Visualização normal

Antes de ontemCybersecurity News
  • ✇Security | CIO
  • S/4HANA’s hidden migration challenge: SAP expert retirement
    While many companies are busy switching from ECC to S/4HANA, an even more critical migration is looming: A large amount of SAP knowledge and experience will soon be lost to retirement. Computerwoche spoke with Uwe Hartmann, founder of FITS-P GmbH, who was responsible for SAP systems as CIO at ABB for many years, about this pending knowledge drain as many SAP experts wind down their careers, as well as ways IT leaders can leverage process mining to help. ‘S/4HANA
     

S/4HANA’s hidden migration challenge: SAP expert retirement

25 de Agosto de 2026, 06:30

While many companies are busy switching from ECC to S/4HANA, an even more critical migration is looming: A large amount of SAP knowledge and experience will soon be lost to retirement.

Computerwoche spoke with Uwe Hartmann, founder of FITS-P GmbH, who was responsible for SAP systems as CIO at ABB for many years, about this pending knowledge drain as many SAP experts wind down their careers, as well as ways IT leaders can leverage process mining to help.

‘S/4HANA creates a solid foundation … but nothing more.’

Computerwoche: Many companies are facing a generational shift, as baby boomers, including numerous SAP experts, are retiring. How great is the risk of this vital enterprise knowledge being lost?

Uwe Hartmann: You have to look at the topic from different perspectives. The knowledge of experienced employees is not limited to technical operation, but above all includes an understanding of how a company’s processes function and how they are controlled in the SAP system.

Generating an order confirmation, for example, is relatively simple. But when this results in a delivery, special labels with barcodes are printed, financial accounting is integrated, and receivables or liquidity planning is initiated, then we are moving into a significantly more complex environment.

These connections aren’t understood overnight. It requires years of experience and in-depth knowledge of the company. The problem I currently see in many companies is that key personnel are retiring, and often there’s no successor yet.

Does the fact that many companies are in the midst of their S/4HANA transformation increase the pressure?

Absolutely. According to current figures, more than half of companies have not yet finished their migration to S/4HANA. If experienced employees leave, significant risks arise.

Studies by Gartner and McKinsey show that a large proportion of S/4HANA projects fail to meet their original cost or timeline targets. Every company faces a real challenge here.

What about after a successful S/4HANA migration? Will SAP experts leaving the workforce have less of an impact then?

No, not at all. The migration to S/4HANA alone won’t solve the problem. Many companies see it primarily as a prerequisite for continued maintenance and support from SAP. But this is similar to a smartphone update: You have the latest version and remain technically up-to-date, but the real added value doesn’t automatically materialize. This is precisely the question many companies are asking themselves: What does S/4HANA offer us beyond the mere maintenance requirement?

In my opinion, the real work begins here. Looking at the evolution of artificial intelligence, one can see how rapidly requirements are changing. Two years ago, AI was still an abstract topic for many. Today, it is increasingly being used productively in business processes. At the same time, SAP is also continuously developing its platform and has invested heavily in AI technologies in recent months.

But it is crucial to use these opportunities judiciously. AI only unfolds its full potential when it is meaningfully integrated into processes. Business processes in companies will very likely look completely different in three or four years than they do today. S/4HANA creates a solid foundation for this, but nothing more. Companies must build on this foundation. This will continue to require experienced employees who understand business processes and can effectively utilize new technologies with the necessary expertise.

‘The only solution then is process mining’

 With time running out, what challenges do you see for organizations still postponing migration?

A successful S/4HANA migration begins long before the project starts. It requires intensive preparation. Companies must first clarify the scope of the migration. They need to determine what investments are necessary and what goals they want to achieve. Only once these foundations are in place should implementation begin.

To do that, companies must have a precise understanding of their existing SAP landscape. How complex is the company? In which countries is it active? Which processes deviate from the standard? How extensively has the system been customized? What in-house developments still exist? How good is the quality of the master data?

Individual customizations and in-house developments are often underestimated. Added to this are master data problems, which affect almost every company. Even seasoned SAP experts cannot know every intricacy of a system by heart.

In such cases, process mining is the only solution. It’s like putting an X-ray machine on the ERP system, revealing hidden risks, dependencies, or special developments within the SAP system. This is crucial because during a migration, it’s the inconspicuous details that often become major problems. The goal is to uncover these blind spots early on, before they become a cost or time trap.

At Sapphire, SAP presented numerous AI agents designed to support S/4HANA migrations by analyzing and documenting processes. What’s your assessment of this development?

That’s definitely a useful addition. But we’re also seeing AI frequently portrayed as a panacea. People forget that this requires a solid data foundation to work.

AI can only deliver meaningful results if the underlying data models are well-structured. You can’t just give a chatbot access to an ERP system and expect it to automatically find optimization potential.

Only process mining platforms with a consistent data model create the conditions for AI to recognize patterns and identify potential improvements.

Darstellung Prozess-Flow in Process Mining Tool
Only SAP experts—or a process mining tool—know the intricacies of these process paths.

FITS-P GmbH

‘The emotional component cannot be replaced.’

Returning to retirement: What can companies do when experienced SAP experts leave the workforce? Is that knowledge irretrievably lost?

Part of it, yes. With every employee, not only is expertise lost, but also personal experience and a strong connection to the company. This emotional component cannot be replaced. Technical knowledge, on the other hand, can at least be partially preserved and made traceable.

With a data-driven approach, new employees can gain an overview. Process mining helps them see how processes run through the system, which customization settings have been made, and which in-house developments are in use. This enables them to form their own opinion and formulate targeted questions, instead of having the entire system explained to them step by step.

A personal handover is of course advisable if possible. But the major advantage is that it is no longer mandatory.

Is the loss of SAP know-how primarily a problem for medium-sized companies, or does it also affect large corporations?

This affects both equally — albeit for different reasons. In large companies, there is often a risk that the focus on details is lost as the company grows. Medium-sized companies, on the other hand, often struggle with more limited personnel resources and are more dependent on individual knowledge holders.

Regardless of company size, I see S/4HANA migration not just as an IT project, but as a strategic opportunity. Of course, the technical migration is the initial focus. But behind it lies a much larger task: Companies need to rethink their processes.

We are currently witnessing changes in processes across almost all areas of life. From digital tickets for public transport and apps for visiting swimming pools to AI-powered services — digital processes are becoming the norm. This trend will continue in businesses and public administration as well.

Therefore, the S/4HANA migration should be used to prepare the company for these changes. Making one’s own processes transparent often leads to a better understanding of the company than before and creates the foundation for adopting new technologies and ways of working more quickly.

At the same time, such a transformation project offers the opportunity to develop new talent. Companies that involve committed employees in the migration early often develop precisely the leaders who will drive the company forward in the next five or ten years. For me, that’s the true vision behind an S/4HANA migration: not just to introduce a new ERP system, but to future-proof the company.

‘What matters is not the number of consultants, but their quality’

What typical errors do you observe in knowledge management in SAP projects?

The true meaning of SAP know-how is often underestimated. I repeatedly encounter projects where employees are deployed who, while dedicated, lack the necessary technical and professional foundation. Anyone who can neither read ABAP code nor understand SAP customizing can hardly assess the numerous customer-specific extensions of a system.

Many believe that documenting processes graphically is sufficient. This is helpful, but it represents only a small part of reality. In practice, hundreds or even thousands of variations may exist for a single business process. These differences can be recognized only by understanding the processes themselves and the underlying system logic.

Equally important is professional project management. Every company should employ an experienced and certified project manager who works according to a clear phase and approval model. Before a project moves to the next phase, all prerequisites must be met.

I personally experienced a project that had to be stopped just two weeks before the planned go-live because the final test revealed that essential business processes had never been fully tested. This wasn’t a technical problem, but an organizational oversight.

That sounds more like a problem for medium-sized companies, correct?

Not necessarily. I see similar challenges in corporations as well. There, the greater risk is that projects will lose touch with operational reality.

My most important advice is: Rely on experienced project managers with sound project management training and bring the necessary SAP expertise on board early. The crucial factor is not the number of consultants, but their quality. Companies should not hesitate to seek external expertise in the early stages of a project. This is usually significantly cheaper than having to correct errors shortly before go-live.

One last question: Some companies are considering having their existing SAP systems maintained by third-party providers instead of migrating directly to S/4HANA. Is this a viable strategy?

I don’t personally know any clients who are taking this approach, but I can understand why companies are considering it. When studies by Gartner or McKinsey show that a large proportion of S/4HANA projects miss their deadlines or budgets, then their reluctance is understandable. After all, those who miss the deadline usually exceed their budget.

Furthermore, many consulting firms are operating at full capacity. Companies are therefore rightly asking themselves whether they can get the best resources for such a project right now, or whether a later date would be more sensible.

Those who still have sufficient support for their existing system and only need to make a few changes can consider using the remaining time strategically. However, it is crucial not to let this time go to waste.

In my view, there’s no way around S/4HANA in the long run. But speed alone isn’t a guarantee of success. Companies that have some leeway today can invest that time to prepare their organization: by training employees, strengthening IT staffing, building the necessary expertise, and refining their own strategy.

In recent years, many companies have paid a high price for their migration projects. By 2028, more tools will be available, and the experience gained from the first large-scale projects will benefit everyone. Therefore, careful preparation can be more sensible than a rushed start.

My advice would therefore be: Use the remaining time wisely. Build expertise, attract the right employees, and align your IT so that it can still successfully support the company in five or ten years. The S/4HANA migration should be part of a long-term future strategy — not just a project to meet a deadline.

See also:

  • ✇Security | CIO
  • Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?
    A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform. On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the syst
     

Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?

13 de Agosto de 2026, 08:00

A few months ago, I was sitting in a glass-walled conference room with the executive team of a fast-growing enterprise. The vice president of customer operations was enthusiastically demonstrating the new automated agent features their software vendor had just pushed into their CRM platform.

On the screen, the software looked brilliant. The agent could read customer complaints, analyze transaction histories and automatically resolve issues. The VP showed us how the system could independently offer retention incentives to unhappy accounts without a human ever touching a keyboard.

Then I asked a simple question: “What is your approval process when the AI decides to grant a $20,000 contract discount to keep a customer from leaving?”

The room went completely silent. The VP looked at the director of IT, the director of IT looked at the chief risk officer, and everyone realized the same thing at the exact same moment. They had spent three months evaluating software licenses and security protocols, but nobody had asked who gave the software permission to sign off on corporate spending.

Major software providers like Salesforce, SAP and Oracle are rapidly moving beyond simple report writers and conversational chatbots. They are embedding active, autonomous agents directly into the transactional core of systems that manage your revenue, customer agreements and financial ledgers. According to Gartner’s latest adoption forecasts, eighty percent of enterprise applications will deploy these embedded capabilities by 2026. These applications do not just summarize data: they issue refunds, alter contract terms and trigger supply chain orders.

When I review these deployments with client teams, the core problem has nothing to do with artificial intelligence. It is a fundamental breakdown in corporate delegation and signing authority.

The breakdown of the corporate signing matrix

Every mature company I work with operates on a clear delegation of authority matrix. This framework dictates exactly who can sign off on financial commitments. A vice president might have authorization to approve spending up to $500,000, a director might sit at $100,000 and a front-line manager might be capped at $500. For two decades, technology leaders have spent millions of dollars building security and compliance controls to ensure every human employee operates strictly within those limits.

Yet when a software vendor releases an update featuring autonomous agents, companies routinely grant these features unrestricted operational freedom. Because the capability arrives as a native feature inside an existing application, business units enable it with a single click. In my advisory work, I repeatedly see organizations grant third-party software features more financial freedom than their own human managers.

This represents a massive blind spot in executive governance. McKinsey’s global surveys on artificial intelligence reveal a striking pattern across the enterprise landscape: while adoption is accelerating at a historic pace, only a tiny fraction of organizations are actively managing the financial and operational risks of automated decision errors.

The quiet cost of shadow delegation

In my audits, this rarely manifests as a dramatic system crash. It plays out as a quiet margin leak. In one organization I reviewed, a department head had enabled an automated customer retention feature over a weekend. The agent noticed an important account expressing frustration in a support ticket, and to prevent the account from churning, it independently applied an unapproved 15 percent discount to their multi-year contract.

The customer was happy, and the account manager considered the client saved. But from an executive perspective, an unvetted third-party algorithm just executed an unauthorized contract modification that eroded company margins. When the finance team conducted a quarterly audit, they did not discover an employee violating spending policy. They discovered a black-box automated decision that bypassed every internal approval control in the company.

When an auditor tests your internal controls, presenting a log showing that a vendor’s algorithm made an unauthorized financial change does not satisfy the requirement. If an action requires managerial sign-off when performed by a human being, letting software execute it independently is a major control failure.

How I advise executive teams to handle automated authority

Protecting your organization does not mean turning off these tools or falling behind on technology. It means treating vendor-supplied agents exactly like third-party contractors who have not yet passed a background check.

Forrester Research emphasizes that extending zero-trust security frameworks to automated business processes is now mandatory for enterprise risk management. Zero-trust simply means that no user, device or automated tool gets implicit trust. Every proposed action must be validated against explicit business rules before it happens.

When I help enterprise teams design these safeguards, we establish a practical three-tiered boundary for automated tools:

  • Read and draft permission: Automated tools can freely analyze trends, draft emails and assemble internal reports. No human sign-off is needed to create a draft, but the system cannot publish or execute anything on its own.
  • Standard administrative permission: Tools can handle routine administrative tasks or process standard requests below a strict financial cap (such as a $50 service credit), provided every single action is logged in an audit file that managers review weekly.
  • Restricted financial permission: Any action that alters contract terms, changes pricing tiers or issues major refunds are strictly held in an authorization queue. The system generates the request, but a human manager must click “approve” before the change hits the live database.

As a technology executive, you cannot control what automated features software providers bundle into their platforms. You can, however, control the financial boundaries and signing authority those tools are permitted to exercise within your business.

What to do at your next executive leadership meeting

  1. Ask for an automated authority inventory: Have your team audit your core software platforms to identify every automated feature currently running with permission to alter financial or customer records.
  2. Revert to draft-only mode: Instruct your team to default all vendor-supplied automated agents to “draft only” until a clear business case justifies giving them independent operational authority.
  3. Establish a firm human-in-the-loop rule: Require a strict organizational policy that no automated system can modify pricing, contracts or financial ledgers without explicit manager approval.

  • ✇Security | CIO
  • SAP dodges German antitrust investigation over data extraction
    SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation. The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release. It launched its investigation int
     

SAP dodges German antitrust investigation over data extraction

3 de Agosto de 2026, 10:02

SAP is not unfairly preventing enterprises from extracting their data from its systems for use with competitors’ applications, the German Federal Cartel Office (Bundeskartellamt) concluded Thursday after a preliminary investigation.

The Bundeskartellamt does not currently intend to initiate abuse proceedings against SAP, although it will continue to monitor developments in what it views as a dynamic market, it said in a news release.

It launched its investigation into SAP’s practices following complaints by software companies including Celonis, a developer of process mining tools, alleging that SAP makes it difficult for customers and third parties to access data from its ERP systems and favors its own Signavio process mining tool.

“Companies must generally also be able to use their own data in third-party applications. With large software platforms, in particular, non-discriminatory access to data is crucial to effective competition,” said Bundeskartellamt President Andreas Mundt. “Our preliminary investigation has found that there are currently sufficient data extraction options available and that there have so far been no indications of exclusionary practices that may be relevant under competition law.”

SAP changed its policies on accessing data held in its applications via APIs in April, prompting customer pushback.

But, said Mundt, the Bundeskartellamt found that despite the API policy change, data extraction options that were previously permissible are still available.

Data extraction is possible

SAP welcomed the Bundeskartellamt decision, saying that “as the authority states, SAP customers and partners have sufficient and permissible technical options to extract data from SAP systems and use it in solutions from other providers. The SAP API Policy does not restrict these capabilities.”

Celonis also issued a statement, noting that the Bundeskartellamt ruling underlined the continued importance of unrestricted data access, and warning, “The decision is based on the key premise that data extraction for software from providers such as Celonis will remain possible even under SAP’s new API policy — a premise that SAP has been unwilling to confirm to date.”

The Celonis statement continued, “We remain steadfast in our conviction that company data belongs entirely to the customers who generate it. No provider should restrict a company’s right to extract its own information or prevent users from working with third-party providers such as Celonis that offer added value to customers.”

Celonis is also attacking SAP’s policies on data extraction in court in California. It filed a complaint in March 2025 alleging that SAP was leveraging its software to “prevent SAP customers from sharing their own data with third-party providers, including Celonis, without paying prohibitively expensive fees.” The judge dismissed some of the claims in that case, leaving three to be tested in a trial then scheduled for December 2026. Celonis has since amended its complaint to include 10 claims, and the trial has been rescheduled for 2027, the company said.

“Our litigation continues to uncover evidence of SAP’s unlawful behavior, including anticompetitive conduct and theft of intellectual property, and we are confident in the evidence that we will present at trial,” Celonis said following the German authority’s decision.

The Bundeskartellamt’s failure to find sufficient evidence to open a ‘formal abuse of dominance proceeding’ is a small win for SAP, said Scott Bickley, advisory fellow at Info-Tech Research, but “CIOs should not mistake it for a validation of SAP’s data access model.”

Although SAP recognizes customers’ right to decide they use their data, it does not make it easy for them to do so, he said. “CIOs may technically retain vendor choice but be faced with expensive replication architectures, API rate and volume restrictions, additional platform costs, performance lags and data migration costs, all with a dependency on an SAP-approved technical pattern, which can be a moving target.”

Data ownership as a procurement issue

Justin Greis, CEO of consulting firm Acceligence, sees the decision as an instructive one for enterprise CIOs.

“This isn’t a reason to stop asking hard questions of your ERP vendor. Whether it’s SAP, Oracle, Microsoft, Salesforce, or anyone else, enterprises should continue to evaluate how easy it is to access their own operational data, integrate third-party applications, and migrate workloads if business priorities change. Those questions are becoming strategic procurement issues, not just technical ones,” Greis said.

CIOs should consider data portability early in the procurement process, said Kaan Dincer, CEO of data migration vendor Settle: “Negotiate export rights, API access on reasonable terms, and documentation of the data model before signing and test a real extraction while the vendor still wants your renewal. The cost of your eventual exit is set on the day you implement, not the day you leave. ERP data now feeds analytics and automation outside the system of record, so access friction that used to be an IT annoyance is becoming a strategy constraint.”

In the SAP case, he said, “the regulator answered a narrow legal question, not the operational one. Declining to open proceedings means the friction was not shown to be anticompetitive. It does not mean the friction is not real. The Bundeskartellamt’s own findings acknowledge that extracting large data volumes is technically demanding and it said explicitly that it will keep watching as access mechanisms and license models evolve. That is not a clean bill of health. It is a decision to hold fire.”

Srinivasulu Reddy Battu, a senior software engineer with cloud vendor ZT Systems, said the big takeaway is the difference between difficult and impossible. SAP’s argument is that the data migration outside of its environment is possible, but Battu said it can be a time-consuming and expensive process.

“When the ruling says ‘various permissible and viable options’ exist, that’s technically true, but it glosses over how much expertise it actually takes to use them,” Battu said. “CIOs should still watch how process mining gets packaged in their contracts. If Signavio comes included by default, teams will naturally start using it and that quietly reduces your negotiating power with other vendors over time. This isn’t just about SAP: Oracle, Microsoft, every major ERP vendor sits on a massive amount of your business data. If any of them decided to tighten their API policies tomorrow, most companies would be scrambling.”

❌
❌