Real outcomes.
Measurable results.
We don't just talk about business outcomes — we deliver them. Here's the evidence.
Multi-country SAP S/4 deployment for a global services organisation
The Challenge
A global media and sports entertainment company needed to modernise its SAP landscape across multiple countries, replacing aging ECC instances with S/4 Public Cloud. Previous attempts with larger SIs had stalled due to cost overruns and a technology-first approach.
Our Approach
Icon led with a process-first methodology: mapping business processes across all regions before configuration. Senior architects ran workshops in each market. Technical delivery was handled from our Vietnam CoE.
"We needed a partner who understood that this was a business transformation, not an IT project. Icon brought senior people who had been in our shoes."
— Programme Director, Global Services Organisation
Automated SAP threat detection for a major financial institution
The Challenge
A leading financial services company in Southeast Asia had no visibility into its SAP security posture. Their SAP landscape — 12 production systems across 4 countries — processed millions of financial transactions daily, but security monitoring stopped at the network perimeter. Regulatory requirements under MAS TRM were tightening and a manual audit had revealed critical vulnerabilities including unpatched components dating back 3+ years, custom ABAP code with injection points, and unmapped RFC connections between systems.
Our Approach
Icon deployed SecurityBridge for real-time, automated security monitoring. The initial assessment uncovered 47 critical vulnerabilities across the SAP landscape, including configuration weaknesses that had existed since the original system build. The platform was fully operational within 6 weeks, with ongoing managed services from our centre of excellence providing 24/7 monitoring, automated alerting, and quarterly security posture reporting for the board.
"SecurityBridge showed us vulnerabilities we'd been living with for years. Within 48 hours of the initial assessment, we had a clearer picture of our SAP risk than in the previous decade."
— CISO, Regional Financial Services Group (Southeast Asia)
Closing the SAP security gap for an APAC manufacturing group
The Challenge
A multinational manufacturing company operating SAP across 6 APAC countries had no centralised view of SAP security risk. Each site managed patching independently, leading to inconsistent security postures. A supply chain disruption at a competitor — caused by an SAP-specific attack — prompted the board to demand an immediate assessment.
Our Approach
Icon ran a SecurityBridge risk assessment across the entire SAP landscape within 5 working days. The assessment identified critical patch backlogs in 3 of 6 sites, vulnerable custom code in production, and over 200 unused RFC connections expanding the attack surface. SecurityBridge was deployed across all sites within 8 weeks, with centralised monitoring from Icon's centre of excellence.
"We went from having no visibility to having a single dashboard covering every SAP system in the group. The board can now see our security posture in real time."
— VP IT, APAC Manufacturing Group
Eliminating the manual testing bottleneck with Tricentis
The Challenge
Continuous SAP updates were overwhelming manual testing capacity. Every release was delayed by 2–3 weeks of regression testing and quality was suffering.
Our Approach
Icon implemented Tricentis unscripted test automation integrated into the client's SAP release pipeline. Transition completed in under 12 weeks with knowledge transfer.
"We went from dreading every SAP release to welcoming them."
— Head of IT Operations