What Are the Key Security Risks in RISE with SAP? Findings from the 2025 Benchmark Report
The SAPinsider RISE with SAP 2025 benchmark report reveals a critical security gap: widespread customer non-compliance with the shared responsibility model. The most significant failure is not implementing SAP’s mandatory security hardening requirements, leaving cloud ERP systems vulnerable and exposing organizations to significant operational, legal, and and reputational risk. The report, based on a survey of 122 […]
What’s New in the Cybersecurity Extension for SAP Version 2.0?
Version 2.0 of the Cybersecurity Extension for SAP is now available, introducing major enhancements to protect business-critical SAP solutions. Key updates include support for SAP NetWeaver AS Java, powerful anomaly detection capabilities, over 400 new threat detection patterns, and updated compliance checks for the latest SAP security benchmarks. Executive Summary Layer Seven Security’s release of the Cybersecurity […]
The Most Critical SAP Security Notes of 2024: A Complete Review
The most critical SAP security notes of 2024 addressed severe vulnerabilities, including two “hot news” notes with a 9.8 CVSS score. These critical patches fixed flaws like missing authentication in SAP BusinessObjects and code injection in SAP CX Commerce, which could lead to complete system compromise if left unpatched. In 2024, SAP released over 150 […]
New Whitepaper: A Clear Path to NIS2 Compliance for SAP Solutions
A new whitepaper from Layer Seven Security provides a clear, actionable guide for achieving compliance with the EU’s NIS2 Directive for organizations running SAP. It details hardening standards, threat detection, and incident response mechanisms specifically for SAP environments, including guidance for SAP RISE, to meet the directive’s strict cybersecurity and reporting requirements. The European Union’s […]
What’s New in Cybersecurity Extension for SAP Version 5.1?
Version 5.1 of the Cybersecurity Extension for SAP introduces significant enhancements, including comprehensive access risk analysis for S/4HANA, compliance monitoring for SAP RISE, expanded threat detection patterns matching SAP ETD CE, and new dashboards for tracking actively and known exploited vulnerabilities based on the CISA KEV catalog. The latest release, version 5.1 of the Cybersecurity Extension for […]
How to Ensure Security Compliance for SAP RISE Solutions
Securing SAP RISE solutions requires adhering to over 120 specific requirements across 12 security areas defined by SAP. Organizations can achieve this compliance by performing automated gap assessments using the Cybersecurity Extension for SAP (CES), which evaluates system settings against mandatory hardening standards to identify and remediate security vulnerabilities. SAP RISE customers, including those using […]
Security Patching for SAP Solutions: Best Practices and Challenges
Security patching for SAP solutions is the most significant action organizations can take to secure their environments against known vulnerabilities. SAP releases security notes on “Patch Tuesday,” the second Tuesday of each month, providing essential corrections. Because unpatched systems are consistently reported as a top-three threat to SAP environments, maintaining an effective patching process is […]
Cybersecurity Threats to SAP Systems: 5 Key Risks and Recommendations
Managing cybersecurity for SAP systems requires addressing unpatched vulnerabilities, ransomware, credentials compromise, system interfaces, and access controls. This report, based on the 2023 Cybersecurity Threats to SAP Systems Report, outlines actionable strategies to secure your environment using SAP ALM platforms and the Cybersecurity Extension for SAP. Executive Summary The 2023 landscape for SAP security is dominated by […]
Securing the Journey to SAP S/4HANA: A Security Framework for S/4HANA Migrations
How can organizations secure their transition to SAP S/4HANA? Organizations must restructure access and technical controls to address significant differences between SAP ERP and S/4HANA. A comprehensive security framework, aligned with best practices, is essential to mitigate vulnerabilities during migration, especially when moving custom programs or transitioning to cloud-based S/4HANA installations. Executive Summary The transition […]
30 Percent of Security Notes in System Recommendations are False Positives
System Recommendations (SysRec) in SAP Solution Manager automatically calculates relevant security notes for SAP systems based on the available software and application components in each system. It provides a cross-system view for required notes using a customizable, user-friendly interface. The use of SysRec is recommended by SAP for the lifecycle management of notes. It connects […]