Listing Thumbnail

    SQL Server Security Assessment for AWS by Sarpedon Quality Lab

     Info
    Identify exploitable privilege paths, audit gaps, weak encryption, and configuration risks in SQL Server on Amazon EC2, Amazon RDS for SQL Server, and connected hybrid environments. This expert-led assessment goes beyond compliance checklists to deliver evidence-backed findings and prioritized remediation guidance tailored to your environment.

    Overview

    Open image

    Identify real SQL Server security risks - not merely failed checklist items

    Sarpedon Quality Lab provides independent security and resilience assessments for Microsoft SQL Server workloads running on Amazon EC2, Amazon RDS for SQL Server, and connected hybrid environments. The assessment is designed and led by Andreas Wolter, a former Microsoft Program Manager for SQL Server and Azure SQL Security with more than 25 years of SQL Server experience and Microsoft Certified Solutions Master credentials.

    Generic vulnerability scanners and benchmark reviews often examine individual settings without determining how identity, permissions, configuration, auditing, encryption, linked servers, and operational practices interact. Our methodology focuses on risks that could actually be exploited in the assessed environment, including excessive privileges, hidden elevation paths, lateral-movement opportunities, unsafe trust relationships, legacy authentication, auditability gaps, and weaknesses in cryptographic and recovery controls.

    Critical questions the assessment answers

    • Who has powerful access to critical SQL Server systems?
    • Are there hidden paths to elevated privileges?
    • Could the available audit evidence support an investigation?
    • Are systems exposed through configuration, legacy access, or weak boundaries?
    • Have backup, recovery, and resilience assumptions been properly validated?
    • Which risks should be addressed first?

    Assessment levels

    • Standard - Approximately 90 proprietary checks: Covers identity context, database configuration, privilege boundaries, in-transit encryption, NTLM deprecation exposure, and legacy weak-encryption discovery. Includes structured executive and technical reporting, a remote Q&A session, and access to an optional Delta-Check re-assessment.

    • Premium - Approximately 120 proprietary checks: Extends coverage to operating-system and backup controls where applicable, SQL Server Audit design and configuration, forensic readiness, log analysis, sensitive-data discovery, and operational security baselines. Includes comprehensive executive and technical reports, prioritized remediation guidance, and a remote Q&A session. Guidance for establishing or improving SQL Server Audit is included; implementation support can be added to the agreed scope.

    • White Glove - More than 140 proprietary checks: Includes a NIST-aligned cryptographic assessment and post-quantum readiness review. The engagement is personally conducted on-site by Andreas Wolter and includes comprehensive executive and technical reporting and one Delta-Check re-assessment.

    The number of SQL Server instances, applicable checks, delivery approach, schedule, and final deliverables are agreed with the customer and documented in the AWS Marketplace private offer.

    Evidence-backed findings and remediation guidance

    Each finding is classified as PASS, OBSERVE, WARNING, or FAIL and includes:

    • Supporting technical evidence
    • A plain-language explanation of the risk
    • Concrete remediation guidance
    • An estimated level of implementation effort
    • Relevant dependencies and contributing conditions

    Attack-path-oriented analysis shows how individual permissions and configuration conditions can combine to create meaningful risk. The reports help technical teams understand what must change and help security and business leaders determine which risks require attention first.

    The assessment can support internal reviews and initiatives aligned with CIS Benchmarks, NIST, ISO 27001, PCI DSS, and HIPAA, but it is not a compliance certification. The optional Delta-Check verifies selected remediation work and documents how the assessed risk has changed.

    Typical use cases

    • First comprehensive security review of an established SQL Server environment
    • Review of an environment previously assessed only through vulnerability scans, benchmarks, or general audits
    • Audit and compliance preparation
    • Ransomware-readiness reviews
    • Cloud migration planning
    • Acquisition due diligence
    • Incident follow-up
    • Privileged-access reviews
    • Review of inherited or long-running SQL Server estates

    Delivery and engagement model

    The assessment uses customer-approved, read-only evidence collection. No persistent agent or additional AWS infrastructure is deployed unless explicitly included in the agreed scope.

    Before purchase, Sarpedon Quality Lab and the customer confirm the target environment, AWS deployment model, number of SQL Server instances, assessment level, delivery approach, schedule, and deliverables. The final scope and price are documented in an AWS Marketplace private offer.

    Highlights

    • Led by a former Microsoft Data Platform Security Program Manager with more than 25 years of SQL Server expertise and Microsoft Certified Solutions Master credentials
    • Identifies hidden privilege-escalation paths, lateral movement opportunities, audit gaps, and architectural risks across SQL Server on Amazon EC2, Amazon RDS for SQL Server, and hybrid environments
    • Delivers evidence-backed executive and technical reports with prioritized findings, concrete remediation guidance, and estimated levels of effort

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    For pre-purchase questions, scoping, and assessment-level selection, contact Sarpedon Quality Lab at:

    https://sarpedonqualitylab.us/contact/ 

    Sarpedon Quality Lab responds to Marketplace inquiries within two business days. After acceptance of a private offer, onboarding instructions and next steps are provided within two business days unless the private offer specifies another schedule.

    Standard, Premium, and White Glove engagements include a remote Q&A session covering findings and remediation guidance. White Glove engagements also include personal on-site participation by lead architect Andreas Wolter as defined in the private offer. Questions concerning delivery, reports, remediation roadmaps, or refund requests can be submitted through the support URL above.

    Software associated with this service