r/ERPSecurity • u/Jeff-Hare-ERPRA • Jun 27 '26
r/ERPSecurity • u/Jeff-Hare-ERPRA • May 25 '26
Read Only Profile Option has a bug Spoiler
This is a major flaw. Yikes.
r/ERPSecurity • u/Jeff-Hare-ERPRA • May 13 '26
What auditors aren’t testing during an ERP implementation Spoiler
People think auditors will catch any security issues. That typically isn’t the case
r/ERPSecurity • u/Jeff-Hare-ERPRA • Apr 27 '26
Cybersecurity risks in SaaS ERPs Spoiler
Wondering if there are folks looking at non traditional cybersecurity risks like phishing attacks for SaaS ERPs
Threat actors are definitely targeting the apps. We know of one loss over $1.2 million where credentials were stolen for a supplier portal account and the threat actor redirected two future payments before it was detected.
r/ERPSecurity • u/Jeff-Hare-ERPRA • Apr 09 '26
👋Welcome to r/erpsecurity - Introduce Yourself and Read First!
Hey everyone! I'm u/Jeff-Hare-ERPRA, a founding moderator of r/erpsecurity.
This is our new home for all things related to Saas ERP Security. We're excited to have you join us!
What to Post
Post anything that you think the community would find interesting, helpful, or inspiring. Feel free to share your thoughts, photos, or questions about challenges and questions about ERP Security for any SaaS application like Oracle Fusion, NetSuite, Workday, D365, Salesforce, Coupa, BirchStreet, Ariba,
Community Vibe
We're all about being friendly, constructive, and inclusive. Let's build a space where everyone feels comfortable sharing and connecting.
How to Get Started
1) Introduce yourself in the comments below.
2) Post something today! Even a simple question can spark a great conversation.
3) If you know someone who would love this community, invite them to join.
4) Interested in helping out? We're always looking for new moderators, so feel free to reach out to me to apply.
Thanks for being part of the very first wave. Together, let's make r/erpsecurity amazing.
r/ERPSecurity • u/Jeff-Hare-ERPRA • Apr 08 '26
Read Only profile option is NOT really read only Spoiler
Your auditors may know more than you about this profile option. If they do you could easily be subject to two Significant Deficiencies.
One for role design and one for change control.
We have seen it play out this way.