The CISO office is excellent.
There's just a gap when it comes to SAP.
We fill the SAP part of the CISO office. Strategic and operational SAP security leadership, risk quantification, board reporting, audit support, SAP vendor management, crisis presence.
The CISO office knows classic IT and networks.
SAP usually isn't part of that.
In most DAX and mid-market companies, SAP is the largest and most critical system of all — and the one with the most specialized security model. The CISO office typically comes from a network, identity or cloud security background. First-hand SAP depth is rarely represented there — not for lack of competence, but because SAP security is a discipline of its own.
This creates a structural asymmetry: the biggest block of risk is also the one that can be reported on least authoritatively in-house. Audits, board questions and vendor negotiations happen with background noise, because no one in the room can technically validate the SAP-specific answers.
A Fractional SAP CISO closes exactly that gap — without a full-time hire, without a headhunter, without an 18-month onboarding.
- SAP Security Notes are assessed, but no one can judge which note is truly critical in your landscape.
- RFC connections between production systems are managed by IT, but no one thinks about them from an attacker's perspective.
- BTP, RISE and S/4 migrations are run by system integrators — whose security promises no one can critically challenge.
- Vendor and consultant access proliferates over years; the CISO office gets the audit finding, but not the SAP-side root-cause analysis.
- Board questions on NIS2 and SAP get passed upward and endured below, because no well-founded answer is available.
- In a crisis, the CISO office decides on system shutdowns — without a solid SAP-side assessment of the knock-on costs to ongoing business.
Choose the depth,
not the person.
All three tiers are 12-month mandates with a fixed monthly presence; unused days roll over within the quarter. One named person, a direct line, no account managers.
For established CISOs who need a competent sparring partner for all things SAP — without handing over a leadership role.
- Monthly strategic sparring (4–6 h)
- Assessment of critical SAP Security Notes
- Reactive escalation channel (4h SLA)
- Quarterly threat briefings
- SAP portions of board reporting
An operational extension of the CISO office: SAP security is actively shaped and represented independently toward the board, vendors and auditors.
- Everything from Tier 1
- Dedicated board slots on the SAP risk situation
- Audit support (internal and external)
- Vendor & SI negotiation sparring
- Quarterly attack path status review
- Co-shaping the SAP security roadmap
For organizations without a dedicated SAP CISO — or during a vacancy or build-up phase. A full SAP security leadership role as an external function.
- Everything from Tier 2
- Accountable SAP security leadership function
- Direct board and supervisory board reporting
- BSI / BaFin / NIS2 communication
- Independent crisis-team presence
- Building and coaching an internal successor
What you actually get.
Several core areas, weighted differently across the tiers — depending on your organization's maturity and needs.
Strategy & roadmap
An SAP security roadmap based on your real landscape — not from a consulting toolkit. Prioritized from an attacker's perspective, aligned with audit, BSI and NIS2 requirements.
Board & supervisory board reporting
SAP risks translated into board language. Quarterly reports, special-situation briefings, prepared answers to typical board and supervisory board questions.
Audit & compliance support
Preparation for and support during internal audits and ISO 27001, BSI C5, NIS2 and SOX reviews with an SAP angle. Answer quality that auditors experience as competent.
Vendor & SI management
Sparring in negotiations with SAP, system integrators and security providers. Security promises checked against reality, not against marketing.
Incident & crisis presence
Available during SAP-relevant security incidents — without a new contract, without an escalation tariff. Crisis-team participation, technical decision papers, communication support.
Threat Intelligence & Hot News
The SAP-specific threat landscape contextualized to your environment. Not a generic newsletter — a concrete assessment: what does this note, this exploit, this campaign mean for your systems?
From the first call to a running mandate
in four weeks.
Intro call
Non-binding, 60 minutes. Content: current SAP landscape, biggest concerns, maturity. Outcome: an assessment of whether a mandate makes sense — and at which tier.
Scoping & offer
A concrete mandate: tier, focus areas, monthly cadence, escalation paths. Fixed monthly price, 12-month term.
Onboarding
Two structured onboarding days: system landscape, stakeholders, ongoing initiatives, open audit items. Connection to internal communication channels.
First monthly slot
First board or CISO-office reporting. A quick-win plan for the first 90 days. From here, the agreed monthly cadence runs.
“We have an excellent CISO office. But on SAP, we relied on what our system integrator told us. Until the audit came. Now, every month, someone is in the room who asks the right questions — before the auditor does.”Paraphrased — existing client, retail
Not for everyone.
For the right ones.
A Fractional CISO is not a disguised pentest and not an outsourced SAP Basis. The mandate works where SAP is strategically critical and a well-founded second opinion is needed between the board, the CISO and the system integrator.
A clear fit if the following applies
- SAP is business-critical (S/4HANA, ECC, BTP, RISE in use)
- A CISO exists, but doesn't come from an SAP background
- NIS2, KRITIS or regulatory pressure is rising
- Multiple system integrators and vendors involved
- The board increasingly asks SAP-specific security questions
- The last audit had SAP-specific findings
- A current or upcoming migration phase (S/4, RISE, BTP)
- A speed advantage from an external, neutral voice is expected
An intro call in 60 minutes.
After that, you'll know whether it fits.
No sales pitch. An honest assessment of whether a Fractional CISO makes sense for you — or whether another log(2) format suits your current situation better.