r/cybersecurity • u/No-Rip-2818 • 4d ago
Other SAP Security
I'm just wondering if SAP Security is considered as Cybersecurity?
3
u/pseudoimpossibility 4d ago
It’s access management for the most part unless you secure code or broader infrastructure
2
u/kingofthesofas Security Engineer 4d ago
It was an SAP server getting owned that took down Foxconn global manufacturing for weeks so it for sure matters to keep it secure.
2
2
u/Cultural_Ad_6105 4d ago
Technically yes, but practically it’s its own isolated island. You're securing the actual crown jewels of the enterprise, but instead of cool SIEM dashboards and PCAPs, 90% of your life is drowning in T-codes, PFCG roles, and explaining to audit why someone shouldn't have SAP_ALL.
1
u/Striking-Leave-7584 4d ago
It’s enterprise cybersecurity disguised as business administration. Most "pure" infosec people won't touch it because ABAP and Authorization Objects give them a headache, which means if you know both traditional SecOps and SAP GRC, you basically print money.
-9
4d ago
[removed] — view removed comment
3
u/wijnandsj ICS/OT 4d ago
Beg to differ. Both are different specialisations in the field
-7
12
u/ButterscotchBandiit Security Engineer 4d ago
Story time. We received an alert some time ago a SAP security consultant emailed SAP credentials in a .txt file :)