Eckhart Mehler

Eckhart Mehler

Hamburg, Germany
Global CISO advising leadership teams on cybersecurity, governance, resilience, and emerging technology risks. Working across international environments where security, regulation, geopolitics, and digital transformation increasingly converge.
13
Jun
Setting the Right KPIs to Measure Zero Trust Success

Setting the Right KPIs to Measure Zero Trust Success

Zero Trust needs KPIs that prove risk reduction, not activity. This article shows how CISOs can measure success through attack-surface contraction, policy accuracy, credential hygiene, segmentation coverage and risk-adjusted ROI.
4 min read
13
Jun
Zero Trust vs. Traditional Perimeter: What’s the Difference?

Zero Trust vs. Traditional Perimeter: What’s the Difference?

Perimeter security was built for a world that no longer exists. This article explains why Zero Trust replaces castle-and-moat assumptions with identity, least privilege, micro-segmentation, continuous verification and adaptive access.
4 min read
13
Jun
The True Cost of a Missed Access Review

The True Cost of a Missed Access Review

Access creep has become a European liability, not an audit nuisance. This article shows how CISOs and CHROs can quantify risk, align with GDPR, ISO/IEC 27001, NIS2 and DORA, and automate evidence-grade access reviews.
4 min read
13
Jun
Identity and Access Management - The Cornerstone of Zero Trust

Identity and Access Management - The Cornerstone of Zero Trust

Zero Trust succeeds or fails with identity. This article explains why IAM is the load-bearing wall of modern security — from MFA, RBAC and ABAC to continuous authentication, JIT access, CIEM, identity telemetry and AI-driven policy.
4 min read
13
Jun
Common Security Vulnerabilities in SAP S/4HANA

Common Security Vulnerabilities in SAP S/4HANA

SAP S/4HANA vulnerabilities often arise from misconfigurations, weak access controls, poor logging, insecure ABAP code, delayed patching and exposed APIs. This article shows how CISOs can reduce these risks systematically.
4 min read
13
Jun
Enhancing Your Incident Response Team for SAP-Related Incidents

Enhancing Your Incident Response Team for SAP-Related Incidents

SAP incidents require more than a generic response team. This article explains how CISOs can strengthen IRT capabilities through SAP-specific training, clear roles, simulations, process integration and business continuity planning.
2 min read
13
Jun
What CIOs and CISOs Should Know About Integrating SOC with SAP

What CIOs and CISOs Should Know About Integrating SOC with SAP

SAP cannot remain outside the SOC. This article explains how CISOs can integrate SAP logs, access controls, automation, AI-driven anomaly detection and joint SOC-SAP processes to protect critical business operations.
3 min read
13
Jun
SAP Security: Debunking the Top 5 Misconceptions Among IT Leaders

SAP Security: Debunking the Top 5 Misconceptions Among IT Leaders

SAP security fails when leaders believe the myths: firewalls are enough, SAP handles everything, cloud means secure, roles are clean and attackers ignore ERP. This article challenges those assumptions and shows what CISOs must control.
3 min read
13
Jun
Risk Management for SAP

Risk Management for SAP

SAP risk management must connect technical controls with business impact. This article explains how CISOs can align SAP security with critical processes, access risks, real-time monitoring, compliance and executive decision-making.
3 min read
13
Jun
Is SAP S/4HANA Truly ‘Secure by Default’?

Is SAP S/4HANA Truly ‘Secure by Default’?

SAP S/4HANA is not automatically secure after deployment. This article challenges the “secure by default” myth and explains why CISOs must enforce custom configuration, patching, audit logging, access control and continuous monitoring.
3 min read