April 10, 2018 By Britta Simms 2 min read

Do you know that 87 percent of Forbes 2000 companies use SAP, and 76 percent of the world’s transaction revenue is processed by SAP systems? With such large sums of money and critical business, personal and financial data at stake, it’s no wonder that cybercriminals are increasingly targeting SAP systems. But what if the largest security risk to these organizations is right within their own walls due to insider mishandling of data, fraud or even an honest mistake?

According to the numbers, it is. IBM Security’s 2016 Cyber Security Intelligence Index found that 60 percent of all cybersecurity attacks were carried out by insiders. Of these attacks, three-quarters involved malicious intent, and one-quarter involved inadvertent actors.

Cooperating to Eliminate SAP Challenges

For this reason, we at IBM have chosen to collaborate with ERP Maestro, a company that focuses on internal cybersecurity via SAP risk reporting and access controls automation. ERP Maestro’s cloud-based tool provides advanced segregation of duties and sensitive access risk reporting that helps our consulting teams quickly diagnose what is wrong and prioritize problem areas that need attention, accelerating resolution of even the most complex SAP access issues. Its capabilities are also utilized for security design and redesign efforts to enable quicker design of roles and authorizations that are industry-focused, compliant and secure.

I sat down with Jody Paterson, CEO and Founder of ERP Maestro, to discuss in detail how we are more efficiently solving some of the challenges our clients are facing with the assistance of ERP Maestro’s technology. Recent trends like SAP HANA migration are bringing security back up to the top of IT priority lists, along with ongoing challenges related to legacy systems like R3 that have developed serious security and audit issues over time. Watch the video below to see the full discussion:

https://www.youtube.com/watch?v=X93uNzB9FAs

Stay Ahead of SAP Risks

In teaming up with ERP Maestro, IBM Security can offer a best-in-class combination of technology and expert services in the SAP application security space. This powerful combination ensures our customers are well-armed to combat internal cybersecurity threats and fraud risks related to excessive access and ineffective controls. I’m excited at the opportunities ahead to make our SAP clients’ environments more secure with this collaboration.

To learn more about our work with ERP Maestro contact your IBM Security representative or visit the IBM Enterprise Security page.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today