Days to Zero: How Ransomware and Accelerated Exploitation are Reshaping SAP Security

10:00 AM ET / 3:00 PM CET

October 29, 2026

Onapsis Research Labs and Recorded Future analyzed over 1.2 million threat-intelligence events (spanning 2023 through H1 2026) to answer a practical question: How is the SAP threat landscape evolving, and how can defenders protect themselves? 

The findings point to speed across the threat landscape:

  • Collapsed SAP Exploit Timelines: The median time between an SAP Security Note release and the first verified public exploitation or proof-of-concept collapsed from 489 days (2021 patches) to 1 to 3 days (2025 and 2026 patches).
  • Broadened SAP Ransomware and Extortion Interest: Ransomware and extortion interest expanded from 1 dominant group in 2022 to 22 distinct groups mentioned together with SAP in H1 2026 (30 groups across the full period).
  • Surging Underground SAP Threat Discourse: SAP threat discussions in underground sources more than doubled  from H1 2023 to H1 2025.

While SAP patches promptly, a critical gap has opened between how quickly flaws are weaponized and how quickly organizations apply the fixes.

Don’t leave your SAP landscape exposed. Register now to secure your place and receive the full research report.

What You’ll Learn

Join us to examine what the evidence reveals and what defenders should adapt across their security operations:

  • Attack Campaign Case Study: How the CVE-2025-31324 campaign unfolded across three distinct waves of attackers.
  • Patch Governance Modernization: What defenders should change about patch governance to address 1-to-3-day SAP patch weaponization timelines.
  • SAP Application-Layer Monitoring: Defensive adjustments required for effective, continuous application-layer monitoring.
  • SAP-Aware Incident Response: Specific changes needed to align incident response practices with SAP-specific threat activity.

Who Should Attend?

This webinar is for the practitioners responsible for securing critical enterprise infrastructure:

  • CIOs and CISOs requiring a definitive map of strategic risk exposure in SAP environments
  • SAP Security Defenders and Security Operations Teams needing actionable intelligence to neutralize active threats
  • Incident Responders & SOC Specialists responsible for application-layer monitoring and SAP-aware threat response.

Speakers

Juan Pablo Perez-Etchegoyen

CTO

Onapsis

TJ Nelson

AVP Insikt Group

Recorded Future

Ready to eliminate your SAP cyber security blindspot?

Let us show you how simple it can be to protect your business applications.

Contact Us