But if an engineer with credentials were to get phished, or were actively malicious, these methods aren't sufficient.
What's the best practice of hardening a database from internal attacks? Let's assume there are <5 people in the company who can be fully trusted.