Larry Harrington: How ERP Security Enables Audit and Compliance
September 16, 2019
As the former Chair of the Institute of Internal Auditors and Former Chief Audit Executive for Raytheon Company, Larry Harrington discusses how ERP security enables the audit and compliance process within organizations, aligning CISOs with the internal audit team and maintaining compliance 24/7. “Today, ERP systems are so complicated… it’s really important to look at security from a different perspective,” Harrington explains. “How do we do a continuous auditing process so we make sure that all the crown jewels are protected 365 days a year.” Check out the rest of the video below!
About the Author
As CEO and Co-Founder of Onapsis, Mariano drives the strategic direction of the company. Under his leadership, Onapsis has become one of the fastest-growing technology and cybersecurity companies in the world. With 20+ years of experience in the cybersecurity industry, both as an executive and as a cyber security expert, Mariano was the first to publicly present on cybersecurity risks affecting ERP platforms and how to mitigate them at major conferences such as RSA, Black Hat and SANS. Mariano’s contributions to the cybersecurity community include developing the first open-source SAP and ERP Penetration Testing frameworks, and uncovering critical zero-day vulnerabilities in SAP, Oracle, IBM, and Microsoft applications. Mariano’s insights are regularly featured in major media outlets such as CNN, Reuters, Wall Street Journal, Nasdaq, Fortune and The New York Times.
More about this author
Further Reading
Holiday Security for Your SAP Systems: Protecting Critical Applications During the Winter Break
As the year winds down, most organizations are focused on closing the books and enjoying the winter break. However, this period of reduced staffing and “code freezes” often creates a dangerous blind spot for SAP security during Winter. While your team is stepping away, threat actors are gearing up to exploit the “holiday lull,” a…
The Year of the Zero-Day: Top SAP Vulnerabilities of 2025
In 2025, the SAP threat landscape shifted permanently. The year was defined by three critical realities: the massive NetWeaver Zero-Day (CVE-2025-31324), a surge in perfect-score deserialization flaws, and a shrinking window of defense where attackers weaponized exploits within hours of disclosure. For security teams, the takeaway from 2025 is clear: traditional patching windows are no…
What Is SAP Security? A Definitive Guide for 2025
SAP security is the comprehensive practice of protecting SAP applications, data, and the business processes they support from unauthorized access and cyber threats. Because SAP systems house an organization’s most business-critical information, including financial, customer, and HR data, ensuring that they’re properly secured is of the utmost importance. A strong SAP application security strategy is…
