The review answers the questions leadership eventually asks.
Are backups merely running, or can the business actually recover? Which configuration choices create avoidable exposure? Is the performance problem caused by queries, design, capacity, or operations? Where does knowledge live if the one person who understands the environment is unavailable?
What is examined
Recovery evidence
Backup coverage, failure signals, restore-test evidence, RPO/RTO assumptions, and dependency gaps.
Availability design
Failover architecture, quorum or replica concerns, monitoring, runbooks, and operational ownership.
Security posture
Access patterns, privileged roles, encryption and audit considerations, patch/build posture, and risky defaults.
Performance risk
Wait patterns, Query Store, blocking, plans, indexing, configuration, storage, and capacity signals.
Operational hygiene
Agent jobs, maintenance, alerts, documentation, ownership, and recurring manual failure points.
Modernization pressure
Version lifecycle, deprecated features, compatibility, licensing, and migration dependencies.
What you receive
- Executive summary: the few risks that matter most to uptime, recovery, security, cost, and delivery.
- Evidence-backed risk register: severity, rationale, affected systems, and confidence—without false precision.
- Technical findings: reproducible evidence and context your engineers can inspect.
- Prioritized roadmap: immediate containment, 30-day fixes, and longer-term improvements.
- Readout session: a working session for technical and business stakeholders, with decisions captured.
- Optional remediation scope: separate from the assessment so you can implement internally or ask Candidus to help.
How production safety works
Discovery uses read-only collection wherever practical. Your team can review what will be collected, and client-run collection is supported when direct access is not appropriate. No remediation is bundled invisibly into the assessment. Any production change requires a separate approved plan with validation and rollback.
What this review does not claim
It does not guarantee that an incident cannot occur, replace a formal penetration test, certify regulatory compliance, or promise a 24/7 response SLA. It gives decision-makers a defensible view of observable database risk and a practical path forward.
