
SAP control technology

SAP control managed services
Your Value

Always fully secured and in control SAP (GRC) environment

Best practice & automated SAP-authorizations and access compliance

Effective 1’st line SAP authorisations & controls treatment

Efficiency via automated SAP IT general controls

S/4 HANA and RISE readiness and compliance by design

Continuous SAP risks & security monitoring and real-time insights

Flexibility and scalability with our SAP experts

Qualiy improvement included in our SAP co-sourcing solutions.

Lowest possible cost of SAP security & control

SAP cost saving via optimized management of SAP licenses and usage
Thanks to the personal approach and quality of there teams in The Netherlands and South-Africa, BR1GHT reached all our objectives set in the first year.
Best practice SAP control tool selection
We guide you through every step of the technology selection process for SAP authorisations and security. From exploring various SAP tools and formulating a solid business case to creating shortlists, organizing demos, managing proposals, and initiating projects, we’ve got you covered. Our goal is to ensure you choose the SAP S&C technology that perfectly fits your current needs while also paving the way for future growth and success. With our support, you can confidently navigate the complexities of SAP technology and unlock new possibilities for your business.
- ZAll SAP security & controls variances of technology (see further).
- ZWe know all available SAP technology and guarantee independence.
- ZProven Methodology: We use a proven selection methodology with a strong track record of successful selections.
- ZExpert SAP consultants: who understand all aspects of SAP controls & security.
- ZWe ensure that the SAP technology meets your needs and fits in your current architecture.

SAP control tool implementations
- ZRapid, value-driven implementations.
- ZFixed-price projects (when feasible) for cost predictability.
- ZHighly skilled and experienced consultants.
- ZExtensive expertise in SAP, security, controls, and IT.
- ZEmpowering your team for a smooth transition and ongoing success.
- ZAligned approach between business (responsible for the content) and IT (responsible for maintainance).
- ZClose the gap in usage and adoption post go-live
- ZOptimize existing implementations for peak performance.
- ZEnsure active business participation for SoD and access risk compliance.
- ZIntegrate various technologies for a comprehensive risk overview.
- ZEducate end users and key users through knowledge transfer.
- ZProvide continuous system updates and workflow maintenance.
Functionalities to look at when selecting SAP control solutions

Access Risk Analysis: Identifying and managing segregation of duties (SoD) conflicts and access risks.

User Provisioning and Certification: Streamlining the creation, maintenance, and removal of user access.

Continuous Controls Monitoring: Automating the monitoring of controls to ensure compliance and detect anomalies.

Role Management: Designing, maintaining, and optimizing user roles for compliance and efficiency.

Elevated Access Management: Managing and auditing privileged access to ensure security.

Security Configuration Reviews: Assessing and improving security settings within SAP systems

Patch Management: Ensuring systems are up-to-date with the latest security patches.

Interface Traffic Monitoring: Monitoring data traffic between systems to detect and prevent unauthorized access

Code Vulnerability Management: Identifying and mitigating vulnerabilities in custom code.

License Management: Analyzing and optimizing SAP license usage.

Data Privacy and Protection: Managing and securing sensitive data to comply with privacy regulations.

Cybersecurity Application Controls: Implementing controls to protect against cyber threats and ensure data integrity.

Access Risk Analysis: Identifying and managing segregation of duties (SoD) conflicts and access risks.

User Provisioning and Certification: Streamlining the creation, maintenance, and removal of user access.

Continuous Controls Monitoring: Automating the monitoring of controls to ensure compliance and detect anomalies.

Role Management: Designing, maintaining, and optimizing user roles for compliance and efficiency.

Elevated Access Management: Managing and auditing privileged access to ensure security.

Security Configuration Reviews: Assessing and improving security settings within SAP systems

Patch Management: Ensuring systems are up-to-date with the latest security patches.

Interface Traffic Monitoring: Monitoring data traffic between systems to detect and prevent unauthorized access

Code Vulnerability Management: Identifying and mitigating vulnerabilities in custom code.

License Management: Analyzing and optimizing SAP license usage.

Data Privacy and Protection: Managing and securing sensitive data to comply with privacy regulations

Cybersecurity Application Controls: Implementing controls to protect against cyber threats and ensure data integrity.
Our SAP control technologies




















SAP control consulting
We then work on realizing a best-practice controlled SAP environment. If needed, we can embed these new best practices into your organization’s workflows, implementing continuous improvement capabilities and integrating all business lines into an effective structure. This ensures robust assurance on your SAP risks. Our approach can include the following SAP S&C areas:
- ZSAP authorisations - managed compliance and risks - realise safeguarding of assets, continuity, fraud prevention and privacy.
- ZSAP security - realising a maximum secured SAP environment.
- ZSAP license management - getting compliant and save costs.
- ZSAP S/4 HANA - FIORI - RISE - manage all the risk in your migrations.

SAP authorisations

SAP security

SAP license management

SAP migration to S/4 HANA & RISE
Request your ...FREE SAP security & controls...assessment
Request your ...FREE SAP security & controls...assessment
Secure your SAP systems with confidence
Areas of expertise
- ZThreat protection for critical SAP systems. Shield your SAP environment against ransomware, phishing, insider threats, and advanced persistent threats using multi-layered security strategies.
- ZVulnerability management. Proactively identify and mitigate vulnerabilities in your SAP systems through regular assessments, patch management, and threat intelligence integration.
- ZReal-time monitoring and Incident detection. Leverage state-of-the-art tools like SecurityBridge to monitor your SAP landscape, detect anomalies, and respond to incidents instantly.
- ZSecurity baseline sssessment. Conduct a comprehensive assessment to ensure your SAP environment adheres to best practices and meets regulatory requirements.
- ZCompliance with global standards. Align with international standards, including ISO 27001, NIS2, and DORA, to maintain trust, avoid penalties, and ensure regulatory compliance.
- ZData protection. Secure sensitive data—such as customer records and financial information—with encryption, access controls, and data masking.
- ZRisk mitigation. Reduce the likelihood of unauthorized access and data breaches by implementing identity management systems and robust security controls.
Benefits of BR1GHT’s SAP cyber security services
- ZEnhanced resilience: Strengthen your SAP systems against cyber threats with proactive security measures.
- ZRegulatory compliance: Meet global compliance standards, minimizing risks of penalties or reputational damage.
- ZReal-time insights: Gain operational visibility with continuous monitoring, detailed reporting, and actionable insights.
- ZOperational efficiency: Streamline processes with automation and advanced IT General Controls to reduce manual effort.
- ZCustomer trust: Safeguard sensitive data to maintain customer confidence and protect your brand reputation.
- ZFuture-proof security: Stay ahead of emerging threats with cutting-edge technology and ongoing optimization.
Protect, Comply, Thrive with BR1GHT
Read what clients think about our SAP sercurity solution, read our solution paper and listen to our podcast
SAP license management
License compliance assessment
Improvement
- ZRISE with SAP Contract Negotiations: We help you navigate the complexities of RISE with SAP contracts, securing favorable terms that maximize the value of your SAP investment.
- ZS/4 HANA Contract Migrations: Our strategic approach supports seamless migrations to S/4 HANA, minimizing disruption and optimizing your SAP landscape for the future.
- ZLicensing Strategies: We identify cost-effective licensing options and develop negotiation tactics tailored to your organization’s specific needs.
- Z3rd Party Access Management: Ensure compliant access for third-party applications interfacing with SAP, preventing unexpected costs and reducing compliance risks.
Read more articles and what clients think about our SAP licensing solution
Areas of expertise
- ZAssess the impact of migration on your existing authorization structures, FIORI applications, and licensing to ensure a smooth transition.
- ZEstablish a robust security and compliance framework within the migration project to safeguard data and meet regulatory standards.
- ZWork closely with finance process owners to identify risks and implement mitigating controls for authorizations and Segregation of Duties (SoD).
- ZRedesign risk rule sets to accommodate new SAP and FIORI transactions, ensuring compliance and operational continuity.
- ZOptimize authorizations and roles to reduce licensing costs, minimize risks, and streamline role maintenance for long-term efficiency.
- ZLeverage SAP RISE capabilities, including cloud-based infrastructure, built-in compliance tools, and embedded intelligence, to drive innovation and operational resilience.
- ZImplement end-to-end migration strategies that integrate business process improvements and align with your organizational goals.
- ZDeliver business / project manager or being your security and controls stream within your S/4 HANA migration (next to or as part of the system / business integrator)
Benefits partnering with BR1GHT for your migration
- ZCost efficiency: Lower operational costs through optimized roles, reduced licensing fees, and streamlined system management.
- ZEnhanced security and compliance: Proactively address risks and regulatory requirements during the migration process, ensuring your systems are protected.
- ZBusiness continuity: Minimize downtime and disruption with a structured, well-executed migration strategy tailored to your needs.
- ZOptimized operations: Modernize processes, implement intelligent automation, and enable faster decision-making with SAP S/4HANA and RISE features.
- ZCloud-driven Agility: Unlock the scalability, flexibility, and resilience of SAP RISE’s cloud infrastructure to future-proof your operations.
- ZFuture-ready ERP: Adopt a cutting-edge ERP system that supports real-time analytics, predictive capabilities, and seamless integration with digital tools.
Your partner for SAP S/4 HANA and RISE with SAP
Read more articles
Read what clients think about us
SAP security & control specialists
Ad-interim. We provide interim specialists in SAP security, authorization, and controls, and tools like Soterion, MARC, and Togglenow. These experts can seamlessly integrate into your S/4 HANA or RISE upgrade projects as security, controls, or finance specialists. They can also support business and finance streams as process owners. Whether you need coverage during peak times, absences, or additional project demands, our specialists—from juniors to seasoned principal consultants—are ready to lead and manage your teams and projects effectively.
Operational support. For ongoing needs, we offer flexible, long-term operational support contracts. Our commitment includes continuous improvement assignments and ad-hoc consultations, ensuring your organization benefits from in-depth knowledge and expertise across all specialist areas. Partnering with us guarantees compliance, resilience, and future-readiness. Choose BR1GHT for a partnership that drives excellence and innovation in all SAP control areas.
Partnering for your success
- ZProven expertise you can trust. Leverage our deep experience and SAP control technologies. Supported by global service centers, we ensure your systems are safeguarded with industry-leading tools and practices.
- ZA seamless extension of your team. Our experts integrate effortlessly, aligning with your processes and objectives to enhance performance and reduce risks—just like part of your team.
- ZProactive control and compliance. Address SAP Segregation of Duties (SoD) and security risks proactively, ensuring full compliance with regulatory standards for your peace of mind.
- ZStructured, comprehensive onboarding. We guide you through a four-phase onboarding program—covering business case development, transition, operation, and improvement—for a solid foundation of success.
- ZFlexibility and scalability to meet your needs. Our skilled SAP specialists provide agile, scalable support for peak periods, ad-hoc needs, or long-term collaboration as your business demands.
- ZDrive efficiency with automation and innovation. Harness the power of IT General Controls and advanced technology to streamline processes, boost efficiency, and reduce manual effort.
- ZCommitment to continuous improvement. We refine controls, optimize processes, and reduce risks to add lasting value to your SAP environment, with transparent management reporting.
Read what clients think about us
Outlining the essential components for effective GRC – the GRC pyramid
In this insightful podcast, Meindert Keuning (BR1GHT) and Emile Steyn (Soterion), guided by host Dudley Cartwright, discuss the critical components of effective Governance, Risk, and Compliance (GRC). Using the GRC Pyramid as a framework, they explore how organizations can achieve a structured and scalable approach to managing SAP security, risk,…
Simplifying SAP S/4HANA migration: insights and solutions from BR1GHT, Soterion, and PwC
Migrating to SAP S/4HANA is a critical step for organizations looking to modernize their ERP systems, optimize business processes, and embrace digital transformation. However, this transition brings unique challenges, especially in managing SAP security and authorizations. In a recent podcast featuring experts from BR1GHT, Soterion, and PwC, we discussed the…
SAP security & GRC trends report
In a recent podcast Meindert Keuning (BR1GHT) and Emile Steyn (Soterion) tackled one of the most pressing issues facing businesses today: the critical shortage of skilled SAP security professionals. The discussion provided actionable insights into how organizations can navigate this challenge while optimizing their SAP security and authorizations. Takeaways from…
The challenge: complex, time consuming and high risk SAP authorizations
SAP authorizations are becoming increasingly complex, especially with the introduction of S/4HANA, Fiori, and modules like SuccessFactors and Ariba. Often, these responsibilities fall on individuals managing it \"on the side,\" which leads to declining quality and increasing risks. Organizations are left vulnerable when these individuals are unavailable due to illness,…
SAP security & compliance
When you are aiming high with your SAP ambition, it is important that the foundation is strong. A well-thought-out strategy, a solid plan, experienced and well-motivated people, partners with in-depth SAP knowledge, the right technology, and a strong security and compliance basis are essential. We add value by making your…
PVH optimizes SAP licensing with BR1GHT, achieving a 34% cost reduction
PVH, the global fashion behind brands like Tommy Hilfiger and Calvin Klein, operates in a complex digital landscape and competitive market segment, where efficient software management is essential. With a significant SAP footprint, PVH sought to optimize its SAP licensing structure to reduce costs and ensure compliance. BR1GHT delivered a…
BR1GHT achieved a 90% SAP authorization and SOD risk reduction at Sound United
We are proud to share that BR1GHT supported Sound United in achieving 90% risk reduction in their SAP environment. Sound United is a leading developer of premium consumer sound and home integration technologies, adding to its broad portfolio of hospital and home medical technology and wellness solutions. Sound United has…
Bridging the Adaptation Gap in GRC Systems: How to Maximise Long-Term Value
Governance, Risk, and Compliance (GRC) systems have become essential technologies for organisations to manage risks, meet regulatory requirements, and ensure internal processes run according best control practices. However, many businesses face a common challenge after system implementation. End users often struggle a long period to fully adopt the new system.…
BR1GHT is Attending the ISACA Risk Event 2024 on 6 Nov 2024!
We are excited to announce that BR1GHT will be attending the fifth edition of the ISACA Risk Event on Wednesday, November 6, 2024, celebrating their first lustrum! This event offers a fantastic opportunity to meet our peers, gain knowledge, and share insights. The ISACA Risk Event, organized in collaboration with…
BR1GHT at VNSG themadag security 2024
BR1GHT will be participating once again as we continue our commitment as SAP security specialists and look forward to meeting our partners and colleagues. Throughout the day, various topics will be covered, including SAP Cloud Security, GRC, Cybersecurity, authorizations, and Identity Management. The program will offer a great mix of…
BR1GHT is attending the 20th edition of the security-congres 2024!
We are excited to announce that BR1GHT will be attending the 20th edition of the Security-Congres on October 9, 2024, at Gooiland Events in Hilversum! This event provides a fantastic opportunity to connect with industry experts, gain insights, and share knowledge. Theme: Expect the Unexpected Cybersecurity measures are often improved…
Navigating SAP’s new licensing landscape: How to optimize costs and maximise value
SAP has updated its licensing model, introducing changes that can significantly impact your costs and compliance requirements. This blog offers an in-depth exploration of SAP licensing, focusing on essential aspects such as measurement and management. We discuss the theoretical framework behind licensing, identify common facts and limitations, and provide a…
Job – Consultant at BR1GHT
We are looking for two experienced consultants to complement our Surinamese team. In this role, you will advise clients on (software) solutions for risk management, compliance and/or (IT-)security. This includes pre-sales, demos, application implementation and specialist consulting. You don’t need to be a specialist in all areas, but if your…
Specialist consulting by BR1GHT
BR1GHT helps clients to gain value in all governance areas with technology, specialist consulting and managed services. With specialist consulting we focus on selecting the right technology and improving the use of technology by the governance functions within the organisation of our clients: internal control, risk management, compliance and internal…
BR1GHT achieves 90% reduction in EVBOX’s SAP security risks
BR1GHT conducted a baseline assessment to identify risks in EVBox's SAP Authorization design. Subsequently, EVBox decided to address these risks by redesigning its SAP Authorizations, aiming for a robust and secure SAP environment.
Introducing SAP augmented access control (AAC): Revolutionizing SAP access management powered by AI
We are exited about the new developments in the area of User Access Management by SAP: the launch of SAP Augmented Access Control (AAC). It is a groundbreaking solution designed to revolutionize access management within organizations. SAP AAC combines cutting-edge technology and artificial intelligent analytics to provide advanced access control…
BR1GHT wins Swedish National Audit Office to provide audit management system
BR1GHT has been chosen to provide the audit management system for the Swedish National Audit Office (Riksrevisionen), and will be partnering with Wolter Kluwer’s TeamMate+ platform to achieve this. The selection process was rigorous, and we are thrilled to be working with the Swedish NAO to bring innovative technology to…
The IIA Global Conference is coming to Amsterdam
As the IIA Conference is coming to Amsterdam, we at BR1GHT are excited to reconnect with our Internal Audit friends from all over the globe!
Available for work – SAP security & compliance expert (remote)
We have senior available who could support you on in SAP implementations on SAP GRC Access Controls, SAP GRC Process Controls and BIS, Service Management and Project Management. You are well known in numerous SAP IT Controls & Compliance projects including Assessment, Migration, Upgrade, Integration, Support, Implementation and Audits. You…
Available for work – IT-auditor (SAP) controls & security specialist
We have a great person and fulltime experienced (senior) IT-auditor and IT-controls (or broader controls) specialist available as of today. Experienced in SAP (multiple modules, controls, authorisation as specialist and trainer), financial & operational controls and project assurance. BIG-4 and consulting firm background. For additional information, please don't hesitate to…
BR1GHT implemented ING’s compliance monitoring system
In September 2020, the Compliance Quality Assurance (CQA) department was established within ING. This department, even more than its predecessors, had the need to conduct thematic or process-oriented compliance reviews. Since the audit function uses TeamMate, and the collaboration with BR1GHT/Wolters Kluwer made us decide to opt for TeamMate to…
BR1GHT @GRC conference Stockholm 26 June 2023
BR1GHT will join one of Europe's biggest conferences on GRC on the 26'th of June 2023. BR1GHT is a global technology solution provider for all the GRC functions within a company; from first line business & finance controls, IT controls & security, GRC & risk management, compliance, and internal audit…
Job – SAP security and compliance specialist
If you are an experiences SAP security & compliance specialist and you are looking for a change, then we have a job opportunity for you. For our Digital Control proposition, we are looking for a colleague who wants to work in our core team on engagements in the field of…