NetSuite Change Control: The False Sense of Security
When it comes to auditing NetSuite, many organizations assume their change control processes are solid. The tickets...
Phishing and Credential Theft: The Fastest Path to ERP Breach
Phishing and Credential Theft is becoming more and more convincing, which is why credential theft remains a top way intrusions start. Verizon’s 2024 DBIR found the human element (things like phishing, misuse, and error) in 68% of breaches, and IBM’s 2024 Cost of a Data Breach report shows phishing as a leading initial vector (≈15%) and among the costliest to remediate. In practical terms: once an attacker has a password, they move quickly—often in minutes—to turn that beachhead into access you didn’t intend.
MFA breaks the “stolen-password → instant access” chain, slowing or halting account takeovers and helps preserve audit integrity and accountability (who did what). This is directly aligned with SOX authentication control objectives and NIST 800-53 IA-2 requirements for multi-factor authentication for privileged (and, ideally, all) accounts.
Zero Trust assumes no implicit trust—every user trying to access the environment is verified, every time. MFA is a core enforcement point in NIST’s Zero Trust model: verify explicitly, use strong authentication, reduce lateral movement.
Reducing lateral movement starts with designing roles around the principle of least privilege, granting users only the access required for their job and nothing more—minimizing the damage a malicious actor could cause if they gain entry. Even with MFA in place, you should still plan to limit the blast radius if an account is compromised. This means tightening access to high-risk permissions, eliminating inter-role and intra-role SoD conflicts unless effective mitigating controls are in place, enforcing reasonable session timeouts, and setting up alerts for high-signal events such as changes to bank details, vendor master records, payroll data, or application workflows. By constraining access and closely monitoring sensitive activities, you reduce the attacker’s potential payoff, even if they make it past the first line of defense. ERP Armor: Assessments can help ensure your access controls are top-tier, so your ERP environment is locked down against both internal and external threats.
What To Do When You Find Accounts / Roles Without MFA
Today’s phishing is fast and relentless; credential theft is still a prime breach trigger, and MFA is the most immediate, high-impact control to stop it. Universal MFA closes one of the most common path to ERP takeover, fraud, and data theft.
When it comes to auditing NetSuite, many organizations assume their change control processes are solid. The tickets...
New research suggests that the age of stem cell donors matters for therapies where donors and recipients are different people. That would seem to make sense given the...