Onapsis Podcasts

1000 Reasons: Lessons Learned from a Decade of Business-Critical Application Security (Fireside chat with JP and Mariano)

Over a decade ago, Onapsis was founded in a small office in Buenos Aires, Argentina. Today, the organization has grown by leaps and bounds with a global presence and capabilities centered around protecting the critical systems of hundreds of the world’s leading brands including 20% of the Fortune 100. Join this fireside chat with two of the founders of Onapsis – Mariano Nunez, CEO, and JP Perez-Etchegoyen, CTO – to hear their take on the state of critical application security, thoughts on modern day SAP and Oracle attacks and threat actor groups, and a new way of thinking about ERP security to protect what matters most to your organization.

Onapsis Podcasts

ERP Digital Transformation: Big Trends and Bigger Security Challenges

As global organizations increasingly adopt cloud technology and undertake digital transformation initiatives, under-resourced teams often prioritize agility and speed over security. This webinar will explore the latest trends influencing ERP digital transformation and the broader challenges of securing these essential systems. Drawing on Onapsis’ decade-long experience in safeguarding top global brands, the session will delve into significant security challenges and threats associated with digital transformation, using insights and real-world examples to illustrate the discussion.

Onapsis Podcasts

Shift Left: Five Reasons Why You Should Extend DevSecOps to Your SAP Environment

What is DevSecOps? It is the integration of security best practices into the application development lifecycle. As digital transformation projects accelerate the creation of new code and applications, security often takes a backseat to business application output. With the average SAP system containing over 2 million lines of custom code, large global enterprises are increasingly concerned about the vulnerability of their critical applications. Join this webinar to understand why you should integrate your SAP application development into a comprehensive DevSecOps framework and learn best practices for getting started with SAP development.

Onapsis Podcasts

The ERP Black Box: Five Reasons Why Your Vulnerability Management Program Must Include Your ERP Landscape

Often seen as a “black box” for several reasons, SAP and Oracle application landscapes present significant challenges for modern security professionals, resulting in a layered security approach around critical systems. However, neglecting to include these ERP applications in your vulnerability management program makes your organization more vulnerable to security breaches and data loss. In this webinar, Onapsis will present five compelling reasons to demystify these systems and integrate SAP and Oracle applications into your overall vulnerability management strategy.

Onapsis Research Labs Briefing: The Latest Threats to SAP Applications July 2023

ON DEMAND

Join the Onapsis Research Labs for a look back at an extremely active year of threats so far in 2023. The tactics, techniques, and procedures of threat actors continue to evolve while the number of potentially exploitable vulnerabilities and applications seem to grow every month. Join the Onapsis Research Labs for both a look back at the first half of 2023 with its elevated threat activity and observed trends as well as a look forward to the second half to help your organization better prepare for the latest threats posing the largest risk to your organizations. 

The Onapsis Research Labs

It’s the world’s leading team of security experts who combine their deep knowledge of critical ERP applications and decades of threat research experience to deliver impactful security insights and threat intelligence focused on the business-critical applications from SAP, Oracle, and SaaS providers. Onapsis Research Labs is, far and away, the most prolific and most celebrated contributor of vulnerability research by the SAP Product Security Response Team. No other research team comes close.

Cyber Tech Talk Features: Eliminating SAP Security Blind Spots with NIST

ON DEMAND

Visibility into the application layer can be a blindspot for many organizations, particularly for security departments, even though a secure application layer is a critical component for building a protected environment. As a key component to both The NIST Cybersecurity Framework and SAP’s framework, the SAP Secure Operations Map, the application layer must be protected. Leveraging these frameworks and best practices can help security, SAP application, and SAP BASIS teams, build cross functional team engagement and strategies to eliminate these blind spots and work together effectively.

In this webinar we discuss a strong foundational strategy to protect SAP environments where they are most vulnerable–the application layer. 

You will walk away with an understanding of how to:

  • Leverage key elements of the NIST and SAP Secure Operations Map frameworks for a more effective security strategy
  • Incorporate application security best practices into creating a more secure, compliant, environment for your SAP applications. 
  • Think about the journey to a more secure environment, including mapping out milestones and points to consider at every phase
  • Address growing complexities of AI as part of the NIST framework

Watch The Defenders Digest

The Defenders Digest

Everything you need to know in the world of ERP security with The Defenders Digest.

Hear directly from Paul Laudanski & JP Perez-Etchegoyen of Onapsis Research Labs as they chat through monthly highlights and need-to-know information around SAP and Oracle security.

What can you expect once a month?

  • Original threat research, analysis and insights from the Onapsis Research Labs team

  • Industry news surrounding ERP application protection

  • Educational security and compliance content

Watch the latest episodes here

Take the Next Step in
Your ERP Security Journey

Reach out to a member of our team if you are interested in how to accelerate your SAP initiatives, securely.

Would you like The Defenders Digest delivered
to your inbox each month?

Onapsis Control Central

Extend DevSecOps to your SAP ABAP applications. A centralized policy engine enables streamlined deployment and management. Step-by-step remediation instructions and integrations with SAP ABAP developer tools accelerate time to issue identification and remediation. 

Organizations are implementing a greater focus on hardening their applications against attack, starting with the development process. A recent survey1 noted that 74% of security professionals have already “shifted left” (i.e., extended security earlier in development cycles) or plan to in the next three years. This shift is particularly important for business-critical applications such as those from SAP since they contain highly valuable corporate data. SAP applications are frequently at the core of large enterprise organizations, supporting the financial, HR, supply chain, sales, ERP, and customer processes needed to function as a global business. 

These applications are also at the core of digital transformation projects, such as the shift to SAP S/4HANA. Analyzing and migrating custom code and data from legacy systems is a headache for developers seeking to migrate code, applications, and systems to the cloud. And building security into the software development lifecycle for SAP custom applications remains a challenge as well. Manual reviews, which are highly prone to error, are often used due to a lack of automated testing solutions for SAP code languages and environments. 

The accelerated pace of these digital transformation projects also forces teams to attempt to balance speed and security…with security frequently tabled in order to meet abbreviated project timelines. Tight development cycles lead to the use (and re-use) of third-party code libraries and developers. However, with little visibility here as well, organizations are forced into even more manual reviews (if at all) to stop the introduction of new security issues. 

Onapsis Control Central addresses these challenges with comprehensive application security testing for SAP ABAP custom applications throughout development. With a centralized architecture for automated assessments, integrations with SAP development environments and change management, and step-by-step remediation instructions, Control Central helps teams rapidly identify and fix issues before they negatively impact production.

“Onapsis helps us gain deeper visibility into code and transport vulnerabilities so we can prioritize our mitigation efforts and reduce risk to our systems.”

– Director SAP Application Development, Fortune 100 Manufacturing Company

How Onapsis Control Central Works

Onapsis Control Central works by scanning systems and inspecting code directly within development environments. Control Central leverages extensive test cases based on best practices and in-depth security analysis and research of SAP applications from the Onapsis Research Labs. Millions of lines of code can be automatically scanned in minutes, and remediation guidance is provided to keep pace with accelerated development cycles.

Security And Compliance

Onapsis’ highest priority is the security of our software and the confidentiality, integrity, and availability of customer information as it flows through that software. We embed the strongest possible security measures into our software development life cycle (SDLC) and into the operating system, database, web security, and logging layers of our products. Onapsis contracts with accredited, third-party, auditing companies who have audited our SDLC process and we have the following certifications: ISO 9001, ISO 20243:2018, ISO 27001:2013,  SOC 1 Type 1/2, SOC 2 Type 1/2, and Veracode Verified Program. Our product design and development requirements follow the OWASP ASVA v4 framework or other industry standard guidelines.

Onapsis Professional Services
Achieve your business objectives at every stage of your journey. Onapsis’ comprehensive professional services offerings target:

Implementation: A paired delivery approach to accelerate time-to-value
Education: Knowledge for teams to successfully operate our platform
Optimization: Enable continuous improvement and alignment to business needs
Administration:
Alleviate resource constraints

Licensing

Onapsis Control Central is licensed as an annual subscription based on the number of target systems. Subscription includes access to all updates available for the respective software license, technical support, and a dedicated account manager. 

Expand and enhance your Control Central deployment with additional premium capabilities:

  • On Change Control: Licensed as an annual subscription based on the number of target systems, it provides a detailed security scanning and approval framework for change management that integrates with SAP CHaRM. It offers a single view of detailed security scans, approvals, and notes related to system changes in addition to enabling  automatic notifications to improve workflows.
  • Control for Transports: Licensed as an annual subscription based on the number of target systems, it provides the ability to check development objects, system settings, application configuration, and data within SAP transports for vulnerabilities. Step-by-step remediation instructions identify flawed transport requests and help prevent costly production errors as well as reduce the risk of system downtime.