CyberScoop urges boards to focus on ERP security

THE BRIEF
CyberScoop argues that boards should take greater responsibility for cybersecurity risks in enterprise resource planning systems, including SAP. The article says a series of high-profile cyberattacks has pushed these traditionally back-office platforms into greater board-level focus. It points to the September 2025 cyberattack on Jaguar Land Rover as an illustration of the potential business impact. According to the report, the incident forced JLR to halt production for six weeks and became the costliest cyberattack in Britain’s history. JLR’s revenue declined 24 percent that quarter, representing a potentially greater-than-$1.2 billion drop in earnings, and the company later reported a 43.3 percent decline in wholesale sales volume in the following quarter. CyberScoop reports that the incident was carried out by the cybercrime group ShinyHunters. The article’s central message is that organizations should treat ERP security and resilience as board-level business concerns rather than routine back-office responsibilities.
WHY IT MATTERS
ERP systems support core business operations, so disruption can extend beyond information technology and affect production, revenue, and sales. CyberScoop’s account of the JLR incident illustrates the scale of impact it associates with an attack on a heavily relied-on enterprise platform. The report also signals a shift in governance: boards are being asked to take more direct responsibility for risks associated with systems that organizations may historically have treated as ordinary back-office infrastructure.
WHO SHOULD CARE
Board members, executives, ERP owners, SAP administrators, risk leaders, security teams, and business continuity planners should care. The report is especially relevant to organizations whose production, revenue, or sales processes depend on enterprise resource planning systems.
WHAT TO DO NOW
- Ask management to identify the organization’s most business-critical ERP systems, dependencies, and recovery priorities.
- Review ERP cybersecurity and resilience risks at board or executive level rather than treating them solely as back-office technology issues.
- Test business continuity plans for scenarios that disrupt ERP-supported production, revenue, or sales processes.
- Request clear reporting on ERP security risk, recovery readiness, and the potential business effects of prolonged disruption.