WOODLANDS ADVISORY
References

Where cyber security decides whether a deal closes.

Woodlands Advisory assesses cyber risk in corporate transactions and takes on security ownership in regulated environments. This page sets out what that experience rests on, who can attest to it, and how each of those people is connected to us.

Background

Three acquisitions, one security remit.

SAP's Business Transformation Management division did not grow organically. It was assembled through acquisitions: Signavio, LeanIX and WalkMe. Each of them arrived with its own technology, its own organisation and its own security posture.

Fabian Hausner came from incident response and worked on the security side while Signavio was being integrated into the group. He later owned security advisory for the entire division, across all three products, as SAP Global Security Advisory Lead.

Anyone on the security side of an acquisition works not with the picture the data room paints, but with what actually runs, what of that is documented, and where the gap between the two remains. That gap is what cyber due diligence is about.

That is the perspective Woodlands Advisory brings to transactions today: the perspective of the side that has to operate the result afterwards.

Fabian Hausner presenting the SAP Signavio Process Transformation Suite to clients
Client presentation on the SAP Signavio Process Transformation Suite.

3

acquisitions in the division: Signavio, LeanIX, WalkMe

Global

security advisory across all three products

Buy side

security ownership before, during and after integration

Voices from that environment

Three people who know this remit at close range.

“He owned the security side while three acquisitions were being turned into one division.”

I got to know Fabian at SAP, initially in an area I was responsible for. Our paths then crossed across several stations, Enterprise Analytics, Signavio, LeanIX. So I did not see one project with him, I saw several years.

The division I ran last was built entirely through acquisitions. Signavio, LeanIX, WalkMe, three acquisitions in quick succession, each with its own technology, its own organisation and its own security posture. Fabian came to us from incident response and first drove the integration inside product engineering itself. He later owned security advisory for the entire division on the go-to-market side, across all three products.

Anyone on the security side of an acquisition sees things that appear in no data room: what actually runs, what is documented, and where the gap between the two sits. He did not review that from the outside, he had to make it work afterwards.

We also founded a company together, ForeYou. There he built and consolidated the IT products and the web presence, and over time he carried the strategic decisions with me. So I know him not only as a security specialist, but as an entrepreneur who thinks a business through from the technology to the numbers.

“He framed technical risk in a way that let our customers decide.”

For context: I am responsible for the security and compliance organisation of SAP Signavio internally, the product security team. Fabian was the counterpart facing the market, as global security advisor for the division.

That applied above all to customers in critical infrastructure, for whom security is not negotiable: governments, defence, healthcare, alongside smaller organisations with the same requirements. In those processes what counts is not the presentation, but whether the answers hold up under examination. He carried that responsibility for critical-infrastructure organisations operating globally.

One sizeable deal with an international group sat for months on unresolved security questions. Fabian brought the responsible people on the customer side together and set out the technical position so that a decision became possible. It was signed shortly afterwards.

The point is not negotiating skill. It is the ability to translate a technical risk into the language of the people who have to answer for it, without the risk being understated in the process.

Dr Daniel Bernau

Dr Daniel Bernau

Senior Manager, Co-Head of Security, Compliance & Engineering Governance, SAP Signavio

Relationship: Responsible for the security and compliance organisation of SAP Signavio. Fabian was his market-facing counterpart in the same division.

“I come from audit. His documentation was the kind you can hand to an auditor.”

I come from audit, previously KPMG and public service. In that school you read every statement together with the follow-up question that would take it apart.

Fabian and I worked in the same client projects at SAP, on documentation that has to survive an audit: governance, risk, compliance and increasingly European AI regulation. In that environment there is documentation that looks good, and documentation you can hand to an auditor. His was the second kind.

In the sale of AI licences he was the last technical station before signature, the security and compliance validation, globally and above all in the European regulatory environment. His judgement enabled deals and kept us from decisions that would have become expensive in regulatory terms.

For my doctoral work on AI governance he was one of the interviews I relied on.

Dr Joshua Nganyadi

Dr Joshua Nganyadi

Sr. Strategic Advisor, SAP · ISO/IEC 42001 Lead Auditor · previously Sr. Auditor & Corporate Governance Services, KPMG

Relationship: Long-standing colleague from our shared Signavio years, joint client projects.

Engagement

Security in a business with no IT function for it.

Scope
ClientRiedel GmbH, manufacturing business, Eschbach, Germany
Starting pointNo dedicated information security function in-house
TopicsData backup, security in day-to-day operations, use of AI in business processes
StatusProject completed, ongoing collaboration

“He first looked at how we actually work, and then told me what was not necessary.”

We are a manufacturing business, not an IT company, and we have nobody in-house whose job is information security. You still cannot avoid the subject.

It was about our data backup, about security in day-to-day operations, and about how to bring artificial intelligence into our information security processes in a security-compliant way.

What I can say: he first looked at how we actually work before proposing anything. He explained the topics so that I could form my own judgement. And he named what we did not need. The project is complete.

Christian Scholz

Christian Scholz

Managing Partner, Riedel GmbH · Eschbach, Germany

Relationship: Client. Completed project, with ongoing collaboration on security questions since.

Partner network

When an incident becomes a proceeding.

For criminal-law matters following a security incident we work with a specialised law firm.

“After an incident, two proceedings run at once, a technical one and a legal one.”

When an attack or a data leak is uncovered, both begin at the same time. Investigators ask questions, deadlines run, and what is secured and documented in the first days later decides questions of responsibility and liability.

Fabian and I work together at that interface: regulation, criminal proceedings following incidents, and the question of how technical findings must be prepared so that they hold up before authorities and courts.

As a criminal defence lawyer I rarely make recommendations. I work with Woodlands Advisory because when it matters, I can build on their results directly.

Relevance

From technical finding to decision.

In a transaction, a security finding only becomes usable once it answers what it means for the price, for the negotiation and for the period after closing. Purely technical reviews regularly fail at that translation.

The experience documented here covers that chain end to end: assessing technical risk, framing it for decision-makers, processes in which a deal hinged on security questions, and integration after the purchase.

On that basis we offer cyber due diligence in transactions as well as security and AI governance ownership in regulated environments. Delivery is handled by a curated team of senior practitioners, supported by a partner network for legal, tooling and forensics.

Growth needs security. Not someday – now.

Whether you face a transaction, need a certification or want to professionalise your security strategy – Woodlands delivers predictable results at boutique speed.

Schedule Initial Consultation →

20 minutes. Confidential. No obligation.