Larry Harrington: How ERP Security Enables Audit and Compliance
About the Author
As CEO and Co-Founder of Onapsis, Mariano drives the strategic direction of the company. Under his leadership, Onapsis has become one of the fastest-growing technology and cybersecurity companies in the world. With 20+ years of experience in the cybersecurity industry, both as an executive and as a cyber security expert, Mariano was the first to publicly present on cybersecurity risks affecting ERP platforms and how to mitigate them at major conferences such as RSA, Black Hat and SANS. Mariano’s contributions to the cybersecurity community include developing the first open-source SAP and ERP Penetration Testing frameworks, and uncovering critical zero-day vulnerabilities in SAP, Oracle, IBM, and Microsoft applications. Mariano’s insights are regularly featured in major media outlets such as CNN, Reuters, Wall Street Journal, Nasdaq, Fortune and The New York Times.
View Author Profile
As the former Chair of the Institute of Internal Auditors and Former Chief Audit Executive for Raytheon Company, Larry Harrington discusses how ERP security enables the audit and compliance process within organizations, aligning CISOs with the internal audit team and maintaining compliance 24/7. “Today, ERP systems are so complicated… it’s really important to look at security from a different perspective,” Harrington explains. “How do we do a continuous auditing process so we make sure that all the crown jewels are protected 365 days a year.” Check out the rest of the video below!
About the Author
As CEO and Co-Founder of Onapsis, Mariano drives the strategic direction of the company. Under his leadership, Onapsis has become one of the fastest-growing technology and cybersecurity companies in the world. With 20+ years of experience in the cybersecurity industry, both as an executive and as a cyber security expert, Mariano was the first to publicly present on cybersecurity risks affecting ERP platforms and how to mitigate them at major conferences such as RSA, Black Hat and SANS. Mariano’s contributions to the cybersecurity community include developing the first open-source SAP and ERP Penetration Testing frameworks, and uncovering critical zero-day vulnerabilities in SAP, Oracle, IBM, and Microsoft applications. Mariano’s insights are regularly featured in major media outlets such as CNN, Reuters, Wall Street Journal, Nasdaq, Fortune and The New York Times.
View Author Profile
Further Reading
SAP Security Notes: August 2026 Patch Day
Critical vulnerabilities in SAP Commerce Cloud, Application Server ABAP for SAP NetWeaver/ABAP Platform and SAP MII. Find out more details in this blog.
The Impact of the NIS2 Directive on Enterprise SAP Landscapes
What is the NIS2 Directive and Why Does It Matter for Enterprise ERP Systems? Directive (EU) 2022/2555 (NIS2) legally mandates essential and important entities across 18 critical sectors to implement continuous cybersecurity risk management sub-measures, strict incident reporting timelines, and direct executive accountability. Business-critical ERP systems running financial, manufacturing, and supply chain operations fall directly…
Protecting the Front Door: Why SAP Web Dispatcher Security is Non-Negotiable
In the modern SAP landscape, the days of “internal-only” access are long gone. As more organizations adopt S/4HANA and embrace mobile-first strategies with SAP Fiori, the perimeter of the SAP environment has shifted. At the center of this shift is the SAP Web Dispatcher. Just as we’ve previously discussed the security risks surrounding SAProuter, the…
