# SAP Cybersecurity from A to Z - the book is ready to download

> A book on SAP security: attack paths, AI agents, a red team lab, NIS2, audit checklists and templates. Download it in English or Polish.

- Source: https://snok.ai/en/news/blog/sap-cybersecurity-a-to-z-book/
- Author: Jacek Bugajski
- Published: 2026-09-29

---
I am immensely proud to share **"SAP Cybersecurity from A to Z. A guide for CIOs, CISOs and SAP teams"**, the English edition of my book "Cyberbezpieczeństwo SAP od A do Z". As far as I know, nothing like it has existed in the SAP world in Polish: 304 pages that take you from the foundations, through authorisations, attack paths and AI agents, to NIS2 and ready-made audit templates. **The book is ready to download in English and in Polish.** The form is at the end of this post.

I have worked on SAP security for more than a quarter of a century. My first assignment as a young consultant at SAP Poland was a penetration test. Within a few minutes I had root on the operating system and the `SAP_ALL` profile in SAP. That was mid-2000. Architecture, tools, regulation and board awareness have changed since then, and I still come across similar cases. So I brought this knowledge together in one place and organised it as practical material for everyday work.

## What you will learn

**How an attacker sees SAP.** The anatomy of an attack, attack paths between systems and how to find them before an attacker does, how to read SAP Security Notes and plan security work around SAP Security Patch Day. Attacker techniques are described from the defender's side only - there are no attack instructions in the book.

**Who really has access.** Authentication and single sign-on, roles and authorisations, including the powerful `SAP_ALL` profile, segregation of duties in SAP GRC Access Control, and how to manage accounts throughout their lifecycle after the end of SAP Identity Management maintenance.

**How AI supports SAP security today - and which new threats it brings.** On one side, SAP Joule and AI agents are a new attack surface: an assistant sees and does whatever its user's authorisations allow, and an instruction hidden in an invoice attachment can change its behaviour. I describe classes of prompt injection aimed at SAP data and the safeguards on MCP gateways through which agents reach the system. On the other side, AI genuinely helps defenders, so a separate chapter covers what to deploy now, what to pilot and what to wait for, where the limit of agent automation in the SOC lies, and how to decide between cloud and local processing.

**How to build your own SAP red team lab.** From the first test question to the environment, four tasks for AI models, criteria for choosing hardware and model, authorisation and control of activities, the first exercise cycle and the cost of running the lab. A separate chapter explains how to commission an SAP security test, read the proposal and accept the report.

**How to detect and respond to an incident.** SAP logs that a SIEM often does not see, SOC work with SIEM and SOAR, and an incident response procedure for SAP.

**How to meet NIS2, GDPR, DORA and ISO 27001 requirements**, including Poland's national cybersecurity act (KSC): who is covered and from when, deadlines, who signs and who reports. A single SAP event may require a notification under KSC or, in financial services, DORA, and separately under GDPR. The book also covers AI Act obligations and how to organise evidence for the auditor.

## Ready-made audit tools

The appendices contain:

- **a quarterly checklist for CIOs and CISOs** with a result card for each control and sample results,
- **a template for rules of engagement and an authorised-targets register for offensive testing** - emergency contacts, a kill switch, system scope and evidence protection,
- **a mapping of chapters to the SAP Secure Operations Map**,
- **a glossary** that aligns the language of the board, security and Basis.

Every chapter opens with a box for the decision-maker listing concrete decisions, and closes with takeaways and review questions for self-study or team discussion. That makes the book a tool for putting the requirements into practice, step by step, with evidence for the auditor.

## Start with KSC-CHECK

If your organisation operates in Poland and is preparing for the new KSC act, fill in **[KSC-CHECK](https://snok.ai/en/tools/ksc-check/)** alongside the book - our SAP readiness check for KSC and NIS2. The result shows where the gaps are, and the book helps close them. Timing matters: under the Ministry of Digital Affairs schedule, self-registration in the register of essential and important entities runs until 3 October 2026.

## How it was written

The cover says it plainly: the authors are Jacek Bugajski, the SNOK RedTeam and large language models. The foundation is knowledge I have gathered over the years. The models helped me organise it, facts were checked against primary sources, and I take responsibility for the content as the author.

## Download the book

I believe this is required reading for anyone responsible for SAP or its security - from the board member who takes the decision to the administrator who implements it. We will send the English edition to the business email address you enter in the form below; the Polish original is available from the Polish version of this post. Comments on the content are welcome at office@snok.ai, and I will take them into account in the next edition.

If you want to test the security of your SAP systems in practice after reading, talk to us about [SAP penetration testing](https://snok.ai/en/offer/sap-security/sap-penetration-testing/), a [NIS2 and DORA audit](https://snok.ai/en/offer/sap-security/nis2-dora-audit/) or securing AI deployments through [AI Security](https://snok.ai/en/offer/ai-automation/ai-security/). The full offer is on the [SAP security](https://snok.ai/en/offer/sap-security/) page. We recently wrote about attack path mapping in our post on [SAPMAP](https://snok.ai/en/news/blog/sapmap-bloodhound-for-sap/), and about the division of labour between a model and a human in [the Jev decision model in UiPath](https://snok.ai/en/news/blog/jev-uipath-maestro-trust-layer-delegate/).

## Sources

- Jacek Bugajski, SNOK RedTeam and large language models, "SAP Cybersecurity from A to Z. A guide for CIOs, CISOs and SAP teams", SNOK Press, Warsaw, September 2026 (English edition of "Cyberbezpieczeństwo SAP od A do Z").
- Ministry of Digital Affairs (Ministerstwo Cyfryzacji), "Nowelizacja ustawy o KSC - najważniejsze terminy", 10.04.2026, and "Uruchamiamy samorejestrację w Wykazie podmiotów kluczowych i podmiotów ważnych", 7.05.2026 (accessed 27.09.2026, as cited in chapter 20 of the book).
