Distributors reached SAP on devices nobody manages.
A fertiliser producer let its distribution partners into one SAP system from their own laptops, and took the SAP server off the public internet on the same day.

Where they started.

The customer is one of India's foremost chemical-fertiliser producers, supplying agricultural demand across several states through regional offices, dealers and a large distribution network.
The SAP-ERP system that runs that network is hosted in a private data centre, and the people who use it most are not employees. Distributors reached it over public IP addresses, from their own unmanaged laptops, scattered across the country.
That made the supply chain the softest edge the company had. It needed access policies that could tell one distributor from another, judge the machine they were using, and stop the SAP server being addressable from the open internet.
What was in the way.
- Unmanaged devicesThird-party distribution partners connected from their own machines, which the company had no way to manage or inspect.
- Policy at a distanceAccess policy had to be configured for distributors spread across many geographies, not for a single office population.
- Public exposureThe supply chain was reachable through public IP addresses, so the SAP server was visible to anyone who looked.
- Device conditionsAccess needed to depend on what kind of device was asking and what state it was in.
What was put in place.
Each control below has its own page. If a row makes a claim, the link is where you check it.
- Need to knowA distributor is granted the applications their role requires and nothing else; there is no directory of the estate to browse.More
- Server withdrawnThe SAP server was taken off public access and made unreachable to anyone who has not already been authorised.More
- Device judgedThe type and posture of the asking device decide whether the session starts, which is how an unmanaged laptop becomes a governable one.More
- One device at a timeA distributor's account is tied to the device it was registered on, so a shared credential does not become a shared entry point.More
- Encrypted end to endThe session runs encrypted from the distributor's device to the SAP server, without a public hop in the middle.More

What the supply chain getswhen the pass expires
Three consequences of granting a partner an application rather than a route into the network that holds it.
Partners, governed
Distributors work on their own hardware under the company's policy, not under an exception to it.
Nothing to scan
The SAP server has no public address left for an attacker to find, so the supply chain stops being the soft edge.
One device, one identity
A credential that leaves the distributor it belongs to does not arrive anywhere useful.
“With cyberattacks targeting weak links in every company’s supply chain, we had to make sure to cover all of our bases and secure our massive network of unprotected distributors. InstaSafe’s SDP approach helped to make our SAP applications accessible only to authorised users, and also secured end-user devices through the Zero Trust Agent. A truly scalable cloud security solution”
Seven more stories, filtered by sector and by the problem they started with.
All customer stories//Ready when you are//
Let a partner in without letting them in.
Bring your riskiest third-party population. We will scope what they should reach and what happens to the rest.
Regulated, air-gapped, or on-premise? See deployment options