Greenfield starts with a new S/4HANA system and migrates only selected data. Brownfield converts the existing ECC system into S/4HANA with most configuration retained. Hybrid combines both by selectively moving processes or data. The right choice depends on transformation goals, customization levels, risk tolerance, and how much process redesign the business can absorb.
Why This Matters for Security Teams
SAP S/4HANA migration is not just a technical choice. It sets the pace for data remediation, process redesign, security model changes, and operational risk. A greenfield move can reduce inherited complexity, while brownfield preserves more of the current landscape and may carry forward technical debt. Hybrid approaches sit between those extremes, but they can also create the most governance ambiguity if scope is not tightly defined.
Security teams often miss that migration style changes the control problem. Brownfield can preserve legacy authorisations, integration paths, and weak credential hygiene unless those issues are deliberately cleaned up. Greenfield gives more room to reset access, but it can still recreate old risk if teams simply clone legacy roles into a new platform. The governance question is therefore not only “which path is faster?” but “which path creates the best chance to remove inherited exposure.” The Ultimate Guide to NHIs — What are Non-Human Identities is useful here because S/4HANA projects often depend on service accounts, API keys, and integrations that behave like non-human identities and must be inventoried early. NIST control guidance also supports this view through NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where identity, access, and configuration change must be managed together.
In practice, many security teams discover migration-driven access sprawl only after the new system is already live, rather than through intentional design and cleanup.
How It Works in Practice
Greenfield, brownfield, and hybrid are best understood as different operating models for transformation, not just different implementation styles. In a greenfield migration, the organisation starts with a fresh S/4HANA environment, then selects which master data, transactional data, integrations, and roles to bring forward. This allows process standardisation, cleaner segregation of duties, and a full redesign of privileged access. In a brownfield conversion, the existing ECC system is upgraded in place, so the security team must assume that many legacy constructs will survive unless actively remediated. Hybrid combines both, such as converting core finance while rebuilding selected business units or moving only specific data domains.
From a security perspective, the main practical difference is how much inherited risk is being carried forward. Greenfield is usually the best point to re-baseline authorization models, remove obsolete roles, replace hardcoded credentials, and validate all technical accounts. Brownfield is often faster, but it requires stronger cutover controls, role clean-up, and testing of legacy integrations. Hybrid needs the most explicit scope control because some domains may be modernised while others remain tied to older patterns. Current guidance suggests treating the migration as an identity and secrets remediation program as much as a platform program.
- Use greenfield when process redesign and role simplification are strategic goals.
- Use brownfield when continuity matters more than redesign, but plan a security hardening workstream.
- Use hybrid when business units have different readiness levels or different regulatory constraints.
- Inventory all non-human identities, especially interfaces, batch jobs, and API integrations, before cutover.
For migration governance, the lesson from NHI security research is simple: old identities and stored secrets do not disappear because the ERP label changes. The SAP SQL Anywhere Monitor Hardcoded Credentials research illustrates how overlooked embedded credentials can become durable exposure points. These controls tend to break down when a brownfield conversion preserves legacy customisations and interface accounts without a full credential and entitlement review.
Common Variations and Edge Cases
Tighter migration scope often increases coordination overhead, requiring organisations to balance cleaner security outcomes against business continuity and delivery deadlines. That tradeoff is especially visible in SAP environments with extensive custom code, third-party connectors, or heavily regulated finance processes.
There is no universal standard for hybrid migration design. Some programs define hybrid as selective data migration only, while others use it to mean a mixed technical path across modules, subsidiaries, or waves. That ambiguity matters because security controls must follow the actual operating model, not the label. For example, a “greenfield” finance rollout that still reuses legacy interface accounts is not a true security reset. Likewise, a “brownfield” conversion that reworks all critical entitlements may behave more like a phased hybrid in practice.
Best practice is evolving around three questions: what data is being retained, what access model is being reused, and which identities are being rebuilt versus preserved. The SAP Breach resource is a reminder that ERP compromise often starts with access paths, not just application flaws. For broader baseline control expectations, NIST guidance on account, access, and system configuration remains relevant through NIST SP 800-53 Rev 5 Security and Privacy Controls. Hybrid models also create edge cases where some business units can adopt new controls quickly while others are constrained by uptime or vendor dependencies; those environments usually require phased policy enforcement rather than a single cutover date.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity and access governance must be reassessed during any SAP migration. |
| OWASP Non-Human Identity Top 10 | NHI-01 | SAP integrations rely on non-human identities that often survive migrations unchanged. |
| NIST SP 800-63 | AAL2 | Stronger authentication helps protect privileged access in transformed ERP environments. |
| NIST Zero Trust (SP 800-207) | SC-7 | Segmentation and controlled access reduce blast radius during ERP transition periods. |
| NIST AI RMF | AI RMF supports structured risk decisions when migration choices affect operational and security risk. |
Rebaseline user, admin, and service access during migration and remove inherited entitlements before go-live.
Related resources from NHI Mgmt Group
- What is the difference between greenfield, brownfield, and bluefield ERP migration approaches for security and governance teams?
- What is the difference between a rules-based secret scanner and a hybrid scanner?
- What is the difference between privilege reduction and secret rotation?
- What is the difference between code scanning and runtime identity monitoring?