Understand SAP security.
Don't just manage it.

Hands-on training from active red teamers and bug bounty hunters. No PowerPoint carousel — real attacks, real systems, real insights.

Online via ClickMeeting
On-site classroom training
Remote: 3×4 hours

Four courses. One goal: making you more secure.

Every course is delivered by active SAP security experts who run penetration tests and red team engagements for enterprise clients every day.

Cloud Security Zero to Hero Hands-On

SAP BTP Cloud & Security — from Zero to Hero

From the fundamentals of SAP Business Technology Platform to secure configuration in production environments. For teams that need to introduce or secure BTP.

Contents

  • BTP architecture & security model
  • Identity & Access Management (IAS/IPS)
  • Cloud Connector hardening
  • Destination configuration & risks
  • SAP BTP Service Marketplace Security
  • API Management & OAuth Flows
  • Monitoring & Audit Logging
  • Secure DevOps for BTP applications
Hacking Hands-On Lab

SAP API Hacking

Offensive testing of SAP APIs: OData, RFC, REST, SOAP and BTP destinations. Real attack techniques against SAP interfaces — with live hacking on test systems.

Contents

  • SAP API landscape: OData, RFC, ICF
  • Authentication bypass techniques
  • SSRF & injection in SAP contexts
  • RFC exploitation & lateral movement
  • BTP Destination Hijacking
  • OAuth Token Manipulation
  • Fiori/UI5 frontend attacks
  • Tooling: Burp Suite, Postman, custom scripts
AI & GenAI BTP Development New 2026

SAP BTP Development with AI, MCP and Security Handling

Secure development on SAP BTP with AI integration: from MCP architecture through LLM connectivity to securing AI-driven workflows in SAP environments.

Contents

  • AI architecture on SAP BTP
  • Model Context Protocol (MCP) in SAP
  • LLM integration & prompt security
  • Securing AI-driven workflows
  • Data Privacy & AI Governance
  • Secure coding for BTP CAP & RAP
  • Attack vectors against AI pipelines
  • EU AI Act & compliance requirements
Threat Intelligence Updated Q1/2026

SAP Current Threat Landscape

Compact briefing on the current SAP threat situation: real attack campaigns, zero-day exploits, darknet activity and what your security team needs to know now.

Contents

  • SAP zero-days 2025/2026 in detail
  • CVE-2025-31324 & follow-up exploits
  • Ransomware campaigns against SAP
  • Nation-state attacks on ERP systems
  • Darknet: what's being traded about SAP?
  • Patch prioritization: what first?
  • Incident response for SAP compromise
  • Strategic recommendations for CISOs

Three formats. Your pace.

Every course is available in all three formats. Choose what suits your team.

💻

Online Live

Interactive sessions via ClickMeeting. Questions, discussion and live demos in real time.

Platform: ClickMeeting
Recording: On request
Participants: Up to 25
Materials: Digital (PDF)
🏢

On-site

Training at your site or at our premises. Including hands-on labs on real SAP test systems.

Location: At your site or ours
Lab access: Dedicated test systems
Participants: Up to 15
Catering: By arrangement

Remote: 3×4 hours

The same content, split across three half-days. Ideal for teams that can't block two full days.

Format: 3 sessions of 4 hours
Spacing: 2–7 days between sessions
Benefit: Time for exercises in between
Platform: ClickMeeting

Who are our courses for?

💼

CISOs & security leaders

Strategic understanding of the SAP threat landscape. Decision foundations for budget, prioritization and incident response.

🛡

SAP Basis & Security Teams

Technical deep dive: configuration, pen testing methodology, hardening measures and operational security.

👨‍💻

SAP developers & architects

Secure coding on BTP, API security, AI integration and sound architecture decisions for SAP projects.

Want a tailored in-house course?

We tailor every course to your specific SAP landscape, your industry and your security maturity. Including analysis of your real system configuration as a training basis.

  • Tailored to your SAP landscape and industry
  • Dedicated lab environment with your system types
  • Combinable with a security assessment
  • Cost-effective from 5 participants
Request an in-house quote →

Our courses are also available through

heise Academy Rheinwerk Directly from log(2)

Request training

Choose a course and a format — we'll get back to you within 24 hours with a concrete offer.

Get in touch →

Or just give us a call — we're happy to advise you personally on format and content.