Why a New Generation of Threat Actors Targets SAP
Show notes
TAKEAWAYS
- Discover why criminal interest in SAP has risen sharply in recent years
- Learn how threat actors now specialize in SAP access, data and social engineering
- Understand why stolen data stays dangerous long after the breach is closed
- Separate the real AI threats from the hype around them
- Focus on the two priorities that cover most of your SAP risk
HOST & GUEST Waseem Ajrab – Host: Managing Director, NO MONKEY Mannie W. – Guest: Head of Research, Lab 1
CHAPTERS 00:00 Introduction to SAP Cybersecurity and Guest Mannie 01:28 Mannie's Journey into Dark Web Threat Intelligence 04:03 Why the Dark Web is a Valuable Source of Threat Intelligence 06:10 Increased Interest in Targeting SAP Systems 08:12 Differences Between Traditional and SAP Security 09:32 Specialization of Threat Actors in SAP and ERP Systems 12:11 Misconceptions About SAP Security and Risks 14:23 Impact of AI on Cyber Threats and Attack Methods 16:24 Future Developments in AI and Cyber Attacks 18:41 Weaponization of Stolen Enterprise Data 21:46 Why Incident Response Often Ends Too Early 23:05 Practical Recommendations After a Breach 24:19 Supply Chain Risks and Data Breach Implications 25:57 Collaboration Between CTI and Incident Response 29:02 Key Priorities for Protecting SAP Environments
New episodes drop regularly, featuring conversations with cybersecurity experts, SAP practitioners, and industry leaders who've been in the trenches. No vendor pitches. No fluff. Just actionable insights you can apply today.
Because curiosity is free – but recovery isn't.
Show transcript
00:00:00: It's realized that SAP is being targeted, you're not protected by the sort of the grandness of your system.
00:00:08: That's number one.
00:00:08: Two Realize SAPs being targeted primarily with known exploits and context-driven social engineering.
00:00:24: Welcome to SAP Cyber Security By No Monkey where we tackle SAP security together Where We Break Down The Complexities Of SAP Cybersecurity And Make Them Real Relevant And Actionable.
00:00:35: I'm Your Host Wasi Majrab.
00:00:37: Every episode we explore the threats, innovations and strategies shaping the future of cybersecurity.
00:00:44: Whether you're in deep technical trenches or leading at sea level this is where we talk openly about it And really what takes to protect systems that run your business.
00:00:54: Alright let's dive-in Manny first off all its great have on show.
00:00:59: looking forward our topic today I think this is the first time we're looking into SAP from a completely different perspective.
00:01:07: One, i like to read about and personally sometimes spend some time but i believe where you spent every waking hour doing so... But before we go in that for our audience as well who might not know you Who Is Manny?
00:01:19: Your journey In The Dark Web Intelligence And How You Ended Up To Some Extend Doing Research Around SAP Environments Manny Over To You.
00:01:27: Thank You
00:01:28: Yeah It Was Nice To See You Here.
00:01:30: I appreciate you having me here on the call.
00:01:33: Yeah, i currently work as head of research at Lab One.
00:01:37: Lab one is a small sort of cybersecurity firm that services specific niche in dark web market but prior to this was working with lead analyst and manager at Accenture's Dark Web Reconnaissance team which did for close eight years, almost nine years.
00:01:55: So I've spent the better part of ten years working in sort-of dark web cyber threat intelligence different fields within this different specialties and Of course across.
00:02:07: This is a journey.
00:02:10: A lot of times you have either a direct relationship with something that's going on with SAP or some recent relationship.
00:02:19: So that's kind of how my interest in sort the specific part of HAP being weaponized by dark web criminals began forming, which is one of those areas I've been looking at over the last couple years.
00:02:32: Interesting!
00:02:33: Now you spent years doing this like... Looking at emerging threats within the dark web and of course briefing, I've seen that you have done a lot different talks.
00:02:43: What drew you to the threat intelligence?
00:02:46: And maybe The Dark Web reconnaissance?
00:02:48: when it comes in general...
00:02:50: I mean i stumbled into it.
00:02:51: It was not anyone.
00:02:54: Very few people set out To do this Because its really a normal career path You know exists When your university or whatever your background is Studying war studies at King's College.
00:03:08: I had an amazing professor there who, uh... At the time was both working as a Professor in King's college but also Working within a CTI firm called Eye Defense.
00:03:17: He recruited me and joined Eye Defense And landed on the Dark Web Reconnaissance Team And i've loved it ever since.
00:03:23: Amazing!
00:03:24: It is under-evaluated or undervalued area of Cyber Security for the audience.
00:03:34: Most of our audience do come from the SAP world, some are really cybersecurity security.
00:03:39: Your research often identifies and this is a section I'd like to dig deeper into later on but in general your research really identifies those trends before they become mainstream.
00:03:50: so before we hear them what makes The Dark Web such a valuable source of intelligence when it comes to defenders?
00:03:57: Like for my defender perspective What Makes It A Very Valuable Source Of Intelligence?
00:04:03: Yeah, I mean you're right.
00:04:04: I feel like I've done my job the best if i know about a threat or an emerging topology before other people.
00:04:13: that's what im hired to do essentially and luckily we have been able to do it quite few times which is good thing.
00:04:20: What makes dark web valuable?
00:04:23: there are two key things.
00:04:25: The Dark Web ecosystem is obviously extremely commercialized.
00:04:28: now that in order for you to do an attack back in the days, just let's say six seven years ago.
00:04:36: You had to be able to do the entire cyber kill chain in-house.
00:04:40: Yes That is a difficult thing to do.
00:04:42: Obviously there are still major groups who can pull this off and obviously the APT Groups But for majority of cyber criminals thats'a difficult thing To Do.
00:04:50: What The Cybercrime or what the dark web sort of enables Is that you can outsource This Kill Chain.
00:04:56: That makes it easier for criminals, but also gives us as researchers different steps that we can understand and analyze.
00:05:04: And in that regards the dark web is unique in its sense from a threat intel perspective.
00:05:10: you could get intel before an attack happens right?
00:05:13: In planning, in trend or emerging phase... ...and of course after an attack has already happened when somebody's trying to sell some data, sell some access whatever may be.
00:05:22: And I
00:05:26: definitely see that, with SAP and now our least topic from that.
00:05:32: So a lot of people when it comes to SAP going deeper into the thing that SAP is just this application A single application It's called an application but at end-of-the-day what entire ecosystem?
00:05:44: But I think attackers seem very differently As you've done research around SAP if.
00:05:52: Has SAP become more vulnerable, more interesting or have attackers become better at actually recognizing that SAP systems can really provide a huge value to whatever motive they have from the dark web perspective?
00:06:09: What's your thoughts on it.
00:06:10: Yeah!
00:06:10: That is great question.
00:06:11: I don't think necessarily SAP has became more vulnerable but the interest in SAP has gone up significantly.
00:06:18: The reputation on the dark web regarding SAP is that SAP is an open SIF.
00:06:24: There are so many integrators, so many software, so much implementation and so many vulnerabilities that SAP views as a view of an extremely vulnerable Open System.
00:06:35: but it's always been viewed this way.
00:06:36: I think we've seen.
00:06:37: the difference Is that We used to just see ransomware.
00:06:42: Right now we see ransomwares with data exfiltration or Data Exfiltrate on its own And for the latter two, SAP has become extremely attractive to target.
00:06:53: Now this is been largely driven by shiny hunters and similar groups doing a ton of attacks against Salesforce... ...and it goes to show how much data you can take from Salesforce.. ..and then people realize well SAP is just same bigger.
00:07:08: so why don't we do that?
00:07:09: Right!
00:07:10: We've seen huge influx of threat actors trying specifically to target SAP, trying to get the data that's stored in SAP.
00:07:18: Because of this centrality that SAP has in global enterprise management right?
00:07:24: And In that regard you could argue SAP is become more vulnerable not because the platform itself has become buggy but rather because the interest in targeting it has gone up from threat actors with dedicated resources and skills to do so.
00:07:38: Do You think It makes Right now like I had some guests over over the last few episodes and they were within the SAP world or what I like to call it, Japanese World for years.
00:07:51: And they see a difference from compromising your traditional domains ,your traditional environment .
00:07:58: From your perspective coming out of not from within or within SAP but from that perspective do you think is any different than compromising?
00:08:12: No, it's just more available.
00:08:14: Right?
00:08:14: I mean security related to SAP has been overlooked for a while.
00:08:18: right there are specific companies obviously that deals with SAP Security but in the conversations i've heard around like around SAP let say three four years ago security was very much an afterthought.
00:08:30: yeah
00:08:31: and this means that very old school techniques reuse credentials social engineering credentials Infostila credentials, leaked passwords that kind of stuff really works well against SAP still and it yields a massive upside from the criminal.
00:08:48: Absolutely
00:08:49: I mean there are still within these guests they were talking about finding twenty years ago And with in Nomaki when we're doing some sort of pentesting We're still finding those similar ones whether this default credentials or open services which is insane to have It.
00:09:03: There's still...I think not huge but maturity of awareness, what SAP systems can do?
00:09:11: It is still missing on the greater part organizations who are using SAP.
00:09:17: You mentioned something around threat actors.
00:09:20: Do you see any kind of specialization towards SAP or in general ERP Systems when it comes to data theft or extortion or resell?
00:09:31: What do you see from that perspective?
00:09:32: Yeah
00:09:33: we're seeing that now.
00:09:34: We've seen threat actors that have specific knowledge and specific skills, specifically around targeting SAP and other ERP systems.
00:09:42: Couple of different ones right?
00:09:44: We've seen thread hackers that have either worked with SAP in their professional career or has now specialized in targeting so much they are offering as a service.
00:09:53: And what I mean by this is it's no longer easy to just get a set of credentials login and be on with it.
00:10:01: That only works if the company is completely negligent.
00:10:06: What we're seeing is obviously there's a lot of MFA protection and so on.
00:10:08: And now that there are criminals out here who really understand how does humans and SAP interact?
00:10:13: How do businesses integrate SAP, having the knowledge inside them helps to be able to social engineer access into SAP systems.
00:10:22: We see this as service in dark web.
00:10:28: Okay, well where's the valuable data?
00:10:30: Or Where is the valuable system stored with SAP.
00:10:32: I can guide you to that so You don't have to exfiltrate a terabyte of data and just get The five gigabytes they really matter.
00:10:39: we see thread address That are specialized in gaining initial access specifically around SAP.
00:10:44: right i mean last August We saw huge campaign With different kind of thread address that only used cve- Twenty twenty five thirty one before the NetWeaver one as a way to get access and resell that.
00:10:55: So there is set of thread hackers now on The Dark Grip, that are SAP native That understands how it works.
00:11:02: Some will also have skills when it comes for example some of the Oracle Suite or Salesforce Sweets but some specific only to SAP.
00:11:09: Interesting One interesting thing we've seen here I think i showed you this in presentation earlier was A threat actor that has a data indexing service.
00:11:21: He helps ransomware understand the date of this deal and he had specifically built a machine learning module designed to work with Data taken from SIP system.
00:11:30: how, How that data is stored within SAP?
00:11:32: Okay And it goes to show The effort money being put into understanding and targeting SAP.
00:11:38: I mean It's a topic Right after where we look into how has AI definitely improved this for different threat actors?
00:11:48: So from that aspect of now really cyber or threat actors, That are specifically targeting this part of the environment within organizations.
00:11:58: For organization's perspective what do you believe is a misconception when it comes to Cybercrime or organized cyber crime in this ecosystem?
00:12:09: Anything from that perspective?
00:12:11: Yeah.
00:12:11: I mean, there's a lot of misconceptions across the board.
00:12:15: right one is i'm not at risk.
00:12:16: A lot of organizations think they're not a risk because it may Not be you know a billion dollar organization or even if They are a billion-dollar Organization and they've invested a tonne Of money in cybersecurity did thing to another risk.
00:12:27: everyone said risks.
00:12:27: we see It all time If its not directed through your supply chain.
00:12:31: The second Thing Is thinking That having MFA Having You Know some sort of firewall having a little bit of threat until this enough To protect you Right, I mean you need to be constantly on your... And of course the problem is that SAP is so vast, it's so differently integrated.
00:12:47: So many implementations and systems are either public-exposed or not publicly exposed That becomes extremely difficult to understand what your risk profile in SAP is.
00:12:59: I think another huge misconception is that the only cybercrime criminals who pose a risk for you are APTs China Russia.
00:13:07: The majority of cybercrimes made up by by ordinary, low-skilled medium skilled dark group criminals who get lucky and weaponize it.
00:13:18: And then finally the final misconception I love...I don't know how much focus there is on AI?
00:13:24: I think they are real implementations of criminals using AI.
00:13:28: There's real threats also.
00:13:30: thing that a tonne of hype right.
00:13:33: one loves talking about Mythos.
00:13:34: Mythos has never been used by criminal groups by focusing on the theoretical AI threats rather than their real AI threads.
00:13:46: I completely agree with that, we do see also when it comes to utilization of AI there's a lot being an expert and improving whatever you are developing exploitation or either from a defensive perspective.
00:14:03: But from that perspective, do you see a careless attack attacks going on or that significant shift?
00:14:10: From an adversary perspective when you are using LLM more.
00:14:14: You're using AI to conduct any kind of attacks.
00:14:17: Do you see any kind Of lagged usey Any kind of shifts that are happening?
00:14:22: for me That's the area.
00:14:23: Yeah I mean everyone's favorite thing To say When it comes to AI right is The same three things Everyone says all the time.
00:14:30: It lowers the barriers to entry And it increased scale and speed, right?
00:14:35: Theoretically all of that is true.
00:14:37: I think we have yet to see this adopted unmask.
00:14:42: There are areas where we see it Right like for example We don't see any poorly written Nigerian prince emails anymore because It will be done with an LLM.
00:14:54: But we also Don't see mass adoption Of entirely AI driven attack chains.
00:15:01: That is the exception to rule rather than rule.
00:15:05: I think what we are seeing for example, is threat actors being able find exploits from patches much quicker.
00:15:12: reverse engineering of patches right.
00:15:14: so We have actually seen that The window in which an organization can patch has gone down quite significantly and it's a real thing really truly matters.
00:15:24: you cant If your window of patching is currently anything more than two days, you're so far behind.
00:15:29: it doesn't even matter.
00:15:30: You might as well just leave your patches unpatched right?
00:15:32: Unpatched exactly yeah.
00:15:34: So we have seen that does matter.
00:15:36: We've also seen for example that productors are stealing data and then putting in through LLMs different kind of AI models And understanding what they take.
00:15:45: That helps guide a ransomware group to find the different data They steal from an SAP system And figure out what matters?
00:15:53: What's leverage?
00:15:54: how can I use this in the supply chain and so on.
00:15:56: So there are true weaponizations of AI, it's just not... It is not the mythos finding a zero-day exploit in a vulnerable system right?
00:16:08: Yeah absolutely!
00:16:09: And based upon what you see from that perspective like in terms of the dark web What kind of developments let say over A few years that might concern you or concerns the most when it comes to these areas.
00:16:24: Yeah,
00:16:24: I mean good point!
00:16:25: I think i first started talking about deepfakes back in twenty seventeen was the first piece we did on and presented at Black Hat in twenty twenty one.
00:16:34: That's only gonna get worse right?
00:16:36: It was difficult because you needed a lot of data And you needed high quality data.
00:16:41: Now, You don't need a lot of Data and you Don't Need High Quality Data so more people in an organization can be deepfaked?
00:16:47: If you can suddenly Deepfake assist admin who is maybe not as protected or as high profile As the CEO then you've got an easy access into an Organization.
00:16:57: We also see obviously The supply chain.
00:17:01: Implications for Databricks from an organization are now higher than they have ever been because drugers Can find pieces of Nugget within trove of stolen data that they previously couldn't find, right?
00:17:12: If you stole one terabyte of data two years ago.
00:17:14: You had to be extremely lucky to find the two three four files That matters.
00:17:18: now you can just run it through different kind of AI models either Uncentered ones jailbroken versions of censored once or self-built ones and then you could use that too Targeted a supply chain at that company rights.
00:17:31: And Of course Theoretically looking ahead we could get into scenario in which the patching cycles has to be less than an hour to be relevant.
00:17:39: And of course, vulnerabilities could be discovered from a zero-death perspective but we're still far out from
00:17:44: that.".
00:17:44: Yeah I think there's a lot off...I mean up to this point were talking about patching for everything.
00:17:51: it is one the biggest issues in the last X amount years i've been with in this industry or coming form the cyber security also perspective..i think we always have had problem with patching.
00:18:03: A lot organizations have!
00:18:05: I want shift towards your recent or your focus that you're currently looking into, which is quite interesting.
00:18:13: I think to a lot of organizations have SAP as this kind of core functionality and environment within those crown jewels they are called in an organization.
00:18:25: so one area you've researched extensively for example how stolen enterprise data can be weaponized.
00:18:37: Can you explain what that looks like?
00:18:41: Yeah, absolutely.
00:18:41: So it used to be the enterprise data was stolen in big bulks right two three four hundred gigabytes or more.
00:18:48: and The entire value of that dataset from a criminal perspective Was the leverage of it.
00:18:54: And if a criminal group didn't get a ransom payment They would then leak It and That Would Kind Of Be The End Of That Leak Right Which Is Nobody or where a few people could download four hundred gigabytes of unstructured data and understand it to any degree, were would carry on malicious value.
00:19:11: Now we've seen that's changing.
00:19:13: threat.
00:19:13: actors are spending the time in resources It takes to understand the data That has been taken either by themselves Or some other ransomware group who is leaked for free.
00:19:22: Many of these does this indexation analysis via machine learning AI.
00:19:28: Some People do it via dedicated analysts On The Team.
00:19:32: Some groups, like Holkrumsek or Anubis does it almost like an investigative journalist report.
00:19:38: And some groups use a combination of this with a little bit of LLM help and so on and so forth.
00:19:43: What that means when a threat actor steals data from a crown jewel system-like SAP... ...and then takes the time to analyze it?
00:19:51: Means all the skeletons in the closet will be found.
00:19:56: That means higher pressure during victim's negotiation if you find The data that truly matters, either this in the intellectual IP.
00:20:05: That matters.
00:20:06: or the sort of creative accounting that can lead to a fine or the proof of lack of cybersecurity stuff like This where you can now suddenly get into the criminal negligence Or the fine territory.
00:20:19: they obviously have A higher impact?
00:20:21: The second thing is We've seen that groups are increasingly pivoting so They're using data taken from breach one To target company two Company three Company four.
00:20:33: And that happens in two different ways.
00:20:35: There's the hard data, which is the credentials tokens keys right.
00:20:40: finding That kind of data can directly enable a secondary targeting.
00:20:43: We've seen shiny hunters do this multiple time now.
00:20:46: The other part of that Is to soft data?
00:20:48: Right all the things that are not credentialed soft or not credentials keys Tokens and so on So forth.
00:20:55: and for example we had a case recently where our UK company was breached.
00:21:00: Okay Threadockers then found a couple of invoices and a couple documents from that company to some their clients, weaponized those documents to target the client.
00:21:11: And now you have downstream attack against two clients coming form the original mother-company right?
00:21:16: No!
00:21:17: This means there's just much higher risk overall for these supply chain breaches.
00:21:22: You're no longer protected by the fact data is difficult get or difficult understand.
00:21:26: People will take time to analyze.
00:21:27: it obviously need protect yourself.
00:21:29: I
00:21:31: mean, it is an interesting perspective.
00:21:32: So for me to think about this like here are organizations actually ending that incident response too early?
00:21:41: Do you?
00:21:41: and assuming that the danger is done after the system has been restored
00:21:46: Yeah many people aren't.
00:21:47: Many People Are Ending It Too Early And i Think Some Of It Is Not Because They Don'T Realize Just A Threat It's just because Traditionally There'S Been Nothing You Can do About It Right?
00:21:55: yeah Because If Your Third Party has one terabyte of unstructured data lying on the dark web, it's not your data.
00:22:02: And you could be breaking the law if you just download that data right?
00:22:07: The first thing then will happen is these companies go to their intel provider and say hey can tell me what my exposure here?
00:22:13: And most companies can't do that, right?
00:22:15: That's a difficult thing to do from the technical perspective and from a legal perspective.
00:22:19: Which is what obviously we're kind of working on it in lab one-that is our modes... ...that's why its an interesting field for me to be in but.. But It just a difficult things!
00:22:29: I think many companies realize there potentially is threat out there.... The level effort you to uncover becomes so high thats not worth it.
00:22:41: You
00:22:41: have to hope that the level of effort for criminal to weaponize it has also so high, That's not going to happen.
00:22:45: And thats kind.
00:22:46: what is changing now?
00:22:47: The math is changing.
00:22:48: So would you maybe recommend shortly on What might be possible activities after a breach?
00:22:57: After an incident response process?
00:22:59: What should we include as initial steps For organization take from this perspective?
00:23:05: It depends little bit.
00:23:06: if your are one who had data breach So its your data that been taken.
00:23:11: You need to understand what was taken.
00:23:13: How am I at risk of secondary attacks?
00:23:16: Is there an invoice out there that drives up the risks, for example a business email compromise attack?
00:23:23: or is it a recent PEN test report which shows what vulnerable systems we have and how to exploit them right now?
00:23:29: So if its your own data you really needs to understand who does this affect then it's important.
00:23:40: But you're in the supply chain of somebody who had a nasty data breach.
00:23:44: You really need to understand, am I exposed?
00:23:46: Right?
00:23:47: do i have contract data that can expose some sort of partnership?
00:23:53: Do I have integration data that could expose keys token sessions whatever.
00:23:58: Do I have invoices and material data that can drive up the risk of a CEO attack or business evil compromise attack?
00:24:05: Right.
00:24:05: To some degree, it's not your responsibility because it is your third party And ideally responsible third parties should tell you about this.
00:24:12: But its difficult thing to do.
00:24:13: It's costly so you need to be vigilant That there isn't elevated risk for US organization from a third-party database.
00:24:21: Whether or Not that is rotate keys Rotate tokens actually change our banking details so that we know that were not gonna make a involuntary transfer or something, right?
00:24:32: Like it depends on what the relationship is between you and your third party.
00:24:37: I mean absolutely!
00:24:38: With SAP environments.
00:24:39: you said supply chain attacks are increasing... Not everybody but to some extent there's organizations who would still think that SAP is somehow within their environment quite isolated.
00:24:54: that kind of supply chain or what kind of integrations interfaces are connected makes it quite, I wouldn't say scary but quite risky for organizations and scary when you have similar to the last couple.
00:25:06: I forgot when was the last breach, which happened recently and that company lost a lot of money due to certain facts.
00:25:14: Of...I mean there were lots more going on but at least from this perspective.
00:25:18: so with it being said And of course is quite important.
00:25:22: where incident response plans are now extended To that second wave or second attack what can possibly go wrong?
00:25:29: From threat intelligence point-of view how could become practical part from your perspective, from your opinion of SAP security instead of simply adding it?
00:25:40: because you said that perfectly in the beginning.
00:25:42: You said that part is now becoming more commercialized.
00:25:46: we have these Dashboards, we have all of this.
00:25:48: How can it become a practical part of SAP security rather than just simply another dashboard on an operation center?
00:25:57: Yeah I mean you're absolutely right!
00:25:59: The best CTI is the stuff that works directly with either your SOC preemptively or work directly with your incident response Right.
00:26:06: so traditionally i think incident responses very siloed from CTI And it shouldn't be like, right?
00:26:12: Good internet response should have the threat intel.
00:26:15: that matters.
00:26:15: But here the responsibility is also on the threat Intel people.
00:26:19: God knows there's so much shitty CTI out there.
00:26:22: just tells you emerging threats or somebody will give a report showing your last month ransomware attack and I hate those because they've zero predictive value to tell what next month's ransomware is going.
00:26:36: So the responsibility is, incident response should reach out to CTI.
00:26:40: They have value to add but CTIs then also own up for that responsibility and not give every single useless IOC or useless report.
00:26:50: If somebody got breached with an SAP system from let's say...I'm just saying something random here The kill-and-randomware group Right?
00:27:00: A good CTI should then focus on a month old IOCs from Killen at Max and little bit of background about what have we seen in terms of Killen's behavior after a breach.
00:27:10: Do they honor an agreement, do they leak data?
00:27:12: how much data to the on average take are known to pass that data onto someone else who weaponizes it?
00:27:18: right?
00:27:19: so more collaboration between CTI and incident response.
00:27:26: For the love of everything holy, cut CTI down to something that actually matters and is not just an overflowing dashboard with a report nobody cares about.
00:27:34: I absolutely agree!
00:27:35: And i've seen dashboards like this where we try make something out of it in terms of use case and sometimes data.
00:27:44: that's unusable crap.
00:27:47: I
00:27:50: mean, in my opinion right.
00:27:51: you almost need to split CTI into two disciplines.
00:27:54: Right?
00:27:54: There's strategic CTI which most of the time is too useless shit that's valuable for a C-suite who may want understand a bit of Threadscape.
00:28:03: and then there are tactical actionable CTI.
00:28:06: it's much less apart from market but thats stuff matters.
00:28:11: so on
00:28:13: these areas where?
00:28:16: Now I do see a lot happening also in the SAP space.
00:28:20: As you said, it's becoming somehow attractive... It has always been important but now there is this special thing around that we've seen at the last couple or two years.
00:28:33: Hasn't always been an attractive target?
00:28:35: But criminals are just realising it and thats why the threat is amplified.
00:28:39: Exactly!
00:28:39: Right?!
00:28:40: I cannot agree more with you..I can not disagree.
00:28:43: i don´t know though.
00:28:45: completely.
00:28:46: So to maybe wind down a little bit, if you were advising a CISO that is responsible for... A part of his responsibility is protecting those SAP environments.
00:28:59: what would be at the top off your priority list?
00:29:03: Okay number one realize SAP is high risk at the moment.
00:29:07: right nobody gets fired.
00:29:08: Nobody loses their job If China weaponizes some sort of extreme zero-day exploit against you.
00:29:14: When you get into trouble, where do you find?
00:29:17: Where are you fired?
00:29:18: is if in various low-skill threat actors weaponizes something that should have patched a month ago.
00:29:25: So realize that SAP is being targeted and not protected by the sort of the grandness of your system.
00:29:33: That's number one.
00:29:34: Two Realize SAPs being targeted primarily with known exploits And context driven social engineering.
00:29:41: Now these two are threat types.
00:29:44: we're currently seeing that leads to attacks.
00:29:46: And both of them are extremely manageable, right?
00:29:48: Known exports you manage by patching rapidly quickly and efficiently against all of your systems.
00:29:55: obviously with that also need... You need to understand what your exposure is publicly in sort-of behind flywalls.
00:30:01: The second thing is context driven social engineering.
00:30:04: realize that threat actors are primarily hacking into your organizations via your employees.
00:30:10: They speak local language German, Dutch Italian Spanish English.
00:30:15: Right?
00:30:15: They speak that local language fluently and in some instances they also understand how humans and SAP interact.
00:30:21: so have training Have awareness do drills around these context-driven social engineering exploits with local language.
00:30:30: If you do those two things You're eighty percent of the way outside of that right.
00:30:36: better implementation And demand more from your supply chain.
00:30:40: Make your supply chain as secure and as you are.
00:30:44: And, You know, you're ninety-ninety five percent of the way.
00:30:47: I think
00:30:48: it hits against every single thing.
00:30:50: No If some state actor somewhere wants to drive Some high powered zero day exploit against you that's gonna happen.
00:30:57: i'm certain That at some point in The future club is going To come out with some sort Of zero day exploited against SAP but those Are not the type of threats?
00:31:04: You can preemptively work Against right.
00:31:06: focus on what you Can.
00:31:08: I mean, with those two specific priorities you just listed.
00:31:13: I think organizations who take that initiative are as you said on a maturity level... On the proactive maturity level than their peers.
00:31:22: there then industry peers or so one.
00:31:25: i'd like to leave it at that because i think There's A lot more That we can discuss With?
00:31:30: The topic with how Can also intelligence bring a lot of value, how can we bring security teams going into the different teams?
00:31:39: But I think i'm gonna take you up on another podcast later onto really dig deeper in to this.
00:31:45: So Manny thank you very much and Thank You for joining me.
00:31:48: any last words before our audience Before We shut This Down
00:31:52: No!
00:31:52: I appreciate your being here...I Think Your Doing A Lot Of Really Good For The SAP Sort Of Security Space.
00:31:58: Raising Awareness Is The First Thing We Have To Do.
00:32:00: so I Appreciate You Having Me Here And I'd Love To Talk To You Again.
00:32:03: I appreciate you having me here.
00:32:05: You're doing a lot of good simply by raising awareness and i'd love to come back another time and talk more with you!
00:32:10: Thankyou very much Manny, we will see you again.
00:32:13: other than that thankyou.
New comment