7 min read

AI Attacks in SAP RISE: The Visibility Problem Inside the Managed Cloud

SAP RISE changes who operates your ERP—but not who is accountable for its security. AI-driven attacks exploit fragmented visibility across cloud providers, identities, APIs, and contracts. The biggest detection gap may not be technical. It may already be written into your RISE agreement.
AI Attacks in SAP RISE: The Visibility Problem Inside the Managed Cloud
Visual concept by Eckhart Mehler. Image generated with AI, 2026.

Part 4 of the Series: AI-Driven Attacks


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


When SAP introduced RISE, much of the discussion focused on modernization, operational efficiency, and accelerated cloud adoption. Infrastructure became a managed service, operations shifted to SAP and hyperscaler environments, and customers gained a simplified operating model for one of their most critical business platforms.

From a cybersecurity perspective, however, RISE introduced something else.

It fundamentally changed who controls the environment, who operates it, who monitors it, and who is ultimately responsible when something goes wrong.

Many organizations still equate managed services with managed security.

They are not the same.

AI-driven attacks expose this misconception more clearly than any previous generation of threats. They do not exploit the fact that SAP operates the infrastructure. They exploit the fact that responsibility is distributed while visibility is fragmented.

The greatest AI-related risk in SAP RISE may therefore not be that attackers become invisible.

It may be that customers are contractually unable to see enough to detect them.


RISE Changes Control, Not Accountability

Cloud transformation often creates a dangerous illusion.

As operational responsibility moves to a service provider, executives instinctively assume that cyber risk follows.

It does not.

A RISE customer remains accountable for the confidentiality, integrity, and availability of business data. Regulatory obligations do not move to SAP. Financial accountability does not move to the hyperscaler. Audit findings remain the customer’s responsibility. The board continues to answer to regulators, auditors, shareholders, and customers—not the managed service provider.

What changes is operational control.

Infrastructure is no longer administered directly. Large parts of the operating environment disappear behind provider-managed services. Administrative access is shared across multiple organizations. Maintenance activities become provider-controlled. Support processes increasingly depend on contractual agreements rather than internal technical authority.

This distinction becomes critical during an AI-assisted intrusion.

The attacker does not need to compromise every component of the landscape. It is sufficient to exploit the boundaries between responsibilities, because every shared operating model creates interfaces, and every interface introduces assumptions.

Artificial intelligence is exceptionally effective at identifying assumptions that humans never documented.


The Visibility Problem Starts with the Operating Model

Traditional on-premises SAP environments provided security teams with extensive technical visibility.

Operating systems could be examined directly.

Network traffic could be captured.

Database activity could be analyzed in detail.

System administrators could acquire forensic images, preserve evidence, or investigate suspicious behavior without depending on external providers.

RISE fundamentally changes this relationship.

Customers receive an enterprise application platform rather than unrestricted access to the infrastructure supporting it.

This is not inherently a security weakness.

In many cases, professionally operated cloud environments provide stronger operational security than traditional data centers.

The challenge lies elsewhere.

Security operations depend on visibility.

Detection depends on telemetry.

Forensics depend on evidence.

When these capabilities become partially controlled by service providers, the customer’s ability to independently investigate incidents changes fundamentally.

Many organizations discover these limitations only after a major security event, when investigators begin asking questions that can no longer be answered because the necessary data was never available in the first place.


AI Changes the Scale of the Visibility Challenge

Traditional attackers usually focused on individual systems.

An SAP application server.

A privileged administrator.

A vulnerable interface.

An exposed RFC connection.

AI changes this approach completely.

Modern AI systems rapidly correlate relationships across entire technology ecosystems.

Instead of targeting isolated systems, they analyse identities, integrations, APIs, business processes, trust relationships, cloud services, and communication paths simultaneously.

A modern SAP RISE landscape rarely consists only of SAP S/4HANA.

It typically includes SAP Business Technology Platform, Identity Providers, SAP Integration Suite, Cloud Connector, APIs, Microsoft Entra ID, hyperscaler services, third-party SaaS platforms, business partner integrations, developer environments, automation frameworks, and increasingly AI-enabled business services.

Each component generates different telemetry.

Each component belongs to different operational teams.

Each component follows different logging standards.

Each component retains data for different periods.

Each component answers to different contractual obligations.

An AI-assisted attacker correlates all of them.

The defender often cannot.


Shared Responsibility Creates Shared Blind Spots

The shared responsibility model has become one of the defining characteristics of enterprise cloud security.

Unfortunately, it is also frequently misunderstood.

The model explains who is responsible for operating individual components.

It does not guarantee that anyone has complete visibility across the entire attack chain.

SAP observes platform operations.

The hyperscaler observes infrastructure.

Identity providers monitor authentication.

Security products analyse the telemetry they receive.

Customers understand their own business processes.

External service providers monitor selected environments.

Every participant sees part of the picture.

Nobody automatically sees the whole picture.

For AI-driven attacks, this fragmentation creates ideal operating conditions.

The attacker benefits from organizational boundaries that were never designed for coordinated, machine-speed adversaries.


The BTP and API Challenge

The rapid adoption of SAP Business Technology Platform has dramatically expanded what organizations can build around SAP.

Extensions can be developed faster.

Business processes become more flexible.

Applications integrate more easily.

Innovation accelerates.

So does complexity.

Every new application introduces additional identities.

Every integration establishes new trust relationships.

Every API creates another possible attack path.

Technical users, OAuth clients, service keys, destination services, integration accounts, application routers, event-driven architectures, automation platforms, and AI services all require authentication.

Each represents a legitimate mechanism for conducting business.

Each can also become a legitimate mechanism for conducting malicious business.

AI systems excel at analysing these relationships.

They rapidly identify unused privileges, inconsistent authorization models, excessive permissions, undocumented interfaces, and forgotten service accounts.

Unlike traditional penetration testing, AI does not become tired.

It does not stop after identifying one weakness.

It continuously searches for combinations that humans never considered dangerous because no single configuration appears critical in isolation.


Business Logic Becomes the Target

One of the most important consequences of AI-driven attacks is that technical compromise becomes less important than business compromise.

Traditional cyberattacks often focused on obtaining administrative privileges.

Modern attacks increasingly focus on obtaining business influence.

An attacker who successfully manipulates supplier master data may never require operating system access.

An attacker who changes payment information may never deploy malware.

An attacker who abuses APIs may never exploit a software vulnerability.

Instead, legitimate interfaces perform unauthorized business actions.

To a traditional monitoring platform, many of these activities appear entirely normal.

Valid credentials.

Approved APIs.

Successful authentication.

Authorized transactions.

From a purely technical perspective, everything functions exactly as designed.

The compromise exists within the business process itself.

This distinction becomes increasingly significant as organizations automate more decisions using AI agents and workflow orchestration platforms.


Provider Access Deserves Greater Attention

Every managed cloud environment requires privileged administrative access by the provider.

This is operationally unavoidable.

Yet relatively few procurement projects examine this topic in sufficient detail.

CISOs should not simply ask whether provider access exists.

They should ask how it is governed.

Who receives privileged access?

Under which approval procedures?

How are emergency accesses documented?

Which administrative activities remain visible to the customer?

Which logs are preserved?

How long are they retained?

Can they be exported?

Can they be correlated with customer telemetry?

Can investigators independently reconstruct provider activities during a forensic investigation?

These questions are no longer operational details.

They are strategic security requirements.


Who Detects an AI Attack?

Perhaps the most underestimated challenge within SAP RISE is the assumption that somebody else will detect sophisticated attacks.

In reality, detection responsibility is distributed across multiple organizations.

SAP monitors the managed platform.

Hyperscalers observe cloud infrastructure.

Microsoft Defender analyses identities, endpoints, and workloads.

Microsoft Sentinel correlates available telemetry.

Specialized SAP security platforms such as Onapsis understand SAP-specific attack patterns.

Internal SOC teams contribute business knowledge.

External managed security providers deliver continuous monitoring services.

Each performs an essential function.

None possesses complete situational awareness.

Detection therefore becomes an integration challenge rather than a product selection exercise.

Organizations that simply deploy more security tools rarely solve the underlying problem.

They often create additional dashboards without eliminating existing blind spots.


Contracts Define Detection Capability

Perhaps the most uncomfortable realization for many CISOs is that detection capability is increasingly determined during procurement rather than during incident response.

Technology cannot provide access to logs that were never contractually included.

Threat hunters cannot analyse telemetry they are not permitted to receive.

Investigators cannot preserve evidence that no longer exists.

Many cloud contracts understandably emphasize availability, service quality, maintenance windows, and operational performance.

Far fewer specify requirements for forensic transparency.

Modern procurement should therefore address questions such as:

Who owns security logs?

Which telemetry remains available to the customer?

How long is it retained?

Can raw log data be exported?

How quickly must providers notify customers of suspicious activity?

How are provider administrative activities documented?

How is forensic evidence preserved?

Can customer SIEM platforms receive complete security telemetry?

Can specialized SAP monitoring platforms integrate without restriction?

These questions determine detection capability long before the first incident occurs.


Availability Is Not Visibility

Cloud service agreements frequently promise impressive availability figures.

Availability, however, is not synonymous with security.

An environment can achieve outstanding uptime while providing only limited forensic transparency.

Likewise, an excellent incident response process does not automatically guarantee that investigators possess sufficient evidence to understand what happened.

Managed services improve operational resilience.

They do not automatically improve investigative capability.

Incident response is not forensic transparency.

Forensic transparency is not security visibility.

Security visibility is not complete situational awareness.

These distinctions matter because AI-assisted attackers increasingly operate within legitimate business processes rather than outside them.

When technical indicators become less obvious, contextual visibility becomes far more valuable than infrastructure ownership.


Preparing for the Next Generation of SAP Attacks

Organizations often ask whether AI creates entirely new attack techniques.

In many cases, it does not.

Instead, AI industrializes existing techniques.

It reduces the expertise required.

It accelerates reconnaissance.

It correlates information across organizational boundaries.

It identifies hidden relationships between systems that were previously too complex for manual analysis.

The visibility challenges within SAP RISE already exist today.

Artificial intelligence simply magnifies their operational consequences.

The organizations that will detect tomorrow’s attacks most effectively will not necessarily own the most sophisticated security technologies.

They will be the organizations that negotiated the right visibility, integrated telemetry across their entire SAP ecosystem, governed identities consistently, and clearly defined detection responsibilities before the first incident occurred.


Conclusion

SAP RISE represents one of the most significant transformations in enterprise computing.

It also represents one of the most significant transformations in enterprise cyber defense.

The strategic question for CISOs is no longer who operates the infrastructure.

It is who possesses sufficient visibility to understand what is happening inside it.

As AI continues to compress attack timelines and increase the scale of adversarial automation, visibility becomes a strategic capability rather than a technical feature.

The organizations that remain resilient will not simply purchase managed services.

They will ensure that managed services remain observable.

Because in the age of AI-driven attacks, the greatest risk inside SAP RISE may not be that attackers become invisible.

It may be that customers have contractually surrendered the visibility required to detect them.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.