Fractional SAP CISO — at board level

The CISO office is excellent.
There's just a gap when it comes to SAP.

We fill the SAP part of the CISO office. Strategic and operational SAP security leadership, risk quantification, board reporting, audit support, SAP vendor management, crisis presence.

Live Briefing 2:00 min
SAP for CISOs · Episode 01
Today: Risk Evaluation
► Play now — the 2-minute story
2–4
Days / month
12
Months commitment
4h
Escalation SLA
30+
Years of SAP depth
Why this service exists

The CISO office knows classic IT and networks.
SAP usually isn't part of that.

In most DAX and mid-market companies, SAP is the largest and most critical system of all — and the one with the most specialized security model. The CISO office typically comes from a network, identity or cloud security background. First-hand SAP depth is rarely represented there — not for lack of competence, but because SAP security is a discipline of its own.

This creates a structural asymmetry: the biggest block of risk is also the one that can be reported on least authoritatively in-house. Audits, board questions and vendor negotiations happen with background noise, because no one in the room can technically validate the SAP-specific answers.

A Fractional SAP CISO closes exactly that gap — without a full-time hire, without a headhunter, without an 18-month onboarding.

  • SAP Security Notes are assessed, but no one can judge which note is truly critical in your landscape.
  • RFC connections between production systems are managed by IT, but no one thinks about them from an attacker's perspective.
  • BTP, RISE and S/4 migrations are run by system integrators — whose security promises no one can critically challenge.
  • Vendor and consultant access proliferates over years; the CISO office gets the audit finding, but not the SAP-side root-cause analysis.
  • Board questions on NIS2 and SAP get passed upward and endured below, because no well-founded answer is available.
  • In a crisis, the CISO office decides on system shutdowns — without a solid SAP-side assessment of the knock-on costs to ongoing business.
Three engagement tiers

Choose the depth,
not the person.

All three tiers are 12-month mandates with a fixed monthly presence; unused days roll over within the quarter. One named person, a direct line, no account managers.

Tier 1
CISO Sparring
2 days / month

For established CISOs who need a competent sparring partner for all things SAP — without handing over a leadership role.

  • Monthly strategic sparring (4–6 h)
  • Assessment of critical SAP Security Notes
  • Reactive escalation channel (4h SLA)
  • Quarterly threat briefings
  • SAP portions of board reporting
Suitable for: Mid-market, 500–2,000 employees
Tier 3
Acting SAP CISO
4 days / month

For organizations without a dedicated SAP CISO — or during a vacancy or build-up phase. A full SAP security leadership role as an external function.

  • Everything from Tier 2
  • Accountable SAP security leadership function
  • Direct board and supervisory board reporting
  • BSI / BaFin / NIS2 communication
  • Independent crisis-team presence
  • Building and coaching an internal successor
Suitable for: KRITIS, public authorities, enterprises in transition phases
Scope of services

What you actually get.

Several core areas, weighted differently across the tiers — depending on your organization's maturity and needs.

🎯

Strategy & roadmap

An SAP security roadmap based on your real landscape — not from a consulting toolkit. Prioritized from an attacker's perspective, aligned with audit, BSI and NIS2 requirements.

📊

Board & supervisory board reporting

SAP risks translated into board language. Quarterly reports, special-situation briefings, prepared answers to typical board and supervisory board questions.

Audit & compliance support

Preparation for and support during internal audits and ISO 27001, BSI C5, NIS2 and SOX reviews with an SAP angle. Answer quality that auditors experience as competent.

🤝

Vendor & SI management

Sparring in negotiations with SAP, system integrators and security providers. Security promises checked against reality, not against marketing.

🚨

Incident & crisis presence

Available during SAP-relevant security incidents — without a new contract, without an escalation tariff. Crisis-team participation, technical decision papers, communication support.

🔍

Threat Intelligence & Hot News

The SAP-specific threat landscape contextualized to your environment. Not a generic newsletter — a concrete assessment: what does this note, this exploit, this campaign mean for your systems?

How getting started works

From the first call to a running mandate
in four weeks.

01 / Week 1

Intro call

Non-binding, 60 minutes. Content: current SAP landscape, biggest concerns, maturity. Outcome: an assessment of whether a mandate makes sense — and at which tier.

02 / Week 2

Scoping & offer

A concrete mandate: tier, focus areas, monthly cadence, escalation paths. Fixed monthly price, 12-month term.

03 / Week 3

Onboarding

Two structured onboarding days: system landscape, stakeholders, ongoing initiatives, open audit items. Connection to internal communication channels.

04 / Week 4

First monthly slot

First board or CISO-office reporting. A quick-win plan for the first 90 days. From here, the agreed monthly cadence runs.

“We have an excellent CISO office. But on SAP, we relied on what our system integrator told us. Until the audit came. Now, every month, someone is in the room who asks the right questions — before the auditor does.”
Paraphrased — existing client, retail
Who this is for

Not for everyone.
For the right ones.

A Fractional CISO is not a disguised pentest and not an outsourced SAP Basis. The mandate works where SAP is strategically critical and a well-founded second opinion is needed between the board, the CISO and the system integrator.

A clear fit if the following applies

  • SAP is business-critical (S/4HANA, ECC, BTP, RISE in use)
  • A CISO exists, but doesn't come from an SAP background
  • NIS2, KRITIS or regulatory pressure is rising
  • Multiple system integrators and vendors involved
  • The board increasingly asks SAP-specific security questions
  • The last audit had SAP-specific findings
  • A current or upcoming migration phase (S/4, RISE, BTP)
  • A speed advantage from an external, neutral voice is expected

An intro call in 60 minutes.
After that, you'll know whether it fits.

No sales pitch. An honest assessment of whether a Fractional CISO makes sense for you — or whether another log(2) format suits your current situation better.

Investment level: well below a full-time CISO · fixed monthly price · 12-month term