Eckhart Mehler

Eckhart Mehler

Hamburg, Germany
Global CISO advising leadership teams on cybersecurity, governance, resilience, and emerging technology risks. Working across international environments where security, regulation, geopolitics, and digital transformation increasingly converge.
13
Jun
Cloud security responsibilities in SAP RISE

Cloud security responsibilities in SAP RISE

SAP RISE does not remove customer accountability. This article explains how CISOs can map shared security responsibilities across the SAP Cloud Lifecycle — from IAM and data governance to monitoring, configuration and compliance.
3 min read
13
Jun
SAP access to personal data

SAP access to personal data

SAP access to personal data must be transparent, monitored and contractually controlled. This article shows how CISOs and DPOs can enforce least privilege, logging, SoD, vendor obligations and GDPR-aligned accountability.
4 min read
13
Jun
Audit readiness with SAP RISE

Audit readiness with SAP RISE

SAP RISE audit readiness depends on more than provider assurance. This article shows what auditors expect from CISOs: clear shared responsibilities, strong access controls, documentation, monitoring, evidence and operational oversight.
4 min read
13
Jun
What if SAP RISE isn't fully ISO/IEC 27001 auditable?

What if SAP RISE isn't fully ISO/IEC 27001 auditable?

SAP RISE may simplify cloud transformation, but not audit responsibility. This article explains how CISOs can close ISO/IEC 27001 auditability gaps through SLAs, evidence chains, monitoring, third-party attestations and hybrid governance.
3 min read
13
Jun
ISMS meets RISE

ISMS meets RISE

SAP RISE must be governed as an external service within the ISMS. This article explains how CISOs can align RISE with ISO/IEC 27001:2022, shared responsibility, risk management, SLAs, monitoring and audit readiness.
3 min read
13
Jun
Why SAP RISE isn't a "set and forget" model - and how CISOs can shape its success

Why SAP RISE isn't a "set and forget" model - and how CISOs can shape its success

SAP RISE is not a self-running transformation model. This article explains why CISOs must shape architecture, IAM, monitoring, compliance, supply-chain security and continuous validation from the start.
4 min read
13
Jun
Building a Cloud-Era SAP Security Team: Roles, Skills, and Responsibilities

Building a Cloud-Era SAP Security Team: Roles, Skills, and Responsibilities

SAP security in the cloud is no longer a Basis task. This article explains why CISOs need a modern SAP security team combining architecture, cloud engineering, IAM, threat detection and governance capabilities.
3 min read
13
Jun
Emergency and Recovery Plans for SAP in the Azure Cloud

Emergency and Recovery Plans for SAP in the Azure Cloud

SAP recovery in Azure is not covered by cloud availability alone. This article explains how CIOs and CISOs should define RTO/RPO, clarify shared responsibility, test disaster recovery and protect business continuity.
5 min read
13
Jun
Integrating SAP into Your Central ISMS

Integrating SAP into Your Central ISMS

SAP on Azure must be integrated into the ISMS after go-live, not treated as a finished project. This article outlines five CISO priorities: policies, risk assessment, responsibilities, monitoring and audit trails.
5 min read
13
Jun
Centralized Monitoring with Microsoft Sentinel: Integrating SAP Logs in Real-Time

Centralized Monitoring with Microsoft Sentinel: Integrating SAP Logs in Real-Time

SAP security cannot stay isolated from enterprise detection. This article explains how integrating SAP and HANA logs into Microsoft Sentinel gives CISOs real-time visibility, threat correlation, audit evidence and faster incident response.
4 min read