Latest

13
Jun
Why SAP RISE isn't a "set and forget" model - and how CISOs can shape its success

Why SAP RISE isn't a "set and forget" model - and how CISOs can shape its success

SAP RISE is not a self-running transformation model. This article explains why CISOs must shape architecture, IAM, monitoring, compliance, supply-chain security and continuous validation from the start.
4 min read
13
Jun
Building a Cloud-Era SAP Security Team: Roles, Skills, and Responsibilities

Building a Cloud-Era SAP Security Team: Roles, Skills, and Responsibilities

SAP security in the cloud is no longer a Basis task. This article explains why CISOs need a modern SAP security team combining architecture, cloud engineering, IAM, threat detection and governance capabilities.
3 min read
13
Jun
Emergency and Recovery Plans for SAP in the Azure Cloud

Emergency and Recovery Plans for SAP in the Azure Cloud

SAP recovery in Azure is not covered by cloud availability alone. This article explains how CIOs and CISOs should define RTO/RPO, clarify shared responsibility, test disaster recovery and protect business continuity.
5 min read
13
Jun
Integrating SAP into Your Central ISMS

Integrating SAP into Your Central ISMS

SAP on Azure must be integrated into the ISMS after go-live, not treated as a finished project. This article outlines five CISO priorities: policies, risk assessment, responsibilities, monitoring and audit trails.
5 min read
13
Jun
Centralized Monitoring with Microsoft Sentinel: Integrating SAP Logs in Real-Time

Centralized Monitoring with Microsoft Sentinel: Integrating SAP Logs in Real-Time

SAP security cannot stay isolated from enterprise detection. This article explains how integrating SAP and HANA logs into Microsoft Sentinel gives CISOs real-time visibility, threat correlation, audit evidence and faster incident response.
4 min read
13
Jun
SO/IEC 27001 Update 2022/2023 – New Requirements for SAP S/4HANA in the Azure Cloud

SO/IEC 27001 Update 2022/2023 – New Requirements for SAP S/4HANA in the Azure Cloud

By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
4 min read
13
Jun
Debunking the Myth: “SAP Makes ISO/IEC 27001 Redundant?”

Debunking the Myth: “SAP Makes ISO/IEC 27001 Redundant?”

SAP certification does not replace your own ISMS. This article explains why vendor controls, shared responsibility and multi-cloud integrations still require enterprise-wide ISO/IEC 27001 governance, risk management and auditability.
5 min read
13
Jun
Cloud Security Architecture for SAP

Cloud Security Architecture for SAP

SAP cloud security depends on five foundations: segmentation, IAM, monitoring, encryption and business continuity. This article shows how CISOs can turn them into a resilient architecture aligned with ISMS governance.
6 min read
12
Jun
Lessons Learned: An SAP Security Incident and How It Could Have Been Prevented

Lessons Learned: An SAP Security Incident and How It Could Have Been Prevented

SAP incidents rarely start with one catastrophic failure. This article shows how delayed patching, excessive privileges, weak monitoring and untested response plans can turn minor oversights into serious business impact.
3 min read
12
Jun
Responding to a Cyberattack on SAP Systems

Responding to a Cyberattack on SAP Systems

A cyberattack on SAP is a business crisis, not just a technical incident. This guide explains how CISOs can contain compromised systems, preserve evidence, assess impact, restore securely and strengthen SAP resilience after an attack.
3 min read