Securing SAP from the Inside Out: OS-Level Security for IT Leaders
SUSE, Friday, September 25th, 2026
SUSE argues SAP security must extend to the Linux OS layer using SELinux mandatory access control, deployed in phases.
SUSE argues that traditional SAP security spends most of its budget on application-layer controls while the underlying Linux operating system remains a critical, often overlooked attack surface.
Since SAP HANA and S/4HANA rely directly on Linux for processes, memory and network traffic, a compromised OS process can enable lateral movement.
Mandatory Access Control via SELinux tightens this by confining processes to only the resources they need, limiting the blast radius of a compromise and mitigating zero-day exploitation.
To avoid unplanned downtime, SUSE recommends a phased rollout starting in permissive mode, where SELinux logs policy violations without blocking operations.