SAP & ERP Penetration Testing
SAP ERP penetration testing across NetWeaver, RFC and SAPRouter. We find default creds, SoD gaps and financial-fraud paths, fixed price with a full report.
SAP ERP penetration testing examines the platform that runs your finances, supply chain and payroll, where a single weakness can mean fraudulent payments, altered records or a full compromise of the system your business depends on. We test SAP and other major ERP platforms the way an attacker with a foothold would, then hand you a fix list your Basis and security teams can action.
What SAP and ERP penetration testing covers
ERP systems are where the money lives, yet they are often the least-tested part of the estate. They are complex, business-critical, and frequently guarded by the assumption that because they sit on an internal network, nobody can reach them. Attackers who phish a laptop or breach a VPN reach them easily, and once inside SAP the payoff is enormous: purchase orders, vendor bank details, salary data, the general ledger itself.
We assess the platform layer and the business layer together. That means the SAP NetWeaver technical stack, the RFC and gateway interfaces, SAPRouter, default and weak credentials, and privileged profiles like SAP_ALL, alongside the business-logic and authorization design that governs who can approve a payment or change a vendor’s bank account. For non-SAP estates we bring the same approach to Oracle E-Business Suite and Microsoft Dynamics.
How we test an ERP platform
SAP is not a web app, and testing it well takes engineers who understand both offensive security and how the platform is actually built. We run a phased assessment tuned to the ERP world.
Discovery and fingerprinting
We map the landscape: application servers, the message server, SAPRouter, exposed dispatcher and gateway ports, the SAP versions and support-package levels in play, and any web-facing components such as Fiori or the Web Dispatcher. Version and patch state matter because SAP publishes monthly security notes, and unapplied notes are a reliable way in.
Authentication and default accounts
ERP systems ship with standard accounts, and installations that never changed them are common even in large companies. We check SAP* , DDIC, EARLYWATCH and their equivalents for default or weak passwords, test the RFC and gateway interfaces for unauthenticated access, and probe SAPRouter for permissive route rules that let an outsider reach systems that should be internal only.
Platform exploitation
Where the technical stack is vulnerable, we verify it. The RECON vulnerability in the NetWeaver Java stack, for example, allowed unauthenticated attackers to create an administrative user, and similar critical flaws surface regularly. We confirm real exposure carefully, on non-production systems where possible, so we never risk your live financial data.
Authorization and business-logic testing
This is where ERP testing earns its value. We examine the authorization design for over-broad profiles, unchecked privilege escalation to SAP_ALL, and, most importantly, segregation-of-duties failures. A user who can both create a vendor and approve a payment to that vendor can commit fraud without any technical exploit at all. We trace those paths through the real business process.
Vulnerability classes we find in ERP systems
The findings that matter in an ERP engagement rarely look like a typical web bug. They are platform-specific, and they hit the business directly.
Default credentials and standard accounts
Standard SAP accounts with known default passwords remain one of the most frequent and highest-impact findings. A single unchanged SAP* or DDIC password can grant sweeping access, and these accounts are documented publicly, so an attacker does not need to guess.
Exposed RFC, gateway and SAPRouter
Interfaces built for system-to-system communication are often reachable by users who should never touch them. An open SAP Gateway or a permissive SAPRouter route can allow command execution or access to internal systems from outside the ERP boundary.
Segregation-of-duties and fraud paths
The classic ERP risk is a person holding two roles that should never be combined. Create-vendor plus approve-payment, or post-invoice plus release-payment, opens a direct route to fraudulent disbursement. We identify these SoD conflicts and show the concrete transaction sequence that would exploit them.
Missing SAP security notes
SAP releases patches through monthly security notes, and critical ones affecting NetWeaver, the Internet Communication Manager and other components appear regularly. Systems that lag behind on notes carry known, exploitable flaws. We identify which relevant notes are unapplied and rank them by real risk to your environment.
Insecure interfaces and integrations
ERP systems rarely stand alone. They exchange data with banks, tax portals, warehouses and middleware, and those integration points are frequently authenticated with static credentials or trusted by IP alone. We test the interfaces and the trust between systems, since a weak link in an integration can hand an attacker the same reach as a compromised ERP account.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
The report speaks to the people who own ERP risk: leadership, Basis administrators, and the internal-audit or finance teams who care about fraud exposure.
Technical findings with reproduction
Each technical issue includes the impact, a CVSS score, the exact steps to reproduce it, and a specific remediation, whether that is applying a named SAP security note, resetting a standard account, or locking down a gateway ACL. Evidence accompanies every finding.
Business-risk and SoD findings
Segregation-of-duties conflicts are presented in business terms, with the transactions involved and the fraud scenario they enable, so your finance and audit teams understand not just that a gap exists but what it would cost. We recommend the role and authorization changes to close each one.
A prioritized remediation roadmap
ERP changes cannot all happen overnight, so we rank fixes by risk and effort, giving you a defensible order of work. A free retest after remediation confirms the highest-risk issues are genuinely resolved.
Compliance and standards mapping
ERP testing supports both security frameworks and the financial-controls obligations that ride on top of these systems.
ISO 27001 and financial controls
ISO 27001:2022 control A.8.2 covers privileged access rights and A.8.3 information access restriction, both central to ERP authorization design. Segregation-of-duties findings also feed the financial-reporting controls that internal and external auditors examine, since ERP is where those controls are enforced or bypassed.
GDPR, DORA and PCI DSS
ERP platforms hold employee and customer personal data, bringing GDPR article 32 into play for the technical measures protecting them. Financial entities running SAP under DORA can fold the results into ICT risk-management reporting. Where the ERP touches cardholder data, PCI DSS 4.0 requirement 11.4 penetration-testing obligations apply. We map every finding to the framework you name and provide an attestation letter.
Why manual ERP testing beats a generic scanner
General-purpose vulnerability scanners barely understand SAP. They do not speak RFC, they cannot reason about a segregation-of-duties conflict, and they will miss the authorization path that lets a warehouse clerk approve their own purchase order. ERP security demands engineers who know the platform: how NetWeaver is structured, what a dangerous transaction code looks like, and how a technical foothold turns into financial fraud. That expertise is the difference between a scan that reports open ports and an assessment that shows how someone could reroute a supplier payment into their own account.
Platforms and modules we cover
ERP is a family of very different products, and each carries its own risks. We tailor the assessment to what you actually run.
SAP ECC and S/4HANA
Whether you are on long-running ECC or have moved to S/4HANA, we test the NetWeaver foundation, the Fiori front end, and the HANA database layer beneath. A migration is a particularly good time to test, because roles are being rebuilt and authorization mistakes made during the project are easy to bake in permanently if nobody checks them.
Finance, procurement and HR modules
The modules that move money and hold personal data draw the most attacker interest. We focus authorization and segregation-of-duties testing on the finance, procurement and payroll processes, tracing who can create a vendor, approve an invoice, change bank details, or run payroll, and which combinations of those rights create a fraud path.
Oracle EBS and Microsoft Dynamics
For non-SAP estates we bring the same rigor to Oracle E-Business Suite and Microsoft Dynamics, covering their technical stacks, default and shared accounts, integration interfaces, and the authorization design that governs financial transactions. The platform changes, but the questions an attacker asks do not.
Pricing
ERP engagements are scoped to the size and complexity of the landscape: how many systems and clients, whether we test the technical platform, the business authorizations, or both, and whether it is SAP, Oracle EBS or Dynamics. These are complex platforms, so pricing sits at the higher end of application testing.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Platform review | Single SAP or ERP system, technical-stack testing, default-credential and interface checks, missing security notes, report | 5–8 working days | from €3,500 |
| Platform plus authorization | Technical testing combined with an authorization and SAP_ALL review and privilege-escalation paths | 8–12 working days | €6,000–€12,000 |
| Full ERP assessment | Multiple systems and clients, deep segregation-of-duties and fraud-path analysis, exec + technical + audit report | 12–20 working days | €8,000–€20,000+ |
| Compliance add-on | Mapping and attestation for ISO 27001, DORA, GDPR or PCI DSS requirements | with any tier | from €800 |
| Custom / large estate | Global ERP landscape, S/4HANA migration assurance or blended red-team objectives | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote
FAQ
How much does SAP ERP penetration testing cost?
Will you test on our production ERP?
Do you check for default SAP accounts like SAP* and DDIC?
Can you find segregation-of-duties problems that enable fraud?
Do you test Oracle E-Business Suite and Microsoft Dynamics too?
Does this help with ISO 27001, DORA or financial-controls audits?
How long does an ERP engagement take?
What will you deliver?
Related services
Enterprises across Europe running SAP, Oracle E-Business Suite or Microsoft Dynamics as the backbone of finance, procurement and payroll. It matters most before an S/4HANA migration, ahead of a financial-controls or ISO 27001 audit, or when internal audit has flagged segregation-of-duties concerns that need independent verification. Manufacturers, retailers and financial firms that run their core operations on ERP gain the most, because a single fraudulent transaction path can cost far more than the assessment.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.