Independent Diagnostics

Database assessments

Most database problems are found twice: once by an assessment, or once by an outage. An assessment gives you the same information at a time you chose, with each finding rated for severity, costed in effort, and written so it survives a budget conversation.

Nothing is changed during an assessment. Vendor-neutral findings.

Why it matters

The case for a database assessment

The first step in any major initiative, and the one most often skipped.

A clear, prioritized plan

A ranked set of recommendations scoped to your business priorities and reviewed by a senior consultant, rather than a tool export with several hundred warnings in it.

Hidden risk, surfaced early

Security gaps, end-of-life exposure, untested recovery, and compliance shortfalls found while they are still findings rather than incidents.

A foundation for every initiative

AI, cloud, and modernization plans all require a documented starting point. Without one, the first phase of the project becomes the assessment anyway, at project rates.

What is a database assessment?

A database assessment is a structured, read-only evaluation of a database environment that produces a documented baseline, severity-rated findings with root cause analysis, and a prioritized remediation plan. Fortified Data runs four assessments covering overall health, security, cloud readiness, and AI readiness, across Microsoft SQL Server, Azure SQL, Oracle, PostgreSQL, and MySQL, on premises and in AWS, Microsoft Azure, and Google Cloud.

Every assessment is a fixed-scope engagement delivered by senior consultants, and every one produces a written report rather than a verbal debrief.

An assessment is the first step in any major initiative, because every other initiative assumes a baseline that usually does not exist in writing. A migration business case, an AI program, a modernization roadmap, and a licensing renewal all need to start from a documented picture of what is actually running, how it performs, and what it costs.

The read-only part matters more than it sounds. Nothing is changed during a Fortified Data assessment, which means it can run against production without a change window and without the political weight of a project. What you get back is a decision document: what is wrong, how badly, what fixing it involves, and what it is worth.

What every Fortified Data assessment produces

The scope differs. The output does not.

  • A documented baselineInventory, configuration, and measured performance recorded as they actually are, which is the reference point every later change gets measured against.
  • Severity-rated findingsEach finding ranked by risk and business impact rather than listed flat, so the first thing on the list is the first thing worth doing.
  • Root cause, not symptomEvery finding traced to why it is happening. A list of alerts is a monitoring export. An assessment explains the mechanism behind them.
  • Effort and cost attachedEach recommendation carries an implementation estimate and a projected return, so the report can be read by a finance function as well as an engineering one.
  • A prioritized roadmapImmediate actions, short-term initiatives, and longer-term strategy separated out, rather than a single undifferentiated backlog.
  • Senior consultant reviewFindings are produced and reviewed by senior consultants. There is no junior data-collection pass handed upward for interpretation.

When to run an assessment

An assessment is worth its cost when a decision depends on information nobody currently has in writing.

  • A major initiative is being scopedA migration, modernization program, or AI investment needs a baseline before the business case can be defended.
  • Nobody can explain the environmentThe people who built it have moved on, the documentation is stale, and every question about it produces a different answer.
  • An audit is comingA compliance review, a security audit, or a licensing true-up is scheduled, and you would rather find the gaps first.
  • Costs are rising without a causeLicensing or cloud database spend is growing faster than the workload that justifies it, and nobody can point at what changed.
  • Performance has degraded graduallyNothing broke. It just got slower over two years, and there is no baseline to measure against.
  • A second opinion is neededAn internal recommendation or a vendor proposal involves real money, and you want it checked by someone with nothing to sell alongside it.

The four assessments

Each one is a fixed-scope engagement. They can be run individually or sequenced, and findings from one feed the scope of the next.

Database Health Check

The broad diagnostic. Six areas in one engagement: environment discovery, performance, security, availability, cost, and scalability, with a scored report and a remediation roadmap.

See what it covers

AI Readiness

Whether the data foundation can carry an AI initiative. Data quality, governance, lineage, pipeline compatibility, and the security controls AI workloads require.

Check AI readiness

Cloud Readiness

Workload-by-workload analysis of what should move, what should be rebuilt, and what it will cost, with a sequenced migration plan and a cost-benefit comparison.

Assess cloud readiness

Security

Configuration hardening, access control, privileged accounts, encryption, and audit evidence, evaluated against the frameworks in scope for your data.

Review security posture

Why Fortified Data

What you are buying beyond the report

Senior consultants only

Findings are produced and reviewed by senior consultants. There is no junior data-collection pass handed upward for interpretation, which is the model that produces a long report nobody can act on.

Nothing to sell alongside it

Fortified Data has no license resale, no platform to place, and no product waiting at the end of the recommendation. That is what makes an assessment usable as a second opinion on someone else's proposal.

One engagement across a mixed estate

SQL Server, Azure SQL, Oracle, PostgreSQL, and MySQL assessed together, on premises and in cloud, and reported in one document rather than split across separate platform reviews.

Where to start

Which assessment answers your question

Most organizations arrive with a symptom rather than a product name. This is the mapping.

  • Something is wrong and nobody can say whatPerformance has drifted, incidents are more frequent, and there is no baseline to argue from. Start with the database health check, which covers all six areas in one engagement.
  • An audit or a breach is the worryAccess controls, privileged accounts, encryption, and audit evidence need checking against the frameworks in scope. The database security assessment is the targeted one.
  • A cloud move is being consideredThe question is which workloads should move, which should be rebuilt, and what it costs either way. The cloud readiness assessment produces the sequenced plan and the cost comparison.
  • An AI initiative is being scopedThe model is rarely the constraint. Data quality, governance, lineage, and pipeline readiness are, and the AI readiness assessment establishes whether the foundation can carry the investment.
  • More than one of these is trueStart with the health check. It covers the breadth, and its findings scope whichever specialist assessment turns out to be worth running next.

Common questions about database assessments

What is the difference between a database assessment and database monitoring?

Monitoring reports what is happening now and alerts when a threshold is crossed. A Fortified Data database assessment examines configuration, architecture, security controls, licensing, and growth trend together, and finds the problems monitoring was never configured to look for. A backup job that reports success every night but has never been restore-tested is the clearest example: monitoring records it as healthy, and only an assessment that tests the restore establishes whether it is.

Which assessment should we start with?

The database health check is the broad diagnostic and the usual starting point, because it covers performance, security, availability, cost, and scalability in one engagement and will point at whichever specialist assessment the environment actually needs. Where the question is already specific, such as an upcoming licensing true-up or a scoped cloud migration, Fortified Data runs that assessment directly.

Does an assessment require downtime or changes to our systems?

No. Fortified Data assessments are read-only. Configuration, performance data, and metadata are collected and analyzed, and nothing in the environment is modified during the engagement. That is what allows an assessment to run against production without a change window.

Which database platforms can Fortified Data assess?

Microsoft SQL Server, Azure SQL, Oracle, PostgreSQL, and MySQL, running on premises or in AWS, Microsoft Azure, and Google Cloud. A mixed estate is assessed in a single engagement and reported in a single document rather than split across separate platform reviews.

Do we have to be a Fortified Data client to request an assessment?

No. Every Fortified Data assessment is a fixed-scope engagement that stands on its own and is written so that any outcome is possible afterwards, including remediating internally. Organizations use assessments to decide whether to fix the environment themselves, to scope a project, or to size a managed service.

What does an assessment cost?

Fortified Data scopes each assessment to the number of database instances, the platforms involved, and whether the environment runs on premises, in cloud, or both, so there is no single list price. Scope and price are agreed before the assessment begins, and the engagement is fixed-scope rather than open-ended.

Find out what is actually in the environment

An assessment gives you a documented baseline, severity-rated findings, and a costed roadmap. What you do with it afterwards is your decision, and the report is written so every option stays open.

Let us show you what's possible.

Two ways to start

Read-only. Nothing changes during the assessment.