SAP powers some of the world's most critical business processes and that's exactly why attackers love it. Despite its importance, SAP security remains a blind spot for many security teams.
Drawing on a decade of hands-on experience defending SAP environments, this session explores why SAP systems are such attractive targets, how the threat landscape has evolved, and the security pitfalls that organizations repeatedly overlook. Through real-world lessons learned, we'll examine common misconfigurations, overlooked attack paths, and the unique challenges of securing enterprise-critical SAP systems.
Rather than focusing solely on what can go wrong, the session also provides practical guidance on improving SAP security hygiene, reducing attack surface, and preventing the issues that attackers most commonly exploit.
Whether you're a security practitioner, SOC analyst, penetration tester, or architect with little or no prior SAP experience, you'll leave with a clearer understanding of the risks hidden within SAP environments and actionable ideas to better protect one of the enterprise's most valuable assets.
This is a vendor-neutral, non-commercial session focused entirely on practical knowledge, real-world experience, and lessons learned from the field.
The talk will include the following aspects:
1. Understanding SAP in the Enterprise Landscape:
- what SAP is and its role in large organisations
- overview of the most widely used SAP products by the business, IT and OT
- business processes typically managed by SAP systems.
2. SAP Architecture and Deployment Models:
- common SAP deployment models and security considerations
- common integrations with core enterprise systems and potential pivoting possibilities
- typical trust relationships and common attack surfaces.
3. Security Challenges and Vulnerability Trends:
- the most common SAP vulnerabilities and misconfigurations
- recent security trends and attack techniques
- why SAP environments are often a blind spot for SOC and security teams.
4. Improving SAP Security and Visibility
- protection strategies for SAP environments
- detection and monitoring approaches for SOC teams
- immediate actions to strengthen SAP security posture.