Automated monitoring of SAP cyber security and compliance
A cloud-based solution that watches your SAP landscape continuously — secure configuration, compliance, and security events — so intrusions are caught the moment they happen.
Why it exists
It's all about ensuring the confidentiality, integrity, and availability of SAP systems and data. Traditional tools weren't built to hear what SAP is saying.
Increasing vulnerabilities and attacks
SAP security vulnerabilities are uncovered regularly, many easily exploitable, resulting in more attacks on SAP systems.
Lack of visibility
Monitoring SAP security threats is often cumbersome and sits outside the purview of traditional SIEM and SOC operations.
Inadequate cybersecurity controls
Traditional SAP assessments focus on SoD, passwords, and security auditing — no longer sufficient on their own.
No clear responsibility
In most organizations, no one is explicitly responsible for SAP cybersecurity — IntrudeGuard gives that person a system to own.
Advantages
Built to be dropped into a live SAP landscape without disruption.
Cloud-based
A cloud-based solution for automated monitoring of the SAP landscape.
Automated monitoring
Compliance, secure configuration, and security events — system settings, parameters, patch and release management, technical components (GW/MS), RFC, and more, plus deviating user behavior.
No add-on required
No need to install any add-on and no custom code required.
On-premise and cloud
Covers SAP BTP (global and subaccounts), SAP Cloud Identity Services (IAS/IPS), SAP SuccessFactors, and SAP ABAP.
Any SAP architecture
Compatible with S/4, ECC, BW, SolMan and more — on premise, private cloud, or SAP RISE.
Multiple alerting
ITSM integration, SIEM integration, email, Teams, and more.
Very low effort
Low implementation and maintenance effort, with no downtime required.
Key checks and features
- Covers all typical IT controls as part of an external financial audit
- Detects attempts to compromise key system components
- Flags user and access management attempts by anyone outside the access solution team
- Watches for deviating user behaviour, including execution of critical activities
- Surfaces account compromise and account sharing
- Flags non-compliant changes to secure setup and configuration
- Detects abnormal data extraction
- 300+ use cases out of the box
What generic security tools miss
Firewalls, antivirus, and off-the-shelf SIEM weren't built to read SAP's own protocols. These are the patterns they let straight through.
Behavior in the system
Data access
Downloading, displaying, or changing critical tables
Session activity
Logon from several workstations for individual users
Credentials
Password spray attacks, and logons with users like SAP* and DDIC
Interfaces
RFC gateway exploitation attempts, and RFC hopping between connected systems
Privilege
Debugging in production, and assignment of SAP_ALL or SAP_NEW
System behaviour
Profile parameter changes and execution of critical programs or remote function modules
Configuration of the system itself
Patching
Missing critical SAP notes, and outdated DB, kernel, Web Dispatcher, or SAP Router versions
Connections
Insecure connections between SAP systems, and open access control lists around critical components
Secrets
A secure store still running its default encryption key, and old or insecure password hashes
Defaults
Default accounts left with default passwords, and insecure default values across most parameters
Auditability
Inactive logging capabilities that let activity go unrecorded
Change control
A system change option left too open
Want to try? We've got you covered.
One month, free
A free trial for one month with all core features included.
Dedicated support
Dedicated support even during the trial period, not just after you sign.
Free assessment
A free-of-charge SAP security assessment and pentest of your SAP landscape.