Securing Software Supply Chains for SAP Landscapes
Software supply chain attacks are among the most sophisticated cyber threats, targeting information systems by compromising third-party software, builds, or trusted interfaces. By exploiting these dependencies, threat actors can introduce malicious backdoors into otherwise secure environments without detection. Why are software supply chain attacks a major risk for SAP? The catastrophic SolarWinds attack demonstrated how […]
Protecting SAP Systems from Ransomware Attacks: An Integrated Strategy
Ransomware attacks have surged by 300% over the past year, posing a critical threat to business infrastructure. While many organizations focus on hardening host operating systems, securing the underlying OS is insufficient for SAP environments. Attackers often exploit the trust relationships between SAP applications and the OS to execute privileged commands, bypass detection, and deploy […]
Protecting SAP Systems from Ransomware Attacks
Recent high-profile incidents, such as the Colonial Pipeline attack, have highlighted the devastating impact of ransomware on critical infrastructure. With ransomware attacks increasing by 300% over the past year, organizations face significant operational risks: the average downtime from an attack is 21 days, while full recovery can take up to 287 days. Why host-level security […]
Cybersecurity Extension for SAP Identifies Signatures of Active SAP Cyberattacks
Recent research confirms that attackers are actively targeting and weaponizing vulnerabilities in SAP applications. With some unprotected cloud installations being compromised in under three hours, and patches being weaponized in less than 72 hours, organizations must move beyond basic patching to implement active threat detection. The Reality of Active SAP Exploitation A joint report by […]
Securing Linux Platforms for SAP HANA and S/4HANA
SUSE Linux Enterprise Server (SLES) is the leading operating system for SAP HANA and SAP S/4HANA solutions, supporting 85 percent of HANA deployments worldwide. SLES for SAP Applications is optimized to support high availability and persistent memory and endorsed by SAP. Securing operating systems is a critical component of SAP system hardening. Vulnerable hosts can […]
Layer Seven Security’s Cybersecurity Extension for SAP® Solutions Achieves SAP® Certification as Integrated with SAP NetWeaver®
Toronto, Canada – March 8, 2021 – Layer Seven Security today announced its Cybersecurity Extension v3.4 for SAP® Solutions has achieved SAP®-certified integration with the SAP NetWeaver® technology platform. The solution has been proven to integrate with SAP solutions, providing automated vulnerability management, threat detection and incident response for SAP applications and infrastructure. “We are delighted to […]
SolarWinds Attack: Lessons Learned for SAP Cyber Security
The software supply chain attack suffered by SolarWinds may have impacted as many as 425 of the US Fortune 500, the top ten US telecommunications companies, the top five US accounting firms, all branches of the US Military, the Pentagon, the State Department, the world’s largest cybersecurity firm, as well as hundreds of organizations worldwide. […]
Compliance Reporting for the SAP Security Baseline
The SAP Security Baseline is a widely used benchmark for securing SAP applications. The benchmark includes SAP recommendations for system hardening, authentication and authorization, logging and auditing, and other areas. The recommendations draw on SAP security notes, guides and whitepapers. The SAP Security Baseline was updated by SAP earlier this year and provides an up-to-date […]
Anomaly Detection with Cybersecurity Extension for SAP
Threat detection is commonly performed through rules or signature-based pattern matching. Detection engines compare actual events with patterns of malicious events to discover indicators of compromise (IOCs). IOCs discovered by detection engines typically trigger an alarm or alert for a suspected security breach. Pattern matching is a tried and tested method to identify known exploits […]
SAP Discloses Critical Vulnerabilities in ASE Databases
SAP customers are urged to apply a series of recent patches released by SAP for the Adaptive Server Enterprise (ASE). SAP ASE, previously known as Sybase SQL Server and Sybase ASE, is a widely deployed database platform used for both SAP and non-SAP applications. According to SAP, ASE is used by over 30,000 customers worldwide, […]