April 10, 2018 By Britta Simms 2 min read

Do you know that 87 percent of Forbes 2000 companies use SAP, and 76 percent of the world’s transaction revenue is processed by SAP systems? With such large sums of money and critical business, personal and financial data at stake, it’s no wonder that cybercriminals are increasingly targeting SAP systems. But what if the largest security risk to these organizations is right within their own walls due to insider mishandling of data, fraud or even an honest mistake?

According to the numbers, it is. IBM Security’s 2016 Cyber Security Intelligence Index found that 60 percent of all cybersecurity attacks were carried out by insiders. Of these attacks, three-quarters involved malicious intent, and one-quarter involved inadvertent actors.

Cooperating to Eliminate SAP Challenges

For this reason, we at IBM have chosen to collaborate with ERP Maestro, a company that focuses on internal cybersecurity via SAP risk reporting and access controls automation. ERP Maestro’s cloud-based tool provides advanced segregation of duties and sensitive access risk reporting that helps our consulting teams quickly diagnose what is wrong and prioritize problem areas that need attention, accelerating resolution of even the most complex SAP access issues. Its capabilities are also utilized for security design and redesign efforts to enable quicker design of roles and authorizations that are industry-focused, compliant and secure.

I sat down with Jody Paterson, CEO and Founder of ERP Maestro, to discuss in detail how we are more efficiently solving some of the challenges our clients are facing with the assistance of ERP Maestro’s technology. Recent trends like SAP HANA migration are bringing security back up to the top of IT priority lists, along with ongoing challenges related to legacy systems like R3 that have developed serious security and audit issues over time. Watch the video below to see the full discussion:

https://www.youtube.com/watch?v=X93uNzB9FAs

Stay Ahead of SAP Risks

In teaming up with ERP Maestro, IBM Security can offer a best-in-class combination of technology and expert services in the SAP application security space. This powerful combination ensures our customers are well-armed to combat internal cybersecurity threats and fraud risks related to excessive access and ineffective controls. I’m excited at the opportunities ahead to make our SAP clients’ environments more secure with this collaboration.

To learn more about our work with ERP Maestro contact your IBM Security representative or visit the IBM Enterprise Security page.

More from

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today