05/06/2026
If your organisation runs SAP, there's a good chance your security team has a significant blind spot - it is better not to wait until an incident happens...
Most enterprises have a SIEM - a centralised platform that collects security logs and alerts from across the IT environment. The problem is that standard SIEM tools are built for infrastructure: network devices, firewalls, endpoints, cloud services. They're very good at what they're designed for.
But SAP is different here.
Actions in SAP applications - are not visible at the infrastructure level. Meta information like an employee's organisational position is similarly unavailable outside the SAP application layer.
So if someone inside your organisation is slowly exfiltrating sensitive financial records through a legitimate SAP transaction, your SIEM won't see it and your firewall won't flag it. It looks like completely normal business activity - because from an infrastructure perspective, it is.
This is the problem that SAP Enterprise Threat Detection (ETD) was built to solve. And a new reference architecture from the SAP Architecture Center - contributed by Fortinet - shows precisely how ETD and enterprise SIEM/SOAR platforms can work together to give security teams full visibility across both layers.
How the two-layer approach works:
SAP ETD gathers logs from active SAP systems, pseudonymises them for privacy, enriches and normalises the data, and then loads it into SAP HANA. Predefined attack patterns - developed from ERP auditing guides, SAP's Anomaly Detection Lab, and security notes - are applied to detect potential threats and generate alerts.
Those structured, SAP-aware alerts are then forwarded to your existing SIEM or SOAR platform - Splunk, Microsoft Sentinel, FortiSIEM, or whichever tool your SOC already uses. Your security team gets the full picture: SAP application events correlated with the broader infrastructure context, with automated response playbooks able to act on either layer.
ETD understands SAP event semantics, reducing the configuration burden in the SIEM system and bridging the gap between IT infrastructure and SAP security - with licencing based on monitored users rather than unpredictable data volumes.
The result is a Security Operations Centre that no longer has to treat SAP as a separate, opaque environment. SAP threat intelligence feeds directly into enterprise security operations — and your SOC finally has the full picture.
📍If you're responsible for SAP security, enterprise architecture, or SOC operations, this reference architecture is worth reviewing carefully