing every identified gap without disrupting a live reporting environment.
Key Goals:
- Establish least-privilege access across authentication, server roles, and host-level administration
- Close encryption gaps across data at rest, data in transit, and backup files
- Build sustainable logging, patching, and access-review processes the client's team can run going forward
Solution Provided by Geopits
Geopits ran the assessment as a structured, four-part engagement covering identity, data protection, monitoring, and patch posture.
Reviewed authentication mode, default account exposure, and administrative role membership across SQL logins, Windows logins, and service accounts.
Evaluated encryption at rest, in-transit encryption, data masking, and backup encryption practices against current standards.
Assessed audit configuration, login logging scope, and patch level against the latest available cumulative update.
Delivered a risk-ranked action plan covering authentication, privilege, encryption, auditing, and patching, sequenced for safe rollout on a production system.
.avif)
Key outcomes
12 high-severity issues prioritized
7 administrative accounts reviewed
Zero of three core encryption controls active
Patch level gap identified
Conclusion
The assessment gave the client's team a clear, risk-ranked view of where its SQL Server environment stood: which accounts held more access than they needed, where encryption was missing, and where visibility into activity was absent. Geopits is now working with the team to close these gaps in a sequence that protects the live reporting environment throughout.
Ready to Transform Your Data?
Geopits works alongside your team as a strategic partner, starting with stabilizing your current databases, then modernizing your data infrastructure, and ultimately helping you unlock the full potential of AI.
Happy Clients so far
Databases Managed
Successful Migrations
