Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: SAP BTP Security: Threat Landscape & Cloud Risks

Onapsis
06/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Absolutely. Thank you, Alex. So yeah, to begin with, hey, like, we're going to be covering security for BTP multiple different services the architecture and strategies to push security forward but let's start with understanding why is security important, especially in the concept in the context of cloud and BTP services. And I wanted to start with a couple of examples. For those of you who are more familiar with the concept of SAP nodes, or more specifically SAP security nodes. Those are the nodes that customers need to consume address, take care of, but specifically focused on components around BTP or cloud applications. And we're going to be talking about these throughout the different slides and different sections of this presentation but it's important to understand that even though organizations are going down the path of embracing cloud going to cloud consuming cloud services. Security is something that we need to address, and it's our data. Hence, it's our responsibility and we ultimately responsible for securing this. In this case, we are seeing a couple of SAP security nodes, addressing security issues in different services and different parts of BTP. And with the corresponding CVSS, the criticality as you can see these are very critical, and the CVEs, so the specific vulnerabilities that were being addressed by these security nodes. So, even if we are in the cloud, SAP security nodes can be applicable in some cases. So we should be taking care of as well. Going down the path of understanding why, I think it's important to go back to research that we released together with Flashpoint a couple of months ago, and this research was focused on understanding what's been the evolution of the threat landscape, specifically focused on SAP applications for the past five years. For the past four years. And in this research, we highlighted, or we uncovered a 400% increase in ransomware incidents involving SAP data, SAP applications, 490% increase on criminal conversations, talking about SAP vulnerabilities and SAP exploits. A 220% increase in discussions involving URLs that match specifically to SAP technology. A 400% increase on the price of publicly available, sorry, of exploits. Actually, these are not publicly available, these are exploits for sale. Specifically focused on SAP applications, remote command execution exploits. So these are four indicators that highlight the evolution from 2020 to 2023, including the end of 2023, covering data points that are coming from basically threat intentions, right? Open, deep and dark web, cyber criminal forums, paste sites, code sites, blogs, different sites which are used by threat actors to exchange information, communicate, release exploits, release code, different things. So all of that gets condensed into a platform and we use the Flashpoint Intel to be able to identify these data points. So all in all, I encourage you to go into this research to see more information and more details, but the threat landscape for SAP applications is increasing and this also involves applications that are running in the cloud, right? This is not just limited to on-premise installations. Next slide, please. And if we want to take a look at who is behind this or who are the threat actors that are actively targeting these applications, well, there's a little bit of everything. When we look at the spectrum of threat actors targeting SAP business applications, we have all the way from very sophisticated, well-resourced APTs, state-sponsored actors, all the way to less sophisticated, less resourced script kiddies, for example, right? They go and exploit vulnerabilities in the background as well. And in between, we have financially motivated actors like FIAT 7 or FIAT 13 that profit out of compromising these applications or Cobalt Spider, which is also another actor that is known to target these applications. What do they do? Well, they exploit SAP vulnerabilities, they exploit its payment systems, exfiltrating financial statements, or even performing financial fraud. But all of these are mechanisms that these threat actors have found to be able to monetize on compromising SAP applications.

TL;DR

  • SAP security notes apply to cloud and BTP services with critical vulnerabilities requiring attention, demonstrating that cloud adoption doesn't eliminate security responsibilities.
  • Research with Flashpoint uncovered a 400% increase in ransomware incidents involving SAP data and a 490% increase in criminal discussions about SAP exploits from 2020-2023.
  • Threat actors targeting SAP applications range from sophisticated state-sponsored APTs to financially motivated groups like FIN7 and Cobalt Spider who exploit vulnerabilities for fraud and data theft.

Summary

This presentation examines the critical security considerations for SAP Business Technology Platform (BTP) and cloud services, emphasizing that cloud adoption does not eliminate security responsibilities. The speakers discuss the evolution of the threat landscape targeting SAP applications, highlighting research conducted with Flashpoint that reveals dramatic increases in ransomware incidents, criminal exploit discussions, and the price of SAP-specific exploits over a four-year period. The content addresses SAP security notes applicable to BTP services, the spectrum of threat actors from state-sponsored APTs to financially motivated groups, and the various attack vectors used to compromise SAP environments. The presentation underscores that organizations remain ultimately responsible for securing their data in cloud environments, with security issues ranging from critical vulnerabilities (high CVSS scores) to sophisticated exploitation techniques used by criminal actors for financial fraud and data exfiltration.

Chapters

0:00 - Introduction to BTP Security
0:37 - SAP Security Notes for Cloud
2:10 - Threat Landscape Research Findings
4:43 - Threat Actor Spectrum

Key Quotes

1:21 "Security is something that we need to address, and it's our data. Hence, it's our responsibility and we ultimately responsible for securing this."
2:41 "We uncovered a 400% increase in ransomware incidents involving SAP data, SAP applications, 490% increase on criminal conversations, talking about SAP vulnerabilities and SAP exploits."
4:18 "The threat landscape for SAP applications is increasing and this also involves applications that are running in the cloud, right? This is not just limited to on-premise installations."

FAQ

Are SAP security notes still relevant for cloud and BTP deployments?

Yes, SAP security notes addressing critical vulnerabilities with high CVSS scores apply to BTP and cloud services. Organizations remain responsible for addressing these security issues even in cloud environments, as the data ultimately belongs to the customer.

What types of threat actors are targeting SAP applications?

The threat landscape includes sophisticated state-sponsored APTs, financially motivated groups like FIN7 and Cobalt Spider, and less sophisticated actors. These groups exploit SAP vulnerabilities for various purposes including ransomware, financial fraud, payment system exploitation, and data exfiltration.


Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Threat Intelligence
  • Application Security
  • Technical Deep Dive
  • Webinar
  • SAP BTP Security
  • Cloud Security Responsibility
  • SAP Security Notes
  • Threat Landscape Evolution
  • Ransomware Targeting SAP
  • Criminal Exploit Markets
  • APT Threats
  • Financial Fraud
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: SAP BTP Security: Threat Landscape & Cloud Risks

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Master Active Directory Certificate Services and Maintain Your Edge
                https://www.truthinit.com/index.php/channel/2018/master-active-directory-certificate-services-and-maintain-your-edge/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Outsmarting You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-outsmarting-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Building Resilience Against Hybrid Threats in a Dark Cloud Environment
                https://www.truthinit.com/index.php/channel/2011/building-resilience-against-hybrid-threats-in-a-dark-cloud-environment/
              • 07/08/2026
                02:00 PM
                07/08/2026
                Understanding the Crucial Role of Context in AI Data
                https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-ai-data/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Agentic Trust in Practice
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-agentic-trust-in-practice/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Worthy Security Team for Maximum Defense Effectiveness
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-worthy-security-team-for-maximum-defense-effectiveness/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Master Agent-Ready Skills in 30 Days with Cyera Agent Security
                https://www.truthinit.com/index.php/channel/2036/master-agent-ready-skills-in-30-days-with-cyera-agent-security/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Master Active Directory Certificate Services and Maintain Your Edge

                06/30/202601:00 PM ET
                • Jul
                  01

                  Schutz von KI in Anwendungen, Agenten und APIs.

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      How to Prevent Your AI from Outsmarting You

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Building Resilience Against Hybrid Threats in a Dark Cloud Environment

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version