SO/IEC 27001 Update 2022/2023 – New Requirements for SAP S/4HANA in the Azure Cloud
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Debunking the Myth: “SAP Makes ISO/IEC 27001 Redundant?”
SAP certification does not replace your own ISMS. This article explains why vendor controls, shared responsibility and multi-cloud integrations still require enterprise-wide ISO/IEC 27001 governance, risk management and auditability.
Cloud Security Architecture for SAP
SAP cloud security depends on five foundations: segmentation, IAM, monitoring, encryption and business continuity. This article shows how CISOs can turn them into a resilient architecture aligned with ISMS governance.
Lessons Learned: An SAP Security Incident and How It Could Have Been Prevented
SAP incidents rarely start with one catastrophic failure. This article shows how delayed patching, excessive privileges, weak monitoring and untested response plans can turn minor oversights into serious business impact.
Responding to a Cyberattack on SAP Systems
A cyberattack on SAP is a business crisis, not just a technical incident. This guide explains how CISOs can contain compromised systems, preserve evidence, assess impact, restore securely and strengthen SAP resilience after an attack.
The Spyware Industry
Spyware is no longer a niche surveillance issue — it is a global market for intrusion, repression and cyber power. This series explores the industry’s actors, economics, exploit techniques and practical defenses for CISOs and policymakers.
The Definitive Guide to Advanced Persistent Threats (APTs)
Advanced Persistent Threats are not isolated attacks — they are strategic campaigns of persistence, espionage and disruption. This series helps CISOs understand APT tactics, motivations, real-world cases, defense strategies and emerging AI-driven threats.
Fortifying Your SAP S/4 HANA
SAP S/4HANA is business-critical infrastructure, not just an ERP system. This series helps CISOs and CIOs address SAP security, SOC integration, Zero Trust, incident response, vulnerabilities, compliance and operational resilience.
Securing SAP RISE with ISO/IEC 27001:2022
SAP RISE is not a set-and-forget platform — it is a shared-responsibility governance challenge. This series shows how CISOs can integrate RISE into ISO/IEC 27001, GDPR, cloud security, audit readiness and resilience.
Securing SAP S/4 HANA on Microsoft Azure
SAP S/4HANA on Azure is not just a cloud migration — it is a governance, compliance and security architecture challenge. This series guides CISOs from shared responsibility and ISMS integration to Sentinel monitoring, IAM, recovery and resilience.