New Onapsis X1 Release Streamlines Compliance for SOX and NERC Mandates Affecting SAP Customers

Addition of significant compliance checks to Onapsis X1 now available

Cambridge, MA - September 12th, 2013 Onapsis Inc., the leading provider of solutions to audit and protect ERP systems from cyber-attacks, today announces the addition of significant compliance checks to its product Onapsis X1. These checks will enable organizations to save a considerable amount of time and proactively enforce compliance policies by automatically auditing their SAP systems and validating that these requirements are being followed. Also, organizations will shorten external audit time and prevent audit failures by preparing in advance for these reoccurring compliance checks.

Robert H. Clark, PwC principal, leads PwC's SAP security and controls team in the U.S. commented: "PwC has been working with Onapsis and our SAP clients to assess and remediate cyber-security related risks. I am looking forward to this new version and testing the anticipated capabilities to see how they can meet our client's demands in managing risks across their SAP environments."

Mariano Nunez, CEO of Onapsis, leads the company’s strategy and product direction, “Working together with the leading SAP customers and Audit firms in the world, we were able to identify the most critical SAP cyber-security IT controls that are now required by Sarbanes-Oxley (SOX) and North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) mandates. We’re excited to help our customers streamline their compliance audits, ensure they stay both compliant and secure regarding the latest SAP cyber threats affecting their industries,” stated Mariano.

Onapsis X1 is the industry’s first comprehensive SAP-certified solution for the automated application security assessment of SAP systems. Backed by the frequent updates from the Onapsis Research Labs, Onapsis X1 detects insecure SAP ABAP and Java configurations, missing SAP Security Notes and patches, dangerous user authorizations, insecure interfaces between SAP systems and threats affecting SAP mobile platforms. Following Onapsis X1’s detailed mitigation procedures, customers can increase the security level of their platform, decrease business fraud risks and enforce evolving compliance requirements.

Available in September, this new version of the Onapsis X1 product provides SAP customers with the ability to continuously check for any elements of their SAP systems that do not meet compliance mandates. These could include insecure configurations, changes to the SAP platforms, missing SAP Security Notes and other security risks that would prevent them from passing compliance audits. With this continued expansion of the product capabilities, Onapsis further enables enterprise customers to implement a holistic cyber-security process and mitigate threats targeting their SAP platforms.

About Onapsis

Onapsis provides the most comprehensive solutions for securing business-critical applications. As the leading experts in SAP cyber-security, Onapsis’ enables security and audit teams to have visibility, confidence and control of advanced threats, cyber-risks and compliance gaps targeting their enterprise applications

Headquartered in Boston, MA., Onapsis serves over 160 Global 2000 customers, including 10 top retailers, 20 top energy firms and 20 top manufacturers. Onapsis’ solutions are also the de-facto standard for leading consulting and audit firms such as Accenture, IBM, Deloitte, E&Y, KPMG and PwC.

Onapsis solutions include the Onapsis Security Platform, which is the most widely-used SAP-certified cyber-security solution in the market. Unlike generic security products, Onapsis’ context-aware solutions deliver both preventative vulnerability and compliance controls, as well as real-time detection and incident response capabilities to reduce risks affecting critical business processes and data. Through open interfaces, the platform can be integrated with leading SIEM, GRC and network security products, seamlessly incorporating SAP applications into existing vulnerability, risk and incident response management programs.

These solutions are powered by the Onapsis Research Labs which continuously provide leading intelligence on security threats affecting SAP systems. Experts of the Onapsis Research Labs were the first to lecture on SAP cyber-attacks and have uncovered and helped fix hundreds of security vulnerabilities to-date affecting SAP Business Suite, SAP HANA and SAP Mobile deployments.

For more information, please visit, or connect with us on Twitter, Google+, or LinkedIn.