The fileservers also need to write into the db. The downloads must be logged, the stats, the rewards in the rewards plugin, the download tracker... You can't just prevent them to write.
If someone gets access to your server, it's over. Having a different mysql user to fileservers doesn't...