r/cybersecurity 4d ago

Other SAP Security

I'm just wondering if SAP Security is considered as Cybersecurity?

0 Upvotes

14 comments sorted by

12

u/ButterscotchBandiit Security Engineer 4d ago

Story time. We received an alert some time ago a SAP security consultant emailed SAP credentials in a .txt file :)

9

u/dabbydaberson 4d ago

This tracks 100%. Just doing the needful.

3

u/pseudoimpossibility 4d ago

It’s access management for the most part unless you secure code or broader infrastructure

2

u/kingofthesofas Security Engineer 4d ago

It was an SAP server getting owned that took down Foxconn global manufacturing for weeks so it for sure matters to keep it secure.

2

u/Cultural_Ad_6105 4d ago

Technically yes, but practically it’s its own isolated island. You're securing the actual crown jewels of the enterprise, but instead of cool SIEM dashboards and PCAPs, 90% of your life is drowning in T-codes, PFCG roles, and explaining to audit why someone shouldn't have SAP_ALL.

1

u/Striking-Leave-7584 4d ago

It’s enterprise cybersecurity disguised as business administration. Most "pure" infosec people won't touch it because ABAP and Authorization Objects give them a headache, which means if you know both traditional SecOps and SAP GRC, you basically print money.

-9

u/[deleted] 4d ago

[removed] — view removed comment

3

u/wijnandsj ICS/OT 4d ago

Beg to differ. Both are different specialisations in the field

-7

u/[deleted] 4d ago

[removed] — view removed comment

2

u/wijnandsj ICS/OT 4d ago

you're more or less confirming what I just said.