Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Keeping Your ERP Systems Secure In The Cybercriminal World
Articles

Keeping Your ERP Systems Secure In The Cybercriminal World

ISBuzz TeamBy ISBuzz TeamJuly 13, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When business-sensitive data is hacked or leaked the consequences can be disastrous for an organisation. ERP (enterprise resource planning) systems can be particularly attractive targets for hackers because to a cybercriminal they look like honeypots of valuable data. Whether that data is customer credit card details, business financial data or intellectual property, if cybercriminals obtain it they can sell it on the underground economy. Other risks include hacktivism where groups will post sensitive customer data publicly to highlight security flaws, which can significantly impact a company’s reputation, or cyber-espionage whereby competitors obtain access to valuable intellectual property.

We believe industrial companies and manufacturers could be playing catch-up when it comes to security. Banks, government agencies and B2C retailers have long been at higher risk of attacks due to the nature of the data they hold and the regulations surrounding this data, but they are not the only targets. Research from internet security firm Symantec shows that attacks on smaller firms (those with less than 250 employees) now make up 43% of all attacks observed, and the manufacturing industry tops the table as recipients of malicious spam. Apart from the impact on customer operations and business reputation, it’s a company’s own legal responsibility to ensure that data is properly secured, encrypted and protected, with hefty legal fines (to say nothing of the loss of business) for non-compliance.

As hacking techniques continue to evolve in their sophistication, those responsible for protecting ERP systems have a plethora of issues to consider: are firewalls secure, are passwords complex enough, are systems regularly patched and updated and are staff adequately trained, so that cybercriminals can’t get in through the back door via a Trojan horse infected email? Many IT managers have been led to conclude maintaining on-premises ERP systems securely is a time-intensive and expensive challenge, and are looking into cloud-based alternatives in order to delegate application security responsibilities to a more qualified team.

In modern reality, security threats are mitigated when a company is hosting ERP in the cloud as opposed to on premises. Vendors entrusted with ERP business information maintain highly secure datacentres, protected 24 hours a day, 365 days a year. They invest in the latest intrusion detection systems, have fully trained expert staff, and take on the responsibility of keeping data secure, encrypted and protected.

However, there are several considerations organisations must be aware of when moving ERP systems to the cloud:

  • Is cloud right for you? It may be that your business is comfortable with the security measures, back-up, patching and upgrades programme it currently employs, and that fixed and mobile security are both equally considered.
  • Verify the security steps that your cloud ERP vendor deploys. Do they encrypt data while in transit, provide intrusion detection systems and hire certified and background checked employees? Is the vendor audited by an independent review organization?  Are they able to provide transparency into their policies and processes?
  • Check the regulatory requirements pertinent to your business and the geographies you operate in, and ensure that any PII (personal identifiable information) or other sensitive data will be well protected by an ERP vendor which has proven security experience and can demonstrate best practices in systems management procedure.
  • Hacks and data leaks can often stem from a lack of employee understanding or vigilance, whether that’s around your security processes or the implementation of systems.Remember that while business growth is to be celebrated, with growing numbers of users comes a growing risk that someone is going to do something careless.  Education is the key to ensuring that employees aren’t the weak link in your security chain and putting training and best practices in place can mitigate this threat.

If organisations are confident that the above points have been heeded and all preparatory steps have been taken then relocation of ERP systems to the cloud is recommended. However, companies need to feel assured that they are employing the right cloud vendor and its employees are fully trained before making this shift.

[su_box title=”About Craig Downing” style=”noise” box_color=”#336588″][short_info id=’82770′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}