UX4Tech · SAP Security & Identity Governance

The workforcenobody onboarded.

IBM just put a price on a problem SAP teams have carried for twenty years. It is sitting in your production system right now, and nobody has taken attendance since go-live.

Scroll
DOC UX4T-BLG-027CLASS PUBLICSOURCES VERIFIED 30-JUL-2026VER 2.0READ ~7 min
01 · The price

IBM didn't find a new problem. It found the invoice.

The 2026 Cost of a Data Breach Report reads like a bill arriving for a decade of deferred maintenance.

0
Global average breach cost — a record, up 12%
0
US average, more than double the global figure
0
To identify and contain a breach

Those numbers will get quoted in a hundred board decks this quarter. Alongside them, the finding that is driving the AI-governance conversation: AI-driven attacks rose 56% year over year, and among organizations reporting a security incident involving an AI model or application, 92% were missing basic access controls — role-based access, multifactor authentication, and the like — on those models and applications.

The industry read that and started bracing for a wave of ungoverned machine identities.

02 · The turn

If you run SAP, that wave already hit.
Years ago.

The non-human identity problem is not arriving. It has been in production since your last go-live, and it has a name you already use every day.

Open any large SAP landscape and count the identities that are not a person logging in:

RFC connection users wiring system to system · Batch and background job users running the nightly load · Technical, service, and communication users behind every interface · Integration accounts for middleware, Ariba, SuccessFactors, Fiori, third-party tools

These are non-human identities in every sense that matters. They act. They hold authorizations. They move data at machine speed. And most were created for a go-live in 2018, granted broad access “to be safe,” and never reviewed since. Passwords that do not expire. Wide profiles nobody dares to trim. Owners who left the company in 2022.

Industry estimates put non-human identities at roughly 50 to 1 against human ones in large enterprises. Whatever your exact ratio, the governance question is identical — and in SAP it is not a forecast. It is an inventory you already own.

03 · The exposure

Three findings in this report land harder on SAP than on anything else in your estate.

Finding 01 · Detection

The clock went backwards.

Mean time to identify and contain rose to 247 days — reversing five consecutive years of improvement. Breaches running past the 200-day mark cost about a third more than those closed sooner.

SAP READA dormant technical user is precisely the kind of thing that keeps a breach quiet for 200+ days. Nothing alerts. Nothing looks anomalous. Machine-to-machine traffic is the baseline.
Finding 02 · Third parties

Supply chain compromise is the single most expensive aggravating factor.

Where a business partner becomes the attack path, IBM finds it adds more to the bill than any other factor measured — and those breaches take the longest to identify and contain.

SAP READIn SAP, the partner attack path is the interface account, the consultant ID, the middleware credential. You are not exposed to a supply chain abstraction. You are exposed to a specific user ID with a specific profile.
Finding 03 · Location

On-premises data now figures in the largest share of breaches by location.

And that share has grown two years running.

SAP READThat is the ECC and S/4 on-prem estate, and it is moving in the wrong direction while the attention goes elsewhere.
◆ Critical — highest-severity finding

The dormant RFC user with SAP_ALL is the whole report in one object. It is a non-human identity. It has no owner. Its credential does not expire. Its traffic is indistinguishable from normal operations. It is on-premises. And it is frequently the account a third party was given during a project that ended four years ago. Every aggravating factor IBM measured, converging on one line in USR02.

One more, for anyone still arguing this is a technology purchase rather than a governance program: IBM ranks identity and access management second among all cost-reducing factors measured, behind only a DevSecOps approach. The control that pays is the one your team already knows how to run.

04 · The answer

The cleanup is doable now — and it starts with a count.

You cannot govern what you have not inventoried. The first concrete, do-it-this-quarter step is simple to say and rarely done.

Produce a complete inventory of every non-dialog and technical user in your SAP systems — and for each one, answer four questions: who owns it, what can it do, when was it last used, and does its access still match its job?

That single scan surfaces the ungoverned population: the dormant RFC user with SAP_ALL, the interface account nobody claims, the technical ID whose owner left in 2022. It turns an abstract ratio into a named list you can act on — expire, scope down, or retire.

Four commitments, applied to the identities you already have.

Our SAP-native security practice has spent two decades on exactly this discipline. The four commitments we bring to AI agents apply one-for-one to the non-human identities already in your system.

01

Every identity is inventoried and owned

No anonymous RFC or technical user. Each one carries a named accountable owner who is still employed.

GOVERNED EYESan account with no owner is a finding, not a footnote.
02

Every credential has an expiry

The dormant-account door closed. Access that was granted for a project ends when the project does.

GOVERNED EYESnon-expiring is a deliberate, documented exception — never a default.
03

Every action has a record

Machine-speed activity you can actually audit — what the identity did, not only what it was permitted to do.

GOVERNED EYES“it was authorized” is never accepted as proof “it was appropriate.”
04

Every access still matches a job

Or it gets scoped down or retired. Entitlement is re-earned on a cycle, not inherited from a 2018 cutover.

GOVERNED EYESthe reviewer is never the person who provisioned it.
05 · The sequence

Do the count before you do the AI program.

There is a sequencing argument buried in this report, and it is the most useful thing in it.

Close to seven in ten breached organizations lack governance policies for managing AI or spotting unapproved use, and fewer than one in five coordinate their governance teams with their security teams at all. Meanwhile shadow AI — staff using unapproved tools — figured in 43% of security incidents, more than double the prior year's share.

The instinct is to answer that with a new AI governance program, a new platform, a new budget line.

The better move is to notice that the discipline you need already exists inside your SAP GRC practice — and that its first customer is the non-human population you already have. Inventory. Ownership. Expiry. Evidence. Prove the control plane works on the technical users sitting in production today, then extend it to agents as they arrive.

That order is cheaper, it is auditable now, and it does not depend on a technology you have not bought yet.

06 · This quarter

Let's take attendance.

Count your non-dialog users. Ask who governs them. If the honest answer is “no one, and not since go-live,” you have found your share of IBM's $11.5M — and it is cleanable now, without waiting for the AI-agent future to arrive.

The breach report is a bill for a workforce nobody onboarded. In SAP, that workforce has been on the payroll for years.

The identities existThe discipline existsThe count is the difference
Request a non-dialog user read

Source ledger — every figure, and where it came from

ClaimSourceYearStatus
Global average breach cost $4.99M, up 12%, record highIBM / Ponemon — Cost of a Data Breach2026VERIFIED
US average ≈ $11.5M, more than double globalIBM / Ponemon — Cost of a Data Breach2026VERIFIED
AI-driven attacks up 56% year over yearIBM / Ponemon — Cost of a Data Breach2026VERIFIED
92% of orgs with an AI-related incident lacked RBAC / MFA-class controls on AI models and appsIBM / Ponemon — Cost of a Data Breach2026VERIFIED
Mean time to identify and contain rose to 247 days — first rise in five yearsIBM / Ponemon — Cost of a Data Breach2026VERIFIED
Breaches past 200 days cost ~⅓ moreIBM / Ponemon — Cost of a Data Breach2026VERIFIED
Supply chain compromise adds more to breach cost than any other single factorIBM / Ponemon — Cost of a Data Breach2026VERIFIED
On-prem data in largest share of breaches by location, growing two yearsIBM / Ponemon — Cost of a Data Breach2026VERIFIED
IAM ranks second among cost-reducing factors, behind DevSecOpsIBM / Ponemon — Cost of a Data Breach2026VERIFIED
~7 in 10 breached orgs lack AI governance policies; <1 in 5 coordinate governance and securityIBM / Ponemon — Cost of a Data Breach2026VERIFIED
Shadow AI present in 43% of security incidents, more than double prior yearIBM / Ponemon — Cost of a Data Breach2026VERIFIED
Non-human to human identity ratio ~50:1 in enterprise environmentsIdentity Defined Security Alliance — not IBM2026RE-SOURCED

Sampling note. IBM and the Ponemon Institute studied roughly 602 organizations breached between March 2025 and February 2026. Figures describe organizations that suffered a breach — not all organizations. Cost figures exclude certain regulatory penalties. We publish this ledger because a governance argument that cannot show its own sources is just an opinion with a statistic attached. Every row carries its report year, because the single easiest way to get an annual benchmark wrong is to quote last year’s edition of it.