SAP RISE Is Never “Set and Forget”
Why Continuous Governance Determines the Success of Enterprise Transformation
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Cloud transformation has fundamentally changed the way organizations think about technology.
For decades, enterprise software projects followed a familiar pattern.
Requirements were gathered.
Architectures were designed.
Systems were implemented.
Go-live was achieved.
The project was closed.
Operations began.
Security often mirrored this lifecycle.
Risk assessments were performed before implementation.
Controls were validated before production.
Penetration tests were completed shortly before go-live.
Compliance documentation was finalized.
The project was declared secure.
This mindset no longer reflects reality.
Modern enterprise platforms do not remain static after implementation.
They evolve continuously.
New services appear.
Artificial intelligence becomes embedded.
Integrations expand.
Threat landscapes change.
Business processes adapt.
Provider responsibilities evolve.
Regulatory expectations increase.
SAP RISE represents exactly this transformation.
Many organizations still approach SAP RISE as an implementation programme.
In reality, it introduces an entirely new operating model.
That distinction changes everything.
From a CISO perspective, the most dangerous misconception surrounding SAP RISE is not misunderstanding cloud security.
It is believing that security can ever be considered complete.
The phrase “set and forget” has never officially been associated with SAP RISE.
Yet many transformation programmes unintentionally operate as though it were.
The project team finishes.
Budgets shift elsewhere.
Governance returns to business as usual.
Periodic audits continue.
Everyone assumes the platform will remain secure because operational responsibility has been transferred.
Nothing could be further from reality.
SAP RISE is not a finished product.
It is a continuously evolving ecosystem.
Every monthly update.
Every newly connected application.
Every integration.
Every identity.
Every API.
Every AI capability.
Every provider enhancement.
Every business process redesign.
Changes the organization’s security posture.
Security therefore cannot remain tied to project milestones.
It must become part of operational governance.
This represents one of the most profound shifts in enterprise cybersecurity.
The CISO no longer protects only technology.
The CISO protects an operating model.
An operating model built upon distributed responsibilities, cloud-native services, multiple providers, artificial intelligence and continuously changing business relationships.
Success is therefore no longer determined by achieving a secure go-live.
It is determined by maintaining control long after the implementation team has disappeared.
Organizations that understand this distinction treat SAP RISE differently.
Implementation becomes only the first milestone.
Governance becomes permanent.
Verification becomes continuous.
Resilience becomes measurable.
Control becomes the true objective.
SAP RISE Is an Operating Model—Not a Project
One of the greatest misconceptions surrounding SAP RISE is the belief that it represents a cloud migration project.
Projects have beginnings.
Projects have endings.
Projects deliver outcomes.
Operating models do not.
They evolve continuously.
This distinction fundamentally changes the role of cybersecurity.
Traditional ERP programmes largely focused on implementation quality.
The objective was clear.
Deliver the new platform.
Stabilize operations.
Transfer responsibility.
Close the programme.
SAP RISE changes that logic entirely.
Organizations no longer implement software that remains largely unchanged for years.
Instead, they join an ecosystem that evolves every day.
Infrastructure changes.
Platform services mature.
Identity integrations expand.
Business Technology Platform capabilities increase.
Artificial intelligence becomes embedded.
Business Data Cloud continuously grows.
Security capabilities evolve.
Threat actors evolve even faster.
This means that the security architecture approved today may no longer represent the architecture operating twelve months later.
The project has ended.
The environment has not.
This creates a fundamental governance challenge.
Traditional project governance assumes that implementation risk decreases over time.
Cloud ecosystems often behave differently.
Operational complexity frequently increases after go-live.
Business users request new integrations.
Departments adopt additional services.
Partners receive access.
External identities accumulate.
Automation expands.
AI assistants begin influencing workflows.
Every enhancement appears individually reasonable.
Collectively, however, they continuously reshape enterprise risk.
The most mature organizations therefore stop thinking about SAP RISE as a transformation project.
They begin treating it as a permanent governance programme.
The difference is subtle.
Its consequences are enormous.
Governance does not finish at go-live.
Governance begins there.
The Myth of “Shared Responsibility”
Every discussion about cloud security eventually introduces the Shared Responsibility Model.
The model itself is both valuable and necessary.
It explains which security responsibilities remain with the provider and which remain with the customer.
Unfortunately, many organizations interpret this model far too narrowly.
Shared responsibility often becomes psychologically translated into shared accountability.
It is not.
The Board remains accountable.
Executive management remains accountable.
Regulators hold the organization accountable.
Customers trust the organization.
Not its cloud provider.
This distinction becomes increasingly important as enterprise ecosystems become more distributed.
SAP may operate parts of the infrastructure.
Hyperscalers may operate physical platforms.
Identity providers authenticate users.
Managed service providers administer environments.
System integrators maintain extensions.
Third parties operate connected applications.
Artificial intelligence increasingly supports business decisions.
Responsibilities become fragmented.
Accountability does not.
This creates one of the defining governance challenges for modern CISOs.
Who verifies that every participant performs their responsibilities effectively?
Who challenges assumptions?
Who validates security controls?
Who independently confirms operational resilience?
Who accepts residual risk?
Responsibility matrices cannot answer these questions.
Governance can.
The Shared Responsibility Model should therefore never be interpreted as a mechanism for reducing organizational responsibility.
It should instead be viewed as a coordination model requiring significantly stronger governance than traditional on-premises environments.
The more responsibilities become distributed…
…the more important independent verification becomes.
Cloud transformation does not eliminate governance.
It makes governance indispensable.
Continuous Change Creates Continuous Risk
Traditional enterprise software evolved relatively slowly.
Major upgrades occurred every few years.
Infrastructure remained stable.
Architectures changed gradually.
Security programmes therefore evolved at a manageable pace.
SAP RISE fundamentally alters this rhythm.
Modern cloud environments change continuously.
New platform capabilities appear.
Existing services improve.
Security controls evolve.
Identity relationships expand.
Third-party integrations multiply.
Artificial intelligence becomes embedded across business processes.
No individual change appears particularly significant.
Collectively, however, they permanently reshape the organization’s attack surface.
The traditional concept of a stable production environment gradually disappears.
Organizations instead operate within an environment of continuous evolution.
This has profound implications for cybersecurity.
Security can no longer rely primarily on implementation assurance.
Implementation assurance answers a single question.
“Was the environment secure when we went live?”
That question remains important.
It is no longer sufficient.
Operational assurance asks something entirely different.
“Is the environment still secure today?”
And perhaps even more importantly:
“Will it remain secure tomorrow?”
These questions require fundamentally different governance models.
Annual assessments become insufficient.
Static documentation quickly loses relevance.
Architecture diagrams become outdated.
Risk registers require continuous review.
Identity governance becomes ongoing.
Detection engineering never stops.
Recovery planning evolves continuously.
Security becomes operational rather than project-based.
The organizations that struggle most with SAP RISE are rarely those that implement weak security controls.
They are those that assume yesterday’s controls automatically remain sufficient tomorrow.
Cybersecurity has always been a moving target.
Cloud platforms simply accelerate that reality.
Go-Live Is Where the Real Security Work Begins
Project teams often celebrate go-live as the successful completion of years of planning.
Executives congratulate delivery teams.
Budgets close.
Programme structures dissolve.
Operational ownership transfers to business-as-usual organizations.
From a project management perspective, this is entirely logical.
From a CISO perspective, it marks the beginning of a very different journey.
Because after go-live, something fundamental changes.
The organization no longer evaluates planned architecture.
It governs living architecture.
The difference is profound.
During implementation, assumptions dominate.
Design assumptions.
Capacity assumptions.
Security assumptions.
Provider assumptions.
Compliance assumptions.
After go-live, assumptions must gradually be replaced by evidence.
Evidence that identities remain governed.
Evidence that privileged access remains appropriate.
Evidence that monitoring still detects meaningful threats.
Evidence that recovery remains achievable.
Evidence that business processes continue operating securely despite constant change.
This transition from implementation assurance to operational assurance represents one of the defining responsibilities of the modern CISO.
Unfortunately, many organizations underestimate its importance.
Security governance often decreases after implementation.
Exactly when it should mature.
Successful SAP RISE programmes therefore establish governance mechanisms before the project concludes.
Operational architecture reviews.
Continuous risk assessments.
Identity governance cycles.
Provider assurance reviews.
Recovery exercises.
Security telemetry validation.
AI governance.
Executive reporting.
These activities are not operational overhead.
They are the mechanisms that preserve confidence in a continuously changing enterprise platform.
The most resilient organizations understand a simple truth.
Go-live is not the finish line.
It is the point where governance becomes more important than implementation.
The CISO Is No Longer a Project Reviewer—But a Control Architect
For many years, CISOs were invited into transformation programmes at specific milestones.
Review the architecture.
Assess the risks.
Approve the security concept.
Validate compliance.
Support go-live.
The project continued.
The CISO moved on to the next initiative.
That operating model no longer reflects how modern enterprise platforms evolve.
SAP RISE continuously changes after implementation.
Consequently, the CISO’s role must also evolve.
The modern CISO should no longer be viewed primarily as a security reviewer.
The CISO becomes the architect of organizational control.
That distinction is significant.
A reviewer evaluates decisions that have already been made.
A control architect helps design the mechanisms that allow the organization to remain secure as future decisions are made.
Those mechanisms extend far beyond traditional cybersecurity.
They include governance.
Operational resilience.
Identity.
Provider assurance.
Artificial intelligence.
Risk ownership.
Recovery.
Executive reporting.
Security architecture therefore becomes only one component of a much larger governance system.
The CISO should continuously ask questions that project teams often overlook.
Can we independently verify provider activities?
Can we investigate incidents without assumptions?
Can we understand every privileged identity?
Can we prove regulatory compliance with evidence rather than documentation?
Can we recover business operations if multiple providers are simultaneously affected?
Can we govern AI before AI begins governing us?
These questions rarely delay projects.
Instead, they prevent organizations from discovering uncomfortable truths after implementation.
Control is not established through policies.
It is established through continuously functioning governance mechanisms.
The CISO is responsible for ensuring those mechanisms exist long after implementation has finished.
Identity Becomes a Living Security Boundary
Identity has always been important.
Within SAP RISE, it becomes fundamental.
Traditional ERP environments primarily authenticated users.
Modern enterprise ecosystems authenticate everything.
Human users.
Administrators.
External consultants.
Suppliers.
Applications.
Integration services.
Machine identities.
Certificates.
Containers.
APIs.
Business workflows.
Robotic Process Automation.
AI agents.
Autonomous processes.
Each identity represents a potential pathway into critical business processes.
The growing number of identities is not the greatest challenge.
The challenge is that relationships between identities evolve continuously.
Partners change.
Services expand.
Applications integrate.
Temporary permissions become permanent.
Emergency accounts remain active.
Machine identities multiply silently.
AI agents request additional permissions.
Without continuous governance, identity complexity gradually exceeds organizational understanding.
This creates one of the greatest long-term risks within SAP RISE.
Organizations often know who their employees are.
They frequently struggle to explain which non-human identities currently possess privileged access.
From a CISO perspective, identity governance therefore becomes an operational discipline rather than an administrative process.
Periodic access reviews remain valuable.
Continuous identity assurance becomes essential.
Organizations should understand:
Who can access business-critical processes?
Who authorizes privileged changes?
Who governs machine identities?
Who owns certificates?
Who validates trust relationships?
Who reviews AI identities?
Identity governance is no longer simply about authentication.
It increasingly determines whether organizations remain capable of governing their own enterprise.
Security Validation Must Become Continuous
Historically, security validation largely occurred before production.
Architecture reviews.
Configuration assessments.
Penetration testing.
Compliance verification.
Acceptance documentation.
These activities remain important.
They simply no longer provide lasting assurance.
Cloud environments continuously evolve.
Security assurance must evolve with them.
Validation therefore becomes a permanent operational capability.
Configuration should continuously be evaluated.
Identity continuously reviewed.
Detection continuously tested.
Recovery continuously exercised.
Provider assurances continuously verified.
This represents a profound cultural change.
Security no longer validates projects.
Security validates operations.
One practical consequence concerns penetration testing.
Many organizations still perform penetration tests annually.
That frequency reflected traditional infrastructure lifecycles.
Modern cloud ecosystems evolve monthly.
Sometimes weekly.
Testing strategies therefore require corresponding adaptation.
The objective is not simply increasing testing frequency.
It is aligning validation with operational change.
Every significant architectural change should trigger security evaluation.
Every major integration should trigger risk assessment.
Every AI capability should trigger governance review.
Every privileged access model should be periodically challenged.
The same principle applies to recovery.
Recovery documentation provides limited assurance.
Recovery exercises create confidence.
Organizations rarely discover weaknesses because documentation is incomplete.
They discover weaknesses because assumptions prove incorrect during realistic scenarios.
Operational validation therefore becomes one of the defining characteristics of mature SAP RISE governance.
AI Changes the Security Lifecycle Forever
Artificial intelligence introduces a completely new dimension into SAP governance.
Unlike traditional software features, AI continuously learns, evolves and influences decision-making.
The security implications therefore extend far beyond technology.
SAP’s growing AI ecosystem—including Joule, Business Data Cloud, intelligent automation and future autonomous capabilities—changes how organizations operate.
Business users increasingly rely on AI-generated recommendations.
Operational decisions become supported by intelligent assistants.
Knowledge becomes contextual.
Processes become adaptive.
Security must therefore expand its scope.
Traditional cybersecurity focused primarily on protecting systems.
Modern cybersecurity must also govern decision support.
The CISO should begin asking questions that previously belonged to entirely different disciplines.
What business decisions increasingly depend upon AI?
Can those recommendations be independently verified?
Who validates model behaviour?
Who governs prompts?
How are AI agents authorized?
Can AI-generated actions be audited?
Can organizations reconstruct why recommendations were made?
What happens if AI services become unavailable?
These questions are no longer theoretical.
As AI becomes embedded within enterprise platforms, they become governance requirements.
Organizations that wait until autonomous processes dominate business operations will discover that effective governance becomes significantly more difficult.
AI governance therefore cannot become a separate programme operating independently of SAP governance.
The two are rapidly converging.
Future SAP governance will increasingly become AI governance.
And future AI governance will increasingly depend upon enterprise architecture.
The Supply Chain Never Stops Expanding
Enterprise platforms rarely operate in isolation.
SAP RISE increasingly connects organizations with suppliers, logistics providers, financial institutions, customers, cloud services, external APIs and business partners.
Every connection creates business value.
Every connection also expands the trust boundary.
Traditional third-party risk management often evaluates suppliers before onboarding.
Contracts are signed.
Security questionnaires completed.
Due diligence concluded.
The relationship becomes operational.
Unfortunately, operational reality does not remain static.
Suppliers change.
Subcontractors appear.
Cloud providers evolve.
APIs are modified.
New integrations emerge.
Identity relationships expand.
Artificial intelligence begins consuming external information.
The supply chain therefore becomes dynamic rather than static.
This fundamentally changes supplier governance.
Periodic assessments remain necessary.
Continuous supplier assurance becomes increasingly important.
The CISO should understand not only who current suppliers are.
The CISO should understand:
Which suppliers influence critical business processes?
Which providers operate privileged infrastructure?
Which partners process sensitive information?
Which APIs represent critical dependencies?
Which AI services introduce external decision support?
Which provider failures could interrupt essential operations?
Supply chain governance therefore evolves beyond procurement.
It becomes enterprise resilience.
The objective is not eliminating external dependency.
The objective is ensuring that external dependency never becomes uncontrolled dependency.
Executive Governance Must Continue After the Project Ends
One of the most common mistakes in major transformation programmes is dissolving governance structures immediately after successful implementation.
Steering committees disappear.
Executive reporting becomes less frequent.
Security oversight returns to operational routines.
Risk discussions gradually lose strategic attention.
This creates a dangerous governance vacuum.
Cloud platforms continue evolving.
Executive oversight often does not.
The CISO should therefore advocate for governance structures that survive implementation.
Not because projects failed.
Because projects succeeded.
Successful transformation creates a permanent operating model.
Permanent operating models require permanent governance.
Executive management should therefore continue receiving meaningful security information long after go-live.
Not implementation metrics.
Operational governance metrics.
Examples include:
- Identity governance maturity
- Provider assurance status
- Recovery readiness
- Detection capability
- AI governance maturity
- Dependency concentration
- Supply chain resilience
- Operational risk trends
- Executive risk acceptance
- Strategic control indicators
These discussions belong at Board level.
Not because executives require technical detail.
But because digital transformation increasingly shapes enterprise risk.
The most successful SAP RISE programmes are not those that finish fastest.
They are those that establish governance capable of adapting for the next decade.
Because implementation eventually ends.
Leadership never does.
Operational Assurance Is the New Measure of Success
For decades, organizations measured the success of enterprise transformation through familiar indicators.
Projects delivered on time.
Budgets remained under control.
Systems became available.
Business processes continued operating.
Audit findings were closed.
Compliance certificates were issued.
These remain valuable achievements.
They are no longer sufficient.
Modern enterprise platforms require a different definition of success.
Operational assurance.
Operational assurance is the continuous ability to demonstrate—not merely assume—that critical business processes remain secure, resilient and under organizational control despite constant change.
This distinction is subtle.
Its implications are profound.
Implementation assurance asks:
“Did we build the right environment?”
Operational assurance asks:
“Can we continuously prove that the environment remains trustworthy?”
That requires evidence rather than assumptions.
Evidence that privileged identities remain governed.
Evidence that provider obligations continue to be fulfilled.
Evidence that monitoring still detects meaningful threats.
Evidence that recovery remains achievable.
Evidence that AI-assisted business processes continue operating within acceptable risk boundaries.
Evidence that executive management retains informed oversight.
The objective is no longer maintaining static compliance.
It is maintaining dynamic confidence.
This represents a significant evolution in enterprise cybersecurity.
Security programmes increasingly become assurance programmes.
The role of the CISO therefore shifts from protecting technology to continuously validating trust.
What Boards Should Ask About SAP RISE
Boards rarely need technical detail.
They require confidence that enterprise risk remains understood and governed.
Unfortunately, many executive dashboards continue focusing primarily on project delivery metrics.
Migration progress.
Infrastructure availability.
Budget consumption.
Service levels.
Patch status.
These indicators describe activity.
They do not necessarily describe control.
Executive management should increasingly ask different questions.
- Control
Can we independently govern our critical SAP environment?
Do we understand where operational control begins and ends?
- Identity
Do we know every privileged identity—including machine identities and AI agents?
Can we continuously verify that access remains appropriate?
- Visibility
Can we independently investigate security incidents?
Do we possess sufficient evidence without relying entirely on provider-generated information?
- Recovery
Can we restore business operations under realistic crisis conditions?
Have we recently demonstrated that capability?
- Dependency
Which external providers represent strategic operational dependencies?
How concentrated have those dependencies become?
- Artificial Intelligence
Where does AI already influence business decisions?
How is that governance exercised?
Can recommendations be challenged?
Can automated actions be explained?
These questions are not intended to discourage innovation.
They ensure that innovation remains governed.
Cloud transformation should reduce technical complexity.
It should never reduce executive visibility.
Executive Recommendations
SAP RISE represents one of the most significant changes many organizations will make to their digital operating model.
The objective should never be to resist that transformation.
The objective should be to govern it deliberately.
Several strategic principles have become increasingly important.
Treat SAP RISE as a Permanent Governance Programme
Implementation eventually finishes.
Governance never does.
Executive sponsorship, security oversight and operational assurance should continue throughout the lifecycle of the platform.
Move from Security Reviews to Continuous Verification
Security cannot depend upon one-time assessments.
Organizations should establish recurring validation of identities, monitoring, recovery, provider assurance and architectural dependencies.
Continuous verification creates continuous confidence.
Design for Control Rather Than Compliance
Compliance demonstrates conformity with external requirements.
Control demonstrates the organization’s ability to govern itself.
The latter should always remain the strategic objective.
Govern Identity as Enterprise Infrastructure
Identity increasingly represents the primary security boundary.
Human users, machine identities, APIs, certificates and AI agents require continuous governance rather than periodic administration.
Build Independent Visibility
Provider dashboards remain valuable.
Independent enterprise monitoring remains essential.
Organizations should preserve the ability to investigate, correlate and validate security events using evidence under their own governance.
Exercise Recovery Under Realistic Conditions
Recovery documentation provides assurance only on paper.
Operational resilience is demonstrated through exercises that include degraded services, provider disruption, identity compromise and complex business scenarios.
Integrate AI Governance into SAP Governance
Artificial intelligence should not become a parallel governance initiative.
Its identities, data, decision-making, permissions and risks increasingly belong within enterprise security architecture.
Measure Operational Dependency
Every organization should understand where operational dependency exists.
Identity.
Monitoring.
Recovery.
Knowledge.
Artificial intelligence.
Business Data Cloud.
Third-party integrations.
Dependencies cannot be eliminated.
They can—and should—be governed.
Conclusion – Governance Is the Product
The greatest misconception surrounding SAP RISE is not technological.
It is organizational.
Many transformation programmes still assume that the primary objective is implementing a secure cloud platform.
That objective is incomplete.
Cloud platforms continuously evolve.
Artificial intelligence continuously evolves.
Business processes continuously evolve.
Threat actors continuously evolve.
Governance must therefore evolve as well.
Security is no longer a deliverable.
It is an operational capability.
The CISO no longer simply protects infrastructure.
The CISO protects organizational confidence.
Confidence that business processes remain trustworthy.
Confidence that risks remain understood.
Confidence that providers continue performing their responsibilities.
Confidence that identities remain governed.
Confidence that recovery remains achievable.
Confidence that executive management retains meaningful control.
Ultimately, SAP RISE is not simply about moving ERP into the cloud.
It represents a redesign of how organizations operate, govern and make decisions.
Technology enables that transformation.
Governance determines whether it succeeds.
The organizations that will benefit most from SAP RISE over the coming decade will not necessarily be those with the fastest implementations.
They will be those that continuously verify, challenge and improve the operating model they have created.
Because digital transformation is never finished.
Neither is cybersecurity.
And neither is governance.
The future of enterprise resilience will therefore not be determined by the quality of implementation alone.
It will be determined by the quality of continuous governance.
That is why SAP RISE is never “set and forget.”
It is—and always will be—a permanent governance programme.
For the modern CISO, that is not an operational burden.
It is one of the most important strategic responsibilities of digital leadership.
Publication Note & Disclaimer
This article was originally published on LinkedIn on April 15, 2025 and may have been edited or updated for publication on this site.
It reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion