Meet the Authors

Key Takeaways What you need to know
  1. Cyber incidents now rank among the top three business risks, prompting organizations to prioritize security budgets over other operational risk categories.

  2. Vendor certifications like ISO 27001 establish a governance baseline but require additional SAP-specific vetting for security partners.

  3. While external partners conduct security assessments, internal teams must retain oversight for contract management and validating remediation outcomes.

addIT Dienstleistungen GmbH & Co KG, a subsidiary of Atos since 2011 and Carinthia’s largest IT service provider, has staked out a position on cybersecurity that starts with a risk claim: the company states that cyber incidents have climbed into the top three business risks facing organizations today, ranking ahead of natural disasters, political change, and damage to brand image. Founded in 2001 and now employing around 120 business technologists across Klagenfurt, Villach, Vienna, and Ljubljana, addIT presents its response to that risk landscape as an End-to-End Security approach built across assessment, protection, and operational layers.

addIT’s End-to-End Security Approach

addIT describes its cybersecurity practice as an End-to-End Security approach, covering the full arc from initial risk discovery through ongoing operations. The company works with partners to conduct security assessments and penetration tests, positioning this diagnostic stage as the entry point for engagements. From there, addIT moves into implementation, installing endpoint protection and network solutions intended to close the gaps that assessments surface.

The approach concludes with managed security services, which addIT operates continuously as part of ongoing client engagements.

Explore related questions

In SAP environments generally, penetration testing typically covers RFC, gateway, and HANA-layer risks beyond standard infrastructure testing, and organizations often layer governance, risk, and compliance tooling, including segregation-of-duties analysis, on top of network and endpoint controls.

Governance and Certification Backbone

addIT supports its security claims with a certification record built over more than a decade. The company has held ISO 9001 quality management certification since 2008 and implemented ISO 20000, the international standard for IT service management, as part of a matrix certification tied to parent company Atos. It added ISO 14001 environmental management certification in 2016, followed by ISO 27001 certification for information security management in 2017.

The nine-year span across these four certifications reflects a sustained build-out of governance and compliance capability. ISO 27001 speaks directly to information security management practices, distinct from the quality and service management standards that preceded it.

SAP customers assessing a security partner’s governance maturity often use certifications like ISO 27001 as one input alongside frameworks specific to SAP environments, such as SAP’s security baseline guidance. addIT’s certification stack offers a general governance signal but is not itself an SAP-specific credential, and buyers should weigh it alongside direct evidence of SAP security experience.

What This Means for SAPinsiders

Cyber risk now outranks physical and market risk. addIT’s claim that cyber incidents rank among the top three business risks suggests SAP teams should expect security budget requests to compete more directly with, and potentially outweigh, funding requests tied to other operational risk categories. Internal risk registers built around physical or market disruption scenarios may need updating to reflect this shift.

Certifications establish a governance baseline for evaluating SAP security partners. Buyers can use a stack like ISO 9001, ISO 20000, ISO 14001, and ISO 27001 as a starting checklist for vendor governance maturity, but none of these certifications confirm SAP-specific security depth. Procurement teams should pair certification review with direct questions about SAP landscape experience.

Partner-delivered assessments still need internal oversight. Because addIT conducts security assessments and penetration testing together with partners rather than entirely in-house, SAP security teams retain responsibility for contract oversight and outcome verification. Delegating the technical work does not remove the need for internal governance of findings and remediation timelines.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All