# Jarosław Zdanowski - SAP Basis & Cybersecurity Expert · SNOK

> Partner at SNOK. SAP Basis and SAP Security expert with experience in projects for global organisations operating complex SAP environments. At SNOK, he is…

- Source: https://snok.ai/en/news/blog/author/jaroslaw-zdanowski/

---

# Jarosław Zdanowski

SAP Basis & Cybersecurity Expert

Partner at SNOK. SAP Basis and SAP Security expert with experience in projects for global organisations operating complex SAP environments. At SNOK, he is responsible for developing SAP security services, including SecurityBridge, bowbridge, SAP Security Patch Day and SAP penetration testing. Today, he also supports clients in designing secure Enterprise AI architecture and selecting optimal hardware and cloud solutions.

Expertise

Publications

## 19 articles

16 September 2026

### Secure SAP S/4HANA conversion - what the programme does to your attack surface

No steering committee ever minutes the decision to widen the attack surface for two years. That is exactly what gets approved: a change freeze on SAP ECC, production copies in project systems, emergency access for the system integrator, custom code that nobody scanned for security, and a RISE model where you raise the patch request. None of those steps is a mistake. Together they are a window.

15 September 2026

### TrustBroker 5.1 - SSO and MFA for SAP without Active Directory

For two decades, single sign-on to SAP GUI meant Kerberos and Microsoft Active Directory. SecurityBridge has built OpenID Connect into the SNC library, so that dependency stops being a technical necessity - and phishing-resistant authentication finally reaches the SAP GUI login.

10 August 2026

### The code nobody wrote. Securing ABAP in the age of AI assistants

An assistant generates ABAP faster than a human can read it, and pull requests co-authored with AI carry up to 2.74 times more security findings. Here are the seven mechanisms by which that code damages an SAP system, three layers of defence built on SecurityBridge, and an accountability model that answers the real question: who signs the transport.

28 July 2026

### NIS2 and Poland's KSC Act in SAP: register by 3 October

Poland's amended cybersecurity act has been in force since 3 April 2026, and the application to the register of essential and important entities is due by 3 October. Most fines are deferred by two years, but the first audit in 2028 will ask for evidence from the period running right now. In most companies SAP produces no evidence at all, because nobody watches it.

21 July 2026

### SAP hardening - why it is a process, not a project

Your company stands on documents, and those stand on the SAP foundation. In 90 seconds we show the five layers of hardening and why a single patch is not enough.

14 July 2026

### SAP Security Patch Day - July 2026

SAP has released its July security patch bundle: 16 new notes, 1 GitHub advisory and 3 updates to earlier notes. Four HotNews vulnerabilities lead the list, including a memory corruption flaw in NetWeaver AS ABAP with CVSS 9.9. Here is what to patch first.

7 July 2026

### Safe Tuesday with SNOK: an AI agent on both sides of the attack

Over the course of a few weeks, an AI agent stood on both sides of the attack: as JADEPUFFER, a fully autonomous ransomware, and as a tool companies are just letting into their SAP systems - under siege from a cascade of critical vulnerabilities. We explain why the difference is not the model, but the leash.

30 June 2026

### AI in SAP without Joule: how to safely bring artificial intelligence into an on-premise system

Joule requires BTP and a newer SAP release. Most Polish companies run ECC or an older on-premise S/4HANA. We show how to give AI safe access to SAP data without a conversion - with UiPath as a controlled execution layer.

10 March 2026

### SAP Security Patch Day - March 2026

The second Tuesday of March - time for another SAP Security Patch Day. This time SAP published 20 security notes. Fewer than in February? Indeed. But there are still two critical vulnerabilities with a CVSS score above 9.0 - a

17 February 2026

### Automation in SAP Security – moving from reactive compliance to continuous hardening

When did you last carry out a comprehensive security review of your SAP environment? If the answer is "at the last audit" – you have a problem. In a world where the number of critical SAP vulnerabilities rose in 2025

10 February 2026

### SAP Security Patch Day - February 2026

SAP published 29 new security notes as part of the February 2026 Patch Day (including updates and interim releases). This nearly matches the record from July 2025 and signals that 2026 is starting intensively for SAP se

3 February 2026

### How to Build Zero Trust for Identity in the SAP World

Just a few years ago, the enterprise security perimeter ran along firewalls and proxy servers. Anyone "inside" was treated as trustworthy. Anyone "outside" – as a potential

27 January 2026

### SAP as a critical attack vector in 2026 – from critical patches to mature security

2025 will go down in history as a turning point in how SAP system security is perceived. A zero-day vulnerability in the NetWeaver Visual Composer component (CVE-2025-31324), a global attack campaign run by

13 January 2026

### SAP Security Patch Day – January 2026

SAP published 17 new security notes as part of the January 2026 Patch Day. This is one of the most serious Patch Days to date - it includes 4 critical vulnerabilities (HotNews) with a maximum CVSS of 9.9. KEY THREATS: 1/ SQL Injectio

16 December 2025

### SAP Penetration Testing – Why Your ERP System Needs Ethical Hackers

9 December 2025

### 🔒 SAP Security Patch Day – December 2025: A comprehensive review of all vulnerabilities

25 November 2025

### Security in the age of BTP – where SAP's responsibility ends and yours begins

18 November 2025

### SAP S/4HANA 2025 – when security is standard

11 November 2025

### SAP Security Patch Day – November 2025
