field notes

Notes on SAP security and compliance

What we're seeing across SAP landscapes, written for the people who have to keep them safe.

detection · 6 min read

Five signs your SAP landscape has a blind spot

Most breaches aren't dramatic — they're a quiet gap in visibility that nobody noticed until it mattered. Here's what those gaps usually look like.

Read the post

tooling · 5 min read

Why generic SIEM tools miss SAP-specific threats

SAP speaks its own language — RFC calls, authorization objects, transaction codes. Tools built for generic infrastructure often can't hear it.

Read the post

compliance · 7 min read

Preparing for your next SAP compliance audit

What auditors actually ask for, and how to have the evidence ready before they ask instead of scrambling after.

Read the post

detection · 4 min read

Privilege escalation in SAP: what it looks like in practice

A walkthrough of how escalation attempts actually show up in logs, and the patterns worth building rules around.

Read the post

operations · 5 min read

Alert fatigue is a security risk, not just an annoyance

When every alert looks urgent, the real ones get missed. How to tune severity so your team can trust the queue.

Read the post

compliance · 6 min read

Mapping detection rules to control frameworks

A practical look at connecting individual security events to the specific controls they help satisfy.

Read the post

Want posts like this in your inbox?