Making Your ERP a Pillar of  Your Cybersecurity

Making Your ERP a Pillar of Your Cybersecurity

Share This Post

By Renato Cudicio, MBA – President, TechNuCom

When we talk about cybersecurity, the first things that come to mind are antivirus software, firewalls, multi-factor authentication, and intrusion detection tools. These safeguards are essential, but they only cover part of the risk.

For mid-sized organizations, the most serious consequences often arise at the very core of business operations: fraudulent changes to a supplier’s banking information, unauthorized access to confidential data, improper approval of payments, loss of critical information, or the inability to determine who performed a specific transaction.

Cybersecurity is therefore no longer just about preventing an intrusion. It also requires knowing where data is located, who can access it, what actions each person is authorized to perform, and how important decisions are controlled.

This is precisely where a well-implemented Enterprise Resource Planning (ERP) system can become a powerful cybersecurity asset.

Data and processes have become targets

Every day, a company handles quotes, orders, contracts, invoices, personal information, banking information, employee data, and sometimes strategic intellectual property.

Cybercriminals no longer seek only to encrypt servers using ransomware. They can also steal information, commit identity theft, divert payments, compromise accounts, or directly disrupt business processes.

Two incidents that occurred in North America in 2026 illustrate this trend.

In January, Canada Computers & Electronics detected a breach in a system supporting its e-commerce site. Personal information and credit card data belonging to certain customers who had made a purchase as guests were compromised. The company had to investigate, notify the authorities, and offer credit monitoring services to those affected.

In June, Chick-fil-A suffered an automated attack that relied on the reuse of credentials obtained from an external source. The attackers were able to access certain loyalty accounts and view personal information, reward balances, and partial payment data.

These events serve as a reminder that a security breach does not necessarily begin with a high-profile attack on core infrastructure. It can originate from a peripheral system, an inadequately protected account, or a process with incomplete controls.

The question management must ask is therefore no longer just, “Is our network secure?” It must also ask, “Are our data and processes properly governed?”

An ERP system does not replace security tools

An ERP system does not replace a workstation protection solution, a firewall, or a threat detection system. Nor does it exempt a company from applying security patches, monitoring its network, protecting its backups, or training its employees to avoid phishing scams. Its role lies on a different level: that of data and process governance.

The National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 structures risk management around six complementary functions: govern, identify, protect, detect, respond, and recover.

An ERP system primarily contributes to governance and protection. It helps clarify where information is located, who can access it, which operations are authorized, and how important transactions must be validated.

Centralize to Reduce the Risk Surface

In many companies, information remains scattered across spreadsheets, email inboxes, local directories, SharePoint, Teams, Dropbox, and various specialized applications.

This fragmentation creates risks that are difficult to manage:

  • conflicting versions of the same document;
  • files sent to the wrong recipient;
  • confidential data downloaded to personal devices;
  • sharing links that remain active;
  • information stored in systems where no one actually monitors access.

In our article “More Tools Mean Less Efficiency,” we already explained that this fragmentation increases errors, duplicate data entry, and a lack of visibility. It also widens the attack surface: every application, every integration, every account, and every local copy represents an additional element that needs to be protected.

An ERP system like Odoo can bring together sales, purchasing, accounting, inventory, projects, and many other functions within a single environment. It doesn’t automatically eliminate all copies of data, but it significantly reduces the need to create parallel files to circulate information.

Centralization also facilitates the implementation of consistent policies regarding access, retention, backup, and traceability.

Monitoring Privileges That Accumulate Over Time

One of the key benefits of an ERP system lies in its ability to assign access rights based on roles, responsibilities, and the data in question.

In Odoo, permissions can determine, for example, whether a user is authorized to view, create, edit, or delete a specific type of information. Data validation rules can then be used to restrict access to specific folders or datasets.

In a real-world business, the main risk generally does not stem from an obviously absurd configuration. Rather, it arises from the gradual accumulation of privileges.

A manager changes roles but retains the access rights associated with their former position. A consultant is temporarily granted extended permissions that are never revoked. An integration uses a technical account with excessive permissions. A user is granted a one-time exception to resolve an emergency, and that exception becomes permanent.

Taken in isolation, each of these adjustments may seem reasonable. Over several years, however, they create an environment in which certain individuals or systems have far more power than necessary.

Access management must therefore be viewed as an ongoing process. It requires periodic review of accounts, groups, exceptional authorizations, and administrative privileges.

Managing Changes in Responsibilities and Departures

Staff changes represent another vulnerability.

When an employee is promoted, transferred, or assigned to a specific project, their new permissions are generally added quickly. However, their previous permissions are not reviewed as systematically. This leads to combinations of privileges that were never intended.

Departures pose a comparable risk. Deactivating a user account is not always sufficient. It is also necessary to review access to external applications, API keys, mobile devices, shared email accounts, technical accounts, and documents that may have been synchronized locally.

A centralized ERP system facilitates this work by providing a single point of reference for determining an individual’s responsibilities, recent activities, and associated permissions. However, this requires coordination among human resources, management, and IT teams.

Strengthen Identity with Multi-Factor Authentication

A password can be stolen through phishing, reused across multiple platforms, or exposed in a third-party data breach.

Multifactor authentication adds a second form of identity verification, thereby reducing the risk that a compromised password alone will be enough to log in. Odoo allows you to enable and enforce this protection for the relevant users.

However, deployment must be carefully managed. Administrator accounts must be prioritized for protection, recovery methods must be controlled, and mechanisms that allow temporary bypass of multi-factor authentication must be monitored.

Strong protection quickly loses its value when an overly permissive recovery process allows it to be bypassed.

Making Operations Truly Traceable

When an incident occurs, management must be able to quickly answer four questions:

Who viewed or modified the information? When? What validation was performed? What was the status of the file before the intervention?

A properly configured ERP system can track various useful details: status changes, approvals, messages associated with a file, assigned tasks, dates of action, and user identities. Additional logging or audit mechanisms can be added when the level of risk warrants it.

This traceability facilitates internal controls, investigations, and demonstrating compliance. It can also reveal anomalies: an unusual approval, a modification made outside the normal process, a transaction executed at an atypical time, or an inconsistent sequence of actions.

However, it is essential to precisely define what should be logged. Odoo does not automatically log every view or modification in all configurations. The level of traceability must be determined based on the sensitivity of the data, the company’s risks, and its contractual or regulatory obligations.

Securing Processes, Not Just Files

Cybersecurity must also protect the integrity of operations.

In a purchasing process, for example, a single person should not be able to create a supplier, modify its bank details, place an order, and authorize payment without additional oversight.

An ERP system allows you to set approval thresholds, separate certain responsibilities, and require additional validation when specific conditions are met: a new supplier, a change in bank details, an unusual amount, or a transaction conducted outside the usual parameters.

These controls reduce errors, as well as the risks of internal fraud, identity theft, and payment misappropriation.

Security thus becomes an integral part of day-to-day operations, rather than a theoretical policy confined to a document.

Preparing for Business Continuity

Centralization offers significant benefits, but it also creates a dependency. When the ERP system becomes the nerve center of the company, its availability and recoverability become critical.

Backups must be performed regularly, protected, encrypted when necessary, and retained in accordance with a documented policy. Above all, they must be tested.

A backup whose restoration has never been verified does not yet guarantee business continuity.

Management must determine:

  • the maximum amount of data the company can afford to lose;
  • how long it can operate without its ERP system;
  • which functions to restore first;
  • who is responsible for the recovery;
  • the procedure to follow if the primary environment is unavailable.

These decisions fall under enterprise risk management, not solely the IT department.

Technology Is No Substitute for Governance

No ERP system can prevent an authorized person from making a bad decision. A user can still approve a request too quickly, send information to the wrong recipient, or disclose an authentication code to a persuasive fraudster.

An ERP system must therefore be accompanied by clear procedures, appropriate training, and a culture of vigilance.

Employees must understand not only how to use the controls, but also why they exist. When a validation process is too cumbersome, poorly understood, or disconnected from operational realities, users will inevitably seek to circumvent it.

A good control must be proportionate to the risk, integrated into the workflow, and simple enough to be applied consistently.

A secure ERP is a rigorously governed ERP

An ERP can become a cornerstone of cybersecurity because it centralizes information, controls access, structures validation processes, and improves traceability.

But Odoo is not secure simply because it is installed.

You must limit administrative privileges, apply the principle of least privilege, enforce multi-factor authentication, review permissions, secure integrations, monitor logs, perform updates, and test backups.

The ERP must also be operated within a secure infrastructure that is monitored and supported by documented processes. It is in this context that an environment governed by a SOC 2 Type 2 attestation takes on its full significance. As we explained in our article on SOC 2 Type 2 certification, this certification focuses on the ongoing application and evaluation of controls.

It does not guarantee invulnerability. Rather, it demonstrates a structured level of governance, documentation, monitoring, and verification.

A well-designed ERP system in a poorly secured environment remains vulnerable. Conversely, a highly secure infrastructure will never compensate for excessive permissions or poorly defined processes.

Cybersecurity is the result of all these factors working together: the tool, its configuration, its hosting, its procedures, and the people who use it.

Would you like to determine whether your Odoo’s access controls, processes, and environment truly align with your company’s risks?  Contact  TechNuCom to identify which improvements to prioritize.

More To Explore

Take a minute to get to know us

The people behind TechNuCom