Protecting SAP Assets Against State-Sponsored Malware Threats

In response to heightened global cyber activity, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a joint statement urging organizations to strengthen their defensive posture. With the risk of destructive, state-sponsored malware spreading to business networks, organizations must prioritize the protection of mission-critical assets, particularly SAP environments, against advanced persistent threats.

Why is the current cyber threat level high?

Recent geopolitical events have increased the risk that destructive malware—such as the WhisperGate and HermeticWiper strains—could target government and business networks. These destructive tools are designed to permanently corrupt data and render systems unbootable by masquerading as ransomware. To counter these threats, CISA and the FBI recommend a proactive security approach:

  • Secure remote access: Ensure all remote entry points are hardened.
  • Patch vulnerabilities: Maintain rigorous patch management for all software.
  • Limit attack surface: Disable unnecessary ports and services.
  • Enhance monitoring: Improve detection and response capabilities for potential intrusions.

How can Layer Seven Security help protect SAP environments?

To support organizations in securing their critical SAP infrastructure during this period of elevated risk, Layer Seven Security is providing the Cybersecurity Extension for SAP free of charge for up to three months.

This SAP-certified add-on for SAP Solution Manager provides comprehensive protection by implementing advanced vulnerability management across the entire SAP stack, including applications, databases, and host layers. Key capabilities include:

  • Vulnerability Management: Identifies flaws in custom ABAP code and system configurations.
  • Advanced Detection: Monitors event logs for over 600 indicators of compromise.
  • Anomaly Detection: Uses SAP HANA-powered analytics to identify unusual system and user behavior.
  • Lifecycle Integration: Connects with System Recommendations to manage security note implementation.

How to secure your SAP landscape

Organizations should immediately evaluate their current SAP security posture and consider the following defensive measures:

Defensive LayerSecurity Action
Application LayerPatch custom ABAP code and monitor for suspicious behavior.
Database LayerHarden Oracle and other database configurations.
InfrastructureSecure gateways like SAProuter and Web Dispatcher.
Host LayerMonitor and manage vulnerabilities at the operating system level.

Frequently Asked Questions

What are WhisperGate and HermeticWiper?

WhisperGate and HermeticWiper are destructive malware strains that masquerade as ransomware. Unlike traditional ransomware, they have no data-recovery capabilities and are designed to permanently corrupt data and make infected hosts unbootable.

What does the Cybersecurity Extension for SAP (CES) monitor?

CES monitors the entire SAP stack, including application gateways (SAProuter, Web Dispatcher), databases, and host operating systems. It detects over 600 indicators of compromise and uses anomaly detection to identify unusual user or system activity.

How can I access the free license for the Cybersecurity Extension for SAP?

Organizations can CONTACT Layer Seven Security directly via email to discuss licensing the Cybersecurity Extension for SAP free of charge for up to three months to help secure their mission-critical SAP applications.

Share the Post: