Prioritise controls that reduce access risk and improve evidence quality. That usually means role rationalisation, privileged access oversight, Firefighter logging, automated certification workflows, and clear accountability for who approves exceptions. Teams should also ensure the governance model works across hybrid ERP states, because controls that only function after migration leave a risky gap during transition.
Why This Matters for Security Teams
SAP S/4HANA cutover is not just a technical migration. It is a governance stress test where legacy roles, emergency access, and exception handling meet a changing control plane. The highest-risk failures usually come from access paths that were acceptable in the old ERP state but become opaque during transition. NHI Management Group’s research on the Top 10 NHI Issues shows that weak credential discipline and limited monitoring are recurring drivers of compromise, and those same patterns often appear in ERP cutovers.
For teams preparing cutover, the first priority is not to perfect every control. It is to make sure access is explainable, reviewable, and reversible while the environment is split across hybrid states. That means knowing who has privilege, why they have it, how exceptions are approved, and where evidence will come from if something goes wrong. The control model should also align with broader governance expectations such as the NIST Cybersecurity Framework 2.0, especially for access management and auditability. In practice, many security teams encounter toxic access combinations only after cutover freeze has started, rather than through intentional pre-cutover review.
How It Works in Practice
The most effective starting point is to reduce the number of access decisions that must be made manually during cutover. Role rationalisation should come first, because outdated SAP roles often encode broad entitlements that no longer match current business processes. Security teams should map critical business functions to a small set of approved access patterns, then identify where emergency access, developer access, and temporary business exceptions still rely on human memory instead of policy.
For SAP-specific transition work, governance should focus on five operational controls:
- Review and simplify role design before cutover so inherited access is not carried forward unchanged.
- Require privileged access oversight for all administrative and Firefighter activity, with logging that can be independently reviewed.
- Automate certification workflows so approvers see current usage, not stale spreadsheets.
- Separate approval authority from execution authority for exceptions and urgent access.
- Preserve evidence across both legacy and target states so audit trails do not break during the move.
This is consistent with NHI governance guidance in the Ultimate Guide to NHIs — Regulatory and Audit Perspectives, which emphasises that control design should produce defensible evidence, not just policy statements. It also maps cleanly to the access and audit outcomes described in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs, where credential and entitlement lifecycle management are treated as operational controls rather than periodic clean-up tasks. Security teams should treat Firefighter logs, certification decisions, and exception approvals as primary evidence sources, then test whether those records survive interface delays, batch jobs, and dual-system dependency chains. These controls tend to break down when cutover spans multiple SAP landscapes because access evidence becomes fragmented across systems that do not share a single authoritative audit trail.
Common Variations and Edge Cases
Tighter access governance often increases cutover overhead, requiring organisations to balance speed against the risk of carrying forward excessive privilege. That tradeoff becomes sharper when the business demands a rapid go-live or when legacy controls cannot be fully replicated in the new environment.
Some teams prioritise SoD cleanup first, but current guidance suggests that this is only effective if privileged access and exception logging are already reliable. Otherwise, SoD findings can be waived without strong evidence, which weakens the entire approval chain. Others assume that post-go-live monitoring can compensate for weak pre-cutover governance. That is risky because once business users start transacting in the new ERP state, remediation becomes more disruptive and harder to prove.
Edge cases also appear in hybrid operations. If some transactions still run in the legacy system while others move to S/4HANA, controls must work across both states or they will create blind spots. For that reason, the most practical first controls are the ones that improve visibility immediately: role cleanup, privileged access oversight, and certification workflows with clear approver accountability. Those priorities also align with the broader non-human identity problem space described in The State of Non-Human Identity Security, where over-privilege and weak monitoring are persistent failure modes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Privileged access and credential oversight are central during SAP cutover. |
| NIST CSF 2.0 | PR.AC-4 | Cutover governance depends on least-privilege access and reviewable entitlements. |
| NIST AI RMF | Risk governance helps teams prioritise accountability during complex ERP transition. | |
| CSA MAESTRO | Hybrid-state control consistency is a core governance issue in complex transformations. |
Use AI RMF governance principles to assign ownership, review exceptions, and document cutover risk decisions.
Related resources from NHI Mgmt Group
- How should security teams migrate identity governance from on premises platforms to cloud based identity security without disrupting access controls?
- How should security teams reduce hidden SAP access and change risks without relying on manual controls?
- How should security teams prioritise NHI remediation in cloud environments?
- How should security teams use IAST and RASP in NHI governance?