What's Happening?
Organizations migrating their Enterprise Resource Planning (ERP) systems to SAP's cloud-based offering, RISE with SAP, must understand that while SAP manages much of the underlying infrastructure, customers retain significant security, governance, and compliance
responsibilities. RISE with SAP combines SAP S/4HANA Cloud, infrastructure, and technical operations under a single subscription, aiming to reduce operational overhead for customers. However, a shared responsibility model for security is introduced, where accountability is distributed across SAP, its infrastructure providers, implementation partners, and the customer's internal teams. Misconceptions about this shared model can lead to critical security controls falling through the cracks, potentially exposing organizations to audit findings, delayed incident response, governance failures, and increased cyber risk. Key areas where customer responsibility remains paramount include business resilience beyond basic backups, network segmentation, comprehensive security monitoring within SAP applications, regulatory compliance, and overall governance.
Why It's Important?
This shared responsibility model is crucial for U.S. businesses, particularly those in regulated industries, as it directly impacts their cybersecurity posture and compliance obligations. A misunderstanding of these responsibilities can lead to severe financial penalties, reputational damage, and operational disruptions. For instance, while SAP performs backups, customers are responsible for ensuring business resilience through explicit disaster recovery (DR) contracts and testing, which is vital for recovering from cyberattacks or outages. Similarly, organizations must design their enterprise network architecture and implement network segmentation, even though SAP secures the underlying cloud infrastructure. The distinction between SAP's monitoring of infrastructure health and the customer's responsibility for monitoring security threats within SAP applications is also critical for detecting and responding to internal and external threats. Ultimately, the onus remains on the customer to demonstrate compliance with regulations like SOX, GDPR, HIPAA, and FDA 21 CFR Part 11, regardless of where their SAP system is hosted.
What's Next?
Organizations adopting RISE with SAP should immediately review SAP's Roles and Responsibilities document to clearly understand the division of duties. They must validate that critical security and governance responsibilities, such as disaster recovery, network segmentation, and application-level security monitoring, are explicitly addressed in their contracts and internal processes. This includes verifying that optional services like SAP Firewall as a Service (FWaaS) and LogServ are included if required for their security architecture. Furthermore, organizations need to establish a documented responsibility matrix that clearly assigns ownership for every critical security control across all involved parties: SAP, hyperscale cloud providers, managed service providers, implementation partners, and internal teams. Regular reviews of this model and proactive engagement with SAP and partners will be essential to prevent security gaps and ensure continuous compliance and operational resilience.
Beyond the Headlines
The shift to cloud-based ERP systems like RISE with SAP represents a broader trend in enterprise technology, where the lines of responsibility for security and compliance are becoming increasingly blurred. This evolution necessitates a fundamental change in how U.S. businesses approach IT governance and risk management. It moves beyond simply outsourcing infrastructure to a more complex co-management model, requiring a sophisticated understanding of shared risk. The ethical implication is that organizations cannot simply assume their security burden is fully transferred to a cloud provider; they must actively participate in defining and enforcing their security posture. This also highlights the growing demand for cybersecurity expertise within organizations, as internal teams must now navigate complex cloud security frameworks and integrate them with their existing security operations. The long-term shift will likely see a greater emphasis on contractual clarity, robust internal security frameworks, and continuous auditing to ensure accountability in these shared environments.













