Generated by All in One SEO v5.0.1.1, this is an llms.txt file, used by LLMs to index the site. # Hexadius ## Sitemaps - [XML Sitemap](https://www.hexadius.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [File Upload Vulnerabilities](https://www.hexadius.com/file-upload-vulnerabilities/) - File uploads are a common feature in web applications, but if not handled correctly, they can become a serious security risk. Attackers can exploit weak upload mechanisms to execute malicious code, compromise data, or even take control of a server. - [Why AMS Isn't Securing Your SAP?](https://www.hexadius.com/why-your-ams-isnt-securing-your-sap/) - Organizations that manage SAP security effectively have separated operations and security clearly. And AMS is often not equipped to handle this. - [SAP AMS Provider vs. Specialized SAP Security Services Provider: What's better for an organization?](https://www.hexadius.com/sap-ams-provider-vs-specialized-sap-security-services-provider-whats-better-for-an-organization/) - A specialized SAP Managed Security Services provider helps complement the SAP AMS model and address SAP security gap. - [Best Practices for Large‑Scale System Onboarding into IGA Solution](https://www.hexadius.com/best-practices-for-large-scale-system-onboarding-into-iga-solution/) - Onboarding hundreds of systems into IGA can unlock huge automation, compliance, and security benefits — but only with the right strategy and governance. This blog provides on best practices for large scale system onboarding. - [How System Onboarding Drives Stronger ROI for your IGA Deployment?](https://www.hexadius.com/how-system-onboarding-drives-stronger-roi-for-your-iga-deployment/) - More systems you onboard into IGA solution, the more value you unlock across security, compliance, automation, and operational efficiency. - [SailPoint Support & Enhancement Services](https://www.hexadius.com/sailpoint-support-enhancement-services/) - Implementing SailPoint is just the beginning. Hexadius can help you unlock the value of your investment with tailored and flexible maintenance and support services customized for SailPoint IIQ and ISC solutions. - [Why Organizations Should Outsource SAP Security Management to a Specialized SAP Security Provider](https://www.hexadius.com/why-organizations-should-outsource-sap-security-management-to-a-specialized-sap-security-provider/) - Outsourcing SAP Security to a specialized service provider is a competitive advantage. isn’t just about cost savings—it’s about strengthening resilience, reducing risk, and ensuring your SAP landscape stays secure, compliant, and future‑ready. - [Why Managing Non‑Employees Is Critical in IGA — and How SailPoint’s Non‑Employee Risk Management Transforms the Game](https://www.hexadius.com/why-managing-non-employees-is-critical-in-iga-and-how-sailpoints-non-employee-risk-management-transforms-the-game/) - In many organizations, contractors, vendors, partners, and temporary staff make up a significant portion of the workforce. Yet their access is still too often managed through emails, spreadsheets, and manual processes. That’s a major security blind spot. - [How to Leverage Flowcharts for effective Requirements Document?](https://www.hexadius.com/how-to-leverage-flowcharts-for-effective-requirements-document/) - In the world of identity and access management (IAM), flowcharts often seem like a mundane task reserved for documentation. Yet, their value goes far beyond aesthetics or formality. Flowcharts serve as a powerful visual tool that bridges the gap between technical teams and non-technical stakeholders, offering clarity where words alone may fall short. - [Rethinking Identity Governance: The Power of Native Change Detection in SailPoint ISC](https://www.hexadius.com/rethinking-identity-governance-the-power-of-native-change-detection-in-sailpoint-isc/) - SailPoint Native Change Detection (‘NCD’) offers a smarter way to monitor and remediate out-of-band access changes that could otherwise fly under the radar. - [Managing Non-Employee Access: Risks, Challenges & How SailPoint Helps](https://www.hexadius.com/managing-non-employee-access-risks-challenges-how-sailpoint-helps/) - Managing non-employee access has unique challenges. SailPoint NERM solution provides tailored solutions to manage non-employee risks. - [Supporting SailPoint IGA Customers Beyond Go-Live: Enhancing ROI Through Ongoing Support & Maintenance](https://www.hexadius.com/supporting-sailpoint-iga-customers-beyond-go-live-enhancing-roi-through-ongoing-support-maintenance/) - Implementing SailPoint IGA solution is a major step in strengthening enterprise identity and access management — but success doesn’t stop at go-live. In fact, the real value is realized through continuous optimization, adaptability, and support. - [SAP Role Redesign and S/4 HANA Transformation](https://www.hexadius.com/sap-role-redesign-and-s-4-hana-transformation/) - One of the questions, which often comes up during SAP S/4 HANA transformation planning is whether the SAP role redesign should be performed before, or during the transformation. This blog from Hexadius aims to provide some insights to help you decide. - [‘Segmentation’ in SailPoint Identity Security Cloud](https://www.hexadius.com/segmentation-in-sailpoint-identity-security-cloud/) - Segmentation, a standard feature in ISC, offers numerous advantages beyond security, including increased efficiency, better user experience, reduced errors, better resource allocation, and improved scalability. - [SAP S/4 Security and License Optimization – How Are They Interrelated?](https://www.hexadius.com/sap-s-4-security-and-license-optimization-how-are-they-interrelated/) - Compliant user access in SAP S/4 HANA goes beyond security & compliance and assists in optimizing license costs also. - [Managed Services: A Strategic Solution for Modern Organizations](https://www.hexadius.com/managed-services-a-strategic-solution-for-modern-organizations/) - Managed services offer a comprehensive solution for organizations looking to optimize their IT operations, reduce costs, and enhance security. - [Modernizing Identity Security with Microsoft Entra ID](https://www.hexadius.com/modernizing-identity-security-with-microsoft-entra-id/) - Microsoft Entra ID (formerly Azure Active Directory or Azure AD) is a cloud-based Identity and Access Management (‘IAM’) service. It helps organizations manage user identities, control access to resources (such as apps, data, and devices), and provides secure access to applications and services both on-premises and in the cloud. - [Conditional Access Policies with Microsoft Entra ID](https://www.hexadius.com/conditional-access-policies-with-microsoft-entra-id/) - Microsoft Entra Conditional Access plays a crucial role in achieving a balance between security and accessibility by enforcing context-aware access policies based on identity signals, device health, and risk insights. - [Is your Web App using Weak Cipher Suites?](https://www.hexadius.com/is-your-web-app-using-weak-cipher-suites/) - Weak cipher suites can leave systems vulnerable to attacks, potentially exposing sensitive data. This blog post will explore what weak cipher suites are, why they are risky, and provide an example of how attackers exploit them. - [The Rise of Broken Access Controls](https://www.hexadius.com/the-rise-of-broken-access-controls/) - Recent surveys have found that 94% of applications tested have some form of access control weakness (OWASP, 2021). Often overlooked, this vulnerability poses a serious risk to web application security. - [Implementing Attribute-Based Access Control (‘ABAC’) using SailPoint Dynamic Roles](https://www.hexadius.com/implementing-attribute-based-access-control-abac-using-sailpoint-dynamic-roles/) - SailPoint's Dynamic Role feature provides an excellent mechanism to implement ABAC, which is an efficient and effective concept for granular access controls. - [Designing an IAM System](https://www.hexadius.com/designing-an-iam-system/) - A clearly defined IAM design helps keep the organization's information safe and make sure only the right people can access it. It is crucial to ensure an appropriate design for the IAM system before starting the deployment program. Skipping or rushing the design phase can lead to security gaps, operational inefficiencies, compliance issues, and costly rework. - [Why VAPT is Essential for Your Organization's Security](https://www.hexadius.com/blog/why-vapt-is-essential-for-your-organizations-security/) - Discover why VAPT (Vulnerability Assessment and Penetration Testing) is essential for safeguarding your organization’s security and protecting critical data. - [Laying the foundation for a successful IAM program – setting the expectations!](https://www.hexadius.com/blog/essentials-for-a-successful-iam-program/) - Identity and Access Management (‘IAM’) is becoming an increasingly important part of digital transformation. With remote working (or hybrid) becoming a norm, people work from outside their usual office network, accessing organizational resources as remote workers. - [The Dos and Don’ts of a successful testing in IAM projects](https://www.hexadius.com/the-dos-and-donts-of-a-successful-testing-in-iam-projects/) - A good testing ensures a successful project. IAM project with large number of stakeholders and system integrations requires a very comprehensive and focused training. - [Mass Assignment Vulnerability](https://www.hexadius.com/mass-assignment-vulnerability/) - This blog discusses Mass assignment vulnerability that occurs when an application automatically maps user-supplied input to internal object fields without proper restrictions. - [Managing Service Accounts in SailPoint IdentityIQ](https://www.hexadius.com/managing-service-accounts-in-sailpoint-identityiq/) - IIQ allows organizations manage service account in a compliant and secure manner. This blogs details how this can be achieved. - [How to perform Access Certification Effectively and Efficiently?](https://www.hexadius.com/how-to-perform-access-certification-effectively-and-efficiently/) - Access certification is an essential part of the governance and compliance framework. However, this is also a very time consuming and often not effective. This blog explores the reasons and shares some good practices. - [Hexadius and SecurityBridge Partner to Strengthen SAP Cybersecurity Across APAC](https://www.hexadius.com/hexadius-and-securitybridge-partner-to-strengthen-sap-cybersecurity-across-apac/) - Hexadius expands its SAP security offering with SecurityBridge’s advanced cybersecurity solutions, providing full-spectrum protection for enterprises in the region. - [Prototype Pollution Vulnerability (Part 2)](https://www.hexadius.com/prototype-pollution-vulnerability-part-2/) - JavaScript is built around Prototypes, which are like blueprints for objects. Prototype Pollution vulnerabilities can be misused to mess with the prototype and affect every object that uses that blueprint. Attacks can inject fake properties into the prototype, making the app behave in unexpected or dangerous ways. - [Prototype Pollution Vulnerability (Part 1)](https://www.hexadius.com/prototype-pollution-vulnerability-part-1/) - JavaScript is built around Prototypes, which are like blueprints for objects. Prototype Pollution vulnerabilities can be misused to mess with the prototype and affect every object that uses that blueprint. Attacks can inject fake properties into the prototype, making the app behave in unexpected or dangerous ways. - [How to manage identities and access in SAP?](https://www.hexadius.com/how-to-manage-identities-and-access-in-sap/) - Explore the key differences between SAP IdM & Cloud Identity Services and understand how to manage upcoming depreciation of IdM. We also explain how SAP Cloud Identity Services integrates with third party IAM solutions like SailPoint. - [Planning SAP Onboarding into SailPoint ](https://www.hexadius.com/blog/planning-sap-onboarding-into-sailpoint/) - Just like any IT project, a good plan goes a long way in ensuring a smooth and timely system onboarding. Before starting the onboarding itself, it is important to understand the overall SAP landscape of the organization. The SailPoint engineers should coordinate with SAP technical team to understand the landscape before starting any onboarding activities. - [11 things CISOs still need to know about SAP ‘cyber’ security](https://www.hexadius.com/blog/things-cisos-must-know-about-sap-cyber-security/) - As the IT landscape gets more complex, the job of a Chief Information Security Officer (‘CISO’) is getting more and more complex. CISOs need to keep track of a constant wave of new technologies and how to secure them. - [What comes first – SAP SoD remediation or SAP Role Redesign?](https://www.hexadius.com/blog/sap-sod-remediation-or-sap-role-redesign/) - Hexadius has been involved in multiple SAP Segregation of Duties (‘SoD’) remediation projects. These projects tend to be complex due to the special authorization structure in SAP. Many of these remediation projects encounter issues related to the SAP role design. A bad role design often makes it difficult to remove SoD risk violations. - [Extending identity security journey to SAP systems](https://www.hexadius.com/blog/extending-identity-security-journey-to-sap-systems/) - SAP is one of the most commonly used enterprise systems. And SailPoint is one of the most popular Identity Governance and Administration (‘IGA’) systems. Both are leaders in their respective domains and therefore, many large organizations are using both these systems. - [Pros and Cons of undertaking SoD remediation before or as part of SAP S/4HANA transformation](https://www.hexadius.com/pros-and-cons-of-undertaking-sod-remediation-before-or-as-part-of-sap-s-4hana-transformation/) - As companies move from SAP ECC to SAP S/4HANA, integrating SoD into the project plan can enhance security and compliance. However, deciding whether to begin the SoD initiative before or during the migration can significantly impact the project's success. This blog highlights some of pros and cons of both approaches. - [Business case for including SAP in SOC](https://www.hexadius.com/business-case-for-including-sap-in-soc/) - Monitoring SAP as part of SOC operations is essential for maintaining a robust security posture. It not only protects critical business assets but also ensures compliance and operational continuity. - [Best practices for SAP SoD management using SailPoint](https://www.hexadius.com/best-practices-for-sap-sod-management-using-sailpoint/) - Hexadius shares the best practices for managing unique requirements related to SoD in SAP using SailPoint. - [Clearing the confusion, let’s understand IAM](https://www.hexadius.com/blog/understanding-iam/) - Before we get into understanding the IAM world, let’s first understand the first key aspect of IAM. Any organization will have broadly two types of users – internal and external. - [The IAM trifecta](https://www.hexadius.com/blog/the-iam-trifecta/) - When we talk about IAM, it is mostly in the context of cybersecurity and zero-trust. Most of the IAM initiatives are also driven by the cybersecurity team. - [Onboarding SuccessFactors as an Authoritative Source](https://www.hexadius.com/blog/onboarding-successfactors-as-an-authoritative-source/) - Learn how to implement onboarding SuccessFactors as an authoritative source for trusted business insights. - [SailPoint deployment with SAP GRC/ Access Control](https://www.hexadius.com/blog/sailpoint-deployment-with-sap-grc/) - Simplify your SailPoint deployment with SAP GRC. Discover best practices, integration tips, and expert insights to enhance your IAM. - [My reflections on SailPoint Navigate events over the years](https://www.hexadius.com/blog/my-reflections-on-sailpoint-navigate-events-over-the-years/) - Reflecting on key moments and insights gained from SailPoint Navigate events over the years. - [Blind SQL Injection (CVE-2023-4188)](https://www.hexadius.com/blog/blind-sql-injection-cve-2023-4188/) - CVE-2023-4188 details a critical Blind SQL Injection vulnerability. Learn what it is, how it works, and how to secure your systems. - [Reflected XSS (CVE-2023-4189)](https://www.hexadius.com/reflected-xss-cve-2023-4189/) - Reflected XSS refers to when application receives input in such a way that it is rendered in an unsafe manner - processed by server then passed to the victim. ## Pages - [Home](https://www.hexadius.com/) - Cybersecurity service provider, IAM, SAP Security, VAPT, CSRO, CREST and GRC. - [SAP Cybersecurity – Zero Trust in SAP ERP - Continuous Assurance for a Connected Enterprise](https://www.hexadius.com/sap-cybersecurity-zero-trust-in-sap-erp-continuous-assurance-for-a-connected-enterprise/) - Zero Trust in SAP ERP - Continuous Assurance for a Connected Enterprise Format: Webinar Register HERE. About the Event As SAP environments evolve into hybrid, cloud-first ecosystems, traditional security models based on implicit trust are no longer enough. Join Hexadius Consulting and SecurityBridge for an insightful webinar exploring how organizations can adopt a Zero Trust - [SAP Cybersecurity – Why Legacy Security Models Fail and What Modern SAP Enterprises Need?](https://www.hexadius.com/sap-cybersecurity-why-legacy-security-models-fail-and-what-modern-sap-enterprises-need/) - Why Legacy Security Models Fail and What Modern SAP Enterprises Need? Format: Webinar Register HERE. About the Event SAP environments are more complex than ever - and the way most organizations secure them simply hasn't kept up. Threats have changed, landscapes have shifted, and the old approach of periodic reviews, static role assignments, and manual - [Events](https://www.hexadius.com/events/) - Events Upcoming IDENTICA 2025 "Exploring the AI-Powered Future of Identity & Security" – 6th December 2025 | The Grand Magrath Hotel, MG Road, Bengaluru, India (Gold Sponsor) Read more Upcoming KauSAP CIO Partner Exchange with Hexadius "Security by Design: How to Maximize and Secure Your SAP Transformation Investment" – 20th November 2025 Ascott Hotel, BGC - [About Us](https://www.hexadius.com/about-us/) - About us Established in 2009 in Singapore, Hexadius is a boutique professional services organization focused on assisting our clients navigate the cybersecurity risks and threats without impeding its business objectives and growth. Hexadius partner with our clients to understand their unique challenges & objectives design solutions and identify best technology to effectively manage cybersecurity implement - [SAP Access Control Workshop - 2025](https://www.hexadius.com/sap-access-control-workshop-2025/) - SAP Access Control Workshop 2025 Format: Instructor-Led Classroom Training Singapore SAP authorization is complex, and it is becoming even more complicated as organizations move from traditional on-prem implementation to a hybrid implementation consisting of on-prem and cloud-based SAP systems. This one-day SAP Access Control workshop will help you understand the SAP authorization concept and how - [Blog](https://www.hexadius.com/blog/) - Blog Stay Informed Receive our latest blogs directly in your inbox Read more Previous 1 2 … 10 Next - [Managing Segregation of Duties (‘SoD’) in SAP – Training Workshop](https://www.hexadius.com/managing-segregation-of-duties-sod-in-sap-training-workshop-2/) - Managing Segregation of Duties (‘SoD’) in SAP – Training Workshop Format: Instructor Led Classroom Training Manila, Philippines SAP ERP (whether ECC 6.0 or SAP S/4 HANA) is often the crown jewel application and needs to be closely guarded against frauds and unauthorized transactions. That’s why Segregation of Duties (‘SoD’) is an important component of SAP - [Careers](https://www.hexadius.com/careers/) - Join us in redefining the way to deliver cybersecurity professional services SEE OPEN POSITIONS Our culture Hexadius is dedicated to executing successful cybersecurity projects that deliver great value to our clients and exceed their expectations. We take on some of the most complex cybersecurity projects in Identity & Access Management (IAM), SAP Security & GRC, - [Maximizing and Securing Your SAP Transformation Investment](https://www.hexadius.com/maximizing-and-securing-your-sap-transformation-investment/) - Maximizing and Securing Your SAP Transformation Investment Format: In-person Chennai, India About the Event Your SAP systems run the core of your business — but are they truly secure? SAP transformation involves transitioning from legacy SAP ECC system to modern SAP S/4HANA, often incorporating cloud adoption, process redesign, and digital integration. It’s a business-led, technology-enabled - [SailPoint and SAP](https://www.hexadius.com/sailpoint-and-sap/) - SailPoint and SAP Securely Govern Access and Optimize Operations SCHEDULE A CONSULTATION Hexadius has extensive expertise in deployment of SailPoint IGA solutions (IDN and IIQ), SailPoint ARM (which is module for managing the identity and access risks specifically for organizations using SAP ERP systems), & SAP GRC Access Control; as well as SAP security consulting - [IAM Survey - 2025](https://www.hexadius.com/iam-survey-2025/) - Hexadius IAM survey will provide valuable insights into how businesses are managing user access, implementing authentication methods, and addressing governance & compliance requirements. - [Vulnerability Assessment and Penetration Testing (‘VAPT’)](https://www.hexadius.com/vulnerability-assessment-and-penetration-testing/) - Learn about Vulnerability Assessment and Penetration Testing from Singapore's top cybersecurity services company - [Identity and Access Management](https://www.hexadius.com/identity-and-access-management/) - Learn about identity and access management solutions from Singapore's top cybersecurity services company - [MASTERING SAP Collaborate Singapore 2025](https://www.hexadius.com/mastering-sap-collaborate-singapore-2025/) - MASTERING SAP Collaborate Silver Sponsor - Hexadius Format: In-person | 8 - 9 May, 2025 Singapore The independent event for SAP end users, by SAP end users! Mastering SAP Collaborate supports the SAP community across South East Asia with peer-to-peer learning and expert insights in technology, cloud, security, financials, data and analytics. Be part of - [SailPoint IDENTITY DAY BENGALURU 2025](https://www.hexadius.com/sailpoint-identity-day-bengaluru-2025/) - SailPoint Identity Day Bengaluru 2025 Sponsored by Hexadius Format: In-person | April 24, 2025 Bengaluru, India Identity Security, Innovation Realised In today’s digital world, identity security is key to both protection and progress. It builds trust, fuels business growth, and redefines how organizations interact with customers. A recent survey found that 83% of companies have - [SAP cyber resilience – what and how?](https://www.hexadius.com/sap-cyber-resilience-what-and-how/) - SAP Cyber Resilience – What and How? Format: In-person Singapore About the Event SAP security landscape is changing fast. SAP systems are a crucial part of business IT systems, and store sensitive and valuable data such as financial, HR, and customer information. This makes them a target for cyber attackers who aim to steal, manipulate - [SailPoint and SAP](https://www.hexadius.com/sailpoint-and-sap-2/) - SailPoint and SAP Securely Govern Access and Optimize Operations SCHEDULE A CONSULTATION Hexadius has extensive expertise in deployment of SailPoint IGA solutions (IDN and IIQ), SailPoint ARM (which is module for managing the identity and access risks specifically for organizations using SAP ERP systems), & SAP GRC Access Control; as well as SAP security consulting - [SailPoint IDENTITY DAY PHILIPPINES 2025](https://www.hexadius.com/sailpoint-identity-day-philippines-2025-hexadius-sponsor/) - SailPoint Identity Day Philippines 2025 Sponsored by Hexadius Format: In-person | February 12, 2025 Manila, Philippines Our Digital Identities Are Under Attack Now More Than Ever Before In a world where 90% of organizations have faced identity-related security incidents in the past year, robust identity security is not just a shield against threats; it’s a - [Why IAM must be part of your cybersecurity arsenal and how to use it effectively?](https://www.hexadius.com/iam-cybersecurity-event-singapore/) - Why IAM must be part of your cybersecurity arsenal and how to use it effectively? Format: In-person Singapore About the Event Cybersecurity landscape is changing fast and the threats and vulnerabilities keep evolving. However, people (or Identities) continue to be at the heart and therefore, identity security should be a key tool in your cybersecurity - [Contact Us](https://www.hexadius.com/contact-us/) - Get in Touch Email contact@hexadius.com Phone +65 6022 1670 Hexadius Consulting Pte. Ltd. (UEN: 200919801D)f.k.a. Turnkey Consulting (Singapore) Pte. Ltd.60 Paya Lebar Road, #11-30, Singapore 409051 India: Icon Tower Office No. 702, Sr No.114/5 115/1 114/6/3, Baner Gaon, Haveli, Pune- 411045, Maharashtra Philippines: AIA Tower, 9th Floor, 8767 Paseo De Roxas, Salcedo Village Bel-Air, City - [Partners](https://www.hexadius.com/partners/) - Our Trusted Cybersecurity Partners Collaboration that delivers excellence! SCHEDULE A CONSULTATION SailPoint Hexadius is a SailPoint ‘Delivery Admiral’ partner in APAC region. SailPoint’s Delivery Admiral designation is awarded to partners committed to delivery excellence, undergoing significant testing and training around SailPoint technology. Partners are measured on certified resources, implementation experience, and overall partner health. Hexadius - [SailPoint Navigate Singapore 2024](https://www.hexadius.com/sailpoint-navigate-singapore-2024/) - Discover expert-led sessions and workshops at SailPoint Navigate Singapore 2024, focusing on the future of cybersecurity. - [SAP GRC and Cybersecurity](https://www.hexadius.com/sap-grc-and-cybersecurity/) - SAP GRC and Cybersecurity Secure SAP Solutions and Optimize Controls SCHEDULE A CONSULTATION Organizations using SAP solutions face unique challenges in managing security and controls. SAP solutions include traditional SAP solutions such as SAP ECC 6.0, SAP S/4 HANA, as well as SaaS solutions such as SuccessFactors, Ariba, BTP, Concur, etc. SAP also has its - [Managing Segregation of Duties (‘SoD’) in SAP – Training Workshop](https://www.hexadius.com/events/sap-sod-training-workshop/) - Join our SAP SoD Training Workshop to learn effective management of Segregation of Duties and ensure compliance with best practices. - [Case Study](https://www.hexadius.com/case-study/) - Case Study Read more - [Resources](https://www.hexadius.com/resources/) - Cybersecurity Resources Blog Case Study Read more See more Read more See more - [Governance, Risk and Compliance](https://www.hexadius.com/governance-risk-and-compliance/) - Governance, Risk and Compliance (‘GRC’) Drive Operational Resilience SCHEDULE A CONSULTATION Our GRC services help our clients manage the challenges related to IT governance, enterprise risk management, and effective compliance with various legal/ statutory requirements. We help our clients with Information Security Risk Assessment, Information Security Policies & Procedures, ISO27001 Advisory, Information Security Awareness Programs, - [Services](https://www.hexadius.com/services/) - Our Services Identity & Access Management ('IAM') Expert assessments and advisory Seamless system integration Continuous maintenance and support Comprehensive training programs LEARN MORE SAP GRC and Cybersecurity Security assessments Process redesign Integration of robust security measures Ongoing support and training LEARN MORE Vulnerability Assessment and Penetration Testing ('VAPT') Application and infrastructure VAPT SAP cybersecurity assessments - [SAP Access Control Workshop](https://www.hexadius.com/events/sap-access-control-workshop/) - SAP Access Control Workshop Format: Instructor Led Classroom Training Singapore SAP authorization is complex and it is becoming even more complex as organisations move from traditional on-prem implementation to a hybrid implementation consisting of on-prem and cloud-based SAP systems. This one-day SAP Access Control workshop will help you understand SAP authorization concept and how to - [SAP and SailPoint](https://www.hexadius.com/sap-and-sailpoint/) - SAP and SailPoint Hexadius has extensive SAP security and GRC expertise. We have integrated SailPoint with SAP HCM, SAP ECC, SAP S/4 HANA, SAP Fiori, SAP Enterprise Portal, and SAP SuccessFactors apart from other solutions such as Ariba. SAP has unique challenges related to access controls as well as Segregation of Duties (‘SoD’) requirements and - [Privacy Policy](https://www.hexadius.com/privacy-policy/) - Privacy Policy This policy outlines the responsibility of Hexadius Consulting Pte. Ltd. (Hexadius) in relation to the collection, processing, usage and disclosure of your Personal Data (as defined below). This is designed to protect the confidentiality of the Personal Data and regulate the way it is managed. This policy supplements but does not in any - [Terms of Use](https://www.hexadius.com/terms-of-use/) - Terms of Use Acceptance of Terms Hexadius Consulting Pte. Ltd. (‘Hexadius’) services are subject to the following Terms of Use (‘ToU’). Hexadius reserves the right to update the ToU at any time without giving notice to you. The most current version of the ToU can be reviewed by clicking on the ‘Terms of Use’ link ## Case Study - [Multinational Real Estate Organization](https://www.hexadius.com/case-study/large-property-company/) - Our client is a Singaporean multinational real estate operating organization. The organization was evaluating Identity Governance & Administration (‘IGA’) solutions to support its User Access Management (‘UAM’) control activities for its users. - [Regional Semiconductor Company ](https://www.hexadius.com/case-study/regional-semiconductor-company/) - Our client is headquartered in Singapore, with production facilities located in ASEAN and China. The client did not have a Segregation of Duties (‘SoD’) framework, which resulted in large number of SoD risk violations. - [Leading Logistics company with Global presence](https://www.hexadius.com/case-study/leading-logistics-company-with-global-presence/) - Our client is a leading logistics company with worldwide presence. Hexadius was engaged to assist the company with deployment of SailPoint IdentityIQ (‘IIQ’) Identity Governance & Administration (‘IGA’) solution - [A Fintech Company headquartered in Singapore](https://www.hexadius.com/case-study/a-fintech-company-headquartered-in-singapore/) - Our client is a fintech company headquartered in Singapore. The company was looking to deploy an Identity Governance & Administration (‘IGA’) solution to enhance its cybersecurity as well as ensure compliance with various regulatory requirements including MAS. - [Large Utility Company in Singapore](https://www.hexadius.com/case-study/large-utility-company-in-singapore/) - The Company was using multiple independent SAP instances and wanted to implement SAP GRC Access Control on 2 (two0 instances (SAP Customer Relationship Management (‘CRM’) and SAP Industry Solutions: Utilities (‘IS/U’)). - [Property Company in Singapore](https://www.hexadius.com/case-study/property-company-in-singapore/) - Our client multi-national businesses across asset classes such as residential, hospitality, retail, commercial, and logistics and industrial properties. - [Government Agency in Singapore](https://www.hexadius.com/case-study/government-agency-in-singapore/) - Our client is a statutory board in Singapore. The client used SAP ECC 6.0 ERP system along with SAP Enterprise Portal, BW and Fiori systems. It used a custom developed tool for user access provisioning in SAP ERP and Portal systems. The tool also supported basic Segregation of Duties (‘SoD’) analysis. However, the solution was not sufficient to support the increasingly complex SAP landscape. Also, the SoD analysis was not accurate due to system limitations. ## Careers - [Sales and Marketing Executive](https://www.hexadius.com/careers/sales-and-marketing-executive/) - Hexadius is looking for a graduate with minimum 2-3 years of relevant work experience. Relevant experience may come from working with a consultancy, software vendor or B2B software/ consulting sales environment. Experience in selling or marketing cybersecurity services/ products would be an advantage. - [Sales Manager/ Business Development Manager](https://www.hexadius.com/careers/sales-manager-business-development-manager/) - As an Account Executive specializing in Cyber Security in particular Identity and Access Management (IAM), you will be responsible for driving sales and developing strategic partnerships to promote our organisation's IAM solutions. - [Cyber Security Analyst/ Consultant](https://www.hexadius.com/careers/cyber-security-analyst-consultant/) - We are looking for an individual who is a self-motivated learner, has a passion to discover security vulnerabilities and is committed to making a meaningful contribution to Hexadius. While a Technical or Information Security background would be advantageous, intellectual curiosity and a can-do attitude is more important than the subject of your degree. - [IAM Analyst/ Consultant](https://www.hexadius.com/careers/iam-analyst-consultant/) - We are looking for an Identity and Access Management (‘IAM’) consultant to help service our client base. Ideal candidate will have a good knowledge of identity and access management solutions including the following areas: - [IAM Senior Consultant/ Architect](https://www.hexadius.com/careers/iam-senior-consultant-architect/) - We are looking for an Identity and Access Management (‘IAM’) senior consultant/ architect to help service our client base. Ideal candidate will have a good knowledge of identity and access management solutions including the following areas: Identity and Access Governance (‘IAG’) Identity Governance and Administration (‘IGA’) Single Sign-On (‘SSO’) Multi-Factor Authentication (‘MFA’) Password less Authentication - [IAM Business Analyst](https://www.hexadius.com/careers/iam-business-analyst/) - Hexadius is looking for someone with minimum 5 (five) years of relevant work experience. Relevant experience may come from working with a consultancy or end user organization. - [Project Manager](https://www.hexadius.com/careers/project-manager/) - Hexadius is looking for someone with minimum 5 (five) years of relevant work experience. Relevant experience may come from working with a consultancy or end user organization. - [SAP Security/ GRC Consultant](https://www.hexadius.com/careers/sap-security-grc-consultant/) - Hexadius is looking for SAP security and GRC consultant to help service our client base. Ideal candidate will have a good knowledge of identity and access management solutions including the following areas: ## Timeline Stories - [Inaugurates Malaysia Office (Mar 25)](https://www.hexadius.com/cool_timeline/inaugurates-malaysia-office/) - "Start of Malaysia office" 2025 - [SailPoint APAC POTY award (Feb 25)](https://www.hexadius.com/cool_timeline/sailpoint-poty-feb-25/) - SailPoint APAC Partner of the Year Award 2025 - [CREST-accreditation for Penetration Testing services (Jan 25)](https://www.hexadius.com/cool_timeline/crest-penetration-testing/) - CREST- Accreditation for Penetration Testing services 2025 - [2025: First Sailpoint NERM deployment in the region](https://www.hexadius.com/cool_timeline/2025-first-sailpoint-nerm-deployment-in-the-region/) - First Sailpoint NERM deployment in the region 2025 - [2024: ISO27001:2022 Certification](https://www.hexadius.com/cool_timeline/2024-iso270012022-certification/) - ISO27001:2022 Certification 2024 - [2023: Obtained CSRO Penetration Testing Service License](https://www.hexadius.com/cool_timeline/2023-obtained-csro-penetration-testing-service-license/) - Obtained CSRO Penetration Testing Service License 2023 - [Inaugurates Office](https://www.hexadius.com/cool_timeline/1-inaugurates-1st-phillipines-office-2-inaugurates-1st-india-office/) - 1. "Start of Philippines office" 2. "Start of India Office" 2024 - [First staff in Philippines (2024)](https://www.hexadius.com/cool_timeline/first-staff-in-philippines-2023/) - First staff in Philippines 2024 - [Exit Turnkey network and renamed as Hexadius Consulting (2024)](https://www.hexadius.com/cool_timeline/exit-turnkey-network-and-renamed-as-hexdius-consulting-2024/) - Exit Turnkey network and renamed as Hexadius Consulting 2024 - [First SailPoint IdentityNow project](https://www.hexadius.com/cool_timeline/first-sailpoint-identitynow-project/) - First SailPoint IdentityNow project 2020 - [First Ping Identity Project](https://www.hexadius.com/cool_timeline/first-ping-identity-project/) - First Ping Identity Project 2023 - [SailPoint ‘APAC Partner of the Year award](https://www.hexadius.com/cool_timeline/sailpoint-apac-partner-of-the-year-award/) - SailPoint ‘APAC Partner of the Year award 2023 - [First project in Malaysia (2023)](https://www.hexadius.com/cool_timeline/first-project-in-malaysia-2023/) - First project in Malaysia 2023 - [First IAM advisory project (2021)](https://www.hexadius.com/cool_timeline/first-iam-advisory-project-2021/) - First IAM advisory project 2021 - [First project in Philippines (2017)](https://www.hexadius.com/cool_timeline/first-project-in-philippines-2017/) - First project in Philippines 2017 - [First staff in India (2022)](https://www.hexadius.com/cool_timeline/first-staff-in-india-2022/) - First staff in India 2022 - [First SailPoint ‘Delivery Admiral’ award (2022)](https://www.hexadius.com/cool_timeline/first-sailpoint-delivery-admiral-award-2022/) - First SailPoint ‘Delivery Admiral’ award 2022 - [200th project (2022)](https://www.hexadius.com/cool_timeline/200th-project-2022/) - 200th project 2022 - [First IAM implementation project (SailPoint IdentityIQ – 2019)](https://www.hexadius.com/cool_timeline/first-iam-implementation-project-sailpoint-identityiq-2019/) - First IAM implementation project (SailPoint IdentityIQ – 2019) 2019 - [First Managed Security Services (2019)](https://www.hexadius.com/cool_timeline/first-managed-security-services-2019/) - First Managed Security Services 2019 - [First project in Thailand](https://www.hexadius.com/cool_timeline/first-project-in-thailand/) - First project in Thailand 2018 - [First SAP cybersecurity project](https://www.hexadius.com/cool_timeline/first-sap-cybersecurity-project/) - First SAP cybersecurity project 2018 - [Joined Turnkey network and renamed to Turnkey Singapore](https://www.hexadius.com/cool_timeline/joined-turnkey-network-and-renamed-to-turnkey-singapore/) - Joined Turnkey network and renamed to Turnkey Singapore 2015 - [First SAP SoD project (2014)](https://www.hexadius.com/cool_timeline/first-sap-sod-project-2014/) - First SAP SoD project 2014 - [100th project](https://www.hexadius.com/cool_timeline/100th-project/) - 100th project 2015 - [First SAP GRC Access Control implementation (Utilities company – 2013)](https://www.hexadius.com/cool_timeline/first-sap-grc-access-control-implementation-utilities-company-2013/) - First SAP GRC Access Control implementation (Utilities company – 2013) 2013 - [First VAPT project (for a French engineering company – 2013)](https://www.hexadius.com/cool_timeline/first-vapt-project-for-a-french-engineering-company-2013/) - First VAPT project (for a French engineering company – 2013) 2013 - [First project in Australia (SAP post implementation review – 2012)](https://www.hexadius.com/cool_timeline/first-project-in-australia-sap-post-implementation-review-2012/) - First project in Australia (SAP post implementation review – 2012) 2012 - [First project with government agency (SAP authorizations review – 2011)](https://www.hexadius.com/cool_timeline/first-project-with-government-agency-sap-authorizations-review-2011/) - First project with government agency (SAP authorizations review – 2011) 2011 - [First project in China](https://www.hexadius.com/cool_timeline/first-project-in-china/) - First project in China 2011 - [First SAP security project (for a large natural resources company – 2011)](https://www.hexadius.com/cool_timeline/first-sap-security-project-for-a-large-natural-resources-company-2011/) - First SAP security project (for a large natural resources company – 2011) 2011 - [First project in Indonesia](https://www.hexadius.com/cool_timeline/first-project-in-indonesia/) - First project in Indonesia 2010 - [First public SAP security training](https://www.hexadius.com/cool_timeline/first-public-sap-security-training/) - First public SAP security training 2010 - [First corporate SAP security training](https://www.hexadius.com/cool_timeline/first-corporate-sap-security-training/) - First corporate SAP security training 2010 - [Established as Mantran Consulting](https://www.hexadius.com/cool_timeline/established-as-mantran-consulting/) - Established as Mantran Consulting 2009 - [First major cybersecurity project UK](https://www.hexadius.com/cool_timeline/first-major-cybersecurity-project-uk/) - First major cybersecurity project (for a UK-based multinational engineering company – 2010) ## Categories - [Uncategorized](https://www.hexadius.com/category/uncategorized/) - [SailPoint and SAP](https://www.hexadius.com/category/sailpoint-and-sap/) - [India, Philippines](https://www.hexadius.com/category/india-philippines/) - [Singapore](https://www.hexadius.com/category/singapore/) - [Flexible](https://www.hexadius.com/category/flexible/) - [Malaysia](https://www.hexadius.com/category/malaysia/) ## Tags - [Identity and Access Management](https://www.hexadius.com/tag/identity-and-access-management/) - [SAP GRC and Cybersecurity](https://www.hexadius.com/tag/sap-grc-and-cybersecurity/) - [Full Time](https://www.hexadius.com/tag/full-time/) - [SAP Security](https://www.hexadius.com/tag/sap-security/) - [Cybersecurity](https://www.hexadius.com/tag/cybersecurity/) - [VAPT](https://www.hexadius.com/tag/vapt/) - [IAM](https://www.hexadius.com/tag/iam/) - [IGA](https://www.hexadius.com/tag/iga/) - [Identity Security](https://www.hexadius.com/tag/identity-security/) - [GRC](https://www.hexadius.com/tag/grc/) - [SoD](https://www.hexadius.com/tag/sod/) - [SailPoint](https://www.hexadius.com/tag/sailpoint/)