Who Is Jon Longstaff?
Jon Longstaff is the Head of Cloud Security & Compliance for SAP in the Europe, Middle East, and Africa (EMEA) region. He reports directly to SAP's Chief Information Security Officer and oversees security strategy, compliance frameworks, and regulatory engagement for all SAP cloud offerings in the region.
More from this site
Keep reading the latest coverage
Career Path
Longstaff began his career in 2004 as a security analyst at a multinational technology firm. He moved to SAP in 2010, initially working on infrastructure security for the SAP HANA platform. Over the past decade he has held roles such as Security Architect, Compliance Lead, and Director of Cloud Security. His progression reflects a deepening expertise in cloud security best practices, data privacy law, and risk assessment.
Key Responsibilities
• Develop and maintain the EMEA Cloud Security Policy, aligning it with ISO 27001, NIST, and EU‑GDPR requirements.• Lead cross‑functional teams that assess and remediate security risks in SAP Cloud Platform, SuccessFactors, and Ariba.• Coordinate with national regulators (e.g., UK's ICO, Germany's BSI) to ensure compliance with local data protection mandates.• Drive security awareness programs for SAP's partner ecosystem, ensuring consistent security posture across the supply chain.• Represent SAP in industry forums such as Cloud Security Alliance and the European Cloud Forum.
Impact on SAP's Cloud Services
Longstaff's initiatives have reduced incident response times by 30% across EMEA and increased the number of third‑party audits passing without findings. He introduced a cloud‑native threat intelligence platform that aggregates signals from SAP's global security operations center, enabling proactive detection of emerging attack vectors. Under his guidance, SAP achieved compliance with the EU's Digital Operational Resilience Act (DORA) ahead of schedule, positioning the company as a leader in regulatory readiness.
Strategic Focus Areas
Data Privacy & LocalizationLongstaff champions data residency solutions that allow customers to store sensitive data within national borders while still leveraging SAP's cloud services. He works with legal teams to craft data transfer agreements that satisfy the EU‑UK Data Protection Agreement and the US‑EU Privacy Shield (where applicable).
Zero‑Trust ArchitectureImplementing a zero‑trust model across SAP's cloud services, Longstaff ensures that every access request is continuously validated. This includes micro‑segmentation, adaptive authentication, and least‑privilege access controls.
Security AutomationHe promotes the adoption of automated security controls, such as continuous configuration monitoring and automated remediation playbooks, to reduce manual effort and human error.
Industry Recognition
Longstaff has been cited in Gartner's Magic Quadrant for Cloud Access Security Brokers and in the European Cloud Forum's "Top 50 Cloud Security Leaders" list. His speeches at the Cloud Security Summit highlight SAP's approach to balancing innovation with regulatory compliance.
Future Outlook
As cloud adoption accelerates, Longstaff is steering SAP toward a multi‑cloud strategy that supports hybrid environments while maintaining a unified security policy. He is also expanding SAP's partnership with European regulators to pre‑emptively address emerging data protection rules, such as the forthcoming AI Act.