Video: SecurityBridge CEO on SAP Security, AI Risks & 2026 Priorities

Transcription

Hey channel insiders, Katie Bavoso here popping in to quickly remind you about our channel insider email newsletter. It's never been easier to get the week's top channel headlines sent right to your inbox. Just head to channelinssider.com and scroll down on the homepage to find where you can join for free. Okay, on to the episode. Hey channel insiders, welcome back to channel insider partner POV. I'm your host Katie Bavoso and my guest today is Yesper Zerlang, the newly appointed CEO of Security Bridge, a global independent software vendor specializing in cyber security solutions for SAP environments.

Today we dig into Yesper's leadership plan for 2026, which includes heavily investing in channel partnerships. We discuss data poisoning and how it's impacting AI use in cyber security. What CISOs and CIOS struggle with when it comes to implementing compliance and why Yesper sees managed services as the greatest opportunity in 2026. Welcome Yasper. Thank you so much for joining me. >> Thank you Katie. Thanks for having me. Very interesting. Look forward to the talk. >> Very excited to have you here.

Now we are in two very different time zones right now. I am over on the east coast of the United States and you are in Copenhagen. So, how is the weather like? Any any future predictions that you can give me moving forward into the day? >> Well, as a as a weather forecaster, we have a storm coming in. So, um >> it's snow covered. There's ice on the lakes and it's very pretty and Christmas-like. Minus 5° CC, so 28 degrees Fahrenheit and just very crisp and beautiful place to be.

Honestly, with that kind of weather forecast, between you and I, I'm in Massachusetts. We could potentially be in the same place right now. So interesting. >> Well, thank you so much for Braving the Storm to be able to talk to me today. I'd really like to just jump in and get to know you because you spent the past year as chairman of the Security Bridge before stepping into the CEO role where you are now. How does that perspective change the way that you're leading now that you're responsible for not just strategy but actually for execution as well?

Yeah, and that's exactly the key word. I've been on the board as chair for the last 12 months and prior to that actually a senior advisor to the company and uh we've built over the course of the last three or four quarters a whole new strategy for go to market and and it's very exciting and and then as the founders stepped into a more evangelism roles um I was asked to to take on the CEO position and and that was an easy easy choice. So very excited that not only having designed most of the strategy but now I also responsible for executing it.

So really look forward to to this new CEO role. >> You called it an easy choice for you. Talk to me about that. What made it so easy to select because it's not always the case to change positions like that? >> No. And quite often it goes the other way. You are a CEO for a while and then you step into the chairman role. But I think the reason that this is exciting is uh actually what we do and one thing is having great technology. There's always a prerequisite for for a nice journey.

But but when you then also solve real issues that has an you know an actual impact in society if we are a little bit high up in the air. I think the purpose of protecting the world and protecting a lot of companies is very exciting and I think that what security bridge does actually matters to a lot of customers and we solve a tangible problem that that many companies are struggling with and just makes it super exciting. So, so with with a great team and and with the outlook to make a difference, uh this is something that ticked a lot of my personal boxes as well. >> Oh, I love that you say that because when you have a north star like that, in this case, companies absolutely need that protection.

They need that security and knowing that's what's driving you and what you find important in the mission of the job. I agree. That's always very nice to wake up every day going, I know what I have to do. And it's very simple. I have to protect these companies. Once you start there, you can work your way backwards for everything else. Exactly right. >> So, we'll get into more about Security Bridge in a moment, but I'd like to continue to get to know you.

You've led and scaled companies before, including taking one from a small team to a global footprint. So, what lessons from that experience are most shaping how you lead Security Bridge today? When you again wake up every day and engage that mission, what's important to you to move forward based on your experience? >> Well, I think that you know when you work, you spend a lot of hours with what you work with. So, so there's a couple of things that needs to be in place from my perspective.

First of all, you need to work with with quality and you need to work with quality people because they tend to generate quality products and solutions. So, one of the key learnings is is really it's actually about the team. It is about generating a culture where you where you get uh this passion that people are kind of switched on for the same purpose and I think that that works really well. And the challenging part is making sure that this can happen in a in a multicultural environment >> because let's face it, I mean we are with the internet and with cyber in particular and SAP security, it's now become one big digital village.

It's not just small islands or small countries and for sure you know hackers they they don't know boundaries. They don't care if you are in one country or another. It's a global village and and so one of the key learnings here is to communicate simplistically and very clear to everybody on the team where are we going, why are we going there and how are we going to get there. The key experience from my side is to to to take this team spirit and cultural awareness and bring it into something tangible.

Of course, we still want to win the game. We are still competitive. We still need to sell a lot of stuff. We need to support our customers. We need to do customer success. all these disciplines but it all boils down to that everybody's aligned to the same purpose and so that's one of the key things that that I bring in to this equation and next next part of the journey for security bridge >> well let's dig more into security bridge and the mission that you have there security bridge protects SAP environments for large enterprises by reducing cyber risk across missionritical SAP landscapes in a nutshell so who are your customers and what verticals do they typically serve >> well the potential potential customers could be any customer that has an SAP system.

And and the the interesting thing about SAP is that if you take all the global trade in the world and you take all the products from when they're incepted to once they go out of you know fashion, uh 73% of all products in the world touches an SAP system at one time in their life. So it's significant. It's it's a huge part of of what companies do. And I think that it's important that you that we provide solutions uh for this and and that's why I think this company has a huge relevance because one thing is having your your business strategy kind of evolving around SAP we want to be the protecting layer.

So that I mean if you think think security for for SAP you you should think security bridge. >> Very well put. So SAP security is often described as complex or hard to penetrate as security bridge looks towards 2026. this year. What do you believe truly differentiates your approach to delivering and managing SAP solutions in a crowded cyber security market? Because as we know, as important as cyber security is, there's quite a few players in competition inside of this market. >> Yes, there's a lot of competition and and that's really good because that uh keeps everybody on their toes. >> Yeah. >> So, I actually love competition.

The the the special thing about SAP is it kind of a blind spot for security vendors. uh there is a generic cyber industry of course but when you then have the SAP environment it's in itself is quite complex and how we differentiate it is that we are truly born in the SAP ecosystem we have SAP engineers and the whole company was founded on building solution in SAP for SAP by SAP engineers and that's actually the reason for the name security bridge because we want to build the bridge between the SAP enir environment into the the more generic IT security space.

So if you have a sock, everybody knows about you know firewalls, perimeter security, threat intelligence across multiple application and texts and what we do is then we include uh the SAP part of it. So you you coexist, we coexist with everything that that customers have in the first place, but we just add real intelligence from SAP uh that is relevant and fits into whatever the the customers might have in the first place. >> So you've talked about moving from a direct first model to a channel first strategy.

Now I want to get into that that model a little bit more. What does that shift say about how you see the market evolving and how security bridge plans to scale this year? H well first of all I want to really emphasize that it's a core part of the strategy that we move from a direct to an indirect approach and why do we do that it's actually because um that's the best way we feel we feel we can serve our customers because the customers to a large extent already have a trusted relationship to the partner they work for a long time together they know all their pains and they might have built some of the core systems also within SAP uh with the partners and So it's it's obvious for us uh that we can scale faster if we provide solutions that that fits into the channel and so that partners can actually get to know security bridge and deliver our solutions to to their trusted trusted customers. >> You've emphasized to me fewer but better partnerships.

That's going to be a priority for you this year. What makes a partner the right partner for security bridge especially as you expand globally? What kinds of partners are you looking for? especially since security bridge focuses on protecting a very specific vendor environment. Explain that to me. >> Yeah. So, so first of all, the the the ICP or the key customers that we are we are targeting is more towards the enterprise segment. So, more large global enterprises is where we we have a sweet spot and so then you have to work backwards and see what partners are actually focused on this.

Mhm. >> So, so um it is uh the larger system integrators uh the big four or the big six or 10 if you will um that have you know a huge offering on on services evolving around SAP and here we can then add the security aspect uh because today in modern world which is something that have changed you cannot build uh an application within a customer uh as a partner without thinking security first. >> Mhm. and and here we bring something that they they really like because we we speak the SAP language and and so the we're not kind of a foreign security solution that need to be bolted on their their solution.

We can actually seamlessly fit into what they already know about. So the ideal partners are either a large system integrator or it can be an SAP vertical partner and very much so MSSP. So the whole MSSP space is going to change because customers obviously have a challenge of their cyber security. Uh they want this as a service because they cannot manage themselves. And so we provide these uh MSSPs with a full multi-tenant solution of security bridge which means that that they also going to be a significant um channel uh segment for us.

When approaching those partners, how are you incentivizing them to look to security bridge as the trusted partner that they should engage in that partnership this year? I'm trying to say partner so many times in one sentence here, but truly that is the idea. How are you engaging them? How are you incentivizing them to join up? >> Well, first of all, before we even start start about in incentives, it's really important that we build a brand that's trusted.

So the partners know that when they engage with us, they can really rely that what we deliver is is really high high quality that's easy to implement that and we have thought about what the customers are looking for. So that's kind of the ticket to the game. And then once we're in the game, it's a mutual qualification. We are trying to find partners that are willing to invest in this. I would challenge most partners in saying that if they sell a a cyber security solutions for SAP with security bridge, they can minimum 10x the license that they deliver on services and uh two two aspects can be the case.

They might already have the services or we will help build the service together with a partner. So we have a pretty good understanding on what a customer is looking for. So as an example you could say that before you imp implement a security solution you want to know about what is the risk appetite for a customer and we have you know various templates where we can enable the partners so they know how to ask the right questions and so it's not just about buying a solution and all of a sudden there is a magic bullet and and then the the customer is secure.

You need to know what are you trying to secure and why and that whole conversation can be difficult to have if you don't have the skill. But we want to build programs where we can assist the partners and enable them to be able to do this. So this is one of the key things that that we really want to make it easy to work with security bridge for a partner. >> Very well put. So speaking of security, which is a big conversation of today, we got to talk about AI.

There's no way that we can have a conversation without one without talking about the other. AI, as I'm sure you've seen, it's everywhere in cyber security conversations right now, but often in very abstract terms. How are you thinking about applying AI in practical ways that actually reduce workload and risk for your SAP customers? Well, I think there is of course an array of of how you can talk about AI and how how it's going to affect security bridge and what we do.

But but if we if we kind of of take them one by one, it's evident that when you have threat intelligence information that is generated by the security bit solution, it could be a you know an indication of compromise or anything like that. uh security analyst would want to have all the information that is already available somewhere out there and we have already made plugins that that our findings is augmented by AI solution that then build kind of the the heavy lifting of what a security analyst in the past would be having you know what they would have to do they would have to go to multiple sources to investigate um everything around an incident an IP address or or any other threat information or vulnerability and and we we put this in a structured fashion uh right at at the fingertips of the customers through using AI.

So that's a key key way of using it and then there is the the the actual way that we generate code is that we of course want to to use all the new modern tools as well so we can you know bring value to the market much faster in terms of new features and and availability and what have you. But that's kind of you know happens under the surface. But but just rest assured that we as everybody else are very much into selecting carefully what what what makes sense for AI and what is not really there yet.

One area we have we have a whole research team uh with with you know people that are dedicated to the AI aspect of it. And and and one big challenge about AI is data poison. and data poison being that AIs are good but if for some reason the the the language models are inflicted with noisy data and poison the result can be you know really devastating and and I'm sure that the adversaries are also using AI. So we are we we're working on in the lab right now to finding how can we find indications of intruders using AI and how does that affect uh the customers and and through this way um hopefully by applying the our solutions the customers can trust that we we also have um ways of finding out if their data which is their you know biggest resource is being poisoned somehow. >> Interesting.

I hadn't heard the term of data poison and when you add that word in it makes it very Yes. No, I'm I guarantee that I'll hear more about it. Would you mind talking about that a little bit more because it's a term that I haven't heard just yet. So, talk to me more about this term data poison. When did you start realizing this was the right thing to call it based on the patterns that you were seeing? >> Well, first of all, I don't want to take credit for for inventing the word, but but it's just, you know, it it resonates well with me.

I we all used these, you know, copilot or chat GPT and you sometimes use it and you get you get some results that you have knowledge about and and for some reason there's a strange information in there and where how did it get in there? Most of the time it's just by by just you know garbage in garbage out the the the old term uh that AI gets fed in in an improper fashion with with with fake news or or or these things. Or it could be that if you if you take it outside of security, you could say that right now in wartimes uh data poison is for instance that in the Ukrainian Russian uh conflict that we have right now that the parties have been kind of hacking the GPS system.

So you you're using a GPS system and then you think that you your target is is where the GPS says you're going. But then if you have poisoned the GPS, it will actually take you to another place and you'll be caught off guard and then maybe you are put into a trap and then you are vulnerable. That can also happen to data. So that the the adversary will put data into your AI models and it will it will give you suggestions that might be false and that can be exploited.

And so you need tools to be able to to um discover these things. But now we talk a little bit about what is what is happening in in in the lab and is not in the market yet. But I think it's it's a super interesting topic and and the reason for bringing it up is that our customers need to know that we are working on these type of of technologies. >> Absolutely. They see it out there happening in the world just like you were using that analogy with what's going on during the war in the Ukraine and Russia.

So having that known that you're taking that into account and that you're breaking it down to even a smaller level, it's really important that you understand these things and that they see that confidence in you. >> Can you talk a little bit more about what you're doing in the lab? How much can you give away uh when when speaking about that? >> I would rather keep that as a Christmas present for later. uh but I think what the lab does in in general is that we actually are very active on behalf of the customers is one thing is protecting from attacks but we also are proactive in in trying to mitigate what where are there uh you know vulnerabilities within for instance SAP so you know every software company including SAP they will release software that is vulnerable and have you know have holes in them and can be compromised when we find these and we search every single day we have anal analyst lists that are surfing the web and and and and scanning systems.

We will leverage this and and provide a lot of information to SAP for instance so they proactively can ensure when they release their updates that it's much secure by design. >> Excellent. Well, let's continue talking about the important features that you're seeing and that are being applied to these environments. Compliance is obviously another huge topic within cyber security. It's no longer optional, but many organizations still struggle with the how.

What are you seeing CISOs and CIOS wrestle with most when it comes to compliance in SAP environments and how is security bridge helping resolve these challenges? >> Well, I think the big struggle is that there's a lot of focus when you talk compliance in general about the risk posture and and the reason you have compliance is that you have to you have to really know your business processes and document your processes on how do you deal with with the whole flow of of your solutions.

That's the core of compliance. How do you protect personal data and all these things? But what is sometimes missing or often missing is once you have the framework up and running, then you have the big question. So how how do we then stay compliant and how is it not just false security? How can you sleep safe that actually the systems that you have implemented is living up to the expected compliance that you have in place? And this is where you know when you when you're a CISO or a CIO when you look up to the board you are saying you're talking about risk po posture how do you do it that's one way of looking at it but then your daily job is then to look down how do you mitigate how do you do it and that's where you have to discover a solution like security bridge and other uh security tools that then can actually provide the solution for for the compliance because compliance is just you know it's just a a finger in a glass of water the next day once you have delivered delivered your compliance report, it's like nothing happened because the intruder could have come in at 1:00 in the morning and and and and then you are not compliant anymore.

So I think the whole shift on compliance scene from our perspective is that you need to also have solution that are are relevant and continuously make sure that you are living up to those compliant requirements that is being put on companies and and that's a lot and it it's increasing. It is a lot and that's why they need to be able to rely on partners like security bridge and your partner ecosystem to be able to deal with it because it's definitely not their their business of day-to-day.

So I know that they need to break out of that that uh trouble of trying to concentrate on everything. So you said the most important conversations aren't about features but about understanding a customer's business. How do you coach your teams and your partners to show up differently in those conversations? >> Oh, that's a very good question. I think it's um it's a combination of the people you work with and training and it's it's it's making sure that we keep the conversation.

Of course, the product the technology is super important and that's kind of again using that you know term of of of the ticket to the game. needs to be absolutely amazing and stellar technology. But if you do not apply and understand why a customer should need your solution, then you're just, you know, providing solution that doesn't add value to the customer and then you can have them for a year or so and then they they they leave your your your turn and and nobody wants that.

But if you really understand to say to the customer, okay, customer, you want our solution. Yeah. Why? Because I want to be compliant. I want to be me secure. So just send me an invoice. You should have, you know, the boldness to say, well, hold on a minute. What what are you trying to achieve and what does good look like when when you're up and running and and what are your constraints to to your own business and and and understanding this before you you design the final solution is extremely valuable and key and we'll bring this to the partners.

So we will definitely of course onboard them and train them and make sure that they are certified in how our product work but we would also want to work with them on certifying them on how you have a good security conversation with their customers. >> That is a good point because sometimes you have partners or even even internally you have employees who are great at being able to execute but it's that communication to the people who don't understand that who don't see the behind the scenes that need to have that better understanding on the customer side.

Well, speaking of that, let's put that into into practice. Can you talk to me about a customer success story that you love to tell when you think about security bridge as a success story in its own? What customer success story comes to mind for you when you say this is what we do and this is why we do it well? Well, I think that um you know, one of the challenges we have of course is often customers are not always willing to share their own stories because we are dealing with security and if you expose what you use for security protection then you are your adversaries would know what you're working with and that's you know some people think it could be a disadvantage but one thing as a general theme that I'm very proud of is that when you implement the full security stack from security bridge you need a lot less people and this is the big challenge that a lot of companies have.

They have this notion yes we got to do something but they we don't have time to find out what we need to do and implement and so they are still underwater but we have small security teams that maybe today with a full implementation of how to make sure you are fully patched and your code is secure and you have everything on thread intelligence in place and check and you are compliant. Maybe in an enterprise situation, you could have somewhere between five and 10 people that are are if not full-time, but then on and off very much involved in this.

And if you implement it and do it correctly, maybe you only need a third of these kind of people. And then instead of running around doing basic stuff, your employees can really spend their time on high quality effects of what is being mitigated by the the tool. I mean, if you're vulnerable, we will find out immediately. will also provide out of the box what do you need to do and and it's almost the next next next uh process where in the past it was okay we might think we are vulnerable and we'll find out 3 months too late and then there's a lot of busy work trying to catch up and it's just very painful from a resource perspective so so so the key stories that I think is is the most straightforward is that you get ahead of the curve >> you're not swamped and always being behind and you can start to actually think about how to protect even more smarter and clever uh when you have your resources um freed up for these uh uh simple tasks that the solution will will automatically completely for you. >> As we start to wrap up here today, Esper, I'm curious when you think about moving forward in 2026, where do you see the biggest opportunities for partners this year?

Even if you're not thinking specifically security bridge, I'd love to pick your mind as being so entrenched in this industry. Where do you see the biggest opportunity for partners this year? >> I think if I had to choose one word, it would be managed services. >> Why is that? >> Well, it's because uh if you look at it, I think that you know there's there's a number flowing around whether it's it's two or three million uh cyber security expert that are missing today.

That's open positions on a global level. more than two million people are are are are missing to have a full protection within enterprises. So as an enterprise you need to find the right resource you need to be able to pay them. You need to train them and it moves so fast. So what what's good today doesn't work in 9 months. You need to be up and up and running. And I think the managed security uh providers have uh one of the keys to the solution here because you want to be able to outsource it.

And the managed security providers they are you know they are teamed together. they have a they have you know solid vertical knowledge about security and SAP security and and this way companies can relax and they can outsource this uh they cannot outsource the responsibility but they can outsource the the the groundwork and the trust that it's that their systems are being moni monitored 24/7. So I think that's going to be a key word for for for 26 for for the channel market.

And then I think to be honest if I'm a little bit focused on myself and and security bras and SAP I think that everything ERP not necessarily just SAP but all ERP systems are becoming much more relevant because in the past it was about breaking in that's now you know a lot of solutions out there but what happens if a disgruntled uh employee or or somehow uh you know a password is being sold on the on the dark web and all the credentials are safe and sound and you just surf right into your hardcore ERP systems then what do you do and that's where we wait and take on uh these guys and and can protect uh you know companies uh because I think it's about 28% of all major attacks somehow evolved either weak passwords or or intrusion or or somebody on the inside actually working with the hackers um and which is an alarming number and and our technology can can discover this and and and alert customers if if patterns like this are happening and then they can protect themselves. >> Quite stressful when you think about that coming from the call coming from inside the house so to speak uh to think about that.

But it is something you need to prepare for. Very true. Very true. >> Definitely. >> Yesper. I've had such a great time talking to with you today about SAP about security bridge and about every opportunity for partners. I'm sure that many folks listening have a million more questions. So, where can they go to learn more about SecurityBridge and follow along in your journey this year? >> Well, the easy path is of course security.com. You will have all the information there and and uh you can even go to my LinkedIn profile.

I have all my personal contact, my phone number, my email, everything is there. And that should be the easiest part. If you want to get in touch with us, you have questions, if you're a customer, if you're a partner considering going in this area, we will definitely uh give some advice. >> Thank you very much for your time, Yasper. I look forward to following along with Security Bridge throughout 2026. I hope you have a wonderful day. >> Yeah, same to you.

I look forward to it and I looked forward to a lot of new partnerships in the new year. >> Thanks so much to Yesper for joining me today and thank you for watching or listening. You can check out every episode of Channel Insider partner POV on channelinsider.com or watch us on YouTube at youtube.com/ channelinsider_news and trends. You can also listen to us as a podcast wherever you get your podcasts from. Don't forget to like, subscribe, and follow wherever possible so you never miss an episode.

Come connect with Channel Insider or me, Katie Bavoso, on LinkedIn and X. Once again, I'm Katie Bavoso, and I'll see you next time.

This transcript was generated automatically from the video's captions and may contain errors.

SecurityBridge CEO Jesper Zerlang discusses SAP security, AI risks like data poisoning, and why channel partnerships are key to 2026 growth.

Written By
Katie Bavoso
Katie Bavoso
Mar 25, 2026
1 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

In this Channel Insider Partner POV interview, host Katie Bavoso sits down with Jesper Zerlang, CEO of SecurityBridge, to discuss SAP cybersecurity, AI-driven threats like data poisoning, and why channel-first strategies will define partner growth in 2026.

Zerlang shares insights on securing mission-critical SAP environments, evolving compliance challenges for CISOs and CIOs, and how partners can capitalize on managed security services opportunities in a rapidly shifting threat landscape.


Key Topics Covered:

  • SAP cybersecurity strategy and risk reduction
  • Channel-first go-to-market shift
  • AI in cybersecurity and data poisoning threats
  • Compliance challenges for enterprise IT leaders
  • Partner opportunities in managed security services (MSSPs)
  • Building effective global partner ecosystems

Timestamps:
00:00 – Intro & Channel Insider newsletter
00:27 – Guest introduction: Jesper Zerlang, CEO of SecurityBridge
00:52 – 2026 priorities: channel investment & cybersecurity trends
02:00 – Leadership transition: chairman to CEO
04:06 – Scaling global cybersecurity companies
06:06 – What SecurityBridge does (SAP security explained)
07:11 – Differentiation in SAP cybersecurity market
08:47 – Shift to a channel-first strategy
09:46 – What makes the right partner
11:40 – Partner incentives & ecosystem growth
13:32 – AI in cybersecurity: practical applications
16:09 – Data poisoning explained
18:20 – Security innovation & lab insights
19:12 – Compliance challenges for CISOs & CIOs
21:32 – Customer-centric security conversations
23:18 – Customer success story
25:32 – Biggest partner opportunities in 2026
28:25 – Where to learn more about SecurityBridge
29:05 – Closing remarks

Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.