The data and information security landscape is changing more rapidly than ever before. Hacking expertise is escalating, as is the speed to market and adoption of new technologies. This, along with increasing legislation aiming to protect data owners, presents a major business challenge.

Increasingly, that challenge is not only about protecting the data itself, but about knowing where it physically resides, and which jurisdiction has legal authority over it.

EPI-USE Labs can help you to navigate this complex and critical field with a suite of solutions covering data risk, security, privacy and compliance. To provide our clients with comprehensive protection, we have also partnered with Soterion, whose compliance software solves GRC (Governance, Risk management and Compliance) for SAP clients.

 

Play video
We see every day the news coming out in the press that there are hacking leaks throughout the world. A lot of big suppliers are working for us. They all have access to the test systems. Now when we copy the data, we're bound to protect their personal and sensitive information. For the first time, we now see our real risk exposure, which was even higher than what we anticipated. Compliance was no longer optional. The biggest challenge was that it had gotten really complicated over the years. The complexity of the implementation of GDPR is not only about anonymizing the system, but also archiving a lot of data. We have been doing that quite manually, but at some point, we couldn't make the next step. There's no way we can fix it. We had a very good conversation with EPI-USE Labs, and all the boxes were ticked. Without Soterion, we would have been running blind. And we now have it connected to each of our SAP systems, and we're literally using it on a daily basis. It was really important to have this kind of solution implemented for us. And, of course, it was implemented according to what the regulator was asking us. What we liked is the fact that you could scramble as you extracted the data. Even when we got the extracted files, there is no data in there that someone could have a look at. We work closely with our internal and external auditors, and they're quite happy with what we have done so far. With EPI-USE Labs products, I found it really useful that they're pre-empting my problems. It's really good to work with a supplier that understands the new legislation and is already there with a product.

What are your SAP data privacy and security challenges?

Increase SAP data privacy compliance

Increase data privacy compliance in SAP

The aim of any privacy project is to increase compliance with the required data privacy laws within the company’s jurisdiction. And SAP’s structure makes addressing data privacy compliance particularly tricky. One of the most compelling reasons for data privacy compliance is the enforcement fines; the new laws provide for high financial sanctions to be applied by legal bodies. 

We have been implementing privacy projects around the globe in multiple industries for over 20 years, and have identified essential steps in a common project approach:

  • Identify your risks: Impact and risk assessment
  • Find and map your PII
  • Review access Risk and Controls
  • Clean up the backlog in Production
  • Manage PII in Production copies
  • Handle Data Subject Access Requests (DSARs)
  • Process individual requests for removal
  • Proactive identification of Data Subjects
  • Ongoing audit and review
Respond to Right to Access/Removal

Respond to the Right to Access/Removal in Production systems

Whether you’re adhering to PDPA in Thailand, one of the state laws in the USA, or GDPR in Europe, you are required to provide a response to the Right to Access and deletion of personal data from your environment.

The Right to Removal does not overrule any of your other legal and compliance requirements, such as keeping records for tax audit. You now need to find a way to validate if data is required for any other legal reason, and if not, remove sensitive data from your system.

SAP presents a challenge in data removal; as a relational database, the sensitive data is intrinsically linked with your business transactions. So traditional ways of archiving or deleting mean you need to remove your transactions and master data completely.

EPI-USE Labs provides an alternative in Data Redact, removing the PII from records but leaving the referential integrity of the solution. And Data Disclose provides effective PII mapping in a PDF output, allowing an efficient process to respond to the Right to Access.

Scramble data in non-production systems

Scramble data in non-production systems

Every business needs to test their processes, whether it’s the annual payroll taxation updates, service pack upgrade or new customizations. You don’t want to find out you have an issue with the new processes in Production; so most businesses will take a copy of their Production systems and create test environments.

The number of testing environments varies depending on the business, but a typical set-up would be to have

  • Development with limited to no real data
  • Quality a reduced data copy from Production
  • Pre-production a full copy of the Production database.

The new privacy laws state that you must have informed and explicit consent for the use of the data relating to data subjects. In our experience, most businesses do not have this consent for using data for testing purposes. Even if you did have a consent process there is an additional challenge in understanding what to do for a no-consent response from a data subject.

We recommend data anonymisation with Data Secure, providing direct in-place data anonymisation, or the ability to scramble on exit when linked with Client Sync, part of the Data Sync Manager Suite.

Understand data privacy & security risks

Understand and mitigate your data privacy and security risks

To solve a problem, you first need to understand the problem. For both data privacy and security, you need to understand the risks you hold in your business process and your IT estate.

Consider your business processes and security risks. For example, do your front office or HR colleagues take notes during calls? If so, what is the security process for those notes? Are you following best practice for data security throughout your business? 

Regarding your IT estate, three primary considerations are:

  • External threat: Network and infrastructure security such as firewalls or VPN protection.
  • Internal threat: The risk of access to data in the network/SAP system.
  • Compliance risk: Where is your PII, and how is it being managed?
  • Jurisdictional risk: Where does your data physically reside, and which government could legally compel you to provide access to it? A service provider headquartered in one country, and hosting in another, may expose your data to conflicting legal obligations.

Our comprehensive SAP data privacy assessment service provides transparency about the Internal and Compliance risks for your business.

Drive business-centric GRC for SAP

Drive business-centric GRC for SAP

Governance, Risk and Compliance (GRC) solutions take many aspects of access risk into account. We are partnered with Soterion, offering a fast, efficient analysis of your GRC risks with standard delivered rulesets to cover:

  • Segregation of Duties (SoD)
  • Privacy: users accessing sensitive data
  • Cross-jurisdictional data access
  • Critical transaction risk.

These solutions can integrate between SAP and cloud applications (such as SAP SuccessFactors) to provide a holistic view of your access risk.

Soterion also offers assessment of your system licences, firefighter access processes and more.

Minimize SAP attack surface

Minimize attack surface in your SAP landscape

To protect sensitive data, consider reducing ‘the attack surface’ in your SAP landscape – the topography of the systems and data which can be attacked. Data masking or obfuscation can keep the referential integrity and functionality of your test, training, sandbox and development system data without making data subjects identifiable, or leaving sensitive data fields exposed.

Data Secure, part of EPI-USE Labs’ Data Sync Manager (DSM) suite, is a complete data protection solution that masks SAP data to safeguard sensitive information. It allows the data to function correctly with hundreds of pre-delivered masking rules. New rules can be built from scratch, existing ones extended or content downloaded from other community users on our collaborative platform, Client Central. The result is real-time data protection.

Many companies have integrated SAP landscapes with data distributed across ERP, CRM, SRM, and external environments. Data Secure anonymizes integrated data objects consistently on different systems.

Need to scramble data outside SAP? Our custom development team can build a solution that will scramble data, which extends Data Secure to non-SAP systems.

SOFTWARE

Data Privacy Suite for SAP solutions

Comply with data privacy legislation

Our innovative data privacy and compliance solution helps companies with SAP® systems comply with legislation like GDPR (the General Data Protection Regulation) and other data privacy legislation around the world.

iSphere Cloud 

Protect your data with sovereign cloud options

Masking and redaction protect the data inside your SAP systems. But true data protection also means controlling where that data lives, and who has legal authority over it. Cloud providers headquartered in the US, for example, can carry obligations under laws such as the Clarifying Lawful Overseas Use of Data (CLOUD) Act that may conflict with GDPR or POPIA.  

With iSphere Sovereign Managed Cloud, your SAP workloads run on SAP-certified infrastructure in a jurisdiction you choose and can defend to a regulator,  with both a contractual data-residency commitment and the technical isolation to enforce it. Options span dedicated private, leveraged private, managed public and hybrid, so the data sovereignty of sensitive workloads remains intact, while you keep the flexibility you need. Predictable billing, and a named engineer who knows your environment, replace the egress fees and support queues of the hyperscaler model.

 

Soterion Access Risk Manager

Get business-centric, effective GRC for SAP

With Soterion and EPI-USE Labs, you can assess, update and maintain roles and authorizations in a cost-effective and intuitive way, and comply with data privacy regulations.

Play video
Hi. My name is Dudley Cartwright from Soterion. I'd like to spend a few minutes explaining: what is business-centric GRC and why it's so important for effective access risk management in SAP. Access risk is business risk. What is meant by this is that it is a business decision whether a user in the organisation should have certain access. As an example, if a person in your organisation requires access to both create the purchase order and release the purchase order, which is a typical segregation of duty, it should be your business users who decide if that risk is acceptable to the organisation or not. The challenge facing most organisations is that the business users often have very little visibility as to what access is problematic and is causing a risk violation. And if they do have some form of visibility, you often find that the business users don't understand the access risks being presented to them. SAP authorizations is very technical and complex, and most of the GRC solutions on the market have been developed from a technical audit perspective with very little consideration for its use by the business. These technical and complex GRC solutions are not well adopted by the business users, who generally push this responsibility back onto the IT teams. What ends up happening is that the IT teams run these GRC solutions as back-end solutions with minimal involvement from the business. You often find a high degree of underutilization of the GRC solution because of this. At Soterion, we believe that implementing the correct GRC solution is crucial to enhancing business buy-in and accountability. The GRC solution needs to convert the technical GRC language into a language that the business users can understand. Soterion does this by illustrating all access risks with supporting business process flows. This provides more context to the business users who can then make quicker and more informed decisions. The Soterion solution has been developed to empower the business users with their access risk management activities. Enhancing business accountability of access risk with the use of a business-centric GRC solution will enhance your first line of defence, which in turn will improve the organisation's overall risk awareness and your ability to manage your risk. Should you be interested in seeing a more detailed demo covering other use cases, please don't hesitate to contact us.
 

Archive Central

Ringfencing specific information for regulatory compliance 

Archive Central™ is a role-based, secure web solution that gives Data Privacy Officers (DPOs) or business users access to historical data for queries, reporting and comparisons.  Encrypt sensitive information such as PII for security and regulatory compliance. 

Play video
Whether you're divesting your enterprise or planning to migrate to a new platform or SAP S/4HANA, decommissioning your system presents a unique compliance challenge. How do you store your legacy data cost-effectively and securely? Constant system and database updates make running an SAP display-only system too expensive, and the vast sea of interlinked data tables means you can't simply copy and store the relevant Transactional and Master data separately. There's also the issue of access risk. How do you manage who has access? That's where Archive Central comes in. Archive Central is a role-based secure web solution to get business users access to historical data for Queries and Comparisons while simultaneously ensuring compliance requirements are met. Using proprietary software, we can read, select, and automatically load your SAP data into collections that you can access through a modern web application provided as Software-as-a-Service, allowing you to decommission your SAP system safely, and with the ability to import data from any common machine readable formats such as CSV. Archive Central is capable of archiving data from non-SAP systems as well. Archive Central leverages the metadata to present a business entity for the user with all the related data rather than a set of disparate tables. You'll be able to filter through data easily. Our global search allows you to 'one click and type' to find the records you're looking for. It's also easily configurable, giving you the ability to customise the display to suit your needs. You'll also be able to store all common document formats and image files, so no need to worry about those old payslips, invoices, or certificates. They can be stored and linked with the corresponding data for easy access. You'll be able to track who is viewing data records and what a particular user has done. Don't let your legacy data hold you back. Securely store your legacy data for future Queries and Compliance with Archive Central.

SERVICES

Data privacy consulting

Play video
The first challenge that most businesses face from a privacy point of view is actually understanding how much of the risk they're holding within their data. Most industries have spent, fifteen, twenty years customizing an SAP environment, making it correct for their business process, with no consideration as to how much data they're then proliferating into additional tables. So actually then understanding and mapping that data is quite a large challenge especially because the people that built them have likely retired, moved on, and gone through natural attrition. So it does create quite a large business challenge, and to be able to build your business case for an investment in a privacy solution you first need to know how much risk you are mitigating to be able to follow it through. So to help with that, EPI-USE Labs have utilized our data model mapping that we've been using for the last twenty years to manage SAP data to build a discovery program. Now unlike some of the other competitors on the market, EPI-USE Labs are utilizing SAP domain knowledge that we've built to understand the data dictionary within your system, and we're able to complete a key search of the data elements within that environment based on the list of PII data items that we've already identified. The output list is then validated against whether the data is actually populated because, of course, just because it's in the system doesn't mean you've actually populated it. And we'll then go through a workshop and detailed analysis process with one of our professional services consultants where we will analyze and understand how we can integrate that data back to a data subject for a customer, a vendor or an employee, but also understand what values are maintained and map out that PII challenge for your SAP system. We collect all that information into a single document that has both the business functional requirements from the workshop, as to what retention periods you would like and how data should be affected based on those retention periods - so whether it should be cleared or transformed to a new value, and the same for non-production, for a system copy that you're going to use for testing, you need to have the real data from Production to improve your DevOps process. But you can't have the real data because that is a PII risk, and you would have to have informed and explicit consent from every data subject in your environment to use that data as testing, and no company has entered those clauses into a contract so far to be able to say they're ready. So with that documentation, you have the business requirements of how data should be transformed and then also the technical specification of exactly which tables and fields grouped according to data type to be able to understand where the names, where the telephone numbers, where the bank details exist within the environment. Additionally we now have an enhanced discovery working with one of our strategic partners Soterion. They offer GRC solutions as an alternative to SAP GRC. They have pre-delivered rule sets that are able to analyse your segregation of duties risk. They also have specific rule-sets to review your access to privacy data, to be able to understand who can actually see sensitive data within your SAP system. We also have queries to be able to understand where there's cross legal jurisdictional access. So where somebody from the US is able to access European employee data or vice-versa. Through that analysis, we're able to provide a clear risk assessment of both the access to sensitive data, and where that data is within your environment. Both of these options come as a license free, there is no license cost upfront, there is some professional services cost for around about one and a half to two weeks elapsed time, so in a very short turnaround period we're able to provide you this documentation, which we've seen from some of our clients is being used as audit evidence and passed through to their auditors to be able to help them understand your data model and how you're compliant to the laws. So the data discovery and enhanced data discovery are available from your Account Executives, and we would be happy to discuss them with you. As well as the output of the document, we will also then give you a fixed price, fixed scope implementation cost if you were to choose EPI-USE Labs as your privacy partner to be able to manage that data moving forward.

SAP is one of the most robust systems in the world, but also one of the most complex, and its structure makes addressing compliance with data privacy legislation particularly tricky. Detailed domain knowledge is required to map and understand the cross-functional integration of multiple SAP objects and systems.

As a longstanding SAP Partner, EPI-USE Labs has an in-depth understanding of how SAP data is structured. We have developed in-depth knowledge of SAP, and our integrity mapping is defined both on the individual field level and between systems.

We help our clients comply with data privacy laws by scrambling non-production data copied out of Production systems. We also address the de-sensitisation of data in Production with our redaction technology. Our cutting-edge software combined with our extensive project experience across multiple countries and industries means we can give you expert guidance on your data privacy challenges.

Mass data removal services

Clear historical data you no longer have legal grounds for storing, such as bank account details, with a simple process.

Learn more

Privacy and security assessments

We can help you to understand and identify your Personally Identifiable Information (PII), and assess your access risks.

Learn more

Access risk assessments and role redesign

Get insights into the access risk in your SAP system and mitigate it with a new role redesign that is fit for purpose. 

Get further insights to manage your SAP data privacy, security and risk

Data Security Blogs

Read blogs:
Let's Talk Data Security

Learn more

SAP data privacy Ultimate Guide

Explore ultimate guide:
Road to SAP data privacy compliance

Read more

Data Privacy and Security webinar

Watch webinars:
Data Privacy and Security

Watch more

Privacy and Security success stories

Client success:
Data privacy and security

Learn more

Useful SAP downloads

Download: ebooks,
white papers and more

See more

Get in touch

Manage your SAP data privacy, security and risk