Transcript
My name is Ajit Adani and I am the Sales Director at Napsys for France, Spain and Portugal. Today, we are delighted to have with us Mathieu Bertrand, an associate at Tornky France, a renowned consultant and expert in the SAP system. Our goal today is to explore the crucial subject of SAP security and examine three major questions that an organization must ask to protect its SAP environments. Thank you for joining us, Mathieu. Thank you, Ajit. It's a pleasure to be with you today. My name is Mathieu Bertrand and I have been working in cybersecurity for more than 14 years. My job is to help organizations identify vulnerabilities in their SAP systems and implement robust security measures to protect their processes and critical data. I am looking forward to sharing my ideas with you today. Recent studies show a significant increase in cyber threats targeting SAP systems. We have seen more than 300 successful operations on 1,500 cyber attacks and an increase of 400% of attacks per ransomware on SAP systems over the last three years. How can SAP systems be protected against these threats, Mathieu? This is a crucial question, Ajit. Protecting SAP systems against cyber threats requires an approach at several levels. First, the first level will be the protection of network access points where SAP environments are located. These layers are now where cybersecurity controls are most important. However, beware of the preconceived idea that SAP is sheltered behind this network. Your figures confirm this. The second level will therefore be the application layer to identify and correct potential vulnerabilities. It is essential to shorten the update times of SAP systems with the latest security correctives. Continuous monitoring is also crucial to detect and respond in real time to suspected activities. The last level is human, with training and awareness programs for employees to reduce the risk of attack by social harassment and engineering. What are the most effective strategies? Given the complexity of SAP systems and the high risks associated with their compromise, it is crucial that organizations adopt a more robust strategy to guarantee their security. Can you explain to us what the most effective strategies are, Mathieu? There are several strategies, I have already mentioned a few. If I start again, the evaluation of regular vulnerability, continuous log monitoring, strict access controls, the idea is to be able to switch to a preventive approach, going beyond simple SAP penetration tests, in order to identify and mitigate potential vulnerabilities before they are exploited. The SAP world is by definition proprietary, and therefore complex and non-transparent. Most cybersecurity professionals are not familiar with these specificities. On their part, those in charge of SAP competence centers don't know much about the cyber world. It is therefore key to establish governance and bodies to allow each of these two worlds to speak and understand each other. Thank you, Mathieu. To continue on the last question, the growing adoption of cloud-based SAP solutions and the integration of emerging technologies such as AI pose new challenges, but also new security opportunities. In this context, what should organizations do right now to prepare for these changes? Everyone talks about AI, but I am convinced that the future of SAP security will be shaped by these technologies. AI, automatic learning with machine learning, these technologies will improve the ability to detect and respond to threats. They will enable the analysis of large amounts of data in real time, thus identifying models and anomalies that could indicate a malicious activity. They will also facilitate the vulgarization of technical subjects to non-initiates. But be careful, malicious people without technical skills could be able to launch more or less complex attacks thanks to these new technologies. In addition, as organizations adopt cloud-based SAP solutions, the security of these environments will become even more critical. Migration to the cloud brings undeniable advantages in terms of flexibility and efficiency, but it also requires a new approach to security. Integrating specific measures for these environments. To prepare for these changes, it is important to establish partnerships with security experts who can provide advice and specialized support to navigate in this landscape of constant evolution. Excellent Mathieu, thank you very much. It is clear that the security of SAP systems is a crucial priority for organizations today and in the future. At Onapsis, we are committed to helping companies protect their SAP environments with our 360-degree security solutions. Thank you for listening to us. A big thank you to Mathieu and Turnkey for sharing their expertise. Until next time, stay safe. Thank you.