Realistic attack simulations for SAP landscapes — from on-prem through RISE with SAP to the factory floor. No theoretical audit. No scanner report. Real attacks by real hackers.
Our red team covers the entire SAP attack surface: from the ABAP layer through cloud integrations to the factory floor.
Attacks on the SAP application layer — where the business data lives.
Attacks on cloud services, APIs and the bridges between on-prem and cloud.
Where SAP meets the physical world: MES, SCADA, PLCs and the bridges in between.
Whether on-prem, hybrid or full cloud — every SAP variant has its own weaknesses. We know them all.
Classic on-prem installations with full control — and full responsibility. Often grown over 15+ years, carrying historical legacy.
The most dangerous constellation: on-prem systems with cloud connectivity. The Cloud Connector becomes the bridge for attackers.
SAP as a managed service. Infrastructure at SAP/hyperscaler, but the application layer remains the customer's responsibility — and is often overlooked.
Cloud-native services, custom apps, AI integrations. New attack surfaces that classic SAP security tools don't see.
The nervous system of the SAP landscape. CPI, API Management, Event Mesh — every connection is a potential attack vector.
Where SAP ERP meets MES, SCADA and PLCs. The bridge between office IT and the factory floor is often the weakest point.
Structured, reproducible, documented. From reconnaissance to executive report.
Joint definition of objectives, systems, rules of engagement and escalation paths.
Passive and active reconnaissance: system versions, interfaces, exposed services, OSINT.
Active attacks: exploit vulnerabilities, escalate privileges, perform lateral movement.
Validate business impact: data access, production control, exfiltration — how far do we get?
Executive summary + technical deep dive + prioritized remediation roadmap.
Most red teams stop at IT. We go further: from SAP ERP through MES to the PLC on the production line.
In automotive, pharma and manufacturing, SAP systems are connected directly or indirectly to production systems: via MES (SAP MII/ME), Plant Connectivity (PCo), OPC UA gateways or historically grown RFC connections.
An attacker who compromises SAP ERP can move through these bridges into the OT world — all the way to production control. This isn't a theoretical scenario: it's the reality we find at every third automotive client.
Our OT expertise is not an add-on — it's part of our DNA. Hardware hacking, PLC analysis and SCADA pen testing have been part of our portfolio for years.
Request an OT red team →Active bug bounty hunters on Synack and at hacker conferences. We find vulnerabilities no scanner knows — because we discover them ourselves.
Founded by a former SAP employee. We don't know ABAP, RFC, BTP and the SAP architecture from books — we know them because we built them.
Most pen testers stop at the application. We go further: through network pivoting into the OT world, including hardware hacking on PLCs and IoT.
Owner-operated, no investors, no disclosure obligations. Ideal for public authorities, KRITIS and organizations with the highest confidentiality requirements.
No blank-cheque contract with open-ended effort. Each package has a defined scope, a fixed duration and a concrete deliverable.
Targeted pen test on a single SAP system or a defined attack surface. Fast, focused, with concrete findings.
Realistic attack simulation across the entire SAP landscape. Multiple systems, cross-layer, business impact validation.
The full programme: SAP + IT + OT + hardware. From Fiori login to production control. For automotive, pharma and KRITIS.
In a 30-minute call we clarify scope, variant, timeline and expectations.
No sales pitch — straight to the red team lead.
Or just call us. Discretion goes without saying.
Sie sehen gerade einen Platzhalterinhalt von Facebook. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr InformationenSie sehen gerade einen Platzhalterinhalt von Instagram. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr InformationenSie sehen gerade einen Platzhalterinhalt von X. Um auf den eigentlichen Inhalt zuzugreifen, klicken Sie auf die Schaltfläche unten. Bitte beachten Sie, dass dabei Daten an Drittanbieter weitergegeben werden.
Mehr Informationen