April 10, 2018 By Britta Simms 2 min read

Do you know that 87 percent of Forbes 2000 companies use SAP, and 76 percent of the world’s transaction revenue is processed by SAP systems? With such large sums of money and critical business, personal and financial data at stake, it’s no wonder that cybercriminals are increasingly targeting SAP systems. But what if the largest security risk to these organizations is right within their own walls due to insider mishandling of data, fraud or even an honest mistake?

According to the numbers, it is. IBM Security’s 2016 Cyber Security Intelligence Index found that 60 percent of all cybersecurity attacks were carried out by insiders. Of these attacks, three-quarters involved malicious intent, and one-quarter involved inadvertent actors.

Cooperating to Eliminate SAP Challenges

For this reason, we at IBM have chosen to collaborate with ERP Maestro, a company that focuses on internal cybersecurity via SAP risk reporting and access controls automation. ERP Maestro’s cloud-based tool provides advanced segregation of duties and sensitive access risk reporting that helps our consulting teams quickly diagnose what is wrong and prioritize problem areas that need attention, accelerating resolution of even the most complex SAP access issues. Its capabilities are also utilized for security design and redesign efforts to enable quicker design of roles and authorizations that are industry-focused, compliant and secure.

I sat down with Jody Paterson, CEO and Founder of ERP Maestro, to discuss in detail how we are more efficiently solving some of the challenges our clients are facing with the assistance of ERP Maestro’s technology. Recent trends like SAP HANA migration are bringing security back up to the top of IT priority lists, along with ongoing challenges related to legacy systems like R3 that have developed serious security and audit issues over time. Watch the video below to see the full discussion:

https://www.youtube.com/watch?v=X93uNzB9FAs

Stay Ahead of SAP Risks

In teaming up with ERP Maestro, IBM Security can offer a best-in-class combination of technology and expert services in the SAP application security space. This powerful combination ensures our customers are well-armed to combat internal cybersecurity threats and fraud risks related to excessive access and ineffective controls. I’m excited at the opportunities ahead to make our SAP clients’ environments more secure with this collaboration.

To learn more about our work with ERP Maestro contact your IBM Security representative or visit the IBM Enterprise Security page.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today