Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: SAP Security: Protecting Critical Systems from Cyber Threats

Onapsis
07/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Ajit Adani and I am the Sales Director at Napsys for France, Spain and Portugal. Today, we are delighted to have with us Mathieu Bertrand, an associate at Tornky France, a renowned consultant and expert in the SAP system. Our goal today is to explore the crucial subject of SAP security and examine three major questions that an organization must ask to protect its SAP environments. Thank you for joining us, Mathieu. Thank you, Ajit. It's a pleasure to be with you today. My name is Mathieu Bertrand and I have been working in cybersecurity for more than 14 years. My job is to help organizations identify vulnerabilities in their SAP systems and implement robust security measures to protect their processes and critical data. I am looking forward to sharing my ideas with you today. Recent studies show a significant increase in cyber threats targeting SAP systems. We have seen more than 300 successful operations on 1,500 cyber attacks and an increase of 400% of attacks per ransomware on SAP systems over the last three years. How can SAP systems be protected against these threats, Mathieu? This is a crucial question, Ajit. Protecting SAP systems against cyber threats requires an approach at several levels. First, the first level will be the protection of network access points where SAP environments are located. These layers are now where cybersecurity controls are most important. However, beware of the preconceived idea that SAP is sheltered behind this network. Your figures confirm this. The second level will therefore be the application layer to identify and correct potential vulnerabilities. It is essential to shorten the update times of SAP systems with the latest security correctives. Continuous monitoring is also crucial to detect and respond in real time to suspected activities. The last level is human, with training and awareness programs for employees to reduce the risk of attack by social harassment and engineering. What are the most effective strategies? Given the complexity of SAP systems and the high risks associated with their compromise, it is crucial that organizations adopt a more robust strategy to guarantee their security. Can you explain to us what the most effective strategies are, Mathieu? There are several strategies, I have already mentioned a few. If I start again, the evaluation of regular vulnerability, continuous log monitoring, strict access controls, the idea is to be able to switch to a preventive approach, going beyond simple SAP penetration tests, in order to identify and mitigate potential vulnerabilities before they are exploited. The SAP world is by definition proprietary, and therefore complex and non-transparent. Most cybersecurity professionals are not familiar with these specificities. On their part, those in charge of SAP competence centers don't know much about the cyber world. It is therefore key to establish governance and bodies to allow each of these two worlds to speak and understand each other. Thank you, Mathieu. To continue on the last question, the growing adoption of cloud-based SAP solutions and the integration of emerging technologies such as AI pose new challenges, but also new security opportunities. In this context, what should organizations do right now to prepare for these changes? Everyone talks about AI, but I am convinced that the future of SAP security will be shaped by these technologies. AI, automatic learning with machine learning, these technologies will improve the ability to detect and respond to threats. They will enable the analysis of large amounts of data in real time, thus identifying models and anomalies that could indicate a malicious activity. They will also facilitate the vulgarization of technical subjects to non-initiates. But be careful, malicious people without technical skills could be able to launch more or less complex attacks thanks to these new technologies. In addition, as organizations adopt cloud-based SAP solutions, the security of these environments will become even more critical. Migration to the cloud brings undeniable advantages in terms of flexibility and efficiency, but it also requires a new approach to security. Integrating specific measures for these environments. To prepare for these changes, it is important to establish partnerships with security experts who can provide advice and specialized support to navigate in this landscape of constant evolution. Excellent Mathieu, thank you very much. It is clear that the security of SAP systems is a crucial priority for organizations today and in the future. At Onapsis, we are committed to helping companies protect their SAP environments with our 360-degree security solutions. Thank you for listening to us. A big thank you to Mathieu and Turnkey for sharing their expertise. Until next time, stay safe. Thank you.

TL;DR

  • SAP systems face dramatically escalating threats, with a 400% increase in ransomware attacks over three years and over 300 successful breaches out of 1,500 attempts, requiring organizations to move beyond the false assumption that network perimeter defenses alone provide adequate protection.
  • Effective SAP security demands a multi-layered approach spanning network access controls, application-level vulnerability management with accelerated patching cycles, continuous monitoring for real-time threat detection, and comprehensive employee training to mitigate social engineering risks.
  • Organizations must bridge the critical knowledge gap between cybersecurity professionals unfamiliar with SAP's proprietary architecture and SAP teams lacking cyber expertise by establishing governance structures that enable effective cross-functional collaboration and communication.

Summary

This interview features Ajay Thadhaney, Sales Director at Onapsis for France, Spain and Portugal, in conversation with Mathieu Bertrand, Associate Director at Turnkey France and SAP security expert with over 14 years of cybersecurity experience. The discussion addresses the escalating threat landscape facing SAP systems, with recent data showing a 400% increase in ransomware attacks on SAP environments over the past three years and more than 300 successful breaches out of 1,500 attempted cyberattacks. Bertrand outlines a multi-layered defense strategy encompassing network protection, application-level vulnerability management, continuous monitoring, and employee training. The conversation emphasizes the critical gap between traditional cybersecurity teams unfamiliar with SAP's proprietary complexities and SAP competence centers lacking cyber expertise, highlighting the need for cross-functional governance. Looking forward, the discussion explores how AI and machine learning will transform threat detection capabilities while also potentially empowering less technically skilled attackers, and addresses the unique security considerations organizations must adopt as they migrate SAP workloads to cloud environments.

Chapters

0:00 - Introduction and Context
0:59 - SAP Threat Landscape
2:09 - Effective Security Strategies
3:15 - Cloud and AI Implications

Key Quotes

1:06 "We have seen more than 300 successful operations on 1,500 cyber attacks and an increase of 400% of attacks per ransomware on SAP systems over the last three years."
1:42 "Beware of the preconceived idea that SAP is sheltered behind this network. Your figures confirm this."
2:50 "The SAP world is by definition proprietary, and therefore complex and non-transparent. Most cybersecurity professionals are not familiar with these specificities."

FAQ

What are the most critical layers of defense for protecting SAP systems?

SAP security requires a multi-layered approach: first, protecting network access points where SAP environments reside; second, implementing application-layer security to identify and remediate vulnerabilities with accelerated patching cycles; third, deploying continuous monitoring for real-time threat detection; and fourth, conducting employee training programs to reduce social engineering and phishing risks.

How should organizations prepare for the security challenges of cloud-based SAP deployments?

Organizations must recognize that cloud migration brings flexibility and efficiency advantages but requires a fundamentally new security approach. This includes implementing cloud-specific security measures, establishing partnerships with specialized security experts who understand both SAP and cloud environments, and preparing for the integration of AI and machine learning technologies that will enhance threat detection capabilities while also potentially empowering less sophisticated attackers.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Cloud Security
  • AI & Machine Learning
  • Technical Deep Dive
  • Best Practices
  • SAP Security
  • Ransomware Protection
  • Vulnerability Management
  • AI in Cybersecurity
  • Threat Detection
  • Security Governance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: SAP Security: Protecting Critical Systems from Cyber Threats

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      07

                      Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                      08/07/202611:00 AM ET
                      • Aug
                        19

                        Becoming Agent Ready: Insights and Strategies with Cyera

                        08/19/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version