Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: 2025 SAP Security Threats by Maturity Level

Onapsis
08/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


indicating their greater cybersecurity coverage might have made some of those threats a little bit less concerning. On the other hand, supply chain attacks where attackers, for example, target trusted third-party vendors, they were far more concerning to these respondents. And as you can see, supply chain attacks is a little above halfway down on the list for all respondents. Those who indicated a slightly lower cybersecurity maturity, and that's 38% of respondents, were most concerned about things like unpatched systems, connections to other systems, credentials compromised, weak access controls, and insider threats. So these organizations have an increased investment and maturity of people processing technology across multiple security domains, supporting cybersecurity beyond core protections, but they're missing either strong executive support or they're missing full visibility across the enterprise. So it's interesting to look at the fact that nearly 40% of respondents, yes, unpatched systems are a concern for everybody. They're a little less of a concern for those with a greater cybersecurity maturity. They were sort of only fourth on the list as against first. But it is interesting that those with a greater maturity are more concerned about supply chain attacks, credentials compromised. These are things that are not coming into the top five for respondents that have less executive support or less visibility across the enterprise. And then at the bottom of the list, those with the lowest cybersecurity maturity, in other words, they might have some core protections in place, but they're primarily focused on regulatory compliance with limited advanced cybersecurity capabilities. That was 19%. Or they may be just mostly reactive from their cybersecurity, from a cybersecurity standpoint, and they have sort of a minimal investment in securing critical systems only. That's another 10%. So that 29% of respondents or a little less than a third, they were most concerned about data exfiltration, supply chain attacks, weak access controls, ransomware attacks, or custom code vulnerability. So there, what you can sort of read into that is that the correlation between more traditional SAP security concerns, which is weak access controls, and the primary focus on regulatory compliance or mostly reactive policies indicates that many of those organizations, they might not have moved entirely beyond GRC-type concerns to broader cybersecurity threats. Also, potentially, they're also, what was I going to say? Yes, they are concerned about data exfiltration, but they're more concerned about custom code vulnerability, whereas you notice that wasn't even in the top five for the other two groups, and in fact, it's towards the bottom of the list for respondents as a whole, indicating that maybe those other groups, those that have a greater investment in cybersecurity or particularly have something that might be having more of an impact, which is a stronger executive support, might have already been able to partially or fully address some of those challenges.

TL;DR

  • Organizations with higher cybersecurity maturity prioritize supply chain attacks and credential compromise over traditional concerns like unpatched systems, which rank fourth versus first for less mature organizations.
  • Nearly 40% of respondents have increased security investment and maturity but lack either strong executive support or full enterprise visibility, placing them in a middle tier of security readiness.
  • The least mature organizations (29% of respondents) focus on data exfiltration, weak access controls, and custom code vulnerabilities, indicating they haven't moved beyond GRC-focused security concerns to broader cybersecurity threats.

Summary

This analysis examines how SAP security concerns vary based on organizational cybersecurity maturity levels, drawing from survey data that segments respondents into three distinct groups. Organizations with higher maturity and strong executive support prioritize supply chain attacks and credential compromise, while those with lower maturity focus on foundational issues like unpatched systems and weak access controls. The data reveals that nearly 40% of organizations fall into a middle tier with increased security investment but lacking either full executive support or enterprise-wide visibility. Notably, custom code vulnerabilities rank as a top concern only for the least mature organizations, suggesting more advanced teams have already addressed this traditional SAP security challenge. The findings indicate that security priorities shift dramatically as organizations mature beyond basic GRC compliance toward comprehensive cybersecurity postures, with supply chain risk emerging as a critical concern for those with greater defensive capabilities.

Chapters

0:00 - High Maturity Security Priorities
0:35 - Mid-Tier Maturity Concerns
2:06 - Low Maturity Focus Areas
2:55 - GRC vs Cybersecurity Posture

Key Quotes

0:15 "On the other hand, supply chain attacks where attackers, for example, target trusted third-party vendors, they were far more concerning to these respondents."
1:16 "So it's interesting to look at the fact that nearly 40% of respondents, yes, unpatched systems are a concern for everybody. They're a little less of a concern for those with a greater cybersecurity maturity."
2:55 "So there, what you can sort of read into that is that the correlation between more traditional SAP security concerns, which is weak access controls, and the primary focus on regulatory compliance or mostly reactive policies indicates that many of those organizations, they might not have moved entirely beyond GRC-type concerns to broader cybersecurity threats."

FAQ

How do SAP security priorities differ based on organizational maturity?

Organizations with higher maturity focus on supply chain attacks and credential compromise, while less mature organizations prioritize foundational issues like unpatched systems, weak access controls, and custom code vulnerabilities. The most mature organizations have moved beyond traditional GRC concerns to address sophisticated threats that require enterprise-wide visibility and executive support.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Compliance & Governance
  • Threat Intelligence
  • Technical Deep Dive
  • Best Practices
  • SAP Security
  • Cybersecurity Maturity
  • Supply Chain Attacks
  • Unpatched Systems
  • Access Controls
  • Data Exfiltration
  • GRC Compliance
  • Custom Code Vulnerabilities
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: 2025 SAP Security Threats by Maturity Level

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Sep
                        29

                        Embracing AI Adoption While Maintaining Robust Security Measures

                        09/29/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/29/2026
                          12:00 PM
                          09/29/2026
                          Embracing AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-maintaining-robust-security-measures/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version