Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Onapsis: AI Threats & Defenses in SAP Security

Onapsis
08/01/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


And what are the specific cyber risks to SAP applications that have now changed with AI? What is your view on this? It's a great question. And second, SAP is doing a massive transformation as a business to really focus on AI. They launched the Autonomous Enterprise Vision and Release Strategy, which I think is really, really impactful. I think it starts, the challenges I see start with what you just mentioned. I was actually talking with a CISO a couple of weeks ago. He was very concerned about what this new model is meant. Exactly because one of the points you mentioned, he's like, hey, I used to have the advantage against, I know advanced attackers already know how to hack SAP systems. And they actually saw it with this 2025 campaigns. But at least I knew that most of the world, from a threat landscape perspective, they don't really understand SAP. They don't know how to attack SAP systems. They don't know the proprietary protocols or how to navigate SAP T-codes. And now when you think about it, all those, they are completely democratized, how they can just do a lot of that through their apps. They don't need to be an expert. I think in SAP, also in particular, what happens is we're talking about mission critical systems. So you're going to have now significant more volume as you describe, more patches, more things to launch, more service that you've been attacked on. Even for normal abilities, you can't apply the patch, even if you have, because you may not be able to get a downtime. So you're operating with the systems with non-exposure to normal abilities. I think in that point, that's where the threat intelligence, the context for triage is key. You're not going to be able to fix it. So knowing threat intelligence, which of the 10 things that you're exposed to, which are the two that are actually being exploited by attackers today, right? And they're most likely going to be compromised, kind of supersized with AI. That's definitely an area of opportunity on balance. The other one has to do with all around zero-day detection, right? We're going to see, as you describe, more zero-day vulnerabilities being discovered by LLMs. So having the ability to detect zero-day attacks against SAP is going to be critical. And then something we hear a lot and a lot of concern about is everyone is coding with AI now, right? And creating code way faster, with more volume of code. There's a lot of concerns of whether that code is actually secure. SAP has some capabilities like jewel-based assistance, where you can actually generate code. Based on our analysis, it's very, very important that organizations run those new AI-generated code capabilities through security controls. Otherwise, you're pushing insecure or potentially malicious code into production, which can be very dangerous.

TL;DR

  • AI is democratizing SAP attack knowledge, enabling less-skilled attackers to exploit complex SAP systems without deep expertise in proprietary protocols or T-codes.
  • Mission-critical SAP systems often cannot be patched quickly, making threat intelligence and exploit prioritization more valuable than comprehensive patch coverage.
  • LLMs are expected to accelerate zero-day vulnerability discovery in SAP environments, raising the urgency for behavioral detection capabilities.

Summary

In this short interview segment, Mariano Nunez of Onapsis outlines how AI is fundamentally reshaping the SAP threat landscape across three dimensions. First, AI is democratizing attacker knowledge: where sophisticated SAP exploitation once required deep expertise in proprietary protocols and T-codes, AI-powered tools now allow less-skilled threat actors to navigate and attack SAP environments without that background. Second, the volume and velocity of vulnerabilities is increasing — mission-critical SAP systems often cannot be patched quickly due to downtime constraints, making threat intelligence and prioritization essential. Knowing which of many exposures are actively being exploited becomes more valuable than attempting to patch everything. Third, AI-generated code introduces a new supply-chain-style risk: as developers use tools like SAP's Joule-based assistant to generate code faster, organizations must ensure that AI-generated code passes through rigorous security controls before reaching production. Failing to do so risks introducing insecure or potentially malicious code into critical business systems. Nunez frames zero-day detection as a growing imperative, noting that LLMs will accelerate the discovery of previously unknown vulnerabilities targeting SAP, making behavioral detection capabilities increasingly critical for enterprise defenders.

Chapters

0:00 - AI Risks to SAP Applications
0:43 - Democratization of SAP Attack Knowledge
1:24 - Patching Gaps and Threat Prioritization
2:15 - Zero-Days and AI-Generated Code Risks

Key Quotes

1:03 "They don't know the proprietary protocols or how to navigate SAP T-codes. And now when you think about it, all those, they are completely democratized, how they can just do a lot of that through their apps."
1:57 "Knowing threat intelligence, which of the 10 things that you're exposed to, which are the two that are actually being exploited by attackers today, right? ..."
2:19 "We're going to see, as you describe, more zero-day vulnerabilities being discovered by LLMs. So having the ability to detect zero-day attacks against SAP is going to be critical."

FAQ

Why is AI making SAP systems more vulnerable to attack?

AI tools are democratizing attacker knowledge, allowing threat actors without deep SAP expertise to exploit proprietary protocols and navigate complex system configurations. Previously, only advanced attackers understood how to hack SAP systems; now that barrier is significantly lower.

What should organizations do when they cannot patch SAP vulnerabilities quickly?

Nunez recommends prioritizing threat intelligence to identify which specific exposures are actively being exploited. Since SAP downtime for patching is often not feasible, knowing which vulnerabilities pose the most immediate real-world risk allows defenders to focus limited resources effectively.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Threat Intelligence
  • AI & Machine Learning
  • Vulnerability Management
  • Technical Deep Dive
  • SAP security
  • AI-driven cyber threats
  • zero-day vulnerabilities
  • threat intelligence
  • AI-generated code security
  • enterprise application security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Onapsis: AI Threats & Defenses in SAP Security

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-revolutionizing-identity-attacks-same-tactics-enhanced-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version