Digital Transformation & Cloud ERPS4HANA CoreFinancials & GRCSecurity & RiskSession

Rethinking Risk, Readiness, and Resilience: Why Most SAP Security Programs Leave You Exposed

Thu, 19 Nov 2026 · 2:55 PM – 3:35 PMLevel 5 - Room 5.5
Gaurav Singh

Gaurav Singh

Senior Manager, SAP Cybersecurity · Under Armour

Gaurav Singh leads SAP Cybersecurity at Under Armour, where he is responsible for securing enterprise SAP environments across S/4HANA, BTP, and cloud infrastructure. A published SAP Press author with 20+ years of hands-on experience, Gaurav has protected organizations through digital transformations – not just governance and access controls, but across the full attack surface: vulnerability management, threat detection, incident response, disaster recovery, and Zero Trust architecture. He has spoken globally at Gartner, SAPinsider, Mastering SAP, ISC2, and other leading industry conferences, and hosts the CyberKriya Podcast, where he brings together practitioners and executives from across the cybersecurity industry. Gaurav's sessions are built for practitioners who want actionable takeaways, not slide decks.

The session

About this session

Most SAP security programs are built around the same foundations: roles, authorisations, segregation of duties, and GRC. They are designed to pass audits. And for a long time, that was enough. It isn't anymore. As SAP landscapes shift toward hybrid and cloud-native environments, the traditional security perimeter is disappearing. Compliance frameworks were never designed to stop a determined attacker – and the gap between being compliant and being genuinely protected is where most organisations are most exposed.

In this session, Gaurav Singh – Senior Manager of SAP Security at Under Armour and co-author of the #1 bestselling SAP Press title Cybersecurity for SAP – makes the case for a fundamentally different approach. Drawing on nearly two decades of experience and the frameworks laid out in his book, Gaurav walks through what a complete SAP cybersecurity program actually looks like: one that bridges the gap between SAP security teams and enterprise cybersecurity functions, and treats protection as a continuous discipline rather than a point-in-time checklist.

This is a session for anyone who has ever assumed that a locked-down role matrix means a secure system – and wants to know what they might be missing.

What You'll Learn

  • Why traditional SAP security leaves critical gaps – and the non-traditional domains most programs overlook, from vulnerability management to threat detection to incident response
  • How to use the NIST Cybersecurity Framework and SAP's Secure Operations Map to build a practical, risk-based security roadmap
  • How attackers actually move through an SAP landscape – and what controls stop them at each stage
  • How to close the divide between your SAP team and your cybersecurity team, and why that divide is your biggest unmanaged risk
  • What the RISE with SAP shared responsibility model means for your security obligations in the cloud
Digital Transformation & Cloud ERPS/4HANA CoreFinancials & GRCSecurity & Risk

More sessions you'll find valuable

Digital Transformation & Cloud ERPS4HANA CoreFinancials & GRCSecurity & Risk

What Would You Do? An Interactive SAP Risk and Security Simulation

View session details
PlatformsApplication Development & AutomationBusiness AI & Joule

Architecting AI Agents with Joule and SAP BTP

Steven Chua

Steven Chua

Enterprise Architecture Advisory · SAP

View session details
Digital Transformation & Cloud ERPBusiness AI & JouleFinancials & GRC

Autonomous Finance - Freeing Capacity Without Losing Control

Saijes Mundadan

Saijes Mundadan

SAP oCFO Lead - ANZ · SAP

View session details