Eckhart Mehler

Eckhart Mehler

Hamburg, Germany
Global CISO advising leadership teams on cybersecurity, governance, resilience, and emerging technology risks. Working across international environments where security, regulation, geopolitics, and digital transformation increasingly converge.
13
Jun
SO/IEC 27001 Update 2022/2023 – New Requirements for SAP S/4HANA in the Azure Cloud

SO/IEC 27001 Update 2022/2023 – New Requirements for SAP S/4HANA in the Azure Cloud

By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
4 min read
13
Jun
Debunking the Myth: “SAP Makes ISO/IEC 27001 Redundant?”

Debunking the Myth: “SAP Makes ISO/IEC 27001 Redundant?”

SAP certification does not replace your own ISMS. This article explains why vendor controls, shared responsibility and multi-cloud integrations still require enterprise-wide ISO/IEC 27001 governance, risk management and auditability.
5 min read
13
Jun
Cloud Security Architecture for SAP

Cloud Security Architecture for SAP

SAP cloud security depends on five foundations: segmentation, IAM, monitoring, encryption and business continuity. This article shows how CISOs can turn them into a resilient architecture aligned with ISMS governance.
6 min read
12
Jun
Lessons Learned: An SAP Security Incident and How It Could Have Been Prevented

Lessons Learned: An SAP Security Incident and How It Could Have Been Prevented

SAP incidents rarely start with one catastrophic failure. This article shows how delayed patching, excessive privileges, weak monitoring and untested response plans can turn minor oversights into serious business impact.
3 min read
12
Jun
Responding to a Cyberattack on SAP Systems

Responding to a Cyberattack on SAP Systems

A cyberattack on SAP is a business crisis, not just a technical incident. This guide explains how CISOs can contain compromised systems, preserve evidence, assess impact, restore securely and strengthen SAP resilience after an attack.
3 min read
12
Jun
The Spyware Industry

The Spyware Industry

Spyware is no longer a niche surveillance issue — it is a global market for intrusion, repression and cyber power. This series explores the industry’s actors, economics, exploit techniques and practical defenses for CISOs and policymakers.
2 min read
12
Jun
The Definitive Guide to Advanced Persistent Threats (APTs)

The Definitive Guide to Advanced Persistent Threats (APTs)

Advanced Persistent Threats are not isolated attacks — they are strategic campaigns of persistence, espionage and disruption. This series helps CISOs understand APT tactics, motivations, real-world cases, defense strategies and emerging AI-driven threats.
5 min read
12
Jun
Fortifying Your SAP S/4 HANA

Fortifying Your SAP S/4 HANA

SAP S/4HANA is business-critical infrastructure, not just an ERP system. This series helps CISOs and CIOs address SAP security, SOC integration, Zero Trust, incident response, vulnerabilities, compliance and operational resilience.
2 min read
12
Jun
Securing SAP RISE with ISO/IEC 27001:2022

Securing SAP RISE with ISO/IEC 27001:2022

SAP RISE is not a set-and-forget platform — it is a shared-responsibility governance challenge. This series shows how CISOs can integrate RISE into ISO/IEC 27001, GDPR, cloud security, audit readiness and resilience.
3 min read
12
Jun
Securing SAP S/4 HANA on Microsoft Azure

Securing SAP S/4 HANA on Microsoft Azure

SAP S/4HANA on Azure is not just a cloud migration — it is a governance, compliance and security architecture challenge. This series guides CISOs from shared responsibility and ISMS integration to Sentinel monitoring, IAM, recovery and resilience.
3 min read