Skip to content

How to use the S/4HANA migration to increase your security posture 

S/4HANA migration

“There are a few constants in life” – a statement that also applies to the SAP user community. It has always been a challenge for SAP customers to bring their large SAP environments to a current release level. Although the vendor has done a lot in the past to simplify this, it is still not a complex undertaking. However, the S/4HANA migration comes with more stumbling blocks that facilitate a chance to rethink the current SAP Cybersecurity approach. 

What is the S/4HANA migration?

In keeping with the current zeitgeist, every SAP customer is talking about S/4HANA migration or S/4HANA transformations. Although the transformation has a much broader business context, it pursues the same goals as the migration. After the project, customers intend to take full advantage of the new functions of the S/4HANA product portfolio.   

Take your chance

With these – sometimes dramatic – changes that organizations undergo in a S/4HANA transformation, there is an opportunity to integrate cybersecurity thinking directly into the architecture and create a secure foundation for future processes and innovations. To paraphrase one of our partners: “Security should be built-in, instead of added on”. 

Starting situation: SAP NetWeaver

Many of the customers we speak with have had SAP environments in place for several years. And so, it is no surprise many are practicing cyber hygiene but have not been able to integrate cybersecurity into their processes and architecture from the ground up. But that is no reason to bury your head in the sand. With the upcoming S4/HANA project, there is an opportunity to make up for this omission from the past. 

What has changed?

I think some experienced SAP experts will ask themselves what makes this “upgrade” project different from the previous ones and what has changed that now leads to this new possibility.  

In my view, there are primarily three things:  

  • Prioritization of cybersecurity: Management has a clear view of the challenge and supports the measures that are necessary for cyber protection.  
  • Innovation in SAP Cybersecurity: Today, it is possible to monitor the security-relevant actions and transactions in the SAP application with a manageable team. The level of automation provided by SecurityBridge, for example, makes it possible to respond to incidents.  
  • Technology shift: Due to the technological change from SAP NetWeaver to S/4HANA, the established process often must be touched. With each change, reliability and efficiency should increase. If we take a file-based interface as an example, you should aim to switch to APIs and encrypt data in transfer.  

Aim high and don't settle for less.

Take the opportunity and put “cyber resilience” on the list of project goals at the very beginning of a project. Include qualified consultants or in-house security architects in all project set-up discussions. Ask how to maintain the achieved security state in the long term. Additionally, please do not forget to integrate efficient SAP Vulnerability Management in the implementation of your project. This includes:  

  • Vulnerability scan  
  • Patching  
  • Custom code vulnerability analysis  
  • Threat detection  

Are you looking for a qualified System Integrator (SI) to address these issues? We will be happy to provide a recommendation. Please do not hesitate to contact us. 

Posted by

Christoph Nagy

Find recent Security Advisories for SAP©

Looking into securing your SAP landscape? This white-paper tells you the “Top Mistakes to Avoid in SAP Security“. Download it now.

SAP security by design
SAP Cybersecurity
Christoph Nagy

6 Principles for Security-by-design for SAP

Security-by-design is a principle that emphasizes the need to build security measures into software systems from the start rather than as an afterthought.

SAP projects need to embed security conciseness to respect this principle and gain a cyber-resilient application. Thus, they should prioritize security when designing and implementing their SAP systems rather than attempting to bolt on security measures afterward. This can help to prevent security breaches and minimize the damage caused by cyberattacks.

Read More »
SAP security by design
Security-by-design is a principle that emphasizes the need to build security measures into software systems from the start rather than as an afterthought. SAP projects need to embed security conciseness to respect this principle and gain a cyber-resilient application. Thus, they should prioritize security when designing and implementing their SAP systems rather than attempting to bolt on security measures afterward. This can help to prevent security breaches and minimize the damage caused by cyberattacks.
coding
Remote Code Execution (RCE) vulnerability in SAP is a type of security issue that allows an attacker to execute arbitrary code on a target system remotely. has gained control of a user's click, they can execute a range of actions, such as transferring funds, changing user settings, or stealing sensitive data.
Management Dashboard
SAP security provider SecurityBridge—now operating in the U.S.—today announced the latest addition to the SecurityBridge Platform—the Management Dashboard for SAP security. The SAP Management Dashboard is a no-cost, additional application for the existing SecurityBridge Platform that combines all SAP data aspects and presents the information through a customizable, single pane of glass security dashboard view.
Hacker mining SAPsecurity
SAP Cybersecurity- SAP Vulnerability
In recent years, cyberattacks against SAP systems have become more common, with attackers gaining network access and then exploring critical applications through port scanning and script-based exploration. Two examples of such attacks that use the SAP RFC SDK are the password lock attack and the password spray attack. In this article, we will outline how to detect these script-based attacks against SAP.