From Strategy to Scale: How JTI Built Continuous SAP Security
Chapters
Share Article
Let's Talk SAP Security
Have questions about SAP Security? We’re here to help. Contact Us
When we first shared JTI’s SAP security story, the company was moving from periodic security assessments toward a more continuous approach to protecting its SAP landscape.
Since then, the journey has continued.
Today, JTI has around 50 to 60 systems connected to SecurityBridge, has expanded its use of the platform, migrated hundreds of privileged users to SecurityBridge PAM, and is bringing SAP security data into its wider security operations.
We sat down with Zaheer Safir, SAP Security Architect Manager at JTI, to hear how JTI’s SAP security approach has evolved – and what comes next.
Prefer to hear it directly from Zaheer? Watch the full interview below:
From Annual Hardening to Continuous SAP Security
Before SecurityBridge, JTI relied on traditional roles and authorization projects, alerts, and periodic hardening activities. But with vulnerabilities constantly emerging across increasingly complex SAP environments, the team recognized that an annual approach was no longer enough.
“We saw that hardening activities once a year were good, but they were not enough. We needed one product that could help us improve our security posture.”
This became one of the main reasons JTI started looking for a platform that could bring different areas of SAP security together.
During its evaluation, JTI compared SecurityBridge with other solutions and found that its breadth of capabilities matched what the team was looking for.
“SecurityBridge was the one that met all our needs. Patch management, vulnerability management, threat detection, custom code analysis – it has a lot of functionality in one tool. That was one of the key reasons why we chose SecurityBridge.”
Expanding Security Across the SAP Landscape
That initial implementation has grown considerably.
JTI now has approximately 50 to 60 systems connected to SecurityBridge, with more planned as its SAP landscape continues to evolve.
The environment already spans different SAP technologies, including SAP S/4HANA, SAP BW, SAP BTP subaccounts, and SAP Cloud Identity Services (IAS). Zaheer also points to SuccessFactors as an upcoming addition and potentially Ariba further down the road.
50–60 connected systems • S/4HANA • SAP BW • SAP BTP • IAS
This expansion reflects a broader challenge for enterprise SAP security: the landscape does not stand still. New systems, cloud services, integrations, code, and users continuously change what needs to be protected.
For JTI, SecurityBridge provides a way to bring these security capabilities together as the environment grows. Built natively inside SAP as one product on one architecture, the
SecurityBridge Platform
provides SAP-specific context and live data without introducing another external security layer.
Moving 600–700 Privileged Users to SecurityBridge PAM
One of the latest steps in JTI’s journey has been privileged access management.
JTI had previously been using SAP GRC Firefighter while other GRC functionality had already been phased out. This left the team looking for a new approach to privileged access.
Working together with SecurityBridge, JTI implemented
SecurityBridge Privileged Access Management (PAM)
and migrated approximately 600–700 users from its previous solution.
“We helped a lot to deploy a compliant, robust solution, and we moved all our users from Firefighter to PAM. So far, the expectations and the results we have seen have been very good.”
For JTI, this means another important security process is now part of the same platform already supporting other areas of its SAP security strategy.
Connecting SAP Security with the SOC
JTI is also taking SAP security beyond the SAP team by connecting SecurityBridge with its broader security operations.
Security data collected from JTI’s SAP systems is sent through SecurityBridge via API integration to
Microsoft Sentinel.
The team has already built several use cases and plans to expand this further.
“We are ingesting all the data that we are gathering from SAP systems. From SecurityBridge, we are sending it straight away via API integrations to Sentinel.”
The next step is to continue building out a broader framework of cybersecurity risks and activities within Sentinel.
Bringing SAP-specific security data and context into the SOC helps security teams incorporate business-critical SAP systems into the processes and tools they already use.
The JTI Story Continues
JTI’s SAP security journey shows what happens when security moves from periodic projects toward an ongoing process.
What started with the need to improve hardening and gain better visibility has expanded across dozens of systems, multiple areas of SAP security, privileged access management, and SOC integration.
- 50–60 systems already connected to SecurityBridge
- 600–700 privileged users migrated from SAP GRC Firefighter to SecurityBridge PAM
- S/4HANA, SAP BW, SAP BTP and IAS already within the landscape
- Microsoft Sentinel integration bringing SAP security data into JTI’s wider security operations
As new SAP technologies and systems become part of the landscape, the team plans to continue expanding its SecurityBridge coverage alongside them.
From annual hardening to continuous SAP security across a growing, connected landscape.
Want to Start at the Beginning?
Read our original JTI customer story to see how the company started implementing its security-first strategy for SAP and why it chose SecurityBridge.
See SecurityBridge in Action
Book a demo today to see how SecurityBridge’s SAP security platform provides all the tools you need to keep your SAP systems secure and compliant.
