SAP systems often form the operational backbone of enterprises, concentrating critical business, employee, and customer data across ERP, SAP HR, SAP CRM, and SAP NetWeaver-based portals, with additional functionality frequently embedded through ABAP or Java custom code. This centrality makes SAP landscapes both a prime audit focus and a high-value attack surface, especially given their complexity, individualized configurations, and exposure through internet-facing components such as SAP Router, portals, or CRM. SAP security is framed as broader than classic Segregation of Duties (SoD) governance: it also includes application platform hardening (patching, configuration, credential strength, and vulnerability management) and custom code risk (insecure or malicious code paths). Growing threat volume and limited specialist staffing increase the need for intelligent, assistive detection and response capabilities.
ERPScan, founded in 2010 and headquartered in Palo Alto with a European HQ in Amsterdam, positions its Smart Cybersecurity Platform for SAP as a holistic suite built on lifecycle phases. Earlier product focus areas—vulnerability management, source code security, and SoD analysis—remain central, now organized into modules for Assess, Detect (including machine-learning-supported user behavior analytics), Respond (tasking, notifications, and integrations), Protect (hardening, automated corrections, and virtual patching), and Monitor (executive-ready visibility). The platform is designed as non-intrusive and agentless, using read-only connectors across many SAP technologies and related databases. It supports one-off scans through continuous operation, discovers SAP landscape topology by network scanning, and visualizes risks via a “threat map.” Integration with broader security and governance ecosystems (SIEM/RTSI, ITSM, GRC, SAP GRC) enables operationalization of findings through APIs, tickets, and exported control monitoring. Strengths include breadth, connectors, analytics, reporting, and deployment flexibility, while challenges include validating fit of agentless/virtual patching approaches, maturing newly added features, and achieving broader global partner reach.
See All Locations
See All Locations