field notes
Notes on SAP security and compliance
What we're seeing across SAP landscapes, written for the people who have to keep them safe.
detection · 6 min read
Five signs your SAP landscape has a blind spot
Most breaches aren't dramatic — they're a quiet gap in visibility that nobody noticed until it mattered. Here's what those gaps usually look like.
Read the posttooling · 5 min read
Why generic SIEM tools miss SAP-specific threats
SAP speaks its own language — RFC calls, authorization objects, transaction codes. Tools built for generic infrastructure often can't hear it.
Read the postcompliance · 7 min read
Preparing for your next SAP compliance audit
What auditors actually ask for, and how to have the evidence ready before they ask instead of scrambling after.
Read the postdetection · 4 min read
Privilege escalation in SAP: what it looks like in practice
A walkthrough of how escalation attempts actually show up in logs, and the patterns worth building rules around.
Read the postoperations · 5 min read
Alert fatigue is a security risk, not just an annoyance
When every alert looks urgent, the real ones get missed. How to tune severity so your team can trust the queue.
Read the postcompliance · 6 min read
Mapping detection rules to control frameworks
A practical look at connecting individual security events to the specific controls they help satisfy.
Read the post