New Report Reveals Global SAP Security Benchmarks

SecurityBridge data shows strengths in system hardening despite persistent gaps in authorizations and data protection.

A new global benchmark report is shedding light on the actual state of SAP security, revealing that while organizations have matured in host-level controls, significant vulnerabilities remain in user authorizations and foundational configurations.

The Cybersecurity Resilience Index for SAP, released by SecurityBridge, analyzed anonymized data from thousands of production environments. The index measures the percentage of compliant security checks across various areas of responsibility to help leaders identify systemic gaps.

According to the findings, the strongest area of SAP security is the operating system, which boasted a 100% compliance rate. This suggests that host-level controls and system hardening are consistently enforced and heavily audited across the sector. Additionally, secure development practices and system integrations both scored 77%, indicating a reduced risk of lateral movement by hackers through insecure interfaces.

However, the report highlighted several areas of concern. SAP Basis, the technical foundation of the SAP environment, scored the lowest at 58%. Security experts warn that weaknesses in this area can undermine audit readiness and create a visibility gap that hampers incident response.

Data protection and authorizations also lagged behind, scoring 65% and 68%, respectively.

"Authorization control gaps strongly correlate with attacker pathways from basic users to elevated privileges," the report stated. These lower scores suggest that many organizations still struggle to detect or remediate overly powerful user permissions, which remain a primary vector for data breaches.

To improve resilience, the report recommends that security teams prioritize the pruning of unused authorization profiles and tighten baseline hardening for SAP Basis to ensure audit logs are properly maintained.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.