Back to blog

Why Identity and Segregation of Duties Are the New Perimeter 

Organizations are implementing new SaaS ERP systems to modernize their enterprise.  Traditional cybersecurity risks are being outsourced to the software provider, yet certain cybersecurity risks still need to be addressed by management.

Managing identity has become one of the most critical elements of enterprise security in today’s complex digital environment. As businesses adopt more SaaS ERP systems, identity and access controls are no longer merely a compliance checkbox; they are also the new security perimeter. Management’s challenge lies in ensuring that the right people have access to the right systems and activities within those systems and that identities are properly secured.

Protecting the modern enterprise includes:

  1. Addressing cybersecurity risks
  2. Ensuring least privilege access
  3. Addressing Segregation of Duties (SoD) conflicts into account.

The Criticality of Least Privilege Access and Segregation of Duties

Traditionally, auditors focus on Segregation of Duties by separating conflicting duties in financially significant activities. For example, ensuring one person cannot create and approve payments. What began as a compliance demand following Sarbanes–Oxley, has now also become a security consideration due to the complexity of today’s systems. However, most compliance programs only look at SoD and do not fully consider the concept of least privilege access or what we refer to as Sensitive Access risks.

When new SaaS ERP systems are implemented, management needs to address:

  1. Cybersecurity threats not addressed by the software provider.
  2. Compliance requirements; Sarbanes-Oxley (and variations throughout the world).
  3. Data Privacy regulations such as GDPR and CCPA.

CISOs and CIOs often assume all cybersecurity risks are covered by the software provider.  However, certain risks at the application tier are management’s responsibility including:

  1. Users/identities including those that aren’t subject to MFA
  2. Configuration of roles
  3. External resources having access to the environment
  4. Integration accounts
  5. Addressing these risks as patches and releases are applied by the software provider

Following are role design / access control risks that management commonly overlook:

  1. Excessive access to the system integrator during Hypercare
  2. Excessive access to managed service providers
  3. Quarterly or semi-annual patches that update seeded roles or partially customized roles that may not be appropriate for all users assigned that role
  4. Access to PII and PHI data including extracting data in bulk through reporting layers and APIs
  5. Users with unauthorized access to administrative privileges
  6. Lack of maturity related to shared configurations / IT configurations
  7. Excessive access to configurations that should be subject to change control
  8. End user roles containing APIs and web services

All these risks underpin the criticality of implementing only fully customized roles as we address in this article.

The Perpetual Patch Cycle means the risks keep coming…

Moving from an on-prem system where management gets to choose when to do upgrades to SaaS ERP systems is a significant paradigm shift we address in this article.  With on-prem systems management can put off upgrades for years.  SaaS ERP systems typically apply upgrades either 2x or 4x a year.  While management benefits from the new features being introduced they don’t always consider that new features and changes to existing features need to be identified and managed. With each patch / release new features are added into seeded or partially customized roles.

Why Access Control software is critical in the modern era

When system implementers develop their scope, most projects are bid and won assuming the use of (mostly) seeded (vendor provided) roles.  Only the astute and experienced management team understand that seeded roles are built for ease of implementation but not fit for long-term use.  Seeded roles are oversimplified and generally have too much access.   Some seeded roles have inherent Segregation of Duties.  Because most projects don’t properly customize roles, the perpetual patch cycle means risks are consistently introduced.

This means management needs a mature security program to identify these changes.  This includes having a managed service partner like ERP Risk Advisors to or a Access Control software that can be used with each patch / release.

Executive Buy-In is Crucial for Effective Identity Governance

Strong identity governance ensures least privilege, and SoD controls doesn’t just happen. Strong identity governance requires resources and commitment from leadership. When executives understand the value of these controls, they are more likely to provide the necessary budget and support for building a secure environment. Securing executive support helps ensure your identity governance efforts are properly resourced and aligned with broader business objectives.

How to move from Crawl to Walk to Run

To get started, you need visibility into your existing identity and access controls landscape.

In our experience most ERP software organizations provide over-provisioned seeded roles, and most System Integrators do not know how to refine and reduce risk in those roles. Without a mature risk advisory and cybersecurity partner, it is unlikely that the implementation was done in a secure and compliant manner.

ERP Risk Advisors is uniquely qualified to address cybersecurity risks, help implement automated controls, address SoD risks, build roles based on the principle of least privilege, , enhance access reviews, and effectively manage movers, joiners, and leavers. Contact us here to set up a meeting with us so we can help your organization’s security and controls program move from a Crawl to a Walk to a Run.


Additional Resources:

  1. 3 Billion Reasons To Do More Than Just Securing The Perimeter (erpra.net)
  2. Auditors Are Talking About SoD Too Much!