SAP Joule, custom BTP agents, MCP servers and LLM pipelines create an entirely new attack surface. We test it offensively — before someone else does.
Companies are rolling out SAP AI agents that independently create postings, trigger purchase orders and change data. No one is asking the security question.
“Just ask Joule for what you need.” SAP AI agents are meant to accelerate business processes: natural-language input, automatic tool selection, autonomous execution. A user types one sentence — the agent performs a posting.
The same chain that accelerates a legitimate process can be abused by an attacker: Prompt injection → agent acts in the user's context → MCP server executes an SAP transaction → the posting is done. No classic authorization concept applies.
SAP AI introduces three layers that appear in no classic SAP security assessment.
Joule, custom BTP agents and AI-driven workflows that autonomously execute SAP transactions.
Model Context Protocol servers that act as a bridge between the AI model and the SAP backend.
The entire chain: from the user prompt through LLM reasoning to the executed SAP transaction.
The Model Context Protocol is the new standard for tool integration in AI systems. In SAP environments, MCP servers become the bridge between agent and backend — and thus the most critical point of attack.
In the '90s, RFC connections linked SAP systems to one another — without anyone checking the security of those bridges. 30 years later we know the result: hundreds of invisible attack paths.
MCP servers repeat this pattern. They connect AI models to SAP backends, define which tools an agent may use, and execute actions in the user's context. Whoever controls the MCP server controls what the agent can do in SAP.
We audit MCP server implementations in SAP environments: tool definitions, authorization model, input validation, output sanitization and the entire trust chain from the user prompt to the SAP transaction.
Request an MCP security audit →From SAP's own agents to custom developments on BTP — every agent type has its own weaknesses.
SAP's embedded AI copilot for S/4HANA, SuccessFactors, Ariba and BTP. Natural-language interaction with SAP transactions.
Custom-built agents on SAP BTP with CAP/RAP that access SAP backends via MCP servers.
AI-driven iFlows, intelligent routing and AI-generated transformations in the Integration Suite.
OpenAI, Anthropic or open-source models connected to SAP systems via APIs.
Structured, reproducible and tailored to SAP-specific AI risks.
Inventory of all AI components: agents, MCP servers, LLM connections, RAG pipelines, tool definitions.
SAP-specific AI threat model: which business processes are at risk from AI abuse?
Prompt injection, tool manipulation, MCP exploitation, end-to-end chain attacks on real systems.
Executive report + technical deep dive + concrete hardening measures for every vector found.
Targeted security audit of a single MCP server or AI agent implementation in SAP.
Complete assessment of all AI components in your SAP landscape: agents, MCP servers, pipelines.
Combination: AI security assessment + full SAP red team. Attack through the AI layer into the SAP backend and back.
Most companies roll out SAP AI agents without asking the security question. We answer it — before an attacker does.
Get in touch →30-minute intro call. Straight with the team that runs the tests.
Sie sehen gerade einen Platzhalterinhalt von Facebook. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr InformationenSie sehen gerade einen Platzhalterinhalt von Instagram. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr InformationenSie sehen gerade einen Platzhalterinhalt von X. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr Informationen