Sharing what we know
Our blog features articles written by SNOK experts - people who work day to day on projects in SAP, cybersecurity, automation, data and Enterprise AI.
We write about real project experience, analyse technology trends, and share our own perspective on solutions that genuinely affect how organisations operate. We like sharing what we know, because technology isn't just our line of work - it's something we're genuinely curious about.
Filter by category

SAP Patch Day August 2026 - 31 notes and the one question IT never asks
31 items, four rated critical, a headline flaw at CVSS 10.0 - the top of the scale. The audit question is not whether you know about them. It is how long it takes you to go from published note to deployed patch, and what evidence you have.

The code nobody wrote. Securing ABAP in the age of AI assistants
An assistant generates ABAP faster than a human can read it, and pull requests co-authored with AI carry up to 2.74 times more security findings. Here are the seven mechanisms by which that code damages an SAP system, three layers of defence built on SecurityBridge, and an accountability model that answers the real question: who signs the transport.

SecurityBridge earns SAP-certified integration for S/4HANA Cloud Private Edition
The SAP Integration and Certification Center confirmed that SecurityBridge Platform 7 integrates with SAP S/4HANA Cloud Private Edition using standard integration technologies. What it changes in RISE projects, and what it does not cover.

It compiles, so it works. ABAP in the age of the coding assistant
The barrier to writing code inside SAP disappeared faster than the gates that inspect it. On the new crowd of ABAP authors, on why the compiler was never a security test, and on the question that keeps coming back: who signs off on the assistant's work. A column by Jacek Bugajski.

Weekly Review W32: what the tool can do - and what it is allowed to do
Seven items from the week of 31 July - 6 August 2026: the 2026 edition of the OWASP Top 10 for LLM applications moves Excessive Agency up to third place, Red Hat finds that only 31 percent of companies have mature oversight of agentic AI, UiPath shows Maestro Case numbers and Autopilot as a coding agent, Polish retailer Żabka confirms an incident through a vendor account, SAP calls agent sprawl a board-level issue, and agentic browsers still fall to hidden instructions.

Tech Thursday with SNOK: Document Understanding 26.7 - documents enter coded workflows
The new Document Understanding preview closes three architectural gaps at once: document processing becomes callable straight from C# code, the extraction model travels through environments together with the automation, and the pipeline starts in the mailbox and ends with a redacted, compliant document. We explain what this changes.

Lenovo ThinkStation PGX hands-on: we put the NVIDIA GB10 AI workstation through its paces
Before it shipped to a client, a Lenovo ThinkStation PGX spent some time in our lab. 128 GB of unified memory, a 120-billion-parameter model running locally and an AI agent working entirely offline. Here is what is inside and what we learned.

Quo vadis, engineer?
Code got cheap and judgment got expensive. A column by Jacek Bugajski on what is left of the engineer in the age of vibe coding: why our sense of speed lies to us, where the false sense of security of unread code comes from, and five questions to ask before generated code reaches production.

The SAP data breach no SIEM will see
A valid logon, zero alerts, and over a few hours hundreds of thousands of customer records leave SAP. The SIEM will not see it, because it monitors the network and logons - not what a user does inside the application. And the regulator will ask for facts, not suppositions.

Weekly review W31: the inventory nobody has
Eleven stories from the week of 27-31 July 2026 around a single question: what exactly is running in your systems, and what can you prove about it. A worm in Word documents spreads through Copilot, an Anthropic model cuts the cost of attacking a NIST candidate from 2⁶⁴ to 2³⁸, shared Claude conversations reach search engines, and NVIDIA gathers more than thirty companies into an alliance for open AI security tooling.

Tech Thursday with SNOK: UiPath Delegate - an agent for a person, not a robot for a process
Twenty years of enterprise automation rested on a single assumption: pick a process, document it, build a robot. UiPath Delegate moves the unit of automation from the process to the person - an employee shows a task once, on their own computer, and gets an executor. We explain how it works and how to use the coming weeks so that on launch day you start with a pilot instead of an analysis.

NIS2 and Poland's KSC Act in SAP: register by 3 October
Poland's amended cybersecurity act has been in force since 3 April 2026, and the application to the register of essential and important entities is due by 3 October. Most fines are deferred by two years, but the first audit in 2028 will ask for evidence from the period running right now. In most companies SAP produces no evidence at all, because nobody watches it.
No articles match these filters.
