The global and independent platform for the SAP community.

Not giving cybercrime a chance even in the crisis

Companies suddenly in remote mode and the defense line on short time: Is this the land of milk and honey for cyber criminals? In fact, the Federal Criminal Police Office (BKA) is recording a high increase in cyber attacks.
Christian Garske, Lufthansa Industry Solutions
December 10, 2020
It Security
avatar
This text has been automatically translated from German to English.

In its special evaluation of cybercrime in the Corona crisis, the BKA found a significant increase in phishing campaigns and attacks on remote connections. Even without the pandemic, IT security experts could not complain about a lack of work. According to the BKA's Federal Situation Report 2019, the number of offenses known to the police has reached a new high.

Ransomware in particular, i.e. extortion software, can pose an existential threat to companies or institutions, because almost every company is now dependent on IT. IT security is therefore indispensable for the success of a company. If companies reduce their IT capacities at this point due to the crisis, it quickly becomes very dangerous. The already strong trend of increasing cyber attacks on companies - both in terms of the frequency, intensity and quality of the attacks - will be further intensified by the crisis.

Do not show weakness

Many companies have already taken steps to better protect their IT in recent years. However, most German companies are still not at the level they should be. These deficits become even more noticeable during the crisis, when companies also have to take completely new approaches in the short term.

One example of this is the home office. What was previously unthinkable in many industries is now often the only option for maintaining production. To ensure that this does not become a risk factor, companies need consistent monitoring of the technologies used for this purpose, processes that are closely interlinked with the IT security organization, and also appropriate sensitization of employees.

What should companies do now to counter the growing threat? Above all, it is important that they adapt quickly and professionally to the new framework conditions, because attackers exploit every available weakness. Particularly now, the knowledge of IT security and digitization experts who know the current standards and best practices should be called upon. If these are not available internally, then external help should be used.

The technical aspects of cyber attacks are diverse and overwhelmingly complex. That's why digital protection cannot be limited to the selection and configuration of technologies and services alone. It is about much more than tools and gadgets. What is needed is a rethinking of the entire corporate culture across all departmental boundaries. Because digital attacks can be carried out on virtually every area of a company, IT security must be guaranteed throughout the company.

Making the job of attackers difficult

If an information security management system has already been established, it must be reviewed and adjusted. If this is not the case, we recommend implementing a prioritized bottom-up approach to improve IT security in the short term. The focus here is on those applications and IT systems that process particularly sensitive information or are critical for maintaining production. The old principle applies: "Protect first and best what is most important."

In addition, offensive checks - so-called penetration tests - are also useful to identify possible weaknesses. The more robust the system becomes, the more difficult it is for the attacker and the more time the defense gains to render him harmless. The right data backup concept also helps against data loss. A regular data backup is one of the mandatory tasks. This is the only way to protect data from loss and damage.

avatar
Christian Garske, Lufthansa Industry Solutions

Christian Garske is Associate Director for Security and Privacy Consulting at Lufthansa Industry Solutions.


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the second time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

More information will follow shortly.

Event date

Wednesday, May 21, and
Thursday, May 22, 2025

Early Bird Ticket

Available until Friday, January 24, 2025
EUR 390 excl. VAT

Regular ticket

EUR 590 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, March 5, and
Thursday, March 6, 2025

Tickets

Regular ticket
EUR 590 excl. VAT
Early Bird Ticket

Available until December 20, 2024

EUR 390 excl. VAT
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2025, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.