Securing SAP Custom Code: DevSecOps for AI-Driven Manufacturing

As manufacturing plants race toward automated digital transformations, a growing reliance on AI-generated software and custom SAP code is quietly expanding enterprise attack surfaces. Amid regulatory pressures like NIS2, UN R155, and TISAX, securing backend ERP systems has evolved from an IT afterthought into an existential operational imperative following high-profile industry breaches.

Modern discrete and heavy manufacturing relies heavily on uninterrupted, synchronized supply chains. When a just-in-time delivery pipeline stalls or welding robots halt unexpectedly, the root cause is frequently traced away from physical hardware and directly into enterprise resource planning software. Threat vectors are shifting rapidly. Attackers now bypass generic perimeter ransomware waves to target the application layer directly, focusing on vulnerabilities hidden within custom ABAP and non-ABAP code repositories.

The financial realities of these security lapses are severe. According to industry impact data following a major data incident at Jaguar Land Rover—which resulted in estimated financial damages of roughly 1,9 Milliarden Pfund and impacted numerous suppliers—manufacturing organizations face immense exposure. With average security breaches in the sector costing millions per event, IT leadership faces a dual mandate: accelerate digital transformation roadmaps while hardening core production systems against sophisticated injection flaws and broken authorization logic.

The Hidden Security Debt of AI-Assisted SAP Development

To keep pace with modern operational demands, software development teams increasingly rely on artificial intelligence assistants like SAP Joule to rapidly generate application code. While these tools dramatically shrink development lifecycles, they frequently lack contextual awareness regarding proprietary corporate logic and enterprise security architectures.

Because Large Language Models operate primarily on statistical pattern matching, they routinely generate functionally sound code that omits vital context-specific access controls. A classic failure mode involves omitting a mandatory AUTHORITY-CHECK statement within an enterprise web portal or inventory management script. Without this explicit authorization barrier, malicious actors or compromised internal accounts can suddenly access sensitive supplier pricing metrics, modify shipment schedules, or exfiltrate intellectual property.

Manual code reviews under tight delivery deadlines frequently miss these granular authorization gaps. Compounding the challenge, the industry faces a profound talent shortage. Industry analyses indicate that 56 percent of IT decision-makers cite a lack of internal cybersecurity expertise as a primary root cause for major security incidents. Internal IT teams are stretched thin, often lacking the specialized SAP security depth required to manually audit complex custom developments or validate code written by automated assistants.

Strict Regulatory Frameworks Mandate Clean Core Architectures

Regulatory bodies no longer view industrial cybersecurity as an optional layer. Regulations implemented across the automotive and heavy manufacturing sectors explicitly demand that software supply chains, update mechanisms, and backend ERP systems prove resilient to intrusion before hitting production environments.

  • UN R155: Mandates a certified Cybersecurity Management System, requiring manufacturers to prove that security is structurally baked into the vehicle lifecycle. A compromised SAP routine that allows the manipulation of software update packages violates this compliance mandate directly.
  • EU NIS2 Directive: Classifies automotive and heavy manufacturing as critical infrastructure, enforcing strict incident notification mandates, deep supply chain risk assessments, and executive-level accountability for cyber resilience.
  • TISAX (Trusted Information Security Assessment Exchange): Acts as a strict gatekeeper for supply chain partnerships across the automotive sector, requiring absolute protection for sensitive CAD data, blueprints, and prototype designs. Unsecured custom code can instantly derail TISAX certification and halt OEM contract participation.
  • GDPR: Connected vehicles continuously stream vast telematics datasets tied directly to vehicle identification numbers and registered owners, exposing enterprises to heavy statutory fines if underlying SAP databases experience data leaks.

Transitioning to modern cloud architectures via strategies like “Clean Core”—exemplified by SAP S/4HANA, SAP Cloud ERP, or RISE with SAP—requires keeping the standard software core pristine. When developers rush custom code into these environments without adequate testing, they inadvertently accumulate technical debt and migrate legacy vulnerabilities directly into new cloud landscapes.

Automating DevSecOps Pipelines for Enterprise SAP Environments

To eliminate these risks without choking innovation velocity, organizations are turning to automated DevSecOps pipelines. Integrating automated code analysis directly into Git repositories, continuous integration workflows, and development environments ensures that every transport request undergoes rigorous inspection prior to deployment.

Security as Code: AI-Driven DevSecOps Pipelines

Platforms like Onapsis Control—recognized within the SAP Endorsed Apps ecosystem—provide automated testing engines designed specifically for the application layer. By scanning both human and AI-generated developments against more than 600 specialized test cases, these tools flag missing authorization objects, unintended dependencies, and policy violations before code reaches production.

Practical deployments demonstrate the viability of this automated approach. Automotive manufacturer Škoda utilized Onapsis tooling to enable numerous developers to systematically address security and quality findings, drastically cutting manual audit overhead while boosting overall system performance and stability.

Securing modern manufacturing lines requires looking far beyond physical firewalls and endpoint protection. By embedding automated security checks directly into the earliest phases of custom SAP development, organizations can satisfy stringent regulatory mandates, safely leverage AI coding assistants, and protect their supply chains from catastrophic disruption.

AI-Driven DevSecOps Part 1: Securing Coding Agents with Model Context Protocol (MCP)
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Argentina Recalls Envoy After President Insults Brazil’s Lula da Silva

Alla Pugacheva Sparks Controversy Over Health and Bold New Look

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.