
Meet the Authors
Pathlock and NTT DATA Business Solutions are extending continuous SOC coverage into SAP transactions, identities, custom code, and business processes.
Pathlock CEO Damon Tompkins says AI is shortening attack timelines while cloud adoption and SAP S/4HANA transformation increase the activity security teams must monitor.
The managed model combines Pathlock’s SAP-specific controls with NTT DATA Business Solutions’ SOC operations to support continuous monitoring and expert-led response.
“The window between a critical SAP vulnerability being disclosed and actively exploited has gone from weeks to days,” Pathlock CEO Damon Tompkins told SAPinsider. “Defenders are now operating against the clock in a way they simply weren’t a few years ago.”
Tompkins attributes much of that acceleration to AI. Identifying targets, finding weaknesses, building exploits, phishing, and writing malicious code can now be done in hours and at greater scale, he said. But he notes the target has changed as well.
SAP was once treated as a protected application behind the corporate firewall. Financially motivated attackers now see it as the destination. “SAP is where the money and the crown-jewel data actually live: payments, vendor master data, financial postings, supply chain,” Tompkins said. “SAP isn’t a stepping stone anymore; it’s the objective.”
Cloud adoption, RISE with SAP, and API-driven integration have expanded the ways users and systems connect to SAP. SAP S/4HANA programs are changing roles, custom code, and security architecture, giving already stretched security teams more to monitor.
Faster threats, broader connectivity, and scarce specialist capacity are making continuous SAP security difficult to sustain internally. Pathlock and NTT DATA Business Solutions are responding with a partnership that delivers SAP controls delivered through continuous SOC coverage.
“I Have a SOC, but Who Is Actually Watching My SAP?”
NTT DATA Business Solutions was hearing similar concerns from its customers. Richard Stahl, head of SAP business development, said organizations wanted security that could move beyond traditional controls and operate inside SAP.
Tompkins described how the relationship began. “Like many successful partnerships, it started with a conversation,” he said. “We met NTT DATA Business Solutions at a trade show in Nuremberg and quickly recognized a strong strategic fit.”
Pathlock brought SAP-native cybersecurity technology and application-level expertise. NTT DATA Business Solutions brought an established SAP practice, global managed-services operations, and a mature security operations center.
Both companies invested in training, validation, and a joint proof of concept. Tompkins said the result was more than a technology integration: NTT DATA Business Solutions’ SOC teams could operate the capability confidently and deliver it to customers at scale.
Their effort centered on a question customers with established security operations kept asking: ‘I have a SOC, but who is actually watching my SAP?’
“In many cases, the answer was effectively no one,” Tompkins said.
Most SOCs are built around network, endpoint, and identity data, he said. They may detect activity around an SAP system without seeing what is happening inside the transactions, authorizations, and business processes the application runs.
That limitation becomes more consequential as SAP environments change.
“As SAP transformation programs accelerate, organizations are facing a growing need for continuous, application-level security that goes beyond traditional controls,” Stahl said. He added that regulatory demands and efforts to integrate SAP into broader SOC operations are exposing the limits of standard security tools.
When the SOC Learns to Speak SAP
Tompkins explained that market demand gave shape to the partnership. “Customers don’t just want assessments anymore, they want ongoing protection,” he said. “This partnership was built to meet that need.”
“A normal SOC is great at infrastructure, network, endpoints, identity, but it doesn’t speak SAP,” he said. Security teams may therefore detect suspicious activity around the system without understanding what it means for the business.
Tompkins pointed to transport control as a clear example.
SAP transports move code and configuration into production, creating what he called a “powerful, mostly unwatched path” through which a malicious change or backdoor could reach a live system. “A generic SOC never sees it; we do,” he said.
Pathlock monitors SAP-specific risks such as privilege escalation, suspicious RFC calls, vulnerabilities documented in SAP Security Notes, and weaknesses in custom code. That visibility becomes important during migrations, when organizations rewrite custom code. AI-assisted attackers are “very good at finding the weak spots” in that code, Tompkins said.
Non-human identities create another control challenge. Service accounts, technical users, bots, and AI-driven automation can operate inside SAP with broad privileges and limited scrutiny. Tompkins said governing those identities is now as important as governing people.
Connecting each signal to an identity and its business context also changes the response. Tompkins said security teams can respond more precisely by revoking access, blocking a transaction, or quarantining a transport instead of disrupting the wider system.
That model requires SAP-specific technology and SOC expertise. Under the partnership, Pathlock provides the technology that connects security signals with identities and business processes, while NTT DATA Business Solutions operates it through its SOC and global managed-services framework.
“We move the SOC from ‘something happened on a server’ to ‘this identity could manipulate this financial process,’” Tompkins said. “That’s what actually matters.”
Why SAP Transformation Is the Time to Rethink Security
SAP transformation creates a natural point to rethink how security operates.
Tompkins said organizations moving to SAP S/4HANA or RISE with SAP are already redesigning roles, custom code, integrations, and security architecture. “It’s far more effective to build continuous protection into that journey than to retrofit it later,” he said.
Stahl described new SAP architectures as making that decision more urgent. The managed service gives organizations adopting SAP S/4HANA or SAP Cloud ERP a way to strengthen compliance and incident response without adding internal specialists.
But transformation is not the only entry point. Companies with mature SOCs may monitor networks, endpoints, and identities continuously but lack the SAP knowledge needed to understand what is happening. The service extends those existing operations into SAP.
That role also explains where the offering sits within NTT DATA Business Solutions. Stahl placed it alongside the company’s managed cloud, SIEM, and SOC services, extending security into SAP across on-premises, private-cloud, and hyperscaler environments.
Tompkins sees that model as part of a wider change in enterprise security. “That’s the same evolution we’ve already seen in cloud security and endpoint security,” he said. “SAP is simply the next critical layer that requires always-on monitoring, detection, and response.”
Faster attackers and stretched security teams are driving that shift, he said. The partnership gives organizations access to continuous SAP-aware protection operated by specialists, with the goal of defending critical systems at the speed of modern threats.
What This Means for SAPinsiders
- SAP-aware SOCs improve response quality. Connecting technical signals to identities and business processes helps teams distinguish routine activity from material risk. That context supports faster, narrower action without disrupting the wider SAP environment.
- Managed coverage turns expertise into scale. Pairing Pathlock’s application controls with NTT DATA Business Solutions’ SOC operations gives customers continuous specialist support. The model can extend mature security programs without requiring every enterprise to build a full SAP security function.
- Transformation becomes a security design opportunity. SAP S/4HANA and cloud programs already change roles, code, integrations, and operating responsibilities. Adding continuous monitoring during that redesign can reduce retrofit work and carry stronger controls into the target environment.



