Raghu Boddu

Raghu Boddu

Principal SAP Security & GRC Architect | Founder

Raghu Boddu is a highly credentialed technology leader and cybersecurity expert with extensive experience in SAP Security, Governance, Risk and Compliance (GRC), and Enterprise Risk Management. He holds prestigious global certifications (including CISA, CFE, CAMS, PMP, and CCISO) and is the author of standard reference books on SAP Access Control, SAP Process Control, and SAP Identity Access Governance (IAG).

LinkedIn Profile → Personal Site →

Articles Published by Raghu

SAP Report SUPRN_REGENERATE_DEPENDENT - Automatically Adjust Derived Roles in PFCG

Published Mar 8, 2026 in sap-s4hana-security

Many SAP administrators update a master role and then spend unnecessary time manually adjusting dozens of derived roles in PFCG. What many don’t realize is that SAP already provides a report that can automate this process - SUPRN_REGENERATE_DEPENDENT.

SAP IAG vs SAP GRC Access Control: Which Governance Model Works Best?

Published Mar 8, 2026 in sap-iag

As SAP landscapes evolve toward cloud and hybrid architectures, many organizations are asking whether SAP Identity Access Governance (IAG) can replace SAP GRC Access Control, or whether both solutions still play a role in modern governance models. This article explores how SAP IAG and SAP GRC Access Control fit into modern SAP security architectures.

Before You Buy an SAP SoD Analyzer: 5 Capabilities That Actually Matter

Published Mar 1, 2026 in expert-recommendations

Evaluating an SAP SoD Analyzer solution? Detection alone does not reduce exposure. Learn the five governance and execution-based capabilities that separate rule-driven scanning from contextual risk intelligence in complex SAP environments.

The Invisible Layer: Why Metadata Is the Next Blind Spot in Enterprise Data Privacy

Published Feb 26, 2026 in sap-cybersecurity

Enterprises have spent the last decade securing what they can see, encrypting databases, masking sensitive fields, tightening access controls, and demonstrating compliance with frameworks like GDPR, California Consumer Privacy Act (CCPA), among others. Yet, beneath these visible controls lies a quieter, far more pervasive layer of risk: metadata.

ThreatSense AI Data Security (TADS) Review - Redefining XDR for SAP and Beyond

Published Feb 5, 2026 in product-reviews

In today’s world of sophisticated cyber threats, securing SAP systems is no longer an add?on, it’s the frontline of enterprise defense. ThreatSense AI Data Security (TADS) breaks new ground.

Regained SAP Security Expert!

Published Feb 1, 2026 in sap-access-control

After a long and unexpected hiatus, SAP Security Expert is finally back home.

S/4HANA Public Cloud vs. Private Cloud: A Security-Centric Perspective

Published Feb 1, 2026 in sap-public-cloud

SAP’s cloud strategy is no longer aspirational—it is directive.

The Magician, the Machine, and SAP Cybersecurity

Published Jan 30, 2026 in podcasts

In this post, we are featuring an insightful podcast episode from the CyberKriya Podcast.

What Actually Optimizes SAP Licenses: STAR, USMM, LAW/SLAW Explained

Published Jan 29, 2026 in sap-licensing

SAP license compliance is not driven by a single report or transaction. It is the outcome of multiple SAP-delivered mechanisms.

SAP Cybersecurity Insights from the Authors of Cybersecurity for SAP book by SAP Press

Published Jan 28, 2026 in podcasts

Sharing Episode 2 of the Cyber Kriya Podcast, featuring Juan Perez-Etchegoyen (JP) and Gaurav Singh.

Configuration Without SPRO: The New Audit Reality of SAP Public Cloud

Published Jan 27, 2026 in sap-public-cloud

For decades, SAP security and audit teams anchored configuration oversight around SPRO.

CPC vs. SPRO: A Security-Centric View of SAP Configuration

Published Jan 27, 2026 in sap-public-cloud

For a long time, SAP teams have relied on SPRO as the primary entry point for understanding configuration.

Why Traditional SAP Audit Controls Fail in Public Cloud

Published Jan 25, 2026 in sap-public-cloud

Traditional SAP audits were designed for a world where customers owned the system end to end. Auditors validated controls by inspecting configuration screens, reviewing system logs, tracing changes, and confirming that powerful technical access was tightly restricted. Visibility equalled assurance, and depth of access was synonymous with risk.

SAP Licensing Optimization: Why "License Saver" Tools Often Create False Savings

Published Jan 22, 2026 in sap-licensing

SAP license optimization has evolved from a procurement exercise into a strategic governance concern.

GRC Compliance Management in SAP: Powering Enterprise-Wide Governance, Risk, and Compliance

Published Jan 21, 2026 in sap-access-control

GRC Compliance Management has become a strategic requirement for enterprises operating complex SAP landscapes.

Mastering SAP GRC Ruleset Manager: A Complete Overview

Published Jan 17, 2026 in sap-access-control

Managing access risk effectively is one of the toughest challenges in Governance, Risk, and Compliance (GRC) frameworks.

Integrating Okta with SAP IAS/IPS by Raghu Boddu: Step-by-Step IAM Best Practices

Published Jan 17, 2026 in sap-btp-security

The complexities of modern enterprise identity and access management (IAM) demand scalable, secure integrations.