Name
From “Shift Left” to “Shift Up” Business-Process-Anchored Security in the Age of AI
Description

For years, “shift left” has meant embedding security earlier in the development lifecycle. But as AI agents become part of core business processes, securing code earlier is no longer enough. Risk increasingly sits within the decisions, data, identities, controls and handovers that make up an end-to-end process.

This session introduces Shift Up, an approach that anchors security in the business process rather than the technical asset alone. Drawing on customer co-engineering experience and a structured Business Process Threat Modelling methodology, it will explore how organisations can use their existing process intelligence tools and SAP capabilities to understand threats in their business context and strengthen governance as AI becomes more embedded in operations.

What You’ll Learn

  • Why embedding AI agents into core business processes requires security teams to look beyond code and technical assets.
  • How Business Process Threat Modelling connects security risks and controls to end-to-end processes and their potential business consequences.
  • How existing process intelligence tools and SAP capabilities can help identify, assess and govern threats that traditional security models may miss.
Phil Burgess Colleen Hebbert
Session Type
Breakout Session