ASUG News + Views
Researchers Warn That SAP Cus­tomers Could Be at Risk from Cyberattacks
Howard Altman Apr 21, 2021
Bookmark
Share Article:

This con­tent is exclu­sive­ly for ASUG members

Log in to access the full arti­cle and explore more resources curat­ed for the ASUG community.

Not an ASUG member? Learn More

Bad actors — either nation-states or crim­i­nal enter­pris­es — are work­ing over­time to get into your sys­tems and take them over for their own nefar­i­ous pur­pos­es. And if you aren’t updat­ing the secu­ri­ty patch­es on your SAP prod­ucts as you should, it’s kind of like going on vaca­tion and leav­ing your house unlocked.

Don’t be sur­prised if you come back and find the place looted.

On April 6, 2021, secu­ri­ty researchers from Onap­sis (the only SAP-endorsed part­ner for cyber­se­cu­ri­ty and com­pli­ance), work­ing with SAP, issued a stark alert. Bad-actor activ­i­ty and tech­niques could lead full con­trol of unse­cured SAP applications.”

That means if you aren’t updat­ing the secu­ri­ty patch­es on your SAP prod­ucts, there is a very good chance cyber crim­i­nals could enter and take over your entire net­work. And that could mean a severe blow to your bot­tom line and rep­u­ta­tion, along with addi­tion­al time, mon­ey, and ener­gy try­ing to clean up the result­ing mess. Adding to the list of poten­tial mis­eries, reg­u­la­to­ry com­pli­ance for finan­cial (Sar­banes-Oxley Act), pri­va­cy (Gen­er­al Data Pro­tec­tion Reg­u­la­tion), and oth­er man­dates may be at risk, as unpatched and mis­con­fig­ured SAP sys­tems present a defi­cien­cy in IT con­trols that would result in audit and com­pli­ance vio­la­tions and penal­ties, the report states.

You Might Be Interested In


Insights Included in Membership
View All Insights
Bookmark
Bookmark
Bookmark
Bookmark