
As more organizations seek to integrate security throughout the entire software development life cycle (SDLC), nine of ten DevOps, engineering and security professionals say they are taking part in a DevSecOps initiative. Given the universal adoption, the DevSecOps market is projected to grow to $37 billion in 2035, up from $10 billion last year.
In the process of implementation, teams are discovering that DevSecOps accelerates the remediation of vulnerabilities while reducing deployment times – a significant step on the road to a modernized security architecture.
However, the protection of SAP systems appears to be precariously overlooked amid the transformation.
This makes for a glaring gap in cyber defense: As organizations increasingly invest in SAP for their enterprise resource planning (ERP) needs, the SAP Business Network now accounts for more than $6.4 trillion in annual commerce. SAP customers generate 84 percent of total global commerce, and 99 of the world’s 100 largest companies are SAP customers.
But DevSecOps appears to stop before it reaches SAP environments. In fact, it takes an average of 97 days to test and deploy SAP patches, yet cyber criminals are capable of weaponizing new vulnerabilities in as little as 72 hours. With our research revealing a 210 percent increase in the active exploitation of SAP vulnerabilities from 2024 to 2025, an immense amount of business-critical applications are now potentially exposed.
So why is this happening? Because security teams commonly assume routine defense practices can apply seamlessly to SAP. But ERP systems operate within a different model than other applications. They rely on transport routes, tightly controlled change processes and complex systems that prioritize stability. Unlike microservices architectures in which teams are able to patch and redeploy a container in minutes, changes to an SAP environment frequently impact a monolithic core in which finance, supply chain and HR data intersect. Just one failure in a single area can halt global business operations.
In addition, most SAP systems are heavily customized using Advanced Business Application Programming (ABAP) code, and a standard vendor patch may break the bespoke process.
As a result, SAP transport routes too often remain an overlooked exposure point, stemming from the disconnect between modern DevSecOps practices and the comparatively slow movement of SAP changes into production. Couple this with the fact that adversaries are only getting faster and better at exploiting vulnerabilities, and it’s easy to see how the gap is widening between how swiftly attackers move and how quickly teams overseeing SAP deployments can respond.
How SAP bottlenecks contribute to risky business
To close the gap, teams must educate themselves on these operational realities, identify where bottlenecks exist in SAP change workflows and direct cyber defense practices accordingly. This will create a shared understanding to help security teams design remediation strategies which better align to SAP operational models.
As for those bottlenecks, they include:
Manual regression testing. With so much riding on SAP in the center of business operations, teams will spend weeks manually verifying that a security patch won’t crash the billing system, payroll, etc.
Siloed tooling. Traditional vulnerability scanners often stop at the network layer without “seeing” the SAP application layer or its transport routes, leading to a lack of actionable data for Basis teams (which essentially function as system administrators for ERP environments).
Change latency. Rigid – and infrequent – release cycles prioritize stability for SAP changes, and this creates a “wait for the next window, whenever it happens …” mindset even for critical security issues.
So how should organizations respond as they seek to close the DevSecOps gap? The first step is acknowledging that they can’t shoehorn SAP operational models into traditional DevOps patterns, and then establishing the following capabilities/practices:
Automated transport inspection. Readily available solutions now allow for the automatic scanning of SAP transports for malicious code and other problems as they move from development to quality assurance. With this, teams avoid the long wait for a manual audit before production.
Continuous monitoring. Because patching takes a while, teams should use real-time monitoring to detect when a cyber criminal is targeting a known vulnerability in the SAP environment. Upon such detection, teams can conduct virtual patching while the formal patch is tested.
Embedded expertise. Rather than lob requirements over a wall, consider embedding a security-minded professional within the SAP Basis team to ensure remediation aligns to operational workflows.
Cyber criminals only need 72 hours – the equivalent of a three-day weekend – to exploit and weaponize vulnerabilities. That’s why we can no longer afford a “fast lane/slow lane” defense approach to DevOps and SAP. Closing the gap requires cultural and technical coordination, so modern security visibility/response is attuned to the unique operational realities of ERP systems.
By identifying and addressing the inherent bottlenecks while implementing automated transport inspection, continuous monitoring and embedded expertise, organizations ensure SAP security emerges as part of the delivery pipeline rather than the exception. And that’s a clear indicator of a truly productive and protected enterprise.
Join our LinkedIn group Information Security Community!











