Securing Your ERP in the Cloud

Cloud Security

Securing Your ERP in the Cloud

RFR Group Consulting Team20 July 2026 6 min read
Back to Knowledge Hub

Your finance team closes the month in the ERP. Your customer pricing, supplier terms, payroll and inventory all live there. So when the board asks "is it safe in the cloud?", the honest answer is: it depends on decisions you still own, because moving to a hosted platform changes where the risks sit, it doesn't remove them.

GCC businesses are moving Sage and other core systems to the cloud faster than ever, drawn by resilience, remote access and freedom from server rooms in 45-degree summers. That is usually the right call. But the organisations that sleep well afterwards are the ones that got a handful of practical things right. Here is what actually matters.

Access control: your side of the fence

The single largest source of ERP incidents is not sophisticated attack. It is excessive access. Accounts that were never disabled when someone left, broad roles handed out during a busy go-live and never revisited, shared logins on the warehouse floor.

In a cloud deployment, the disciplines that protect you are unglamorous:

  • Individual accounts, always. No shared logins, including on the shop floor. Shared credentials make audit trails meaningless.
  • Multi-factor authentication for every user, and without exception for administrators and external consultants. MFA almost entirely stops the most common attack, which is stolen passwords.
  • Role-based access reviewed on a schedule. Match roles to jobs, not to people, and review them quarterly. Leavers should lose access the day they leave; joiners should get the minimum they need.
  • Segregation of duties enforced in the system. The person who creates a supplier should not be the person who pays it. Your ERP can enforce this; it only works if roles were designed to allow it.

A distributor in Jeddah we worked with discovered, during a routine review, that seventeen ex-employees still had active accounts two years after a migration. Nothing bad had happened. The review took an afternoon. That is the point: these controls are cheap precisely because they are boring.

Backups and recovery: ask until you get specifics

"My vendor backs everything up" is not a recovery plan. The questions that matter are about restoration, not backup:

  1. How often is data backed up, and how long is it retained? Daily snapshots retained for 30 days are common; know your actual terms.
  2. How quickly can you restore, and to what point? A recovery time objective of "best efforts" is not an objective.
  3. When did someone last prove it? A backup that has never been test-restored is a hope, not a control.

For most mid-market businesses, an annual restore test is the difference between confidence and assumption. That means actually recovering last month's data to a separate environment and checking it. Put it in the calendar.

Vendor responsibility versus your responsibility

Cloud works on a shared responsibility model, and misunderstanding it is where organisations get caught out. Broadly:

  • The platform provider secures the data centres, the physical hosts, the network and the base infrastructure, and keeps the platform patched and available.
  • You remain responsible for who has access and what they can do, the data you put in, your endpoints (the laptops and phones people log in from), your joiners-and-leavers process, and your own configuration choices.

The dangerous assumptions sit in the gap: believing the vendor monitors your user behaviour, restores a record one of your users deleted, or stops a finance clerk being tricked by a fraudulent payment instruction. They don't. Business email compromise, where a convincing "supplier" asks to change bank details, is a process problem, not an infrastructure one, and it remains the most common way Gulf businesses lose money through their ERP.

Compliance and data residency: the questions to ask

Regulation in the region is evolving quickly, and "it's in the cloud" is not an answer your auditor will accept, and increasingly your customers won't either. Before signing, get written answers to:

  • Where will our data physically reside? Which country and which data centre? Does that include backups and disaster-recovery replicas?
  • Does that location satisfy our obligations? Saudi Arabia's PDPL and sector rules (for example from SAMA for regulated entities) have residency expectations; UAE requirements differ by emirate and industry. If you operate in both, ask the question per entity.
  • Who at the vendor can access our data, under what controls, and is that access logged?
  • What happens to our data if we leave? Export formats, timelines and certified deletion should be contractual, not conversational.
  • Which certifications does the platform hold? ISO 27001 and SOC 2 reports are baseline evidence; ask to see them.

None of these questions are adversarial. A competent provider answers them in writing, quickly. Reluctance to do so is itself an answer.

Where to start

Cloud ERP, properly governed, is more secure than the server under the stairs it replaces. But "properly governed" means access reviews that happen, restores that get tested, and a clear-eyed view of which responsibilities never left your desk.

If you're planning a move, or you're already in the cloud and unsure where you stand, an RFR Group security and readiness assessment will map your current controls against this framework and hand you a prioritised list, not a lecture.

cloudsecuritymigration

Want to Talk Through Your Own Situation?

Book a free assessment. We will look at what you are running, what is not working, and whether Sage is the right fix.