Transcript
And what are the specific cyber risks to SAP applications that have now changed with AI? What is your view on this? It's a great question. And second, SAP is doing a massive transformation as a business to really focus on AI. They launched the Autonomous Enterprise Vision and Release Strategy, which I think is really, really impactful. I think it starts, the challenges I see start with what you just mentioned. I was actually talking with a CISO a couple of weeks ago. He was very concerned about what this new model is meant. Exactly because one of the points you mentioned, he's like, hey, I used to have the advantage against, I know advanced attackers already know how to hack SAP systems. And they actually saw it with this 2025 campaigns. But at least I knew that most of the world, from a threat landscape perspective, they don't really understand SAP. They don't know how to attack SAP systems. They don't know the proprietary protocols or how to navigate SAP T-codes. And now when you think about it, all those, they are completely democratized, how they can just do a lot of that through their apps. They don't need to be an expert. I think in SAP, also in particular, what happens is we're talking about mission critical systems. So you're going to have now significant more volume as you describe, more patches, more things to launch, more service that you've been attacked on. Even for normal abilities, you can't apply the patch, even if you have, because you may not be able to get a downtime. So you're operating with the systems with non-exposure to normal abilities. I think in that point, that's where the threat intelligence, the context for triage is key. You're not going to be able to fix it. So knowing threat intelligence, which of the 10 things that you're exposed to, which are the two that are actually being exploited by attackers today, right? And they're most likely going to be compromised, kind of supersized with AI. That's definitely an area of opportunity on balance. The other one has to do with all around zero-day detection, right? We're going to see, as you describe, more zero-day vulnerabilities being discovered by LLMs. So having the ability to detect zero-day attacks against SAP is going to be critical. And then something we hear a lot and a lot of concern about is everyone is coding with AI now, right? And creating code way faster, with more volume of code. There's a lot of concerns of whether that code is actually secure. SAP has some capabilities like jewel-based assistance, where you can actually generate code. Based on our analysis, it's very, very important that organizations run those new AI-generated code capabilities through security controls. Otherwise, you're pushing insecure or potentially malicious code into production, which can be very dangerous.