Skip to main content
Emerging ThreatsMalware & Ransomware

AI Attacks Expose Enterprise Security Gaps

Concerned IT staff stand behind rows of computer terminals in a brightly-lit corporate IT environment with a blurred ERP…

Nearly one in four organizations — 22% — say they experienced a security incident in the past twelve months in which bad actors used artificial intelligence to exploit their critical business platforms.

AI-enabled attacks on ERP platforms

The Onapsis report draws a clear line between AI and operational risk inside enterprise resource planning (ERP) environments: 22% of surveyed organizations reported incidents in the prior year where AI was used by attackers to exploit ERP systems. At the same time, 68.6% of respondents said they were only "somewhat" or "not very" confident that their current security defenses could detect an AI-based attack, signaling a gap between the emergence of AI-enabled techniques and defenders' detection capabilities.

Senior cybersecurity leaders: cautious trust, rapid deployment

Senior cybersecurity leaders express mixed feelings. Seventy percent reported having only some trust or no trust at all in AI to secure their organizations’ most business-critical data. Yet adoption is accelerating: 58% of respondents said their organizations began using AI-based apps or agents that touch their ERP system within the last six months, and 86% reported they have already integrated, or will shortly integrate, AI directly into their ERP code. The juxtaposition — limited trust alongside swift integration — underscores a rapid operational embrace of AI despite persistent security reservations.

Internal resistance: security teams and IT raise flags

Resistance to injecting AI into ERP environments is widespread across business units. Nearly 57% of respondents reported that at least one business unit objected to implementing AI within the ERP environment. The security team registered the highest rate of objection at 41.4%, followed by IT — the function responsible for ERP — at 20.7%. Respondents cited lack of confidence in AI security (75%) and compliance risk (71.6%) as the top reasons for resistance, placing governance and regulatory concerns at the center of internal debates over deployment.

Concrete requirements to build trust: access controls, data protections, sandboxing

Survey participants identified specific controls they expect will be necessary to raise confidence in AI inside ERP systems over the next 12 months. Robust access management controls were the top requirement, named by 61.8% of respondents. Strong personal data protections were next at 45.8%, and sandboxing or digital twin environments were cited by 36.8% as a needed safeguard. These priorities point to a pragmatic checklist: limit who and what can interact with ERP data, harden protections around personal information, and isolate AI testing from production systems.

What this means for technologists, procurement leaders, and security teams

  • Technologists and security teams: Expect pressure to instrument detection and isolation controls quickly — detection confidence is low (68.6% only somewhat/not very confident) while integration plans are widespread (86% integrating or planning to integrate AI into ERP code).
  • Procurement and business leaders: Rapid rollout is already underway (58% began using AI-based apps touching ERP within six months), but procurement will face persistent internal pushback — especially from security teams (41.4%) — and must address compliance risk concerns (71.6%).
  • Security operations and governance functions: To build the trust leaders demand, investments in access management (61.8%), personal data protections (45.8%), and sandboxing/digital twin environments (36.8%) are the explicitly prioritized measures cited by respondents.

The Onapsis data sketches a familiar tension of technological inflection points: adoption outpacing assurance. Organizations are folding AI into the fabric of ERP systems even as a large majority doubts detection capabilities and many business units resist on security and compliance grounds. The near-term battleground is therefore practical and narrowly defined — control who can use AI against ERP data, harden personal data protections, and test AI in isolated environments — rather than abstract debates about AI's benefits. Whether those concrete steps happen quickly enough to close the 68.6% confidence gap is the question the report leaves for executives and security teams to answer.

Source: https://www.securitymagazine.com/articles/102475-majority-of-organizations-unsure-if-they-could-detect-ai-attack