are you putting your organization at risk?

23
© Panaya | An Infosys company PANAYA Oracle EBS is vulnerable to security breaches and hacking Panaya Webinar

Upload: panaya

Post on 22-Jan-2017

524 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA

Oracle EBS is vulnerable to security breaches and hacking

Panaya Webinar

Page 2: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA2

Eyal DiamantDirector, Oracle Product Management

Panaya

Rafi Kretchmer

Today’s SpeakersPANAYA WEBINAR

VP Marketing Panaya

Page 3: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA3

AgendaPANAYA WEBINAR

Challenges in organizations’ security1

Security risks in your Oracle EBS system 2

Changing the paradigm 3

Page 4: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA4

All phone lines have been muted

Please use the Question Panel

There will be 3 short polls during the webinar

We are recording this webinar

Polls results and recording will be provided in a follow-up email as well as any questions we don’t have time to answer

HousekeepingPANAYA WEBINAR

Page 5: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA5

= Average cost of cyber crime incident for a US company(Source: Ponemon Institute)

There were successful cyber attacks in 2015 (Source: Ponemon Institute)

99

$15.4M

PANAYA

Page 6: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA6

ERP security risks –

are you liable?

PANAYA

Page 7: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA

PANAYAPOLL1/3

PANAYA

Page 8: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA8

70% of EBS systems

are at risk

Is your EBS system secure?

PANAYA

Page 9: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA9

Oracle EBS – Exposure to Risk PANAYA WEBINAR

Page 10: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA10

When you see it, it’s too late.

When you see it, it’s too late.

PANAYA

Page 11: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA11

CPU Q32015

CVE-20154743

CVE-20154765

Safe

CPU Q32014

CVE-20144235

CVE-20144213

CPU Q42014

CVE-20146561

CVE-20146479

CPU Q12015

CVE-20140504

CVE-20140489

CPU Q22015

CVE-20150504

CVE-20150489

CVE=Common Vulnerabilities and Exposures

Org. 1 – Low Exposure to RiskPANAYA WEBINAR

Page 12: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA12

CPU Q32015

CVE-20154743

CVE-20154765

CPU Q32014

CVE-20144235

CVE-20144213

CPU Q42014

CVE-20146561

CVE-20146479

CVE-20140504

CVE-20140489

CPU Q22015

CVE-20150504

CVE-20150489

CPU Q12015

CVE-2015-4743 Description : Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.

Link to Bug :https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4743Link to Source:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Org. 2 – High Exposure to RiskPANAYA WEBINAR

Page 13: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA

PANAYAPOLL2/3

PANAYA

Page 14: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA14

Modules you don’t use are more vulnerable to

security breaches.

PANAYA

Page 15: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA15

Curious how you stand compared to your industry benchmark?

Page 16: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA16

Distribution of Oracle EBS customers according to Time-to-Patch

Page 17: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA

PANAYAPOLL3/3

PANAYA

Page 18: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA18

Evaluating the industry standards for MTTP of security and compliance patches

1 Analyzing your code, usage, and patch level of your current system and defining your EBS risk level

2

Lists recommended patches for external risk reduction

No more guess work: we will tell you which patches you need to install and their impact

3 4

PANAYA

How Panaya helps reduce your risk level

Page 19: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA19

RECOMMENDATIONS

YOU

THEMARKET

THEVENDOR

How do we do it?Panaya patch recommendation engine

Page 20: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA20

Q&A

Page 21: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA21

Summary – How Panaya Helps You

PANAYA

Constantly analyzes the latest security patches for you – so you will know exactly what you need to do

1 Builds a personalized risk base test plan so you will know exactly what will be the impact of this patch on your system

2

Helps you to be more proactive and reduces the time your organization is at risk – Improve MTTP

Gives visibility to your executives how you reduce company risk level without adding additional resources

3 4

Page 22: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA22

Curious how you stand compared to your industry benchmark?

Page 23: Are you putting your organization at risk?

© Panaya | An Infosys company PANAYA23

USA Germany Israel Japan Australia