• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » A Manufacturer’s Guide to Business Application Security

Think Tank
Think Tank RSS FeedRSS

A Manufacturer’s Guide to Business Application Security

A GLOWING RED SCREEN SHOWSCOMPUTER  BITS AND BYTES, WITH THE WORD RANSOMWARE AT THE CENTER

Photo: iStock.com/kaptnali

February 24, 2023
Sadik Al-Abdulla, SCB Contributor

Today’s supply chains have become highly volatile and unpredictable. Yet, while issues caused by severe weather and port closures might not be preventable, there are other disasters that can be avoided, such as severe damages caused by a cyberattack.

IBM reports that 23% of ransomware reports tie back to the manufacturing sector, making it the most attacked industry. These incidents not only disrupted operations but also caused millions of dollars in damages. In fact, each manufacturing data breach costs roughly $5 million on average, while taking over 200 days to discover and almost four months to remediate. It’s evident that manufacturing companies still have a long way to go to secure their operations.

As the manufacturing sector continues to rapidly accelerate its digital transformation, it’s critical that these organizations are also prioritizing the security of their enterprise resource planning (ERP) applications amid the unprecedented threat landscape. Otherwise, their digitization efforts are put to waste. Manufacturing companies must invest in cybersecurity tools that can detect and mitigate any critical vulnerabilities or suspicious activity within the ERP. Yet many don’t know where to start when it comes to their business application security strategy. Following are some steps that manufacturers should take to strengthen their cybersecurity defenses.

Understand the current threat landscape. Manufacturers rely on ERP applications to manage their facility processes and operations, such as inventory management, payroll and production scheduling. Given its importance to the organization, an ERP that isn’t well-protected can present countless security issues and leave the business highly vulnerable. Unfortunately, many companies delay in applying necessary patches, or often don’t even realize a vulnerability exists within their application ecosystem.

The three high-severity vulnerabilities found in SAP Internet Communication Manager, a crucial part of SAP business systems, in early 2022 were perhaps one of the most daunting examples of ERP system flaws. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) even added one of the flaws to its Known Exploited Vulnerabilities Catalog (KEV), urging companies to apply the necessary fixes before it’s too late. Despite the push to patch these flaws, many organizations have yet to apply the recommended remediations, leaving themselves vulnerable to threats like data exfiltration and financial damage.

Cybercriminals are well aware of business applications’ profitability and are evolving their tactics to directly target them. For instance, the cybercrime group Elephant Beetle was caught sitting within company networks for months while silently siphoning off millions of dollars. The threat group remained undetected for months on end by blending in and acquainting itself with each company’s financials prior to carrying out fraudulent transactions. Organizations must be prepared to face the new wave of threats, but this can only be done with full visibility into the IT ecosystem.

Obtain deep visibility into ERP applications. Threats like ransomware have traditionally been prioritized by security teams, who spend considerable time and money on defense-in-depth tools that provide layered network protection. Yet, as we witnessed with Elephant Beetle, a direct attack on an ERP can wipe out an organization’s financials, resulting in an incident that’s far more disastrous than a ransomware attack on a printer or desktop. Thus, while network security, intrusion detection and other defense-in-depth cybersecurity technologies are critical investments, they aren’t enough to protect the business application layer.

Security teams must take a deeper look at their cybersecurity strategy to ensure it includes ERP defense. To prevent threats like misconfigurations and unauthorized access, end-to-end visibility into the business application landscape is absolutely critical. This, coupled with strong security controls, will enable teams to keep a close eye on suspicious activity and take a proactive approach to risk management.

Deploy the right security defenses. Data from the Ponemon Institute shows that a majority of security experts understand that defending applications should be a priority, yet nearly two-thirds still struggle to reduce risks and contain attacks on business applications due to a lack of resources. While budget and time restrictions can certainly be a challenge, investing in the right cybersecurity tools can help security teams defend their operations. Application security tools catered to ERP, for instance, are strategic assets to any cybersecurity program. These technologies can alleviate overburdened security teams by continuously monitoring for vulnerabilities and misconfigurations. If an issue is identified, they proactively alert the team and automatically provide recommended steps for corrective action. From there, security teams can understand the severity of each vulnerability and prioritize those that need immediate attention.

Tackle ERP application security threats head-on. The above steps can help manufacturers make more strategic cybersecurity investments and prevent a potential supply chain security crisis. By becoming well-acquainted with new threats and risks, achieving visibility into their business application landscape, and implementing application security tools, companies can confidently ensure they have a strong cybersecurity strategy. ERP applications are facing a new level of risk in 2023, and manufacturers must be equipped to take on any cybersecurity challenge that comes their way.

Sadik Al-Abdulla is chief product officer of Onapsis.

ERP & Enterprise Systems Supply Chain Visibility Regulation & Compliance Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence
  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • DOMINO EFFECT FINANCIAL MONEY KNOCK-ON CONSEQUENCES iStock-Devrimb-1500012566.jpg

    Podcast | The Tariff Conundrum for Supply Chains: Pass Along, or Absorb?

    Supply Chain Finance & Revenue Management
  • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

    Watch: AI and Data Transformation in Distribution

    Artificial Intelligence
  • TWO WORKERS DISCUSS DATA SHOWN ON COMPUTER SCREENS

    Gartner: Gap in SC AI Talent Cannot Be Closed by Hiring Alone

    Artificial Intelligence

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing