Nikon gets the full picture of their risks, thanks to Soterion

Soterion’s GRC for SAP solutions accelerated Nikon Europe BV’s change management and SAP Access Control updates.

Labs_Coloured_blocks
2025 Nikon Icons 1
Automated processes and less manual work
2025 Nikon Icons 2
Reduction of unused SAP accesses
2025 Nikon Icons 3
Full visibility of risks exposure
2025 Nikon Icons 4
Daily updates on users, roles and SM20 logs
Play video
So far, we have been doing SoD review in Excel. But at some point, we couldn't make the next step. We felt we were only touching the tip of the iceberg, and we knew there was much more risk in our system. So that's why we had to look for a mature, sophisticated GRC solution. We already were dealing with EPI-USE Labs for other tools and so we discussed the option to use Soterion. My name is Piet Jan Van Egdom. I work for Nikon Europe BV, currently in the Business Application Services team. The main challenge was we need to comply with the framework similar to the SOX framework in the US. For IT, it means we had to focus on two areas, change management, and SAP access control. We started the project where we established the connection between our SAP system and Soterion cloud. The module that we are using is called Basic Review; the Periodic Review, where the business has to review critical access and SoD risk; and we are using the self-service for password reset, which is going to save our first-line support a lot of time. We now see, in fact, for the first time, our real risk exposure, which was even higher than what we anticipated. So we're now able to fine-tune the risk profile on Soterion. So even after a few months already, you see the benefits that the tool has for us.

 

The challenge: Lack of visibility of their system’s risks

As the Nikon Corporation is listed on the Tokyo Stock Exchange, Nikon Europe BV – and the entire group – is required to be compliant with the J-SOX framework (also known as the Japanese Sarbanes-Oxley Act).

In an attempt to take a visual approach to their SoD (Segregation of Duties) risks, for the past ten years the IT team had been doing everything manually, exporting large amounts of data to Microsoft Excel to analyse SoD conflicts using SM20 log files.

The company realised that they were not getting the full picture, and were only able to skim the surface of their challenge. They needed to find a mature and sophisticated GRC (Governance, Risk and Compliance) solution to help them address compliance.

We were only addressing the tip of the iceberg with our processes; we knew there were many more risks in our system.

Piet Jan Van Egdom, Head of Enterprise Systems Team, Nikon Europe BV
testimonial-quote

Tackling the risks with Soterion for GRC

Nikon Europe BV introduced SAP Access Control, and made a number of management changes. Having realised they needed additional tools to analyse and review critical access and SoD conflicts, they then implemented Soterion as their GRC solution for SAP systems.

As soon as they connected their SAP system to the Soterion cloud, they started to see tangible benefits in their risk management. Their risk exposure was even higher than anticipated, so they immediately started to mitigate the risks that Soterion highlighted.

They used the following Soterion modules:

  • Basis Review: to inspect their SAP Basis configuration against a set of rules based on industry best practices to establish full compliance.
  • Periodic Review Manager: which allows enterprise users to periodically review the access risk of their SAP users in their SAP systems easily and efficiently, to improve the visibility of their GRC environment.
  • Self-Service: for password reset services, which will save the team a lot of manual time in resetting and locking users’ passwords.

We had done it manually, but at some point, we couldn't make it to the next step, so we needed to look for a mature sophisticated GRC solution. We were already working with EPI-USE Labs, so Soterion was the perfect tool for our SoD framework.

Piet Jan Van Egdom, Head of Enterprise Systems Team, Nikon Europe BV
testimonial-quote

Achieving GRC compliance

GRC compliance is a long-term project, but even so, the Nikon team is already seeing benefits from using Soterion.

The IT team saves a lot of manual work time by having a tool with which to automate workflows for new users, reset passwords, clean up superfluous roles or transactions, activate risk templates, and adjust risk settings quickly and easily.

Soterion has given them the ability to understand their company’s risk exposures, and thus the power to act on them.

2025 Nikon compliance Icons 1

Daily updates of users, authorisations, and roles

2025 Nikon compliance Icons 2

Clean-up of superfluous roles and transactions

2025 Nikon compliance Icons 3

Removal of unused SAP accesses

2025 Nikon compliance Icons 4_V2

Fine-tuning risk settings

2025 Nikon compliance Icons 5

Defined organisational structure

We have tangible benefits already. For the first time, we now see our real risk exposure; it was even higher than anticipated. It will take time, but at least now we have the insights that we were looking for.

Piet Jan Van Egdom, Head of Enterprise Systems Team, Nikon Europe BV
testimonial-quote

Industry: Consumer Products

Solution: Soterion

About Nikon

Nikon is a world-leading provider of imaging products and services. Their innovative optics technology – from consumer to professional cameras, lenses to system accessories – is powered by over 100 years of experience. The brand is globally recognised for setting new standards in design and performance.

Nikon is committed to leading imaging culture and enables some of the world’s best visual artists to reach their creative potential through visual storytelling.



Similar stories you might want to read: