What is the SAP Cybersecurity Buyers Guide from SAPinsider?

The SAP Cybersecurity Buyers Guide from SAPinsider is an independent, expert-led assessment designed to help organizations evaluate technology vendors and consultants for SAP security. It provides critical insights into the capabilities required to protect mission-critical SAP environments against modern threats like ransomware, unauthorized access, and data breaches. Executive Summary As SAP landscapes evolve toward cloud-based […]

Maximize Your SAP Security Budget: How to Cut Costs Without Downgrading Cybersecurity

Organizations can maximize their SAP security budgets by shifting from costly third-party tools to native SAP Application Lifecycle Management (ALM) platforms. By eliminating redundant solutions, automating manual patching and compliance audits, tuning security alerts to reduce noise, and streamlining incident response, teams can improve their security posture while simultaneously lowering operational costs. Executive Summary Economic […]

What’s New in the Cybersecurity Extension for SAP

The new release of the Cybersecurity Extension for SAP (CES) brings enhanced threat detection and configuration checks to SAP environments, including CVE/CVSS integration for security notes, directory traversal protection, and expanded Indicators of Compromise (IOC) patterns for Microsoft Server platforms, all designed to improve SAP security posture and compliance. Executive Summary The latest release of […]

Securing the Journey to SAP S/4HANA: A Security Framework for S/4HANA Migrations

How can organizations secure their transition to SAP S/4HANA? Organizations must restructure access and technical controls to address significant differences between SAP ERP and S/4HANA. A comprehensive security framework, aligned with best practices, is essential to mitigate vulnerabilities during migration, especially when moving custom programs or transitioning to cloud-based S/4HANA installations. Executive Summary The transition […]

Securing Microsoft Platforms with the Cybersecurity Extension for SAP

The Cybersecurity Extension for SAP secures Microsoft platforms integrated with SAP by scanning for vulnerabilities across database and operating system layers. It detects over 300 security weaknesses in Microsoft SQL Server and Windows Server, while monitoring logs for indicators of compromise to prevent threat actors from bypassing application-level security. SAP systems are complex ecosystems where the application […]

Securing the SYSTEM User in SAP HANA

The SYSTEM user is the most powerful database user in SAP HANA with system-wide privileges including permissions to create and maintain other users, perform system changes, stop and start services, and create and drop databases and tables. The user is created during the initial setup of SAP HANA. Once the system is setup, the SYSTEM […]

Securing Software Supply Chains for SAP Systems

Software supply chain attacks are advanced cyberattacks that target information systems through third party software. Threat actors compromise systems and data by exploiting software builds or interfaces for trusted software. This enables attackers to introduce malware without detection including backdoors. The recent software supply chain attack experienced by SolarWinds is widely regarded as one of […]

Webinar Playback: Protecting SAP Systems from Ransomware Attacks

Ransomware is headline news, and recent attacks have demonstrated the devastating impact of attacks that target critical infrastructure. According to the Department of Homeland Security ransomware attacks have increased by 300% over the past year, impacting all industries and sectors. The average downtime from an attack is 21 days, but full recovery takes an average […]

Cybersecurity Extension for SAP Identifies Signatures of Active SAP Cyberattacks

Earlier this month, SAP issued a joint report with a security research firm to highlight active cyber threats targeting SAP applications. According to the report, there is conclusive evidence that attackers are actively targeting and exploiting unsecured SAP applications. The report also reveals that some SAP vulnerabilities are being weaponized in less than 72 hours […]

Securing Linux Platforms for SAP HANA and S/4HANA

SUSE Linux Enterprise Server (SLES) is the leading operating system for SAP HANA and SAP S/4HANA solutions, supporting 85 percent of HANA deployments worldwide. SLES for SAP Applications is optimized to support high availability and persistent memory and endorsed by SAP. Securing operating systems is a critical component of SAP system hardening. Vulnerable hosts can […]