Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: 2025 SAP Security Threats by Maturity Level

Onapsis
08/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


indicating their greater cybersecurity coverage might have made some of those threats a little bit less concerning. On the other hand, supply chain attacks where attackers, for example, target trusted third-party vendors, they were far more concerning to these respondents. And as you can see, supply chain attacks is a little above halfway down on the list for all respondents. Those who indicated a slightly lower cybersecurity maturity, and that's 38% of respondents, were most concerned about things like unpatched systems, connections to other systems, credentials compromised, weak access controls, and insider threats. So these organizations have an increased investment and maturity of people processing technology across multiple security domains, supporting cybersecurity beyond core protections, but they're missing either strong executive support or they're missing full visibility across the enterprise. So it's interesting to look at the fact that nearly 40% of respondents, yes, unpatched systems are a concern for everybody. They're a little less of a concern for those with a greater cybersecurity maturity. They were sort of only fourth on the list as against first. But it is interesting that those with a greater maturity are more concerned about supply chain attacks, credentials compromised. These are things that are not coming into the top five for respondents that have less executive support or less visibility across the enterprise. And then at the bottom of the list, those with the lowest cybersecurity maturity, in other words, they might have some core protections in place, but they're primarily focused on regulatory compliance with limited advanced cybersecurity capabilities. That was 19%. Or they may be just mostly reactive from their cybersecurity, from a cybersecurity standpoint, and they have sort of a minimal investment in securing critical systems only. That's another 10%. So that 29% of respondents or a little less than a third, they were most concerned about data exfiltration, supply chain attacks, weak access controls, ransomware attacks, or custom code vulnerability. So there, what you can sort of read into that is that the correlation between more traditional SAP security concerns, which is weak access controls, and the primary focus on regulatory compliance or mostly reactive policies indicates that many of those organizations, they might not have moved entirely beyond GRC-type concerns to broader cybersecurity threats. Also, potentially, they're also, what was I going to say? Yes, they are concerned about data exfiltration, but they're more concerned about custom code vulnerability, whereas you notice that wasn't even in the top five for the other two groups, and in fact, it's towards the bottom of the list for respondents as a whole, indicating that maybe those other groups, those that have a greater investment in cybersecurity or particularly have something that might be having more of an impact, which is a stronger executive support, might have already been able to partially or fully address some of those challenges.

TL;DR

  • Organizations with higher cybersecurity maturity prioritize supply chain attacks and credential compromise over traditional concerns like unpatched systems, which rank fourth versus first for less mature organizations.
  • Nearly 40% of respondents have increased security investment and maturity but lack either strong executive support or full enterprise visibility, placing them in a middle tier of security readiness.
  • The least mature organizations (29% of respondents) focus on data exfiltration, weak access controls, and custom code vulnerabilities, indicating they haven't moved beyond GRC-focused security concerns to broader cybersecurity threats.

Summary

This analysis examines how SAP security concerns vary based on organizational cybersecurity maturity levels, drawing from survey data that segments respondents into three distinct groups. Organizations with higher maturity and strong executive support prioritize supply chain attacks and credential compromise, while those with lower maturity focus on foundational issues like unpatched systems and weak access controls. The data reveals that nearly 40% of organizations fall into a middle tier with increased security investment but lacking either full executive support or enterprise-wide visibility. Notably, custom code vulnerabilities rank as a top concern only for the least mature organizations, suggesting more advanced teams have already addressed this traditional SAP security challenge. The findings indicate that security priorities shift dramatically as organizations mature beyond basic GRC compliance toward comprehensive cybersecurity postures, with supply chain risk emerging as a critical concern for those with greater defensive capabilities.

Chapters

0:00 - High Maturity Security Priorities
0:35 - Mid-Tier Maturity Concerns
2:06 - Low Maturity Focus Areas
2:55 - GRC vs Cybersecurity Posture

Key Quotes

0:15 "On the other hand, supply chain attacks where attackers, for example, target trusted third-party vendors, they were far more concerning to these respondents."
1:16 "So it's interesting to look at the fact that nearly 40% of respondents, yes, unpatched systems are a concern for everybody. They're a little less of a concern for those with a greater cybersecurity maturity."
2:55 "So there, what you can sort of read into that is that the correlation between more traditional SAP security concerns, which is weak access controls, and the primary focus on regulatory compliance or mostly reactive policies indicates that many of those organizations, they might not have moved entirely beyond GRC-type concerns to broader cybersecurity threats."

FAQ

How do SAP security priorities differ based on organizational maturity?

Organizations with higher maturity focus on supply chain attacks and credential compromise, while less mature organizations prioritize foundational issues like unpatched systems, weak access controls, and custom code vulnerabilities. The most mature organizations have moved beyond traditional GRC concerns to address sophisticated threats that require enterprise-wide visibility and executive support.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Compliance & Governance
  • Threat Intelligence
  • Technical Deep Dive
  • Best Practices
  • SAP Security
  • Cybersecurity Maturity
  • Supply Chain Attacks
  • Unpatched Systems
  • Access Controls
  • Data Exfiltration
  • GRC Compliance
  • Custom Code Vulnerabilities
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: 2025 SAP Security Threats by Maturity Level

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  The Automation Escalation: Discovering the AI-Driven Underground Revolution

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Invisible Data: Understanding What You Can't Safeguard

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      The Automation Escalation: Discovering the AI-Driven Underground Revolution
                      https://www.truthinit.com/index.php/channel/2108/the-automation-escalation-discovering-the-ai-driven-underground-revolution/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: Understanding What You Can't Safeguard
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-you-cant-safeguard/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version