New Report Reveals Global SAP Security Benchmarks

SecurityBridge data shows strengths in system hardening despite persistent gaps in authorizations and data protection.

A new global benchmark report is shedding light on the actual state of SAP security, revealing that while organizations have matured in host-level controls, significant vulnerabilities remain in user authorizations and foundational configurations.

The Cybersecurity Resilience Index for SAP, released by SecurityBridge, analyzed anonymized data from thousands of production environments. The index measures the percentage of compliant security checks across various areas of responsibility to help leaders identify systemic gaps.

According to the findings, the strongest area of SAP security is the operating system, which boasted a 100% compliance rate. This suggests that host-level controls and system hardening are consistently enforced and heavily audited across the sector. Additionally, secure development practices and system integrations both scored 77%, indicating a reduced risk of lateral movement by hackers through insecure interfaces.

However, the report highlighted several areas of concern. SAP Basis, the technical foundation of the SAP environment, scored the lowest at 58%. Security experts warn that weaknesses in this area can undermine audit readiness and create a visibility gap that hampers incident response.

Data protection and authorizations also lagged behind, scoring 65% and 68%, respectively.

"Authorization control gaps strongly correlate with attacker pathways from basic users to elevated privileges," the report stated. These lower scores suggest that many organizations still struggle to detect or remediate overly powerful user permissions, which remain a primary vector for data breaches.

To improve resilience, the report recommends that security teams prioritize the pruning of unused authorization profiles and tighten baseline hardening for SAP Basis to ensure audit logs are properly maintained.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.