E-book: Battling Trojan Horses in Your SAP Transports
About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
View Author Profile
Transports are considered an essential part of the SAP environment for day-to-day business. Used to transfer SAP content from one system to another, transports carry incredibly sensitive data, and even a secure production system can be compromised.
When changes are made in your SAP production systems through SAP transports, you are exposing your SAP systems to a high-security risk. Transports are usually considered one of the easiest ways to introduce vulnerabilities, offering a dangerous gateway to these critical systems. These “Trojan horses” are able to stealthily enter your SAP systems and sneak in malicious content, such as espionage, data theft and data manipulation. These damages can be detrimental to your organization and cause significant financial loss, customers to lose trust and fines from regulatory bodies.
While these losses can be substantial, many organizations are still unaware of the potential dangers of SAP transports and the level of security they require. Additionally, many organizations are unaware of these risks, and conventional tools are unable to detect these Trojan horse threats. Transport analysis by Onapsis closes this gap.

About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
View Author Profile
Further Reading
Securing the Clean Core: Why SAP BTP Extensibility Requires DevSecOps
Why SAP BTP Extensibility Requires DevSecOps Implementing an SAP secure clean core strategy requires organizations to move custom code out of the application layer and shift developments to the cloud. Moving custom developments to SAP Business Technology Platform (BTP) prevents core business process disruption during system upgrades, but establishing robust SAP BTP security requires active…
From Runways to Ransomware: Defending SAP Custom Code in the Age of Agentic Commerce
The retail and fashion manufacturing landscape is transforming at a blistering pace. Between the rise of autonomous AI shopping agents and hyper-accelerated trend cycles, brands are deploying cloud-native architectures faster than ever before. However, as organizations push to modernize their SAP environments and leverage AI for custom code development, they are unintentionally opening the door…
Protecting the Assembly Line: How Heavy and Discrete Manufacturing Can Secure SAP Custom Code in the Era of AI and Accelerating Threats
The heavy and discrete manufacturing sector faces unprecedented cyber threats, underscored by the £1.9 billion Jaguar Land Rover breach. As the industry adopts AI to accelerate SAP custom code development, critical new vulnerabilities emerge. With strict regulations like UN R155, NIS2, and TISAX demanding ‘secure-by-design’ systems, reactive security is obsolete. “Shifting left” with a DevSecOps…
