PragmaTrust & Security Focus

Services

Everything that touches
SAP access and risk

Four delivery modes — implementation, upgrades, migrations and support — applied across nine areas of the SAP security estate.

Service lines

Four ways to work with us

Before the technology, the shape of the engagement. Most clients start in one of these four and move between them as the work changes.

Advisory

Security Strategy

Where you are, where you need to be, and the order to do it in — before anyone buys a licence.

  • Current-state assessment and risk baseline
  • Target operating model for SAP security
  • Roadmap sequenced against audit and release dates
  • Tooling selection and business case support
Delivery

Cybersecurity Services

The hands-on work: implementation, remediation and hardening across the SAP estate.

  • GRC, IAG and partner platform delivery
  • Threat detection and vulnerability management
  • Code security and system hardening
  • Audit remediation and evidence preparation
Capacity

Shared Professional Services

Specialist skills on tap, shared across clients — expertise you need regularly but not constantly.

  • Fractional SAP security consultants
  • Offshore, onshore and hybrid resourcing
  • Cover for peak periods and staff gaps
  • Knowledge transfer to your own team
Operate

Managed IT Services

We run it. Monitoring, patching, access reviews and support on a continuing basis.

  • Managed SAP security monitoring
  • Patch and security note management
  • Periodic access reviews and certification
  • Application support across SAP and Salesforce

Delivery modes

And four stages of work

Mode 01

Implementation

New deployments, scoped and configured against your control requirements, with handover documentation.

Mode 02

Upgrades

Version and support-pack upgrades with regression testing on your live rulesets and roles.

Mode 03

Migrations

Platform and landscape moves that preserve control history, approvals and audit evidence.

Mode 04

Support

Managed services — monitoring, patching, access reviews, audit response — on a continuing basis.

Governance and identity

Controlling who can do what

SAP GRC

Access Control, Process Control and Risk Management, configured so the workflow matches how approvals really happen in your business rather than how the default template assumes.

  • Ruleset design, customisation and clean-up
  • Segregation of duties analysis and remediation
  • Emergency access (firefighter) management and log review
  • Access request workflow and approver design
  • User access review and recertification cycles
  • Business role management and role redesign

SAP IAG

Identity Access Governance for estates that are no longer purely on-premise. Useful when access decisions have to span ECC, S/4HANA, SuccessFactors, Ariba and third-party SaaS at once.

  • IAG tenant setup and connector configuration
  • Access request and automated provisioning
  • Access certification and review campaigns
  • Role design across cloud and on-premise targets
  • Bridge scenarios linking existing GRC to IAG
  • Privileged access management in the cloud

Code and infrastructure

The layers audits usually miss

Application security

Access controls assume the platform underneath them is sound. Often it is not — unapplied security notes, custom code with injection paths, and RFC destinations with stored credentials are the common findings.

  • Custom ABAP code vulnerability scanning
  • SAP security note assessment and patch management
  • System hardening: profile parameters, gateway, message server
  • RFC destination and interface security review
  • Transport and change-control security
  • Threat detection and log monitoring design

BTP and cloud security

SAP Business Technology Platform uses a different authorisation model to the ERP most teams know. Extensions built there often get provisioned quickly and governed later.

  • Subaccount and directory governance
  • Role collections, roles and entitlement design
  • Identity provider and trust configuration
  • Cloud Connector and destination security
  • API and integration authorisation review
  • Security posture assessment for cloud tenants

Authentication

Who is actually at the keyboard

Access governance answers what a user is allowed to do. Authentication answers whether the person holding that account is who the account says they are — and SAP passwords alone have not answered it credibly for years.

Flow diagram: a user signs on at their workstation, single sign-on authenticates against Active Directory, a per-system policy evaluates the request, and SAP allows the action — with a step-up MFA branch triggered by high-risk actions.USERWORKSTATION LOGONSSOACTIVE DIRECTORYPOLICYPER-SYSTEM RULESSAPACTION ALLOWEDSTEP-UP MFAHIGH-RISK ACTIONSIGN ON ONCE — PROVE IT AGAIN ONLY WHEN IT MATTERS
Sign on once. Prove it again only when the action warrants it.

TrustBroker single sign-on

SSO for SAP built on the Active Directory infrastructure you already run, so users authenticate once at the workstation and reach SAP without a separate password.

  • SSO across SAP GUI, Fiori, NWBC and web application access
  • Kerberos and SAML-based configuration for on-premise and cloud
  • Works on RISE with SAP and hosted landscapes
  • No additional hardware or parallel identity infrastructure
  • Removal of SAP-side passwords and their reset overhead
  • Multi-tier scenarios where one logon spans several systems

Policy-based MFA and step-up

Not every action needs a second factor, and prompting for one on every screen trains users to click through. TrustBroker holds an authentication policy on each SAP system so the challenge lands where the risk is.

  • MFA using Microsoft Entra ID, Okta, PingID, Duo, RSA SecurID or TOTP apps
  • Step-up authentication after logon — releasing a payment, running a sensitive transaction, viewing restricted data
  • Policies driven by role assignment or the specific action attempted
  • Passwordless authentication paths across SAP workflows
  • Contextual enforcement using SecurityBridge threat signals, where both are deployed
  • Rollout planning that accounts for shop-floor and shared-device users

Partner platforms

Products we are certified to deliver

We are official trusted partners of SecurityBridge, Pathlock and Soterion — which means licensing, implementation and ongoing support can come from one place. TrustBroker sits within the SecurityBridge portfolio and is covered by the same partnership.

SecurityBridge

SAP-native threat detection

Real-time monitoring, vulnerability management, patch and code security built to run inside the SAP stack rather than beside it.

  • Implementation and alert tuning
  • Response playbook design
  • Managed monitoring service
  • Integration with your SIEM
TrustBroker

SSO and contextual MFA

Single sign-on for SAP with multi-factor authentication applied by policy — at logon, or later, when a user reaches something sensitive.

  • SSO for SAP GUI, Fiori and web access
  • MFA via Entra ID, Okta, PingID, Duo, RSA
  • Step-up authentication on high-risk actions
  • Active Directory integration, no new infrastructure
Pathlock

Access governance and CCM

Cross-application access governance and continuous controls monitoring for organisations running SAP alongside other business systems.

  • Deployment and connector setup
  • Risk and control configuration
  • Migration from legacy GRC
  • Automated audit evidence
Soterion

Business-readable risk

SoD analysis expressed in language business owners can approve, plus licence position management to keep your SAP measurement honest.

  • Risk analysis and remediation
  • Licence optimisation
  • Business-owner reporting
  • Rapid deployment engagements

Salesforce

The other system your customers live in

Quotes are raised in Salesforce and fulfilled in SAP. Credit limits sit in SAP and get quoted against in Salesforce. When the two are out of step, sales promises things operations cannot deliver — and the access controls you built on the SAP side stop at the boundary.

Diagram showing SAP holding orders, invoices, materials and credit limits, exchanging data with Salesforce holding accounts, opportunities, quotes and cases — quote-to-order flowing one way, status and credit information flowing back.SAPORDERSINVOICESMATERIALSCREDIT LIMITSALESFORCEACCOUNTSOPPORTUNITIESQUOTESCASESQUOTE TO ORDERSTATUS AND CREDIT BACKONE CUSTOMER RECORD — GOVERNED ON BOTH SIDES
One customer record, two systems of record — governed on both sides.
Implementation

Build and configure

Sales Cloud and Service Cloud set up around your actual sales process rather than the demo org.

  • Object, field and page layout design
  • Flows, validation and approval processes
  • Reports and dashboards people will use
  • Data migration and de-duplication
Integration

Connect it to SAP

The join that makes both systems worth having — built on supported interfaces, not overnight spreadsheet exports.

  • Quote-to-order and order status synchronisation
  • Customer, material and pricing master data alignment
  • Credit exposure visible at the point of quoting
  • Integration via SAP BTP, middleware or API
Access governance

Extend your controls

Our SAP background is the reason to have us do this. Segregation of duties does not respect application boundaries.

  • Profile, permission set and role hierarchy design
  • Cross-application SoD analysis with SAP
  • Field-level and record-level security review
  • Access certification alongside SAP campaigns
Support

Keep it healthy

Salesforce ships three releases a year. Someone has to test what they change before your users find out.

  • Release readiness and regression testing
  • Enhancement backlog and admin support
  • Org health, technical debt and licence review
  • User adoption and training support

Not sure which of these you need?

Describe the problem instead of the product. We will tell you what would actually fix it — including when the answer is nothing new.

Ask us