The global and independent platform for the SAP community.

Why secure code is becoming mandatory - innovation in the cloud and with AI

After the S/4 implementation, the next modernization phase begins for SAP users and with it new security risks. Innovation can only succeed with strong software supply chain security and a zero-trust approach for AI agents.
Peter Körner, Red Hat
April 23, 2026
avatar
This text has been automatically translated from German to English.

Many companies have migrated to S/4, are striving for the clean core principle and see the added value of side-by-side extensions. The ERP core remains stable, while innovations and individual processes are increasingly being implemented outside the system. This is where the challenge begins: added value is increasingly being created by external services, microservices and special solutions that are based on SAP data but run outside the familiar SAP world.

Innovation today is all about new business models, complex process automation and AI-supported workflows that intervene deeply in operational processes. As a result, the focus on security is also shifting: away from the pure protection of a monolithic ERP system and towards securing highly networked, heterogeneous landscapes in which cloud platforms, local data centers and specialized services work together. 

Cloud foundation open source

In order to implement innovations quickly, a robust, well thought-out security architecture that integrates all these levels is required. Open source provides a good foundation here, as modern cloud-native development relies almost exclusively on open source components: Frameworks, libraries, container images and complete platforms. This is particularly true for AI topics; almost all relevant frameworks, pipelines and tools originate from the open source ecosystem. The key question here is how trustworthy these building blocks are and how their use can be controlled.

Open source communities have already responded to the growing risks. Mature concepts such as software supply chain security have been addressing the origin, integrity and maintenance of components for years, while providers such as Red Hat are using these technologies to design hardened, tested and commercially supported platforms. For companies, this means that open source is a welcome part of the solution and can be managed in a structured way. There is also a new factor: agentic AI approaches. This refers less to individual AI agents and more to agentic AI workflows in which systems plan independently, make decisions, call up external tools or orchestrate other agents. This architecture promises enormous leaps in productivity, but it is also associated with particular risks,
as agents install additional software or access additional services via APIs, for example. 

A modern security strategy must take these risks into account. The decisive factor here is a zero-trust approach that makes agents controllable during operation and protects them from manipulation. This involves the areas of identity, behavior and logic. Red Hat's security approach includes the assignment of cryptographically verifiable identities instead of fixed access data, the monitoring of agent behavior and the use of guard rails to check the decision logic of models. These mechanisms supplement software supply chain security, they do not replace it.

Paradigm shift in security strategy

S/4 and Clean Core are necessary prerequisites, but not a sufficient answer to the current innovation and security requirements. The complexity arises outside the ERP system - precisely where the decisive value creation takes place today. For companies, this means a paradigm shift. They must define their own consistent and secure strategy for the development and operation of software, link their innovation roadmap with the security architecture and governance and, if necessary, rethink their partner selection. Today, companies need partners who have mastered both the SAP ecosystem and modern development and security concepts - and who can translate these into resilient, production-ready solutions.

To the partner entry:

avatar
Peter Körner, Red Hat

Peter Körner is Principal Business Development Manager Red Hat SAP Solutions at Red Hat


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the fourth time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

FourSide Hotel Salzburg,
Trademark Collection by Wyndham
Am Messezentrum 2, 5020 Salzburg, Austria
+43-662-4355460

Event date

Wednesday, June 10, and
Thursday, June 11, 2026

AI experience workshop only on June 11, 2026 (limited places)
Bonus: Access to all lectures on June 11, 2026

Regular ticket

Lectures, evening event and, depending on availability, the AI workshop on June 11, 2026
Places at the AI experience workshop are limited and registration is required.

Subscribers to the E3 Magazine Ticket

reduced with promocode CCAbo26

Students*

reduced with promocode CCStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
*The first 10 tickets are free of charge for students. Try your luck! 🍀
EUR 305 excl. VAT.
EUR 590 excl. VAT
EUR 390 excl. VAT
EUR 290 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, April 22 and
Thursday, April 23, 2026

Tickets

AI onlyExperience workshop on April 23, 2026 
Bonus: Access to all lectures on April 23, 2026
Regular ticket
April 22, 2026: Lectures and evening event
April 23, 2026: Lectures and AI workshop
EUR 305 excl. VAT
EUR 590 excl. VAT
Subscribers to the E3 magazine
reduced with promocode STAbo26
EUR 390 excl. VAT
Students*
reduced with promocode STStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
EUR 290 excl. VAT
*The first 10 tickets are free of charge for students. Try your luck! 🍀
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2026, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.