Monday, September 7, 2026
HomeArticleFrom Risk to Resilience: Rethinking ERP Security

From Risk to Resilience: Rethinking ERP Security

Rajbinder Singh Sidhu is an ERP and IT Security leader with over 28 years of experience in enterprise technology, ERP, cybersecurity, governance, risk management, and digital transformation. Over the course of his career, he has worked extensively at the intersection of business processes, enterprise applications, security, controls, and technology leadership.

His expertise spans ERP security and risk management, user access and Segregation of Duties (SoD), IT controls, audit readiness, data governance, cybersecurity, business continuity, third-party risk, and emerging technology risks. He is particularly focused on helping organisations move beyond viewing ERP security as a purely technical issue and instead treat it as a business, risk, and governance priority.

Rajbinder is also the author of ERP Security & Risk Management: A Practical Framework for Controls, Governance, and Audit Readiness, a practical guide designed to help CIOs, CISOs, ERP leaders, consultants, auditors, and risk professionals strengthen the security, resilience, and governance of their ERP environments. This book is available on Amazon at: https://amzn.in/d/0hkymwz1 and on Notion Press at: https://notionpress.com/in/read/erp-security-and-risk-management.

Through his professional experience, writing, and thought leadership, he advocates a practical, business-oriented approach to ERP security, one that connects cybersecurity with operational resilience, financial risk, compliance, data integrity, and executive accountability.

In this interview, Rajbinder shares his perspectives on the evolving ERP security landscape, the risks organisations often overlook, and the governance and control measures required to build secure, resilient, and audit-ready ERP environments.

 

Why should ERP security be viewed as a business and governance issue rather than just an IT concern?

ERP security should no longer be viewed as merely an IT concern because an ERP system is not just a technology platform; it is the digital backbone of the business. It supports critical processes such as finance, procurement, manufacturing, supply chain, HR and financial reporting. Therefore, a compromise can quickly become a business disruption, financial loss, compliance failure and reputational crisis.

The key question is not simply, “Was the system technically secure?” but rather, “What is the business impact if this system is compromised or unavailable?” An ERP outage can stop production, delay payments, disrupt supply chains, affect financial reporting and expose sensitive business and personal data.

This makes ERP security a shared responsibility. IT and security teams are responsible for implementing and operating controls, but business leaders must define risk appetite, process owners must own access and segregation-of-duties risks, and senior management and the Board must provide oversight and accountability.

In my view, effective ERP security is therefore a governance issue: it requires clear ownership, risk-based decision-making, continuous assurance and meaningful reporting to leadership. The most mature organizations treat ERP security not as a technical cost, but as an essential component of business resilience, regulatory compliance and enterprise risk management.

 

What are some of the most common security and control gaps you see in ERP environments?

In my experience, the most common gaps in ERP environments are often not caused by a lack of security tools, but by weaknesses in governance, access management and operational discipline.

One major issue is excessive or poorly governed user access. Users may accumulate privileges over time, while access reviews and timely removal of access are often inconsistent. This can also lead to segregation-of-duties conflicts, where one individual can initiate, approve and process a sensitive transaction single-handedly.

Another common gap is the continued use of shared, generic or highly privileged accounts, sometimes without adequate monitoring.

Organizations also frequently struggle with delayed patching and vulnerability management, particularly where ERP changes are considered risky to business operations.

I also see gaps around custom code, interfaces and third-party integrations. These can significantly expand the attack surface but may not receive the same level of security assessment as the core ERP application.

Finally, logging and monitoring are often insufficient. Many organizations collect ERP logs but do not actively analyse them for suspicious activity or integrate them effectively into their broader security operations.

Ultimately, the challenge is that ERP security requires a combination of strong technical controls, disciplined business processes and clear accountability. A technically secure ERP can still present significant risk if access, processes and governance are weak.

 

How significant are user access and Segregation of Duties (SoD) risks for organisations today?

User access and Segregation of Duties, or SoD, risks are among the most significant control risks in ERP environments today. ERP systems sit at the centre of critical business processes, and inappropriate access can enable fraud, financial misstatement, data theft or unauthorized changes without requiring an external cyberattack.

The challenge is that access requirements evolve continuously. Employees change roles, temporary access becomes permanent, and users can gradually accumulate privileges. Without effective access governance, an individual may eventually be able to initiate, approve and process the same transaction, defeating a fundamental internal control.

SoD is therefore not simply an audit or compliance requirement; it is a key mechanism for preventing errors, fraud and abuse of privileged access. The risks become even greater in complex organizations with multiple ERP systems, cloud applications, custom roles and third-party access.

However, identifying an SoD conflict is only the first step. Organizations must determine whether the conflict represents a genuine business risk, whether the access is necessary, and, where it cannot be removed, whether effective compensating controls exist.

In my view, organizations need a continuous, risk-based approach to identity and access governance, covering role design, least-privilege access, periodic reviews, SoD monitoring and timely removal of access. In today’s environment, excessive access should be treated as both a cybersecurity risk and a business control risk.

 

What should organisations do to strengthen data security and controls within their ERP systems?

Organisations should treat ERP data security as a combination of technology, process and governance, rather than relying on perimeter security alone. The first step is to identify and classify critical ERP data, particularly financial, customer, employee, supplier and sensitive master data, and understand where it is stored, processed, transmitted and shared.

Strong role-based access controls and least-privilege principles should be implemented, supported by regular access reviews, Segregation of Duties (SoD) controls and robust privileged-access management. Access should be based on business responsibilities and removed promptly when roles change, or employees leave.

Organisations should also strengthen controls over master data, transactions, interfaces and APIs, because manipulation of these areas can directly affect financial and operational outcomes. Encryption, secure configuration, vulnerability management and controlled change management should form part of the baseline.

Equally important is continuous monitoring. ERP audit logs should be enabled, protected from tampering and actively analysed to detect unusual access, privileged activity and suspicious transactions.

Finally, organisations need clear data ownership, retention and classification policies, third-party controls, incident-response procedures and periodic control testing.

In short, protecting ERP data requires knowing what matters, who should access it, what they can do with it, and continuously verifying that controls are working as intended.

 

How can enterprises effectively manage third-party and vendor risks connected to ERP environments?

Third-party risk in ERP environments should be managed as an end-to-end risk management process, not simply as a vendor due-diligence exercise. Organisations must first understand which vendors, service providers, consultants and technology partners have access to their ERP systems, data and critical processes, and assess that access based on business impact and risk.

Before onboarding a vendor, organisations should conduct appropriate security and risk assessments, covering areas such as identity and access management, data protection, vulnerability management, incident response, business continuity and regulatory compliance. The level of due diligence should be proportionate to the criticality of the service and sensitivity of the data involved.

Security requirements must then be embedded into contracts and Service Level Agreements (SLAs), including confidentiality, security controls, breach notification, audit rights, data location and protection, subcontractor obligations, vulnerability remediation, business continuity, and secure termination or data deletion.

Importantly, vendor risk does not end after contract signing. Organisations should maintain continuous monitoring and periodic reassessment, particularly when vendors have privileged or remote ERP access.

Finally, access should follow least-privilege principles, be time-bound where possible, monitored and promptly revoked when no longer required.

The objective is to ensure that third-party access does not become the weakest link in the organisation’s ERP security and resilience.

 

Why is continuous audit readiness becoming more important than periodic compliance reviews?

Continuous audit readiness is becoming increasingly important because ERP environments are no longer static. Cloud services, frequent system changes, integrations, remote access, new regulations and evolving cyber threats can alter an organisation’s risk profile long before the next scheduled audit.

A periodic compliance review provides a point-in-time assessment. It may identify control weaknesses, but by the time they are discovered, the underlying risk may have existed for months. Continuous audit readiness shifts the focus from preparing for an audit to maintaining a state of ongoing control assurance.

This requires organisations to continuously monitor key controls such as user access, Segregation of Duties, privileged activity, configuration changes, data integrity, vulnerabilities, interfaces and third-party access. Evidence should also be captured systematically so that control effectiveness can be demonstrated when required.

The benefit goes beyond satisfying auditors. Continuous assurance helps management identify emerging risks earlier, reduce remediation costs, strengthen accountability and improve confidence in financial and operational processes.

In my view, audit readiness should be the outcome of good governance, not an annual preparation exercise. Organisations that continuously know their risks, monitor their controls and maintain reliable evidence are better positioned not only for audits, but also for cyber incidents, regulatory scrutiny and business disruption.

 

What role does strong governance play in improving ERP security and risk management?

Strong governance is the foundation of effective ERP security and risk management because it establishes who is accountable, what risks are acceptable, and how controls are designed, monitored and enforced.

ERP environments span multiple business functions, technologies, locations and third parties. Without clear governance, security decisions can become fragmented, with business priorities, IT operations, cybersecurity and compliance working in silos.

Effective governance begins with clearly defined ownership and accountability for ERP processes, data, access and controls. It should establish policies for least-privilege access, Segregation of Duties, change management, data protection, third-party access, incident response and business continuity.

Governance should also connect ERP risks with the organisation’s broader enterprise risk management framework, ensuring that significant risks are visible to senior management and, where appropriate, the Board. Regular control assessments, risk reporting, exception management and remediation tracking help ensure that policies translate into measurable outcomes.

Most importantly, governance should not be limited to policy documents. It requires continuous oversight, evidence-based assurance, and accountability to close control gaps.

In my view, strong ERP governance creates the bridge between technology and business risk. It ensures that ERP security is treated not merely as an IT responsibility, but as a shared business responsibility supporting operational resilience, compliance, financial integrity and organisational trust.

 

How can organisations build greater resilience into their ERP systems and business operations?

Organisations should build ERP resilience by assuming that disruption will occur and designing systems, processes and people to continue operating or recover quickly when it does. Resilience is therefore broader than disaster recovery; it encompasses cybersecurity, technology, processes, people, suppliers and business decision-making.

The starting point is to identify business-critical ERP processes and their dependencies, determine acceptable recovery objectives, and assess scenarios such as ransomware, system failure, data corruption, cloud or third-party outages, and loss of key personnel.

Organisations should then establish appropriately designed backup, disaster recovery and business continuity capabilities, with resilient infrastructure, tested recovery procedures and clearly defined RTOs and RPOs. Backups should be protected against unauthorised access and ransomware and, critically, recovery should be tested regularly rather than assumed to work.

Resilience also requires strong preventive controls, particularly identity and access management, privileged-access controls, change management, vulnerability management, monitoring and incident response, to reduce the likelihood and impact of disruption.

Finally, organisations should conduct realistic business continuity and cyber-recovery exercises involving business owners, IT, cybersecurity and critical third parties.

Ultimately, ERP resilience means ensuring that the organisation can protect critical operations, detect disruption quickly, recover reliably, and continue serving customers even when technology or external dependencies fail.

 

What are the biggest challenges enterprises face while balancing operational efficiency with strong security controls?

The biggest challenge is that security and operational efficiency can appear to have conflicting objectives. Business teams want speed, flexibility and uninterrupted operations, while security and compliance teams need controls, approvals and restrictions to manage risk.

This tension is particularly visible in ERP environments. Excessive access restrictions can delay legitimate business activities, while overly broad access can create fraud, data loss and compliance risks. Similarly, strong change controls can reduce the risk of unauthorised changes, but poorly designed processes can slow critical business improvements.

The answer is not to weaken controls, but to make them risk-based, intelligent and proportionate. Organisations should distinguish between high-risk and low-risk activities, apply stronger controls where the potential business impact is greater, and automate routine control processes wherever possible.

For example, automated access provisioning and de-provisioning, continuous SoD analysis, privileged-access management, workflow-based approvals and real-time monitoring can strengthen security without creating unnecessary friction.

Equally important is involving business process owners in security decisions. Controls designed without understanding operational realities often become workarounds rather than effective safeguards.

Ultimately, the goal should be secure-by-design operations where security is embedded into business processes and technology rather than added as a barrier afterwards. The right measure is not how many controls an organisation has, but whether those controls reduce material risk while enabling the business to operate effectively.

 

How is AI and intelligent automation changing the security and risk landscape for enterprise systems?

AI and intelligent automation are fundamentally changing the enterprise security and risk landscape by creating new capabilities as well as new risks. In ERP environments, AI can analyse large volumes of access, transaction and system activity to identify anomalies and patterns that traditional, rule-based controls may miss.

It can strengthen areas such as continuous control monitoring, fraud detection, user-behaviour analytics, vulnerability prioritisation, threat detection and incident response. Automation can also reduce human error by accelerating access reviews, SoD analysis, control testing and remediation workflows.

However, AI introduces a new dimension of risk. Organisations must consider data privacy, model security, unauthorised AI access, inaccurate or biased outputs, prompt manipulation, intellectual-property exposure and the use of unapproved AI tools. AI integrated directly with ERP processes creates additional concerns because an incorrect or manipulated recommendation could influence financial, procurement, HR or supply-chain decisions.

The governance challenge is therefore to ensure that AI operates within clearly defined permissions, controls, human oversight and accountability frameworks. Organisations need to know what data AI can access, what actions it can take, how its decisions are monitored, and who remains accountable for those decisions.

Ultimately, AI should not be viewed simply as another security tool. It is both a powerful control-enabler and an emerging risk domain that requires its own governance, security and assurance framework.

 

What new risks should organisations consider as AI becomes more deeply integrated with ERP and business processes?

As AI becomes embedded in ERP and business processes, organisations need to look beyond traditional cybersecurity risks and consider AI-specific risks that can directly affect business decisions and transactions.

One key concern is excessive AI autonomy. If AI agents are given broad permissions to create, modify, approve or execute ERP transactions, a compromised or incorrectly configured agent could cause significant financial or operational impact. This makes identity, least privilege and human oversight critical.

Organisations must also address data leakage and privacy, particularly where AI models can access sensitive financial, employee, customer, supplier or business secrets like product recipe information. Other risks include prompt injection, model manipulation, inaccurate or hallucinated outputs, model drift, data poisoning and inadequate traceability of AI-generated decisions.

There is also the challenge of shadow AI, employees using external AI tools with ERP data without adequate organisational approval or controls. Third-party AI services introduce additional risks around data residency, security, subcontractors and intellectual property.

Finally, organisations need clear AI governance and accountability: defining what AI is permitted to do, what decisions require human approval, how AI activity is logged and monitored, and who is responsible when an AI-driven process produces an undesirable outcome.

Ultimately, as AI moves from advising humans to acting on their behalf, organisations must extend ERP security and internal controls to cover the AI agents themselves.

 

Based on your experience and the key themes of your book, what are the most important steps organisations should take to build a secure and audit-ready ERP environment?

Based on my experience and the key themes of my book, organisations should take a risk-based, business-led approach to building a secure and audit-ready ERP environment.

The first step is to identify critical business processes, ERP assets, sensitive data and their dependencies, and assess the risks associated with them. This should be followed by strong identity and access management, including least privilege, role-based access, privileged-access controls and continuous Segregation of Duties (SoD) monitoring.

Organisations should establish robust controls over master data, transactions, interfaces, configurations and custom developments, supported by secure change management, vulnerability management, logging and continuous monitoring.

Third-party and cloud ERP risks also require appropriate due diligence and contractual safeguards, while business continuity, disaster recovery, ransomware preparedness and incident response should be regularly tested.

Equally important is governance: every critical control should have a clearly defined owner, measurable requirements, documented evidence and a process for managing exceptions and remediation.

Finally, organisations should move from periodic audit preparation to continuous control assurance, using automation where possible to monitor controls and maintain reliable evidence.

My fundamental message is simple: an audit-ready ERP is not created just before an audit. It is the result of continuously managing risk, operating effective controls and maintaining evidence that demonstrates those controls are working.

 

 

 

 

 

 

 

 

RELATED ARTICLES
- Advertisment -
Google search engine

Most Popular

Recent Comments