14 min read

The SAP RISE Steering Committee Is Incomplete Without the CISO

Every SAP RISE Steering Committee already makes security decisions. The real question is not whether the CISO should have a seat at the table, but whether enterprise transformation can be governed without the executive responsible for resilience, operational control and digital sovereignty.
The SAP RISE Steering Committee Is Incomplete Without the CISO
Image by Pexels from Pixabay

Why Enterprise Transformation Requires Security Governance from the Very First Decision


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


Every major SAP RISE programme establishes a Steering Committee.

The agenda is familiar.

Business objectives.

Budget.

Timeline.

Transformation milestones.

Resources.

Implementation status.

Vendor performance.

Programme risks.

Executives meet regularly to review progress and make strategic decisions that shape the future of the organization.

At first glance, these discussions appear to concern delivery.

In reality, they determine something far more important.

They determine how the organization will operate for the next decade.

  • Every decision about architecture.
  • Every decision about cloud services.
  • Every decision about providers.
  • Every decision about integrations.
  • Every decision about identity.
  • Every decision about disaster recovery.
  • Every decision about artificial intelligence.
  • Every decision about operational responsibilities.

Gradually defines the future security posture of the enterprise.

This is why the traditional discussion surrounding the CISO’s participation in SAP RISE programmes has become outdated.

Many organizations still ask:

“Should the CISO have a seat at the Steering Committee?”

That is no longer the right question.

The more important question is:

Can a Steering Committee govern enterprise transformation without understanding the long-term security consequences of its own decisions?

From a governance perspective, the answer is increasingly becoming no.

The misconception originates from an outdated perception of cybersecurity.

Historically, security was often treated as a technical control function.

Projects designed solutions.

IT implemented them.

Security reviewed them.

Audit verified them.

Business accepted the residual risk.

This sequence reflected traditional infrastructure projects.

SAP RISE fundamentally changes that model.

Modern enterprise platforms continuously evolve.

Architecture changes after implementation.

Artificial intelligence becomes integrated.

Business ecosystems expand.

Operational dependencies increase.

Identity relationships multiply.

Provider responsibilities evolve.

Security therefore cannot remain an approval activity performed shortly before go-live.

It must become part of strategic governance from the very first decision.

The Steering Committee already governs enterprise risk.

Whether it recognizes it or not.

Every architectural decision influences future resilience.

Every procurement decision influences future dependency.

Every identity decision influences future trust.

Every provider decision influences future operational capability.

Every AI decision influences future governance.

Ignoring those dimensions does not eliminate them.

It merely transfers them into the future.

Usually at significantly higher cost.

The CISO therefore does not attend the Steering Committee to represent Information Security as an isolated discipline.

The CISO represents something much broader.

The organization’s ability to retain control while transforming itself.

That distinction fundamentally changes the role of cybersecurity.

The CISO is not another stakeholder.

The CISO is one of the executives responsible for ensuring that transformation never compromises enterprise resilience.


SAP RISE Is a Governance Decision — Not an IT Decision

Organizations often describe SAP RISE as a cloud migration.

Technically, that description is correct.

Strategically, it is incomplete.

Moving ERP workloads into a managed cloud environment certainly changes technology.

It changes much more than technology.

It changes how responsibilities are distributed.

How operational control is exercised.

How evidence is generated.

How recovery is organized.

How providers interact with the enterprise.

How digital trust is maintained.

These are governance questions.

Not infrastructure questions.

A Steering Committee therefore does not merely decide how software should be implemented.

It decides how the organization itself will operate.

Should privileged administration remain internal?

Who governs identities?

How should cryptographic trust be managed?

Who owns operational telemetry?

How will recovery priorities be determined?

What dependencies become acceptable?

How should AI capabilities be introduced?

Each answer shapes enterprise governance.

Long before the first productive transaction occurs.

Many Steering Committees unintentionally approach these topics from a project perspective.

Cost.

Schedule.

Resources.

Technical feasibility.

Those factors remain important.

They are not sufficient.

Governance requires balancing opportunity with long-term consequence.

Some decisions cannot realistically be reversed after implementation.

Identity architecture.

Business Data Cloud integration.

Disaster recovery concepts.

Provider operating models.

Artificial intelligence.

Logging architecture.

These become structural characteristics of the future enterprise.

The Steering Committee therefore performs one of the organization’s most important governance functions.

It designs the future operating model.

Cybersecurity cannot review that operating model after it exists.

It must help shape it while decisions are still reversible.


Every Steering Committee Already Makes Security Decisions

One of the greatest misconceptions surrounding enterprise transformation is the belief that security decisions occur during security workshops.

They do not.

They occur throughout the entire programme.

Often without anyone explicitly recognizing them.

Consider a typical Steering Committee meeting.

An executive proposes accelerating implementation by postponing privileged access management.

Another suggests delaying disaster recovery because budgets are constrained.

Someone recommends reducing penetration testing before go-live.

A provider proposes standard administrative processes instead of customer-specific controls.

Business requests additional external integrations.

Artificial intelligence capabilities are introduced to improve productivity.

None of these agenda items may carry the label “security.”

Every one of them changes enterprise risk.

Every one of them influences operational resilience.

Every one of them affects governance.

Security decisions rarely announce themselves.

They frequently appear disguised as business decisions.

That reality makes executive governance particularly important.

The Steering Committee cannot avoid making security decisions.

The only question is whether those decisions are made consciously.

Without appropriate security representation, organizations often optimize locally.

Projects become faster.

Budgets become smaller.

Complexity appears reduced.

Only later do the long-term consequences emerge.

Provider dependency increases.

Identity complexity expands.

Operational visibility decreases.

Recovery becomes more difficult.

AI governance remains undefined.

Residual risk accumulates gradually.

None of these outcomes usually results from poor intentions.

They result from incomplete decision-making.

Good governance requires understanding second-order consequences.

That is precisely where the CISO contributes.

Not by preventing innovation.

By ensuring innovation remains governable.


The CISO Represents Enterprise Risk — Not IT Security

Many organizations continue viewing the CISO primarily as the senior security specialist.

This perception no longer reflects reality.

Modern CISOs operate at the intersection of business, technology and governance.

Their responsibility extends far beyond protecting systems.

They help executive management understand how technology decisions influence enterprise risk.

This distinction matters enormously within SAP RISE.

Project managers naturally focus on delivery.

Architects focus on technical feasibility.

Infrastructure teams focus on operational stability.

Business leaders focus on organizational value.

Finance focuses on investment.

Procurement focuses on contractual relationships.

Every perspective is necessary.

None of them independently represents enterprise cyber risk.

The CISO fills that gap.

Not because cybersecurity is more important than business.

Because cyber risk increasingly shapes business itself.

Operational resilience.

Regulatory exposure.

Data protection.

Digital sovereignty.

Provider dependency.

Identity governance.

Artificial intelligence.

Business continuity.

These subjects extend well beyond traditional IT.

They increasingly influence strategic decision-making.

This broader mandate also changes how the CISO participates in governance.

The CISO should not merely review proposed solutions.

The CISO should continuously help the Steering Committee understand the strategic implications of its decisions.

For example:

If this provider relationship changes, what happens to operational control?

If AI becomes embedded within critical business processes, how will governance evolve?

If identities become distributed across multiple platforms, who retains authority?

If a geopolitical event affects cloud operations, how resilient is the architecture?

If regulations change, how adaptable is today’s design?

These are executive questions.

Not technical questions.

The CISO’s value therefore lies less in identifying individual vulnerabilities.

It lies in identifying governance consequences before they become operational realities.

That is why the CISO represents enterprise risk rather than simply Information Security.

And that is why the Steering Committee becomes stronger—not slower—when that perspective is present.


Security Cannot Vote After the Architecture Exists

One of the most expensive assumptions in enterprise transformation is the belief that security can always be added later.

Experience consistently demonstrates the opposite.

Architecture establishes possibilities.

Governance determines choices.

Once architectural foundations become operational, many governance options become significantly more expensive—or practically impossible—to change.

Identity ecosystems become established.

Provider relationships mature.

Business processes depend upon integrations.

Artificial intelligence becomes embedded.

Operational procedures stabilize.

Recovery strategies become institutionalized.

Changing direction later rarely represents a technical challenge alone.

It becomes an organizational challenge.

This is precisely why the CISO belongs inside strategic governance from the beginning.

Not to approve technology.

Not to delay implementation.

But to ensure that decisions remain aligned with the organization’s long-term ability to govern itself.

Transformation programmes often celebrate speed.

Leadership should celebrate reversibility.

Good governance preserves options.

Poor governance quietly eliminates them.

The Steering Committee therefore carries a responsibility that extends far beyond successful implementation.

It shapes the enterprise’s future freedom of action.

The CISO’s role is to ensure that today’s transformation decisions do not become tomorrow’s strategic constraints.

Because once the architecture exists…

Security can improve it.

Governance can optimize it.

Operations can mature it.

But none of them can easily recover opportunities that were never designed into the operating model in the first place.


Security Cannot Be Reviewed After Governance Has Been Decided

Many organizations still follow a governance pattern that reflects the era of traditional infrastructure projects.

The Steering Committee approves strategic direction.

Architects translate those decisions into technical designs.

Implementation teams build the solution.

Near the end of the programme, security performs its review.

From a compliance perspective, this appears reasonable.

From a governance perspective, it is fundamentally flawed.

By the time the security review begins, the most important decisions have already been made.

The cloud provider has been selected.

The operating model has been defined.

Identity architecture has been approved.

Business processes have been redesigned.

Recovery assumptions have been accepted.

Artificial intelligence capabilities have been introduced.

Budget has been committed.

Contracts have been signed.

Security is therefore no longer reviewing options.

It is reviewing consequences.

This distinction explains why so many security recommendations are perceived as expensive or disruptive.

The recommendations themselves are often correct.

They simply arrive after strategic decisions have become difficult to reverse.

A mature Steering Committee therefore does not ask the CISO to validate completed decisions.

It expects the CISO to shape the decisions before they become architecture.

That is one of the defining characteristics of modern enterprise governance.

Cybersecurity becomes preventative rather than corrective.

Governance becomes proactive rather than reactive.

Transformation becomes deliberate rather than optimistic.

The earlier security becomes part of executive decision-making, the less frequently organizations face expensive redesigns later.


Artificial Intelligence Has Changed the Steering Committee Forever

The Steering Committee of 2026 no longer resembles the Steering Committee of 2020.

Artificial intelligence has fundamentally expanded the scope of executive governance.

SAP RISE is increasingly becoming more than an ERP platform.

Organizations are introducing:

  • SAP Joule
  • Business Data Cloud
  • AI-assisted workflows
  • Intelligent business recommendations
  • Autonomous process automation
  • AI-powered analytics
  • Agentic capabilities
  • External AI integrations

These developments create extraordinary opportunities.

They also introduce entirely new governance questions.

Who authorizes AI access to enterprise information?

Which identities do AI agents operate under?

How are AI recommendations validated?

How are prompts governed?

Who accepts responsibility for AI-assisted decisions?

How is sensitive information protected when consumed by AI?

Can AI-generated actions be independently investigated?

Can organizations explain why an AI-supported recommendation influenced a critical business decision?

These questions cannot be delegated entirely to technology teams.

They require executive governance.

Artificial intelligence therefore changes the Steering Committee itself.

Technology strategy increasingly becomes AI strategy.

Cloud governance increasingly becomes AI governance.

Cybersecurity increasingly becomes decision governance.

The CISO contributes an essential perspective.

Not because AI should be restricted.

Because AI should remain governable.

Organizations that introduce AI without corresponding governance frequently discover that operational complexity increases faster than organizational understanding.

Responsible innovation therefore begins with responsible governance.


The Steering Committee Governs Enterprise Control

Traditional project governance focused on delivering systems.

Modern governance focuses on preserving enterprise control.

That difference is profound.

Every Steering Committee should regularly examine whether the organization continues to retain meaningful control across several strategic domains.

Identity

Who ultimately governs trust?

Can privileged identities be independently managed?

Are machine identities continuously reviewed?

Do AI agents operate within clearly defined authorization boundaries?

Operational Visibility

Can the organization independently observe critical events?

Does the Security Operations Center possess sufficient telemetry?

Can incidents be investigated without relying entirely on provider-generated evidence?

Recovery

Can business processes be restored under realistic conditions?

Have recovery assumptions recently been exercised?

Who determines recovery priorities during complex disruptions?

Provider Dependency

Which providers have become operationally critical?

What happens if contractual relationships change?

Can essential business capabilities continue operating under adverse conditions?

Artificial Intelligence

Where is AI already influencing operational decisions?

Who governs those capabilities?

Can AI recommendations be challenged?

Can AI-generated actions be explained?

Digital Sovereignty

Does the organization continue controlling its own identities?

Its own cryptographic trust?

Its own operational decisions?

Its own evidence?

Its own strategic direction?

These are no longer technical questions.

They are governance questions.

The Steering Committee should therefore measure enterprise control with the same discipline applied to financial performance or operational delivery.

Control is not automatically preserved through successful implementation.

It must be continuously governed.


The CISO Is Not There to Slow Transformation

One of the oldest misconceptions in cybersecurity is that security delays projects.

That perception often emerges because security becomes visible only when risks have already accumulated.

The CISO identifies architectural weaknesses.

Requests additional controls.

Challenges assumptions.

Recommends redesign.

From the perspective of implementation teams, these interventions appear to introduce friction.

In reality, the friction was created much earlier.

It originated when governance decisions were made without understanding their long-term consequences.

The CISO simply makes those consequences visible.

This distinction is important.

Security does not oppose transformation.

Poor governance does.

The objective of the CISO is not to create additional approval gates.

It is to prevent avoidable strategic mistakes.

Well-governed transformation programmes usually progress faster over time.

Architectural rework decreases.

Unexpected compliance issues become less frequent.

Recovery concepts mature earlier.

Identity governance becomes more consistent.

Operational confidence increases.

Executive management makes decisions with greater clarity.

The CISO therefore accelerates sustainable transformation.

Not by reducing security.

By reducing uncertainty.

Transformation programmes succeed when executives understand both opportunities and consequences.

The CISO contributes precisely that perspective.


Governance Does Not End at Go-Live

Many Steering Committees dissolve shortly after implementation.

Project structures disappear.

Governance meetings become less frequent.

Operational ownership transfers to business-as-usual organizations.

From a project perspective, this appears entirely logical.

From a governance perspective, it creates a significant gap.

SAP RISE does not stop evolving after go-live.

Neither do enterprise risks.

Provider services continue changing.

Business processes continue expanding.

Identity relationships continue growing.

Artificial intelligence becomes increasingly integrated.

Regulatory expectations continue evolving.

Threat actors continuously adapt.

Why should governance become weaker precisely when complexity becomes greater?

It should not.

Successful organizations therefore redesign governance after implementation rather than abandoning it.

Project governance evolves into operational governance.

The Steering Committee may change composition.

Its strategic responsibility remains.

Executive oversight should increasingly focus on operational assurance rather than implementation status.

Identity maturity.

Provider assurance.

Recovery readiness.

Dependency concentration.

AI governance.

Operational resilience.

Enterprise control.

These become long-term governance themes.

Transformation eventually ends.

Leadership does not.

The Steering Committee therefore succeeds not because it completes a programme.

It succeeds because it establishes governance capable of supporting the enterprise throughout the entire lifecycle of its digital operating model.


What Every SAP RISE Steering Committee Should Regularly Review

The effectiveness of a Steering Committee is not determined by the number of meetings it holds.

It is determined by the quality of the questions it asks.

Too many SAP RISE governance boards continue to focus primarily on delivery.

Budget.

Timeline.

Resources.

Milestones.

Escalations.

These indicators describe whether the programme is progressing.

They say very little about whether the organization is becoming more resilient—or more dependent.

A modern Steering Committee should therefore continuously review the governance of the operating model it is creating.

Identity Governance

Identity has become the primary security boundary of the modern enterprise.

The Steering Committee should understand:

  • Who governs privileged identities?
  • How are machine identities controlled?
  • How are AI agents authorized?
  • How are external identities reviewed?
  • How does identity architecture evolve over time?

Identity should never become an operational detail delegated entirely to implementation teams.

It represents executive risk.


Operational Visibility

Executives should periodically ask a simple question:

Can we independently understand what is happening inside our own SAP environment?

This includes:

  • Security telemetry
  • Audit evidence
  • Threat detection
  • Log ownership
  • Forensic readiness
  • Monitoring coverage

Organizations cannot govern environments they cannot independently observe.


Recovery Readiness

Recovery should not be measured by contractual Recovery Time Objectives alone.

The Steering Committee should understand:

  • Can critical business processes actually be restored?
  • Have recovery assumptions been exercised?
  • Are provider responsibilities clearly understood?
  • Can recovery priorities change dynamically during a crisis?

Operational resilience is demonstrated through evidence—not documentation.


Provider Dependency

Cloud transformation inevitably creates dependency.

Governance determines whether dependency remains acceptable.

The Steering Committee should regularly review:

  • Critical providers
  • Concentration risk
  • Exit capability
  • Contractual flexibility
  • Operational assumptions
  • Shared responsibility maturity

Dependency should never become invisible.


Artificial Intelligence

Artificial intelligence increasingly influences operational decisions.

That makes AI a governance topic rather than simply a technology topic.

The Steering Committee should understand:

  • Where AI already influences business processes
  • Which AI services process sensitive information
  • How AI recommendations are governed
  • How AI agents receive permissions
  • How AI-generated decisions remain explainable
  • How AI risk integrates with enterprise risk

AI governance belongs at executive level because AI increasingly influences executive outcomes.


Digital Sovereignty

Perhaps the most strategic governance question has become:

Does the organization continue controlling the capabilities on which it depends?

This includes:

Identity.

Cryptographic trust.

Recovery.

Operational evidence.

Decision-making.

Knowledge.

Business continuity.

Digital sovereignty is not achieved through provider selection alone.

It is achieved through continuous governance of enterprise control.


The Steering Committee Should Measure Control—Not Progress

Most Steering Committees receive project dashboards.

Modern Steering Committees should also receive governance dashboards.

These should answer a fundamentally different question.

Not:

“How far has the implementation progressed?”

But:

“How well are we governing the operating model we have created?”

Meaningful governance indicators might include:

  • Identity governance maturity
  • Privileged access assurance
  • Provider dependency trends
  • Recovery readiness
  • Operational resilience
  • Security telemetry coverage
  • AI governance maturity
  • Critical third-party dependencies
  • Residual enterprise risk
  • Executive risk acceptance
  • Dependency concentration
  • Operational assurance status

These metrics are different from operational KPIs.

They support strategic governance.

They help Boards understand whether transformation strengthens or gradually weakens enterprise resilience.

Because governance cannot improve what it does not measure.


Executive Recommendations

Every SAP RISE programme will differ.

Business priorities differ.

Regulatory environments differ.

Architectures differ.

The governance principles, however, remain remarkably consistent.

Make the CISO a Permanent Member of the Steering Committee

Not as an advisor.

Not as an observer.

As the executive responsible for ensuring that transformation decisions remain compatible with enterprise resilience.

Security is not another workstream.

It is one of the dimensions of strategic governance.


Treat Security Decisions as Executive Decisions

Every decision concerning:

  • Identity
  • Logging
  • Disaster Recovery
  • Business Data Cloud
  • Artificial Intelligence
  • Provider Selection
  • Encryption
  • Monitoring

should be recognized for what it truly is:

An executive risk decision.


Govern the Operating Model—Not Only the Project

Project governance eventually concludes.

Operational governance continues throughout the lifecycle of SAP RISE.

Steering Committees should deliberately transition from implementation oversight to operational oversight.


Demand Continuous Assurance

Governance should be based on continuously validated evidence.

Not assumptions.

Not historical project documentation.

Not contractual promises.

Executive confidence should be supported through measurable operational assurance.


Build Governance Around Trusted Boundaries

Every major architectural boundary should remain visible.

Identity.

Data.

Operational evidence.

Provider responsibility.

Recovery.

Artificial intelligence.

Security architecture succeeds when governance understands where trust begins—and where it changes.


Integrate AI Governance From the Beginning

Artificial intelligence should never become an isolated programme.

Its governance belongs within enterprise governance from the first implementation decision.

The Steering Committee should ensure that AI evolves together with enterprise control rather than independently from it.


Measure Strategic Dependency

Every organization should understand where dependency accumulates.

Not only technical dependency.

Operational dependency.

Knowledge dependency.

Identity dependency.

Provider dependency.

AI dependency.

Dependencies cannot always be avoided.

They must always remain governed.


Conclusion – The CISO Does Not Represent Security. The CISO Represents Enterprise Control.

The discussion about whether the CISO deserves a seat at the SAP RISE Steering Committee has become obsolete.

It starts from the wrong assumption.

It assumes that cybersecurity represents another specialist discipline competing for executive attention.

That is no longer true.

Every significant SAP RISE decision already influences enterprise security.

Whether the agenda concerns cloud providers, AI capabilities, identity architecture, recovery concepts, integrations or business transformation, the Steering Committee is making decisions that determine the organization’s future resilience.

The question is therefore no longer whether security should participate.

The question is whether executive governance can be considered complete without understanding the long-term consequences of those decisions.

From a modern governance perspective, it cannot.

The CISO contributes something no other executive function represents in the same way.

The long-term preservation of enterprise control.

  • Control over identities.
  • Control over trust.
  • Control over operational evidence.
  • Control over recovery.
  • Control over provider dependency.
  • Control over AI governance.
  • Control over digital sovereignty.

Cloud transformation is often described as moving systems into the cloud.

In reality, it is about redesigning how organizations govern themselves.

Technology enables that transformation.

Governance determines whether it succeeds.

The most successful SAP RISE programmes will therefore not be remembered because they delivered on time.

They will be remembered because they created an operating model that remained secure, resilient and governable long after the implementation project had disappeared.

That is why the CISO belongs at the Steering Committee.

Not to represent Information Security.

But to ensure that enterprise transformation never comes at the cost of enterprise control.


Publication Note & Disclaimer
This article was
originally published on LinkedIn on April 12, 2025 and may have been edited or updated for publication on this site.

It reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.