Onapsis Study Finds Bad Actors Exploited Nearly One in Four Organizations’ Critical Business Platforms in Past Twelve Months Leveraging AI
Onapsis Study Finds Bad Actors Exploited Nearly One in Four Organizations’ Critical Business Platforms in Past Twelve Months Leveraging AI
New research shows organizations still racing to embed AI into their systems even though they don’t have full confidence they can trust it
BOSTON--(BUSINESS WIRE)--Onapsis, the global leader in SAP cybersecurity and compliance, today released its inaugural The State of AI, Security and ERP study, finding that nearly one in four organizations (22%) report experiencing a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms. The study examined cybersecurity leaders’ biggest concerns and challenges they’re experiencing as more AI technologies get embedded across business operations and critical business platforms such as ERP systems.
Organizations want to accelerate AI adoption across their business operations despite ongoing concerns raised by cybersecurity leaders. Onapsis’ study found that 70% of senior cybersecurity leaders have only some trust or no trust at all in AI to secure their organizations’ business critical data. However, more than half (58%) report that their organizations started using AI-based apps or agents that touch their ERP system within just the last six months, and 86% say they have already integrated, or will shortly integrate, AI directly into their ERP code.
“Allowing AI to expand unchecked while integrating it into the core framework of a business without robust security and compliance guardrails is highly perilous,” stated Mariano Nunez, CEO and Co-Founder of Onapsis. “Regrettably, this scenario has become a reality for numerous enterprises. The critical message from our research is that senior security professionals and executive leadership must remain completely aligned regarding their AI implementation strategies. We cannot allow technological deployment to outpace our defenses, nor should security measures impede artificial intelligence advancement.”
Internal Resistance Is Mounting
There remains significant internal pushback on granting AI access to the most sensitive business data. Nearly 57% of respondents report that at least one business unit has objected to implementing AI within the ERP environment, with the security team topping the list of resistant groups (41.4%), followed by IT (20.7%) — the very function responsible for the ERP. The top reasons cited for resistance were lack of confidence in AI security (75%) and compliance risk (71.6%).
Little Confidence in AI Security’s Current Abilities
The study surfaces a pronounced confidence gap: 68.6% of respondents say they are only "somewhat" or "not very" confident that their current security defenses could even detect an AI-based attack. A similar share — 70.6% — report having only some, or no trust at all in AI applications and agents to secure their organization's most business-critical data. When asked what it would take to build that trust, respondents pointed to robust access management controls (61.8%), strong personal data protections (45.8%) and sandboxing or digital twin environments (36.8%) as the top requirements over the next 12 months.
Cybersecurity Ownership and Expectations are Mixed
Securing the organization’s business critical data within ERP systems amid increased utilization of AI and agentic AI technologies remains a challenging task, and the majority of senior cybersecurity leaders (54%) believe that set of responsibilities sits with them. They also have set a high bar for their ERP vendor partners as nearly 47% expect their vendors to embed sufficient cybersecurity capabilities across their platforms to ensure that critical data never gets compromised. ERP systems will continue to serve as a primary backbone to organizations, many of whom (56%) are currently pursuing or plan to pursue an ERP system transformation project over the next year.
The security partnership between organization and ERP vendor has never been more important than right now. Both must align on a clearer set of shared responsibilities in order to trust that AI can be the difference maker everyone wants it to be without compromising the business in the process.
Methodology
The State of AI, Security and ERP study was conducted in June 2026 among 204 senior-level cybersecurity leaders working at U.S.-based organizations with more than 1,000 employees, spanning financial services, manufacturing, pharmaceuticals, food & beverage, oil & gas, electric & utilities, healthcare and industrial chemicals. All respondents' organizations use leading ERP systems, including SAP (49.8%), Salesforce (31.2%) and Oracle (19%).
About Onapsis
Onapsis is the global leader in SAP cybersecurity and compliance, helping the world’s leading organizations reduce business risk, protect revenue, and keep critical operations running as they accelerate their SAP cloud and AI initiatives. Built for and by SAP defenders, the SAP-endorsed Onapsis Platform enables cybersecurity and SAP teams to proactively prevent breaches, accelerate audits, and respond faster to threats across RISE with SAP, S/4HANA Cloud, and hybrid environments. Powered by intelligence from the Onapsis Research Labs, Onapsis delivers rapid time to value, measurable risk reduction, and the confidence autonomous enterprises need to innovate faster. Connect with Onapsis on LinkedIn or visit https://www.onapsis.com.
Contacts
W2 Communications
Onapsis@w2comm.com
