SAP security and GRC are increasingly critical as organizations modernize core business systems (HR, ERP, CRM, SCM, BW) and add new technology pillars such as SAP HANA, big data, and cloud solutions. Maintaining security and compliance across a continuously changing SAP landscape is driven by legal and regulatory requirements, but also by the need to protect intellectual property and highly sensitive data such as customer information. Mature security programs embed controls across processes and systems, spanning areas from audit and fraud management to identity and access management (IAM), risk management, and process management.
Traditional SAP security emphasizes access governance: managing users, roles, profiles, authorization design, lifecycle workflows, approvals, and recertification, alongside enforcing segregation of duties (SoD) and least-privilege principles. However, SAP security must extend beyond authorizations to secure the full technology stack: hardened operating systems, restricted network access, disciplined patch and update management using available vulnerability and Security Note information, and best-practice configuration of SAP and third-party components. Given evolving internal and external threats, detecting information leakage and enabling real-time anomaly detection with analytics, notifications, and automated responses is increasingly important.
Soterion, headquartered in Johannesburg, delivers GRC software focused specifically on SAP environments, differentiating through ease of use and business-centric user interfaces. It offers on-premises deployment, managed services (including SoD expertise for smaller organizations), and a SaaS option (Soterion Compliance Cloud Platform) with pay-per-use access risk management. Because it runs as an independent application interfacing with SAP (not an ABAP application), it enables a modern UI and supports planned extensions to SAP SaaS services such as Ariba and SuccessFactors. Its modules include Access Risk Manager (enhanced by historical transaction usage analysis and cleanup projections), Basis Review Manager, Elevated Rights Manager, Periodic Review Manager, Employee Self-Service with risk impact analysis, and SAP Licensing Manager. Key strengths are usability, dashboards, drag-and-drop analysis, and graphical business-process context; challenges include limited SAP SaaS coverage today, lack of user lifecycle management, and a smaller partner ecosystem.
See All Locations
See All Locations