Enhancing ERP security through threat modelling, digitization, and external integrations: a comprehensive empirical analysis

Today, Enterprise Resource Planning (ERP) systems form the backbone of the operations of almost any business, and this reliance has come at a high cost: cloud-based ERP and third-party integrations have increased attack surface way beyond what perimeter defenses ever addressed. The study is based on interviews with 66 security practitioners in a variety of enterprise environments, and asks each participant what he or she has seen implemented in the real world, where it has failed to live up to the stated intentions, and what he or she expects will be most significant in the future. There are three salient findings. The first is that there is a significant difference between people’s perception of threat modelling and its use in practice; 70% found it effective but only 15% extensively use it ( \\(\\chi ^2=18.3\\) ; \\(p<0.001\\) ). Second, there are elements of digitization that work against each other—68 percent of respondents say they have made security more robust, and 44 percent say it has made security more vulnerable. Third, integration risks are still a problem: 30% of organisations have experienced incidents related to external integrations, despite 53% implementing API controls. Structured threat modeling organizations are found to have a security posture about 3 times higher as compared to those that do not practice structured threat modeling; however, this is a cross-sectional survey, so we are not claiming causation but association. The most common deficiencies mentioned are unauthorized access (53%), lack of monitoring (47%), and data integrity risk (44%), and many respondents (55%) believe that regulatory compliance is not enough. In order to provide quantitative guidance for making the findings actionable, we introduce a quantitative ERP Security Posture Index (ESPI), a three-phase adoption framework, and a Return on Investment model based on the Gordon–Loeb framework, which yields a central estimate for ROI of 135% for the first year of adoption (sensitivity testing results range from 79% to 535%). The gross cost avoided over 5 years is estimated at $2.18M. In the future, respondents believe that AI/ML monitoring (80%) and blockchain-based solutions (35%) will set the stage for the next generation of ERP security.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-09-16
DOI
https://doi.org/10.1038/s41598-026-67809-y
Primary Topic
ERP Systems Implementation and Impact
Type
article
Field-Weighted Citation Impact
0.00

Funders

Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Enhancing ERP security through threat modelling, digitization, and external integrations: a comprehensive empirical analysis

Sadiqa Arshad, Ammad Ali Khan Jadoon, Adiah Qazi
Scientific Reports
ERP Systems Implementation and Impact
article

Enhancing ERP security through threat modelling, digitization, and external integrations: a comprehensive empirical analysis

Sadiqa Arshad, Ammad Ali Khan Jadoon, Adiah Qazi
article en

Abstract

Today, Enterprise Resource Planning (ERP) systems form the backbone of the operations of almost any business, and this reliance has come at a high cost: cloud-based ERP and third-party integrations have increased attack surface way beyond what perimeter defenses ever addressed. The study is based on interviews with 66 security practitioners in a variety of enterprise environments, and asks each participant what he or she has seen implemented in the real world, where it has failed to live up to the stated intentions, and what he or she expects will be most significant in the future. There are three salient findings. The first is that there is a significant difference between people’s perception of threat modelling and its use in practice; 70% found it effective but only 15% extensively use it ( \(\chi ^2=18.3\) ; \(p<0.001\) ). Second, there are elements of digitization that work against each other—68 percent of respondents say they have made security more robust, and 44 percent say it has made security more vulnerable. Third, integration risks are still a problem: 30% of organisations have experienced incidents related to external integrations, despite 53% implementing API controls. Structured threat modeling organizations are found to have a security posture about 3 times higher as compared to those that do not practice structured threat modeling; however, this is a cross-sectional survey, so we are not claiming causation but association. The most common deficiencies mentioned are unauthorized access (53%), lack of monitoring (47%), and data integrity risk (44%), and many respondents (55%) believe that regulatory compliance is not enough. In order to provide quantitative guidance for making the findings actionable, we introduce a quantitative ERP Security Posture Index (ESPI), a three-phase adoption framework, and a Return on Investment model based on the Gordon–Loeb framework, which yields a central estimate for ROI of 135% for the first year of adoption (sensitivity testing results range from 79% to 535%). The gross cost avoided over 5 years is estimated at $2.18M. In the future, respondents believe that AI/ML monitoring (80%) and blockchain-based solutions (35%) will set the stage for the next generation of ERP security.

Scientific Reports
National University of Medical Sciences (PK), National University of Sciences and Technology (PK)
National University of Sciences and Technology
Openalex Percentile: Top 7%
ERP Systems Implementation and Impact
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.