Implementing SAP BTP Security correctly

Fundamentals, Architecture, and modern Best Practices for a Secure Cloud Landscape

SAP BTP Security is becoming increasingly important because moving business-critical processes to the SAP Business Technology Platform creates new attack surfaces. Classic on-premise approaches are not enough here. It encompasses all measures required to ensure secure operations, secure development, and controlled access across cloud-based SAP landscapes.

This article explains how to secure SAP BTP, how responsibilities are divided in the cloud, and which architectural principles are required for stable and scalable SAP environments.

SAP BTP Security: The Essentials at a Glance

  • SAP BTP extends classic SAP landscapes with cloud and hybrid scenarios – this also creates new attack surfaces.
  • Security on the BTP follows the shared responsibility model: SAP secures the platform, while customers are responsible for configuration, identities, authorizations, and custom code.
  • A consistent architecture and IAM design are critical for a resilient security posture.
  • In practice, the biggest risks come from misconfigurations and missing governance – not from weaknesses in the platform itself.
  • Clear best practices for identities, development, monitoring, and updates help keep the BTP secure in the long run.

What is SAP BTP Security?

SAP BTP Security describes all technical and organizational measures that ensure the secure operation, secure development, and controlled use of the SAP Business Technology Platform.

SAP BTP is often used as a Platform-as-a-Service, but it also includes Software-as-a-Service components, such as SAP Build Work Zone or the SAP Integration Suite as a managed service.

At its Core, SAP BTP Security can be broken down into 3 Areas

1

Platform Security

Platform security is SAP’s responsibility and covers infrastructure, network, tenant isolation, and fundamental security mechanisms.

2

Customer Security

Customer security covers all tasks that customers handle themselves – such as configuring identity services, designing authorizations, or monitoring.

3

Application Security

Application security applies in particular to customer-owned extensions and side-by-side applications, and is a shared responsibility between SAP and the customer for custom development.

A dedicated security concept for SAP BTP is necessary because cloud security differs fundamentally from classic on-premise SAP security.

Security boundaries no longer run along individual systems, but along identities, roles, trust relationships, and architecture decisions. Especially in hybrid landscapes, security doesn’t come from individual measures, but from a consistent, cross-platform design.

The Shared Responsibility Model: Who is Responsible for What?

The SAP Business Technology Platform follows a clearly defined shared responsibility model.

It describes how security responsibility is divided between SAP as the platform provider and the customer as the operator of the respective BTP landscape. This model is the foundation of every secure cloud architecture – yet it is often underestimated in practice.

SAP's Responsibility (Platform Level)

SAP is responsible for the secure operation of the infrastructure and data centers, including relevant certifications.

This includes network security, tenant isolation, and the encryption of data at rest and in transit. In addition, SAP provides central security services that form the basis for secure platform operation.

Customer Responsibility (Usage Level)

Organizations manage identities, roles, and authorizations, configure the security services, and implement the least-privilege principle. Securing custom code, monitoring, incident response, and compliance requirements is also the customer’s responsibility.

Shared Responsibility at a Glance

Security Area SAP's Responsibility Customer's Responsibility
Infrastructure & Network Provisioning Configuration, VPN, Cloud Connector
Identity & Access Providing the services MFA, least privilege
Application & Data Encryption, platform tools Custom code, data protection
Monitoring & Response Audit logs SIEM, incident response
Compliance & Audit Certifications GDPR/CCPA, NIST CSF

SAP BTP Security Architecture in Detail

Cloud Foundry Runtime

Applications are executed in isolated environments. What matters for security is clean service integration, controlled handling of credentials, and clearly defined communication paths.

Kyma Runtime

Kyma offers greater technical flexibility but requires clean governance design. Misconfigurations here can become security-relevant more quickly.

ABAP Environment

The ABAP Environment is fully operated by SAP. Infrastructure-related risks are reduced, while clean authorization and extension concepts remain essential.

Separation of Applications and Tenants

Applications and tenants are logically separated from one another. An application cannot access other applications or subaccounts without explicit configuration and authorization.

This separation is especially security-critical in hybrid scenarios with on-premise connections.

Data Encryption

On SAP BTP, data is encrypted by default both at rest and in transit.

For most scenarios, this default encryption provides a reliable foundation for meeting security and data protection requirements.

Security-relevant Services of SAP BTP

SAP BTP provides services that cover essential security functions. What matters is how they work together within a consistent architecture.

  • SAP Cloud Identity Services for authentication, user management, and identity integration
  • Authorization and Trust Management (XSUAA) for access control within the platform
  • Cloud Connector and Destination Service for secure, controlled connectivity to on-premise systems

Additional services support logging, credential handling, and security checks, but they do not replace a holistic architecture and governance concept.

Current Threat Scenarios for SAP BTP

As SAP BTP usage grows, security risks evolve as well. Most incidents don’t result from platform weaknesses, but from misconfigurations and inconsistent concepts.

Typical Attack Vectors

Regulatory and compliance requirements

4 Best Practices for SAP BTP Security

To secure your SAP BTP architecture, be sure to keep these 4 aspects in mind:

1

Consistently Implement Identity & Access

Federation, MFA, clean role models, and regular reviews.

2

Establish Secure Development

Secure coding, code reviews, and clear guidelines.

3

Prepare Monitoring and Incident Response

Analyze logs, define processes.

4

Run Patch and Update Management

Keep hybrid components up to date and track security advisories.

Reliably implementing SAP BTP Security with Xiting

Xiting helps organizations build consistent, well-documented SAP BTP security architectures.

Our focus is on architecture and IAM design, clear role and governance concepts, and a cross-system view of risk. Training and enablement formats further support embedding the resulting concepts sustainably into operations.

Contact us today for a no-obligation discussion and learn how Xiting can help secure your SAP BTP landscape.

FAQ

What Security Services does SAP BTP offer?

SAP BTP natively provides a number of security services, including identity services, access controls, secure integration services, and logging and auditing mechanisms.

The shared responsibility model describes the division of security responsibility between SAP and the customer. SAP secures the platform infrastructure, while the customer is responsible for configuration, authorization management, securing their own applications, and monitoring.

In the on-premise world, the customer controls the entire infrastructure. With BTP, the focus shifts away from system control toward identities, architecture, and governance.

Stay up to date.

Sign up for the newsletter to receive more information.

Follow @Xiting and @xiting.global on social media.

Melden Sie sich jetzt an!

Get in touch now!

Nehmen Sie jetzt Kontakt auf!