Episode 106 -- The Invisible Attack Surface: Zero Trust for SAP and ERP Environments
In Episode 106 of the Cybersecurity Readiness Podcast Series, I sit down with Holger Hügel, CTO of SecurityBridge and SAP cybersecurity authority with 26 years of experience, to tackle one of enterprise security's most overlooked blind spots.
The August 2024 ransomware attack on Stoli Group USA is a wake-up call. Attackers went straight for the SAP ERP system, crippling financial operations and contributing to a bankruptcy filing within three months. The uncomfortable reality: most CISOs have never formally claimed accountability for SAP security — and most SAP teams don't see themselves as part of the security function.
Holger breaks down the structural gap: SAP systems are simultaneously the most business-critical and least security-governed assets in large organizations. Different languages. Different budgets. No collaboration. The result? Configuration drift, patch backlogs, and monitoring gaps that attackers are happy to exploit.
Filtered through the CPD (Commitment–Preparedness–Discipline) framework, we examine what good governance actually looks like — and the Medtronic case study delivers a clear blueprint.
One finding that should give every CISO pause: SecurityBridge research shows that 67% of organizations address SAP security reactively — triggered only by an audit, a penetration test, or an incident. If your organization is in that 67%, this episode is for you.
Podcast video:
youtu.be/nbWUubz4gvg
Podcast audio:
cybersecurityreadinesspodcas…
Episode summary & discussion highlights:
dchatte.com/episode-106-the-…
All Video Episodes:
youtube.com/playlist...
All Audio Episodes:
cybersecurityreadinesspodcas…