AI-powered softwareArtificial Intelligence

Onapsis Study Finds AI-Driven Attacks Are Reaching ERP Systems Faster Than Security Teams Can Respond

New research reveals growing confidence gap as organizations accelerate AI adoption across business-critical ERP environments.

As artificial intelligence becomes increasingly embedded in enterprise applications, cybersecurity leaders are facing a new challenge: ensuring AI accelerates business value without introducing new risks to the systems that run finance, supply chains, manufacturing, and operations.

New research from Onapsis, a specialist in SAP cybersecurity and compliance, suggests that organizations are adopting AI across their ERP environments at a pace that is outstripping confidence in their ability to secure it. The company’s inaugural State of AI, Security and ERP report highlights a widening gap between AI adoption and enterprise preparedness, with many security leaders questioning whether existing defenses are ready for AI-powered threats.

The findings point to an increasingly complex reality for organizations pursuing AI-enabled ERP transformation while attempting to protect some of their most sensitive business data.

AI Adoption Is Accelerating—Despite Security Concerns

According to the study, 58% of organizations have begun using AI applications or agents that interact with their ERP systems within the past six months, while 86% have either integrated—or plan to integrate—AI directly into their ERP code.

Yet confidence has not kept pace with adoption.

The research found that more than 70% of senior cybersecurity leaders have only limited trust—or no trust at all—in AI’s ability to protect business-critical ERP data, underscoring the tension between innovation and governance.

AI Is Already Being Used by Attackers

Perhaps the report’s most notable finding is that 22% of surveyed organizations experienced a security incident during the past year in which attackers leveraged AI to exploit critical business platforms.

At the same time, 68.6% of respondents said they are not confident their current security capabilities could detect an AI-based attack, suggesting many organizations believe defensive capabilities are lagging behind emerging threats.

Rather than viewing AI solely as a productivity tool, the research highlights its growing role within the cybersecurity threat landscape.

Internal Resistance Reflects Governance Challenges

The report also reveals significant internal debate over granting AI access to ERP environments.

More than half of respondents reported resistance from at least one business unit when implementing AI within ERP systems. Security teams represented the largest source of concern, followed by IT departments.

The primary reasons cited included:

  • Lack of confidence in AI security
  • Compliance and regulatory risks
  • Concerns around protecting sensitive enterprise data

These findings suggest that AI governance is becoming as much an organizational issue as a technical one.

Building Trust Through Stronger Controls

According to Mariano Nunez, CEO and Co-Founder of Onapsis, organizations need to ensure security strategies evolve alongside AI adoption.

“Allowing AI to expand unchecked while integrating it into the core framework of a business without robust security and compliance guardrails is highly perilous. We cannot allow technological deployment to outpace our defenses, nor should security measures impede artificial intelligence advancement.”

When asked what would improve trust in AI, respondents identified several priorities over the next twelve months, including stronger access management controls, enhanced protection for sensitive data, and sandboxed environments where AI can be evaluated safely before deployment.

ERP Security Becomes a Shared Responsibility

The research also highlights evolving expectations around responsibility for securing AI-enabled ERP environments.

More than half of cybersecurity leaders believe protecting ERP data ultimately falls within their own teams, while nearly half expect ERP software vendors to embed stronger cybersecurity capabilities directly into their platforms.

With 56% of surveyed organizations planning or actively pursuing ERP transformation initiatives during the next year, collaboration between enterprise security teams and software vendors is likely to become increasingly important as AI capabilities continue to expand.

Why It Matters

As organizations move from AI experimentation to enterprise-wide deployment, ERP systems are becoming one of the most critical environments requiring governance and protection.

The Onapsis study suggests that while AI adoption is accelerating rapidly, many organizations remain uncertain whether existing security controls are prepared for AI-enabled threats. Closing that confidence gap may prove just as important as deploying new AI capabilities themselves, particularly as ERP systems continue serving as the operational backbone of modern enterprises.

ERP News Editorial Team
+ posts

The ERPNews Editorial Team covers global developments in ERP (Enterprise Resource Planning), enterprise software, cloud platforms, AI, automation, and digital transformation, providing independent news and editorial analysis for senior business and technology leaders. Our reporting focuses on market signals, strategic shifts, and enterprise impact across the ERP and enterprise technology ecosystem.

For editorial inquiries, please contact:
đź“© [email protected]

 

Shares: