Contact us today.

Subscribe me to your mailing list

About Us

We are the first and continue to be leading in business application security research

  • Reveal 3 most critical issues in SAP
  • Leaders by the number of found vulnerabilities in SAP
  • 60+ Innovative Presentations at security conferences
  • Award-winning research papers “SAP Security in figures”
  • 2nd Place on Top Web Hacking Techniques 2012

ERPScan is the most respected and credible Business Application Security provider. Founded in 2010, the company operates globally. Awarded as an ‘Emerging vendor’ in Security by CRN and distinguished by more than 25 other awards – ERPScan is the leading SAP SE partner in discovering and resolving security vulnerabilities.

ERPScan consultants work with SAP SE in Walldorf supporting in improving security of their latest solutions. ERPScan’s primary mission is to close the gap between technical and business security, and provide solutions to evaluate and secure ERP systems and business-critical applications from both, cyber-attacks as well as internal fraud. Usually our clients are large enterprises, Fortune 2000 companies and managed service providers whose requirements are to actively monitor and manage security of vast SAP landscapes on a global scale.


  • 2007 reported vulnerabilities in SAP and Oracle;
  • 2008 Acknowledged for vulnerabilities in SAP and Oracle;
  • 2009 World-first public presentation about SAP Frontend security;
  • 2010 World-first public presentation include attacks on Oracle JDE;
  • 2010 Reported World-first vulnerabilities in SAP BusnessObjects;
  • 2011 World-first public presentation about SAP J2EE security;
  • 2011 World-first product to analyze SAP J2EE Platform security;
  • 2012 World-First public presentation about Oracle Peoplesoft attacks;
  • 2013 World-first Product to combine vulnerability, Code and SoD checks in one platform;
  • 2013 Invented new type of attack against SAP and other applications– SSRF;
  • 2013 World-first vulnerabilities published in SAP Mobile applications;
  • 2014 World-first Training about Business Application Security;
  • 2015 World-first product to analyze Oracle Peoplesoft Platform security;
  • 2015 World-first public presentation about SAP Mobile Platform security
  • 2016 Identified an attack vector against Oil&Gas Companies via SAP software vulnerabilities and misconfigurations
  • 2017 Discovered first proof-of-concept ransom attack against SAP users

Our flagship product is ERPScan Security Monitoring Suite for SAP. This multi award-winning innovative software is the only solution in the market certified by SAP SE covering all tiers of SAP security i.e. vulnerability assessment, source code review and Segregation of Duties. The largest companies from across diverse industries like oil and gas, banking, retail, even nuclear power installations as well as consulting companies have successfully deployed the software. ERPScan Monitoring Suite for SAP is specifically designed for enterprise systems to continuously monitor changes in multiple SAP systems. It generates and analyzes trends on user-friendly dashboards, manages risks, tasks and can export results to external systems. These features enable central management of SAP system security with minimal time and effort.

We use ‘follow the sun’ principle and function in two hubs, located in the Netherlands and the US to operate local offices and partner network spanning 20+ countries around the globe. This enables monitoring cyber threats in real time while providing an agile customer support.

About ERPScan Research Team

The company’s expertise is based on the research subdivision of ERPScan, which is engaged in vulnerability research and analysis of critical enterprise applications. It has achieved multiple acknowledgments from the largest software vendors like SAP, Oracle, Microsoft, IBM, VMware, HP for exposing in excess of 400 vulnerabilities in their solutions (200 of them just in SAP!).

ERPScan researchers take proud in exposing new types of vulnerabilities (TOP 10 Web hacking techniques 2012) and were nominated for best server-side vulnerability in BlackHat 2013. ERPScan experts have been invited to speak, present and train at 60+ prime international security conferences in 25+ countries across the continents. These include BlackHat, RSA, HITB as well as private trainings for SAP in several Fortune 2000 companies.

ERPScan researchers lead project EAS-SEC, which is focused on enterprise application security research and awareness. They have published 3 exhaustive annual award-winning surveys about SAP Security. ERPScan experts have been interviewed by leading media resources and specialized info-sec publications worldwide, these include Wired, Motherboard, The Guardian, International Business Times, Reuters, Yahoo, SC Magazine, The Register, PC World, DarkReading, Heise, to name a few.

We have highly qualified experts in staff with experience in many different fields of security, from web applications and mobile/embedded to reverse engineering and ICS/SCADA systems, accumulating their experience to conduct research in SAP system security.