• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
  • X
  • Facebook
  • YouTube
  • LinkedIn
Support
Screen Connect
Pay Online
SWK logo.

SWK Technologies

Software Solutions & Services

  • Accounting & ERP Software
      • Acumatica Cloud ERP
        • Overview
        • Construction
        • Distribution
        • Field Service
        • Financial Management
        • Manufacturing
        • Professional Services
        • Project Accounting
        • Retail-Commerce
      • Sage Intacct
        • Overview
        • Construction and Real Estate (CRE)
        • Distribution Operations for Sage Intacct
        • Financial Services
        • Healthcare
        • Manufacturing Operations for Sage Intacct
        • Nonprofits
        • Professional Services
        • Sage Intacct Payroll powered by ADP
      • Sage 100
        • Overview
        • Business Intelligence
        • Core Accounting & Financials
        • Distribution
        • Manufacturing
        • Payroll
        • Sage 100 Contractor
      • More Accounting Products
        • QuickBooks
        • Sage 50
        • Sage 300
        • Sage 500
        • Sage BusinessWorks
      • ERP Add-ons
        • ADP Workforce Now
        • Altec
        • Avalara
        • AvidXchange
        • BigCommerce
        • CIMCloud
        • Cloud Hosting
        • DataSelf
        • Fortis
        • FreightPOP
        • Microsoft 365
        • Netstock
        • Ottimate
        • Sage Fixed Assets
        • Sage HRMS
        • Sage Intacct Payroll powered by ADP
        • Savant WMS
        • Scanco
        • ScanForce
        • Solver
        • SPS Commerce
        • Velixo
        • Workforce Go!
      • More ERP Add-ons
        • Bizinsight
        • Concur
        • Crystal Reports
        • Fraxion
        • Fusion RMS
        • FYISoft
        • JobOps
        • KnowledgeSync
        • Lockstep Collect
        • Nectari
        • Pacejet
        • Planning Maestro
        • Sage CRM
        • Sage Intelligence
        • Scissortail HCM
        • Service Pro
        • ShipStation
        • Shopify
        • Starship
        • Sugar CRM
        • Time & Billing Pro
        • Timekeeper
        • True Sky
      • Industries
        • Construction
        • Distribution
        • Financial Services
        • Healthcare
        • Manufacturing
        • Nonprofit
        • Professional Services
        • Retail
  • Managed Cloud Services
      • Managed Services
        • IT Support
        • Cloud Hosting
        • Infrastructure-as-a-Service
        • Managed Cloud Services
        • vCIO
        • Acumatica Infrastructure
      • IT Solutions
        • Backup & Continuity
        • Cybersecurity
        • Email Hosting
        • Microsoft 365 Services
        • Virtualization
  • Consulting & Implementation
    • Business Technology Consulting
    • eCommerce
    • Financing
    • Human Capital Management
    • Managed Cloud & IT Services
    • Partner Program
    • Software Development
    • Software Implementation
  • Resources
    • Help Desk
    • Blog Posts
    • Payments Portal
    • Webinars
    • YouTube Channels
    • Acumatica Resources
    • Sage Intacct Resources
    • Sage 100 Resources
    • IT Resource Pages
  • About
    • About SWK
    • Awards & Recognition
    • Life@SWK
    • Careers
    • Success Stories
    • SWK Gives
  • Contact
    • Contact Us
    • Support
    • Our Locations

DHS Warns of ERP Vulnerabilities

August 29, 2018 by Hector

Home » Blog » DHS Warns of ERP Vulnerabilities

This July, the Department of Homeland Security’s National Cybersecurity and Communications Integration Center (NCCIC) issued an alert that hackers would be increasing focus on Enterprise Resource Planning (ERP) systems. This warning is based on a report released by cybersecurity firms Digital Shadows and Onapsis which detailed research into the rate of attacks and communications of planned future attacks against ERP applications. The report also included evidence that “hacktivist” groups and nation-state cyber attackers were likely involved in these past breach attempts and would continue to pursue ERP systems as viable targets.

ERP software solutions that are not up-to-date or misconfigured are most vulnerable and are being targeted. Legacy ERP systems present several risks to organizations who continue to rely on them, including network security gaps resulting from outdated and unpatched software. Even legacy ERP systems that have been upgraded to integrate with new technology solutions can be exposed to threats. In fact, the report indicates that many outdated software solutions that have been improperly configured for cloud connectivity pose an even greater danger.

Here are the key points from the DHS’ warning to consider if you employ a legacy ERP system:

Legacy ERP Systems

The latest warning from the NCCIC included a reference to a prior warning the DHS had released concerning existing an existing vulnerability in SAP legacy ERP systems in 2016. Though this particular gap had already been patched in 2010, a previous report by Onapsis had found that it was still leaving areas of these legacy ERP systems exposed. The exposure would allow an attacker to remotely access this and all connected systems, giving complete control of the data and processes managed by the software.

The complexity and critical importance of ERP software unfortunately means that changes to the system can lead to operational disruptions depending on how it is implemented and deployed. Some administrators will choose to segment or delay updates to prevent downtime and process shutdown. Aging legacy ERP systems will already be falling behind on crucial patches, so this additional suspension of updates put ERP security at great risk. As the DHS warning demonstrates, these gaps may exist for years without providing any indication of their existence and delaying security software patches will only extend the danger.

Connectivity

Modern ERP systems are increasingly brought into the cloud by publishers to take advantage of the inherent benefits this technology provides. Cloud ERP software provides additional options for application and improvements in communication and data exchange. However, the permeability of cloud software which enables instant interaction also brings potential concerns for ERP security. Although cloud ERP systems still bring the same pitfalls as other networked technology, employing modern security solutions and not relying on traditional measures will ensure that you will not face the same dangers as you would with a legacy ERP system.

Proper ERP security measures will help safeguard cloud solution touchpoints that can be exploited by hackers but require effective best practices. This includes securing all Internet-facing devices that interact with the systems, such as personal desktops and mobile platforms. Smartphones and tablets provide an exploitable attack vector for hackers if they gain access to the device through a malware infection or physical interaction.

However, modern cloud ERP systems also provide the opportunity to remain constantly up-to-date with the latest security software. As long as connection to the hosted network is maintained, security patches will be downloaded as soon as they are released and installed at your discretion. Combined with this and proactive managed network services as well as enforced cybersecurity best practices, modern cloud ERP systems deliver a safer experience than traditional legacy ERP systems that are improperly for Internet-facing functionality.

Data

The primary concern in any network breach is how much data will attackers gain access to afterwards. ERP systems are designed to process, store, and manage critical operational data for an entire organization and a breach of an enterprise-level software solution will put all of this information at risk. Any hacker that finds a way past the external security settings of an ERP system has free reign to records and functions managed by the software.

There is an additional danger emerging for modern businesses within the finance and professional services industries, and which will likely affect virtually every organization with a digital presence in the future. Existing data protection regulations have been strengthened in response to repeated network breaches in recent years that place greater emphasis on safeguarding personal information and impose strict penalties on not doing so. The most comprehensive of these is the European Union’s General Data Protection Regulation (GDPR), yet there are emerging federal and state-level regulatory initiatives as well as trade organization best practices guidelines that are reflective of the GDPR’s requirements.

Should I Upgrade My Legacy ERP System?

Cyber Attackers

The reason this latest threat to ERP software is being taken so seriously is the level of sophistication of the potential cyber attackers involved. Businesses using outdated legacy ERP systems will have to contend with both a larger volume of inexperienced cybercriminals utilizing resources traded on the Dark Web and other illicit forums, and veteran hackers seeking an easier target to exploit. Unsecured legacy ERP systems provide external operators with the ability to siphon data that would otherwise take greater effort to access.

Hacktivist collectives and nation-state cyber attackers also pose a danger as ERP systems provide the key to disrupting organizations and industries they are opposed to. Government-backed hackers have previously used private firms as vectors for stealing data from federal employees and experts predict that commercial businesses will increasingly become legitimate targets in escalating cyberwarfare campaigns. Manufacturers are particularly vulnerable targets as they have been found lacking in cybersecurity best practices and offer cyber attackers employed by foreign powers multiple opportunities to pursue their objectives.

ERP Security Requires Staying Up-to-Date on Your Software

Misconfigured or outdated legacy ERP systems create a serious gap in your network security. Legacy ERP software is not designed to face problems that are emerging in the present and the future, and thus will generate loopholes that will be exploited by determined attackers. To protect your critical data – including personal client information – you must upgrade to a modern ERP system.

Read more here to determine if now is the right time to upgrade your legacy ERP system.

Want to know more?


Category: Blog, Cybersecurity, IT ServicesTag: Cloud ERP, cybersecurity, ERP

Sidebar

Recent Posts

  • How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth
  • Why Financial Services Firms Need Phishing Defense
  • Acumatica General Ledger Training – Key Tips & Tricks
  • Sage Intacct vs. Sage 500: Best ERP for CFOs and Financial Leaders
  • What is the Relationship Between Cybersecurity and Cyber Insurance? 
  • Guide for Sage Intacct Credit Card Management
  • Minimize Tariff Impacts on Your Technology Costs in the Cloud

Categories

Ready to take the next step?

Contact SWK today to get in touch with one of our experts. We’ll go over your business challenges and unique needs, and see where you can unlock new value from your technology and make your operations run easier.

Get in touch!

Our Latest Posts

Recreational Play Structure

How a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth

Read moreHow a Recreational Play Structure Builder Laid the Groundwork for Their Lasting Growth
Hands holding an open silver padlock over a laptop keyboard, symbolizing cybersecurity vulnerabilities that phishing attacks exploit in financial services firms

Why Financial Services Firms Need Phishing Defense

Read moreWhy Financial Services Firms Need Phishing Defense
Black laptop displaying Acumatica General Ledger journal transactions screen on a desk with coffee mug and notepad, showcasing the financial management interface on a computer in an office setting.

Acumatica General Ledger Training – Key Tips & Tricks

Read moreAcumatica General Ledger Training – Key Tips & Tricks

Awards and Accreditations

Top work places in NJ 2020.
Acumatica the Cloud ERP gold certified partner.
The Gold Microsoft partner logo on a black background.
Sage business partner diamond logo.
Dell Technologies Gold Partner
Sage tech partner logo.

Stay in the know!

Subscribe for exclusive ERP, process automation, IT and cybersecurity news.

Twitter
  • Facebook
  • YouTube
  • LinkedIn

Home
About
Contact

Support
Screen Connect
Pay Online
Downloads

SWK logo.

Headquarters:
120 Eagle Rock Ave, Suite 330
East Hanover, NJ 07936

Contact:
info@swktech.com
(877) 979-5462

Copyright © 2025 · SWK Technologies, Inc. · All Rights Reserved · Terms of Use · Privacy Policy

This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. By continuing to browse this site you agree to the use of cookies. Visit our privacy policy to learn more.I understand