Enhancing ERP security through threat modelling, digitization, and external integrations: a comprehensive empirical analysis
Today, Enterprise Resource Planning (ERP) systems form the backbone of the operations of almost any business, and this reliance has come at a high cost: cloud-based ERP and third-party integrations have increased attack surface way beyond what perimeter defenses ever addressed. The study is based on interviews with 66 security practitioners in a variety of enterprise environments, and asks each participant what he or she has seen implemented in the real world, where it has failed to live up to the stated intentions, and what he or she expects will be most significant in the future. There are three salient findings. The first is that there is a significant difference between people’s perception of threat modelling and its use in practice; 70% found it effective but only 15% extensively use it ( \\(\\chi ^2=18.3\\) ; \\(p<0.001\\) ). Second, there are elements of digitization that work against each other—68 percent of respondents say they have made security more robust, and 44 percent say it has made security more vulnerable. Third, integration risks are still a problem: 30% of organisations have experienced incidents related to external integrations, despite 53% implementing API controls. Structured threat modeling organizations are found to have a security posture about 3 times higher as compared to those that do not practice structured threat modeling; however, this is a cross-sectional survey, so we are not claiming causation but association. The most common deficiencies mentioned are unauthorized access (53%), lack of monitoring (47%), and data integrity risk (44%), and many respondents (55%) believe that regulatory compliance is not enough. In order to provide quantitative guidance for making the findings actionable, we introduce a quantitative ERP Security Posture Index (ESPI), a three-phase adoption framework, and a Return on Investment model based on the Gordon–Loeb framework, which yields a central estimate for ROI of 135% for the first year of adoption (sensitivity testing results range from 79% to 535%). The gross cost avoided over 5 years is estimated at $2.18M. In the future, respondents believe that AI/ML monitoring (80%) and blockchain-based solutions (35%) will set the stage for the next generation of ERP security.
Authors
- Sadiqa Arshad (ORCID: https://orcid.org/0000-0002-0328-3988)
- Ammad Ali Khan Jadoon
- Adiah Qazi
Institutions
- National University of Medical Sciences (PK)
- National University of Sciences and Technology (PK)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-16
- DOI
- https://doi.org/10.1038/s41598-026-67809-y
- Primary Topic
- ERP Systems Implementation and Impact
- Type
- article
- Field-Weighted Citation Impact
- 0.00
Funders
- National University of Sciences and Technology