# Managing Customer-Owned Encryption with the New Key Management Service | feat. Sascha Vierlinger Page: https://stenobird.com/podcast/unlocking-sap-btp-742620/managing-customer-owned-encryption-with-the-new-key-management-service-feat-sascha-vierlinger Text version: https://stenobird.com/podcast/unlocking-sap-btp-742620/managing-customer-owned-encryption-with-the-new-key-management-service-feat-sascha-vierlinger.md Podcast: [Unlocking SAP BTP](https://stenobird.com/podcast/unlocking-sap-btp-742620) Published: 2026-02-18T07:00:00+00:00 Episode link: https://podcasters.spotify.com/pod/show/unlocking-sap-btp/episodes/Managing-Customer-Owned-Encryption-with-the-New-Key-Management-Service--feat--Sascha-Vierlinger-e3f7ft5 Audio file: https://anchor.fm/s/10cb2e03c/podcast/play/115637605/https%3A%2F%2Fd3ctxlq1ktw2nl.cloudfront.net%2Fstaging%2F2026-1-17%2Fbae788ee-4c0b-f320-b080-ddbc1983913a.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/unlocking-sap-btp-742620/episodes/managing-customer-owned-encryption-with-the-new-key-management-service-feat-sascha-vierlinger Duration seconds: 2176 ## Resource Niklas Siemer is joined by Sascha Vierlinger, Product Manager for SAP Key Management service, to unpack customer-owned encryption in cloud landscapes—and why more organizations want control of the “last layer” of trust: the keys. They walk through why encryption matters more in the cloud, the difference between SAP-managed vs. customer-managed keys, and what a modern Key Management Service (KMS) needs to deliver: secure key storage, lifecycle controls (enable/disable/delete), auditability, and operational safeguards like the four-eyes principle. The conversation also covers the classic “red button” scenario (cutting off access fast in an emergency), and how SAP’s new KMS is designed as a more scalable, central approach compared to the legacy SAP Data Custodian KMS. ⁠ Download Episode Transcript ⁠ In this episode, you'll learn: Why who controls the key is effectively who controls the data (especially in regulated industries). The three models for key control: Sub-managed keys, Bring Your Own Key (BYOK), and Hold Your Own Key (HYOK). What "key lifecycle" really means (rotation, disabling, deletion—and the very real risks). How SAP's new KMS supports stronger governance with audit logs and multi-party approvals. What to expect commercially (licensed product + connections) and how this fits with SAP BTP usage. ===== Useful Links Key Management Service Product Documentation More about GRC and cybersecurity Subscribe to the Unlocking SAP BTP Podcast: Apple Podcasts Spotify YouTube ===== About the speakers: Sascha Vierlinger Product Manager, SAP Key Management Service Sascha is Product Manager for Key Management at SAP. He has more than 15 years of SAP experience in consulting and product management and is certified SAP Enterprise Architect. Follow Sascha on: Linked… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/unlocking-sap-btp-742620/episodes/managing-customer-owned-encryption-with-the-new-key-management-service-feat-sascha-vierlinger/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/unlocking-sap-btp-742620/managing-customer-owned-encryption-with-the-new-key-management-service-feat-sascha-vierlinger.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.