Meet the Authors

Key Takeaways What you need to know
  1. Rabobank is treating SAP-native security as a migration design topic, wiring controls, monitoring, and compliance into SAP S/4HANA and SAP BTP from day one ahead of the 2027 on-premise phase-out.

  2. With SecurityBridge handling real-time threat detection and monitoring, the bank replaced hours of manual compliance work with dashboards that produce DORA evidence on demand.

  3. SAPinsider benchmark data shows leaders who move security early cut incidents and audit violations, yet broader adoption still lags, leaving a gap SAP Finance migration teams should close now.

Secure and fast are words that usually sit on opposite ends of a tug-of-war for a bank. Rabobank decided to stop choosing between them. The Dutch lender wired advanced security and compliance directly into its SAP landscape, treating SAP-native security as a migration design topic rather than an audit cleanup item. SAP Netherlands has reported that Rabobank is working with SAP and SecurityBridge to harden security and speed compliance reporting across SAP S/4HANA and SAP Business Technology Platform (BTP).

The timing is not accidental. Financial institutions now operate under the EU’s Digital Operational Resilience Act (DORA), which entered into force in January 2025 and requires banks and insurers to demonstrate control over their ICT risk. Regulators no longer accept a binder of policies; they want on-demand evidence that controls work. The backdrop is uncomfortable. SAPinsider’s Benchmark Report found a significant rise in attacks targeting SAP systems and in critical SAP vulnerabilities, including a 2025 zero-day that compromised a large number of systems before it was reported.

Why A Clean Core Became a Security Project

Rabobank’s modernization is driven by a deadline most SAP customers know well. SAP is phasing out its on-premise solution, with mainstream maintenance for SAP ECC ending in 2027. That clock pushed the bank toward a clean core strategy, and it is shaping how the team builds the organization’s security.

Explore related questions

“We see the need to migrate to a clean core. With SAP BTP, we realize our specific business needs outside the core of our SAP S/4HANA ERP solution, so we can respond quickly to changes without compromising operational continuity,” Bas van der Lienden, SAP Basis Consultant at Rabobank, said.

This is worth underlining. SAP BTP is usually pitched as an innovation layer for extensions away from the digital core. However, Rabobank treats it as much a security decision as an architectural one. Keeping custom code out of the core keeps that core standard, upgradable, and auditable, exactly what a regulator wants to see. Security as a design input, not a post-migration cleanup, separates a clean core that stays clean from one that quietly accumulates risk.

Security As A Migration Design Consideration

Rabobank’s approach pulls security into the same planning window as the finance process redesign. In an SAP Finance migration, this means scoping Segregation of Duties (SoD) rule sets, sensitive transaction monitoring, custom code review, vulnerability management, and audit readiness during blueprinting, alongside chart of accounts conversion and universal journal design. Posting authorizations, vendor master changes, and payment run controls are easier to define against a clean SAP S/4HANA process model than to retrofit after close cycles are live, especially in dual-maintenance landscapes where SAP ECC, SAP S/4HANA, and integration layers run in parallel during cutover. Otherwise, audit readiness becomes a compliance treasure hunt with better stationery.

The reason the bank reached for SecurityBridge is simple. The SAP landscape outgrew human-paced controls. The platform provides centralized monitoring, logging, and automated checking of user actions and process anomalies. As van der Lienden explained, real-time threat detection has become a requirement. Rabobank used to have two or three systems, which is why the SAP landscape is so large and complex that one “simply cannot manage it with manual checks anymore.”

The compliance payoff shows up in hours saved. “Previously, we spent hours just manually collecting and validating compliance data,” he observed. “Now we have real-time dashboards that show the current status, and we can immediately signal trends and deviations. That means less administrative burden, faster decision-making, and better evidence.” Under DORA, the ability to produce proof on demand is not a reporting feature. It is the control.

The Shared-Responsibility Question

Early planning also forces teams to settle responsibility boundaries. At the same time, decisions are still open to addressing questions such as who owns patch latency, custom code review, detection within the SAP application stack, and access governance after cutover.

SAPinsider’s benchmark frames cloud SAP security around SAP’s shared responsibility model, with zero trust and continuous monitoring as workloads move to the cloud. The outcomes for leaders that move early are quantified: among those adopting cloud or AI security capabilities, SAPinsider reports 65% reduced security incidents, 55% faster patching, and 30% fewer audit or compliance violations. Yet adoption stays with a minority, fewer than a third of organizations running the broader capabilities SAPinsider has urged for years.

What This Means for SAPinsiders

Move SAP security into blueprinting, not the punch list. With attacks rising and a 2025 zero-day compromising systems before disclosure, late-phase security bets on the assumption that nothing breaks during cutover. SAPinsiders should treat SoD rulesets, custom code review, vulnerability management, and monitoring as design deliverables, scoped against a clean SAP S/4HANA process model rather than retrofitted once close cycles are live.

Lock down shared-responsibility boundaries before the operating model hardens. Answer the ownership questions in writing across SAP, the system integrator, and internal teams before cutover, especially in dual-maintenance landscapes. Regulated finance clients increasingly bring SAP-native tooling, such as SecurityBridge, which secures more than 8,000 SAP systems globally, into the migration scope.

Treat compliance as an evidence engine and mind the adoption gap. Rabobank turned hours of manual compliance work into real-time dashboards, a capability DORA now treats as the control itself. IT leaders should inventory which SAP controls they can prove on demand versus those they must reconstruct manually at audit time, and then close the gap before the next migration milestone forces a decision.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All