We are the first and continue to be leading in business application security
- Reveal 3 most critical issues in SAP
- Leaders by the number of found vulnerabilities in SAP
- 60+ Innovative Presentations at security conferences
- Award-winning research papers “SAP Security in figures”
- 2nd Place on Top Web Hacking Techniques 2012
ERPScan is the most respected and credible Business Application Security provider.
Founded in 2010, the company operates globally. Awarded as an ‘Emerging vendor’ in Security by CRN and
distinguished by more than 25 other awards – ERPScan is the leading SAP SE partner in discovering and
resolving security vulnerabilities.
ERPScan consultants work with SAP SE in Walldorf supporting in improving security
of their latest solutions. ERPScan’s primary mission is to close the gap between technical and business
security, and provide solutions to evaluate and secure ERP systems and business-critical applications
from both, cyber-attacks as well as internal fraud. Usually our clients are large enterprises, Fortune
2000 companies and managed service providers whose requirements are to actively monitor and manage
security of vast SAP landscapes on a global scale.
- 2007 reported vulnerabilities in SAP and Oracle;
- 2008 Acknowledged for vulnerabilities in SAP and Oracle;
- 2009 World-first public presentation about SAP Frontend
- 2010 World-first public presentation include attacks on
- 2010 Reported World-first vulnerabilities in SAP
- 2011 World-first public presentation about SAP J2EE security;
- 2011 World-first product to analyze SAP J2EE Platform
- 2012 World-First public presentation about Oracle Peoplesoft
- 2013 World-first Product to combine vulnerability, Code and
SoD checks in one platform;
- 2013 Invented new type of attack against SAP and other
- 2013 World-first vulnerabilities published in SAP Mobile
- 2014 World-first Training about Business Application
- 2015 World-first product to analyze Oracle Peoplesoft
- 2015 World-first public presentation about SAP Mobile
- 2016 Identified an attack vector against Oil&Gas Companies via SAP software vulnerabilities and misconfigurations
- 2017 Discovered first proof-of-concept ransom attack against SAP users
Our flagship product is ERPScan Security Monitoring Suite for SAP. This multi
award-winning innovative software is the only solution in the market certified by SAP SE covering all
tiers of SAP security i.e. vulnerability assessment, source code review and Segregation of Duties. The
largest companies from across diverse industries like oil and gas, banking, retail, even nuclear power
installations as well as consulting companies have successfully deployed the software. ERPScan
Monitoring Suite for SAP is specifically designed for enterprise systems to continuously monitor changes
in multiple SAP systems. It generates and analyzes trends on user-friendly dashboards, manages risks,
tasks and can export results to external systems. These features enable central management of SAP system
security with minimal time and effort.
We use ‘follow the sun’ principle and function in two hubs, located in the
Netherlands and the US to operate local offices and partner network spanning 20+ countries around the
globe. This enables monitoring cyber threats in real time while providing an agile customer support.
About ERPScan Research Team
The company’s expertise is based on the research subdivision of ERPScan, which is
engaged in vulnerability research and analysis of critical enterprise applications. It has achieved
multiple acknowledgments from the largest software vendors like SAP, Oracle, Microsoft, IBM, VMware, HP
for exposing in excess of 400 vulnerabilities in their solutions (200 of them just in SAP!).
ERPScan researchers take proud in exposing new types of vulnerabilities (TOP 10 Web
hacking techniques 2012) and were nominated for best server-side vulnerability in BlackHat 2013. ERPScan
experts have been invited to speak, present and train at 60+ prime international security conferences in
25+ countries across the continents. These include BlackHat, RSA, HITB as well as private trainings for
SAP in several Fortune 2000 companies.
ERPScan researchers lead project EAS-SEC, which is focused on enterprise
application security research and awareness. They have published 3 exhaustive annual award-winning
surveys about SAP Security. ERPScan experts have been interviewed by leading media resources and
specialized info-sec publications worldwide, these include Wired, Motherboard, The Guardian, International Business Times, Reuters, Yahoo, SC Magazine, The Register, PC World, DarkReading, Heise, to name a few.
We have highly qualified experts in staff with experience in many different fields
of security, from web applications and mobile/embedded to reverse engineering and ICS/SCADA systems,
accumulating their experience to conduct research in SAP system security.