ASUG News + Views
5 Com­mon Cyber­se­cu­ri­ty Risks and 10 Areas to Fix
Mar 31, 2018
Bookmark
Share Article:

I guess mom is always right: We should nev­er trust a stranger. Unfor­tu­nate­ly, most of us don’t heed this advice when exchang­ing sen­si­tive per­son­al data and inter­act­ing freely across wire­less and dig­i­tal com­mu­ni­ca­tion chan­nels. From stolen intel­lec­tu­al prop­er­ty and cus­tomer data to oper­a­tion shut­downs that leave peo­ple vul­ner­a­ble, news head­lines are giv­ing us every rea­son to recon­sid­er our false sense of secu­ri­ty in the dig­i­tal tech­nol­o­gy we use.

In fact, the World Eco­nom­ic Forum’s Glob­al Risks Report 2018 ranks cyber­at­tacks as the third-like­li­est risk, behind data fraud and theft. And as dig­i­tal strate­gies become more sophis­ti­cat­ed with emerg­ing tech­nol­o­gy, mali­cious actors are step­ping up their efforts to extract as much val­ue as pos­si­ble away from brand rep­u­ta­tions, con­sumer trust, pub­lic safe­ty, and entire economies.

This isn’t a real­i­ty that com­pa­nies should ever accept. Dur­ing ASUG’s web­cast Ten Best Prac­tices to Mit­i­gate Risk to Your SAP Sys­tem, Justin Somai­ni, chief secu­ri­ty offi­cer at SAP, and Ming Chang, Amer­i­c­as’ region­al lead for Cloud Infor­ma­tion Secu­ri­ty Aware­ness at SAP, shared which com­mon mis­takes need­less­ly increase cyber­se­cu­ri­ty risks and how orga­ni­za­tions can com­bat them immediately.

Risks That Turn Your IT Land­scape into a Hack­er’s Gold Mine

For years, IT secu­ri­ty has earned a rep­u­ta­tion for being cost­ly and ham­per­ing oper­a­tional progress. Accord­ing to Justin Somai­ni, how­ev­er, secu­ri­ty is actu­al­ly a decid­ing fac­tor that can dic­tate the future suc­cess of every company.

After learn­ing from decades of expe­ri­ences in help­ing, sup­port­ing, and engag­ing cus­tomers to build their dig­i­tal land­scapes and advance their brands, Somai­ni shared the top secu­ri­ty risks that first emerge dur­ing most implementations:

Risk 1: Lim­it­ed con­fig­u­ra­tion secu­ri­ty: Pri­mar­i­ly, the base con­fig­u­ra­tion that com­pa­nies imple­ment lack encryp­tion and prop­er hash­ing of passwords.

Risk 2: Lit­tle to no atten­tion to patch man­age­ment: This poor habit is par­tic­u­lar­ly prob­lem­at­ic when man­ag­ing sys­tems that are crit­i­cal to core busi­ness systems.

Risk 3: Increased attack sur­face for remote func­tion call (RFC) com­mu­ni­ca­tion: Although RFC com­mu­ni­ca­tion may have been set up to allow busi­ness sys­tems to talk to each oth­er, it is pos­si­ble that access rights to the land­scape may have become exces­sive over time and are per­form­ing with a lim­it­ed scope.

Risk 4: Incon­sis­tent encryp­tion enable­ment: While most orga­ni­za­tions focus on encryp­tion with­in a sys­tem, it is equal­ly impor­tant to address this lev­el of enable­ment between sys­tems. This includes con­soles con­nect­ing back to the core busi­ness system.

Risk 5: Weak­ness in code secu­ri­ty: All too often, user-devel­oped code hasn’t been reviewed and ana­lyzed to make sure that it is vul­ner­a­bil­i­ty free.”

Each one of these weak­ness­es can pose risks to con­nect­ed sys­tems that, although unin­tend­ed, can coun­ter­pro­duc­tive­ly obscure any efforts in improv­ing ser­vices, dri­ving inno­va­tion, cre­at­ing pros­per­i­ty, and tack­ling some of the industry’s top priorities.

Top 10 Areas to Close Your Secu­ri­ty Gaps

Although spend­ing on busi­ness sys­tems and data secu­ri­ty is increas­ing, there’s a ques­tion of whether these invest­ments are going far enough. Most com­pa­nies choose to con­cen­trate on tra­di­tion­al and con­verged IT infra­struc­ture secu­ri­ty, such as fire­walls. Yet Ming Chang sug­gest­ed that IT orga­ni­za­tions must go even further.

Chang said that busi­ness­es can strength­en their cyber­se­cu­ri­ty capa­bil­i­ties by address­ing 10 key focus areas:

Area 1: Net­work secu­ri­ty: Define a net­work con­cept with clear­ly struc­tured and dif­fer­ent zones, sep­a­rate high-secu­ri­ty areas, and deter­mine ded­i­cat­ed servers and admin­is­tra­tive roles.

Area 2: Oper­at­ing sys­tem and data­base secu­ri­ty: Imple­ment restric­tive data­base-access mech­a­nisms and ded­i­cat­ed secu­ri­ty require­ments for all oper­at­ing systems.

Area 3: Front-end secu­ri­ty: Deploy secu­ri­ty con­fig­u­ra­tion for both clients and mobile end­points while acti­vat­ing admin­is­tra­tor rules and access-con­trol lists.

Area 4: Cus­tom code secu­ri­ty: Estab­lish cus­tom-code life­cy­cle man­age­ment process­es and use secu­ri­ty source-code scan­ning tools to iden­ti­fy vul­ner­a­bil­i­ties hid­den in programs.

Area 5: Secure main­te­nance of code: Update soft­ware reg­u­lar­ly and review month­ly Com­mon Vul­ner­a­bil­i­ties and Expo­sures (CVE) dis­clo­sures to assess risks to the dig­i­tal landscape.

Area 6: Secure con­fig­u­ra­tion: Address all gaps in pass­word secu­ri­ty, authen­ti­ca­tion, data encryp­tion, and com­mu­ni­ca­tion connections.

Area 7: Com­mu­ni­ca­tion secu­ri­ty: Use encrypt­ed com­mu­ni­ca­tion such as secure sock­ets lay­er (SSL), trans­ports lay­er secu­ri­ty, or secure net­work com­mu­ni­ca­tions. And secure RFC connectivity.

Area 8: Secu­ri­ty audit log: Mon­i­tor all sys­tems and acti­vate the secu­ri­ty audit log and fil­ters for crit­i­cal users.

Area 9: User autho­riza­tions: Build secu­ri­ty aware­ness and clear­ly define and man­age user authorizations.

Area 10: Emer­gency con­cept: Define emer­gency, back­up, and dis­as­ter recov­ery con­cepts to ensure busi­ness con­ti­nu­ity. Pre­pare end-to-end fall­back sys­tems for crit­i­cal process­es and applications.

By fol­low­ing these best prac­tices, com­pa­nies can bet­ter safe­guard their dig­i­tal sys­tems, data, and cus­tomers from the per­ils of cyber threats. This nat­ur­al pro­gres­sion from threat reac­tion to threat detec­tion and pre­ven­tion enables orga­ni­za­tions to enhance not only the pro­tec­tion of appli­ca­tions, but also the over­all per­for­mance of the business.

To get the full sto­ry on these 10 tips, lis­ten to our record­ed web­cast, Ten Best Prac­tices to Mit­i­gate Risk to Your SAP System.

 

You Might Be Interested In


Insights Included in Membership
View All Insights
Bookmark
Bookmark
Bookmark
Bookmark