Skip to content

Jarosław Zdanowski

SAP Basis & Cybersecurity Expert

Jarosław Zdanowski

Partner at SNOK. SAP Basis and SAP Security expert with experience in projects for global organisations operating complex SAP environments. At SNOK, he is responsible for developing SAP security services, including SecurityBridge, bowbridge, SAP Security Patch Day and SAP penetration testing. Today, he also supports clients in designing secure Enterprise AI architecture and selecting optimal hardware and cloud solutions.

Expertise

SAP Basis 24/7SAP SecuritySAP penetration testingSecurityBridgeNIS2 / DORA compliance
LinkedIn profile →

Publications

17 articles

← Back to the blog
Other·

The code nobody wrote. Securing ABAP in the age of AI assistants

An assistant generates ABAP faster than a human can read it, and pull requests co-authored with AI carry up to 2.74 times more security findings. Here are the seven mechanisms by which that code damages an SAP system, three layers of defence built on SecurityBridge, and an accountability model that answers the real question: who signs the transport.

Safe Tuesday·

NIS2 and Poland's KSC Act in SAP: register by 3 October

Poland's amended cybersecurity act has been in force since 3 April 2026, and the application to the register of essential and important entities is due by 3 October. Most fines are deferred by two years, but the first audit in 2028 will ask for evidence from the period running right now. In most companies SAP produces no evidence at all, because nobody watches it.

Safe Tuesday·

SAP hardening - why it is a process, not a project

Your company stands on documents, and those stand on the SAP foundation. In 90 seconds we show the five layers of hardening and why a single patch is not enough.

Safe Tuesday·

SAP Security Patch Day - July 2026

SAP has released its July security patch bundle: 16 new notes, 1 GitHub advisory and 3 updates to earlier notes. Four HotNews vulnerabilities lead the list, including a memory corruption flaw in NetWeaver AS ABAP with CVSS 9.9. Here is what to patch first.

Safe Tuesday·

Safe Tuesday with SNOK: an AI agent on both sides of the attack

Over the course of a few weeks, an AI agent stood on both sides of the attack: as JADEPUFFER, a fully autonomous ransomware, and as a tool companies are just letting into their SAP systems - under siege from a cascade of critical vulnerabilities. We explain why the difference is not the model, but the leash.

Safe Tuesday·

AI in SAP without Joule: how to safely bring artificial intelligence into an on-premise system

Joule requires BTP and a newer SAP release. Most Polish companies run ECC or an older on-premise S/4HANA. We show how to give AI safe access to SAP data without a conversion - with UiPath as a controlled execution layer.

Safe Tuesday·

SAP Security Patch Day - March 2026

The second Tuesday of March - time for another SAP Security Patch Day. This time SAP published 20 security notes. Fewer than in February? Indeed. But there are still two critical vulnerabilities with a CVSS score above 9.0 - a

Safe Tuesday·

Automation in SAP Security – moving from reactive compliance to continuous hardening

When did you last carry out a comprehensive security review of your SAP environment? If the answer is "at the last audit" – you have a problem. In a world where the number of critical SAP vulnerabilities rose in 2025

Safe Tuesday·

SAP Security Patch Day - February 2026

SAP published 29 new security notes as part of the February 2026 Patch Day (including updates and interim releases). This nearly matches the record from July 2025 and signals that 2026 is starting intensively for SAP se

Safe Tuesday·

How to Build Zero Trust for Identity in the SAP World

Just a few years ago, the enterprise security perimeter ran along firewalls and proxy servers. Anyone "inside" was treated as trustworthy. Anyone "outside" – as a potential

Safe Tuesday·

SAP as a critical attack vector in 2026 – from critical patches to mature security

2025 will go down in history as a turning point in how SAP system security is perceived. A zero-day vulnerability in the NetWeaver Visual Composer component (CVE-2025-31324), a global attack campaign run by

Safe Tuesday·

SAP Security Patch Day – January 2026

SAP published 17 new security notes as part of the January 2026 Patch Day. This is one of the most serious Patch Days to date - it includes 4 critical vulnerabilities (HotNews) with a maximum CVSS of 9.9. KEY THREATS: 1/ SQL Injectio

Safe Tuesday·

SAP Penetration Testing – Why Your ERP System Needs Ethical Hackers

Other·

🔒 SAP Security Patch Day – December 2025: A comprehensive review of all vulnerabilities

Safe Tuesday·

Security in the age of BTP – where SAP's responsibility ends and yours begins

Safe Tuesday·

SAP S/4HANA 2025 – when security is standard

Safe Tuesday·

SAP Security Patch Day – November 2025

Get in touch