Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

How to protect ERP data when access to corporate networks is both ubiquitous and for sale on the dark web

By Piyush Pandey
SEC0219-data-Feat-slide1_900px
July 13, 2020

With remote work expanding exponentially, malicious actors are targeting corporate networks more than ever. Remote users accessing corporate networks with (potentially compromised) mobile devices and on home wireless connections increase the potential for a variety of attacks. With a myriad of employees and contractors given ubiquitous access to business data, one thing is clear; identity has become the new security perimeter. Ensuring Enterprise Remote Planning (ERP) data security, privacy and compliance can no longer rely solely on network threat monitoring but requires using a layered identity defense to limit access to and within mission-critical applications. Why? Because malicious access to your network is no longer preventable, but inevitable. Ultimately, the strength of your identity and data security postures will determine your data’s integrity.  

  

Increased dark web sales of network access  

Cybercriminals have identified the expanded threat surface from remote access and responded with an increased interest in acquiring large amounts of personally identifiable information (PII.) Primarily through corporate ERP applications, as this is where the most HCM and financial data is typically stored. According to research by Positive Technologies discussing dark web information sales in 2019, the average price for privileged access to a single local network was approximately $5,000. Globally, malicious actors sold credentials across a variety of industries.   

In the US, the top three industries were:  

  • Service (20 percent)  
  • Industrial (18 percent)   
  • Government (14 percent)  

Meanwhile, in Italy, industrial and service companies topped the list. The United Kingdom’s most targeted industries were service, science, education and finance. Brazil saw attacker interest in government and healthcare.   

In short, no industry is safe. All organizations need to focus on securing their most vulnerable access points to prevent financial losses associated with data breaches.   

   

Start with securing your crown jewel ERP systems  

Organizations looking to accelerate their data security maturity can choose to lock down access across their ERP systems for a “quick win.” According to the 2020 Verizon Data Breach Investigations Report, 67 percent of 2019 data breaches arose from credential theft, social engineering attacks, or errors that enabled malicious actors to gain unauthorized access to sensitive data.   

Many organizations apply role-based access controls (RBAC) that align data access privileges to resources based on job functions. However, in a cloud-based ecosystem, RBAC’s static nature creates a productivity barrier. Cloud resources require a more dynamic approach to access that incorporates additional user attributes such as geolocation, device, IP address, or time of day.   

Attribute-based access controls (ABAC) enable organizations to purposefully limit access according to the principle of least privilege. For example, if the organization knows that an employee should be working from Connecticut, ABAC can prevent access to resources, mask highly sensitive data, or prevent a transaction entirely if the user’s location is suddenly California – or a foreign country.  

These granular, data-centric access privileges can help an organization prevent malicious access to important ERP data, proactively mitigating data security, privacy and compliance risks.   

  

Continuously monitor privileged user activity and behavior  

With ABAC, organizations can set fine-grained access controls that mitigate risks. However, cybercriminals stealing privileged credentials may enter the organization’s IT ecosystem then move around within it unnoticed.    

Privileged users, such as system administrators, need superuser access to do their jobs. While ABAC provides some level of control that can limit the data they access, their job functions require them to add users, delete payees and engage in other potentially risky activities across the ERP ecosystem.   

Thus, privileged credentials are highly sought after on the dark web. Once attackers obtain these privileged credentials, they can move within the organization’s cloud infrastructure nearly unfettered. While ABAC provides a baseline for limiting access, organizations need to layer their defenses at the identity perimeter the same way they created layered defenses at the infrastructure perimeter.   

Continuously monitoring activity and behavior provides valuable visibility into how users engage with data and what they do with their access. For example, organizations may be able to apply time-based ABAC for standard users, since the general human resources employee likely works during daytime hours. However, privileged users may need 24-hour access to respond to outages or other IT events.   

Continuously monitoring their access and behavior provides the additional needed layer of defense at the identity perimeter. By monitoring the privileged user’s activities, the organization can “watch the watchers” and gain visibility into potential credential theft. If the account engages in unusual access, the organization can review whether that access was necessary and document the findings. By tracking the activity back to the user, the organization proves governance and proactively protects data.   

   

Creating layered defense at the identity perimeter to strengthen data security   

With organizations seeking to proactively secure data as part of the move to a distributed workforce, they should draw their first line of defense at the identity perimeter. By establishing dynamic, attribute-based controls, companies can more precisely define access to ERP resources. However, limiting access itself may cause productivity issues, especially when users need to contact IT departments to request additional access.   

Data masking or hiding sensitive information not necessary to the job function creates an additional security layer. Users not only are limited in their access but by masking the data, the access granted eliminates excess access risks associated with visibility of unnecessary, sensitive data. An organization’s payroll manager may not need to see employees’ account information to process the payments. Thus, limiting access and masking data create a double layer of defense.   

Finally, by continuously monitoring user activity and behavior, organizations add a third defensive layer. They limit access on a fine-grained level, mask unnecessary sensitive data and ensure that they investigate irregular activity within their ecosystem.   

By creating a three-layered identity defense, organizations can proactively mitigate many of the risks associated with the increased malicious actor interest in corporate networks. 

KEYWORDS: cyber security Dark Web data breach data security Monitoring Solutions

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Piyush pandey
Piyush Pandey, CEO at Appsian (www.appsian.com) is a technology executive with 18 years of global experience in strategy, sales, mergers & acquisitions, and operations within software companies. Over the last 10 years, he has worked with enterprise software companies including Oracle, Epicor, Concur, Citrix and Microsoft on various transactions. He has held various leadership positions at Procera, Deutsche Bank, Stifel, Wipro Technologies and a wireless startup.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • dark web cyber

    A look into the pricing of stolen identities for sale on dark web

    See More
  • password

    Zoom Database of Credentials up for Sale on Dark Web Forums, Says Report

    See More
  • password

    21 Million Logins for Top 500 Firms Found on the Dark Web

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

  • The Complete Guide to Physical Security

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing