SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

The most valuable data sits where nobody looks.

Cloud configuration and ERP authorization are two doors into your financial and operational data. Sanal Çekirdek treats them not as separate products but as links in the same access chain.

A security exposure usually grows out of accumulated permissions rather than a vulnerability. Roles added over years leave an access map nobody ever prunes.

Permission creep and segregation of duties

ERP risk starts when one user can perform two tasks that are meant to check each other: when whoever raises a record also approves it, the control disappears. Roles are rebuilt around duties rather than around individuals.

  • Conflicting duty pairs are governed by rule, not case by case
  • Old permissions must close when a role changes hands
  • Privileged accounts are granted with an expiry
  • Exceptions are recorded with a reason and a date

Cloud configuration security

Most cloud incidents come from a setting left open rather than an exploit: public storage, a broad network rule, management access never closed. Configuration is not fixed once — it is measured continuously.

  • The benchmark set is chosen against your risk appetite
  • Drift is recorded the moment it appears
  • Remediation advice arrives with its impact stated
  • New accounts and subscriptions enter scope automatically

Integration and interface surface

ERP never stands alone; it talks to payroll, banking, e-invoicing and supplier systems. Those interfaces usually run on service accounts — the longest-lived and most broadly privileged accounts in the estate.

  • Every service account has an owner and a lifetime
  • Key and credential rotation is put on a calendar
  • Interface traffic is watched as a pattern, not as content
  • Unused integrations are closed, not left dormant

Evidence and audit trail

Security work is measured by what can be shown during an audit. Who accessed what, when and on what grounds must be traceable; an authorization with no record counts as one that never happened.

  • Permission changes reconcile against approval records
  • Logs are retained in a tamper-evident form
  • A ready query set answers common audit questions
  • Findings are tracked to a closing date

How we work

  1. Inventory identities and roles
  2. Turn conflicting duty pairs into rules
  3. Select the cloud configuration benchmarks
  4. Set up drift detection and the remediation flow
  5. Operate the audit trail and review cycle

How success is measured

  • No user is left holding a conflicting duty pair
  • Every privileged account carries an expiry
  • Mean time to close configuration drift keeps falling
  • Approval records for permission changes are complete

Frequently asked questions

Aren't ERP and cloud security separate disciplines?

The tooling differs; the chain does not. If a cloud identity is tied to an ERP role, an attacker sees a single path — which is why both are assessed on one access map.

Will cleaning up permissions disrupt the business?

Not when it is staged. Observation comes first, then exception records, then closure; critical roles are never closed without confirmation from the business owner.

Should configuration be scanned periodically?

Continuous measurement is preferable to scanning. A periodic scan cannot see a setting that opened and closed between two runs; drift should surface the moment it occurs.

To see your access map as a single table, start with the role inventory — we will identify the conflicting duty pairs together.

Map your access rights