Skip to Content

ERP and Cybersecurity: Business Data Should Not Only Be Safe on Paper

An ERP security control guide: access control, audit trail, backup, MFA/SSO, and segregation of duties.

ERP holds a company's most valuable assets: financial data, customers, prices, and business processes. That is why its security must not stop at a policy document — it must be embedded in the system.


Security Is Not an Add-On Feature

Many companies only think about security after an incident occurs. Yet ERP is the center of business data; security controls must be part of the design from the start, not patched on afterwards.

1. Access Control & Role-Based Permission

Every user should only access what is needed for their work. Odoo supports role-based groups and access rights — from the module level, to models, down to fields.

Principle: least privilege — grant the minimum access sufficient to work.

2. Record Rules & Multi-Company

Beyond per-menu rights, Odoo governs record rules: users only see data belonging to them, their branch, or their company. For multi-company groups, data separation between entities is maintained at the record level.

3. Audit Trail

Important changes must be traceable: who changed what, and when. Odoo provides the chatter (change log) on many documents, and can record all access via an activity log. The audit trail is the foundation of accountability.

4. Segregation of Duties

The classic accounting control remains relevant: the person who creates a transaction should not be the one who approves it or records the payment. Separate roles to reduce the risk of fraud.

5. Backup

A backup must cover two components:

  • The database (transaction data),
  • The filestore (attachments/documents).

A database backup alone is not enough for a full recovery. Schedule backups and test the restore.

6. Disaster Recovery

A backup without a recovery plan is just a file. Prepare RPO/RTO (how much data may be lost, how long the system may be down), a restore procedure, and drills.

7. Database & Server Security

  • Database access is restricted and encrypted.
  • Credentials are not written in code.
  • Servers are updated and monitored.
  • Administrative access is restricted and logged.

8. MFA / SSO

Enable two-factor authentication for sensitive accounts, and Single Sign-On (SSO) for centralized access control. This reduces the risk of leaked credentials.

A Brief Checklist

Area Question
Access control Role-appropriate?
Record rules Data separated between branches/companies?
Audit trail Changes recorded?
SoD Creator ≠ approver?
Backup DB and filestore, tested?
DR RPO/RTO & restore procedure ready?
MFA/SSO Active for critical accounts?

Closing

A secure ERP is not the one with the most policies, but the one whose controls actually run in the system. Security is an ongoing process — not a one-off project.

Want to review the security of Odoo in your company? Consult with the SDT Team.


Data security

Note: this article is educational. Security needs adapt to the scale and business risk. Written by Sinergi Data Totalindo, PT.

Sinergi Data Totalindo October 6, 2026
Share this post
Archive
Why ERP Should Not Simply Follow Old Processes
Digitalizing old processes vs transforming business processes — and why questioning processes is more valuable than simply automating them.
Chat WhatsApp