Four delivery modes — implementation, upgrades, migrations and support — applied across nine areas of the SAP security estate.
Service lines
Four ways to work with us
Before the technology, the shape of the engagement. Most clients start in one of these four and move between them as the work changes.
Advisory
Security Strategy
Where you are, where you need to be, and the order to do it in — before anyone buys a licence.
Current-state assessment and risk baseline
Target operating model for SAP security
Roadmap sequenced against audit and release dates
Tooling selection and business case support
Delivery
Cybersecurity Services
The hands-on work: implementation, remediation and hardening across the SAP estate.
GRC, IAG and partner platform delivery
Threat detection and vulnerability management
Code security and system hardening
Audit remediation and evidence preparation
Capacity
Shared Professional Services
Specialist skills on tap, shared across clients — expertise you need regularly but not constantly.
Fractional SAP security consultants
Offshore, onshore and hybrid resourcing
Cover for peak periods and staff gaps
Knowledge transfer to your own team
Operate
Managed IT Services
We run it. Monitoring, patching, access reviews and support on a continuing basis.
Managed SAP security monitoring
Patch and security note management
Periodic access reviews and certification
Application support across SAP and Salesforce
Delivery modes
And four stages of work
Mode 01
Implementation
New deployments, scoped and configured against your control requirements, with handover documentation.
Mode 02
Upgrades
Version and support-pack upgrades with regression testing on your live rulesets and roles.
Mode 03
Migrations
Platform and landscape moves that preserve control history, approvals and audit evidence.
Mode 04
Support
Managed services — monitoring, patching, access reviews, audit response — on a continuing basis.
Governance and identity
Controlling who can do what
SAP GRC
Access Control, Process Control and Risk Management, configured so the workflow matches how approvals really happen in your business rather than how the default template assumes.
Ruleset design, customisation and clean-up
Segregation of duties analysis and remediation
Emergency access (firefighter) management and log review
Access request workflow and approver design
User access review and recertification cycles
Business role management and role redesign
SAP IAG
Identity Access Governance for estates that are no longer purely on-premise. Useful when access decisions have to span ECC, S/4HANA, SuccessFactors, Ariba and third-party SaaS at once.
IAG tenant setup and connector configuration
Access request and automated provisioning
Access certification and review campaigns
Role design across cloud and on-premise targets
Bridge scenarios linking existing GRC to IAG
Privileged access management in the cloud
Code and infrastructure
The layers audits usually miss
Application security
Access controls assume the platform underneath them is sound. Often it is not — unapplied security notes, custom code with injection paths, and RFC destinations with stored credentials are the common findings.
Custom ABAP code vulnerability scanning
SAP security note assessment and patch management
System hardening: profile parameters, gateway, message server
RFC destination and interface security review
Transport and change-control security
Threat detection and log monitoring design
BTP and cloud security
SAP Business Technology Platform uses a different authorisation model to the ERP most teams know. Extensions built there often get provisioned quickly and governed later.
Subaccount and directory governance
Role collections, roles and entitlement design
Identity provider and trust configuration
Cloud Connector and destination security
API and integration authorisation review
Security posture assessment for cloud tenants
Authentication
Who is actually at the keyboard
Access governance answers what a user is allowed to do. Authentication answers whether the person holding that account is who the account says they are — and SAP passwords alone have not answered it credibly for years.
Sign on once. Prove it again only when the action warrants it.
TrustBroker single sign-on
SSO for SAP built on the Active Directory infrastructure you already run, so users authenticate once at the workstation and reach SAP without a separate password.
SSO across SAP GUI, Fiori, NWBC and web application access
Kerberos and SAML-based configuration for on-premise and cloud
Works on RISE with SAP and hosted landscapes
No additional hardware or parallel identity infrastructure
Removal of SAP-side passwords and their reset overhead
Multi-tier scenarios where one logon spans several systems
Policy-based MFA and step-up
Not every action needs a second factor, and prompting for one on every screen trains users to click through. TrustBroker holds an authentication policy on each SAP system so the challenge lands where the risk is.
MFA using Microsoft Entra ID, Okta, PingID, Duo, RSA SecurID or TOTP apps
Step-up authentication after logon — releasing a payment, running a sensitive transaction, viewing restricted data
Policies driven by role assignment or the specific action attempted
Passwordless authentication paths across SAP workflows
Contextual enforcement using SecurityBridge threat signals, where both are deployed
Rollout planning that accounts for shop-floor and shared-device users
How it fits with SecurityBridge
TrustBroker became part of SecurityBridge in 2025 and the two integrate: real-time signals such as anomalous logon behaviour or an unrecognised device can decide when MFA gets enforced. It also runs perfectly well standalone if authentication is the only thing you need right now — we deliver it either way.
Partner platforms
Products we are certified to deliver
We are official trusted partners of SecurityBridge, Pathlock and Soterion — which means licensing, implementation and ongoing support can come from one place. TrustBroker sits within the SecurityBridge portfolio and is covered by the same partnership.
SecurityBridge
SAP-native threat detection
Real-time monitoring, vulnerability management, patch and code security built to run inside the SAP stack rather than beside it.
Implementation and alert tuning
Response playbook design
Managed monitoring service
Integration with your SIEM
TrustBroker
SSO and contextual MFA
Single sign-on for SAP with multi-factor authentication applied by policy — at logon, or later, when a user reaches something sensitive.
SSO for SAP GUI, Fiori and web access
MFA via Entra ID, Okta, PingID, Duo, RSA
Step-up authentication on high-risk actions
Active Directory integration, no new infrastructure
Pathlock
Access governance and CCM
Cross-application access governance and continuous controls monitoring for organisations running SAP alongside other business systems.
Deployment and connector setup
Risk and control configuration
Migration from legacy GRC
Automated audit evidence
Soterion
Business-readable risk
SoD analysis expressed in language business owners can approve, plus licence position management to keep your SAP measurement honest.
Risk analysis and remediation
Licence optimisation
Business-owner reporting
Rapid deployment engagements
Salesforce
The other system your customers live in
Quotes are raised in Salesforce and fulfilled in SAP. Credit limits sit in SAP and get quoted against in Salesforce. When the two are out of step, sales promises things operations cannot deliver — and the access controls you built on the SAP side stop at the boundary.
One customer record, two systems of record — governed on both sides.
Implementation
Build and configure
Sales Cloud and Service Cloud set up around your actual sales process rather than the demo org.
Object, field and page layout design
Flows, validation and approval processes
Reports and dashboards people will use
Data migration and de-duplication
Integration
Connect it to SAP
The join that makes both systems worth having — built on supported interfaces, not overnight spreadsheet exports.
Quote-to-order and order status synchronisation
Customer, material and pricing master data alignment
Credit exposure visible at the point of quoting
Integration via SAP BTP, middleware or API
Access governance
Extend your controls
Our SAP background is the reason to have us do this. Segregation of duties does not respect application boundaries.
Profile, permission set and role hierarchy design
Cross-application SoD analysis with SAP
Field-level and record-level security review
Access certification alongside SAP campaigns
Support
Keep it healthy
Salesforce ships three releases a year. Someone has to test what they change before your users find out.
Release readiness and regression testing
Enhancement backlog and admin support
Org health, technical debt and licence review
User adoption and training support
Not sure which of these you need?
Describe the problem instead of the product. We will tell you what would actually fix it — including when the answer is nothing new.