AUSTRALIAN OWNED & OPERATEDMICROSOFT 365 & AZURE SPECIALISTSE8 & ISO 27001 READINESS
Home/Guides/Cloud ERP Infrastructure: What Australian Business Needs
// guides · cloud infrastructure

Cloud ERP Infrastructure: What Australian Business Needs

Every cloud ERP pitch talks about the software. Almost none of them talk about who's responsible for your backups, your access control and your data residency once you've signed.

Published 13 July 2026

DI

Written by

Davide Iaione

Founder & Director, Cloudaid Pty Ltd

Davide Iaione is the Founder & Director of Cloudaid, a Sydney-based managed service provider and IT security consultancy built for professional services firms and growing businesses. He writes from over a decade in Australian IT, across contact-centre leadership, desktop support and independent consulting.

Key takeaways

  • “Cloud ERP” covers two different setups: SaaS ERP (Xero, NetSuite) where the vendor runs everything, and traditional ERP lifted onto cloud infrastructure you're still responsible for securing.
  • Your ERP vendor's uptime guarantee doesn't cover your backups, your access controls or your data residency. That's the infrastructure layer, and it's usually where businesses get caught out.
  • Cloud providers work on a shared responsibility model: the provider secures the cloud and you secure what's in it. Identity, access and configuration are yours regardless of which ERP you pick.
  • Most Australian SMBs don't need to solve the ERP and the infrastructure separately. A managed cloud partner should own the infrastructure side, so the software choice is the only decision left.

Cloud ERP is two different things wearing the same label. Software-as-a-service ERP, like Xero or NetSuite, runs entirely on infrastructure the vendor owns and secures. Traditional ERP (on-premises Dynamics NAV or Business Central, older SAP deployments) can be lifted onto cloud infrastructure like Azure, but someone still has to provision, secure and back up that infrastructure. Vendors rarely explain which one you’re buying.

That distinction matters more than most ERP sales conversations let on, because it decides who’s holding the bag when something goes wrong. A slick product demo doesn’t tell you who’s responsible for your backups. This guide does.

What Counts as “Cloud ERP”?

If your ERP is SaaS (you log into a URL, the vendor pushes updates, and there’s no server for anyone to patch), the vendor owns the infrastructure entirely. Xero, most of NetSuite, and modern Dynamics 365 Business Central all fall into this bucket. You’re buying access, not infrastructure.

If your ERP was “lifted and shifted” onto cloud virtual machines (a traditional on-premises-style ERP now running in Azure instead of a server in your office), you or your provider are still responsible for that infrastructure. It’s cloud in the sense that it’s off-site. It’s not cloud in the sense that someone else handles the operational load.

The Infrastructure Questions Vendors Don’t Answer

Every ERP vendor will quote you an uptime figure. Almost none of them will volunteer answers to the questions that determine whether your business recovers cleanly from a bad day: how backups work, who can access the data, and what happens when a staff member leaves.

In practice, the problem is rarely the ERP software. The businesses that get burned are the ones who assumed the vendor had their backups covered, their access reviewed and their integrations locked down, and found out otherwise during an incident rather than before one.

Who’s Responsible for What: The Shared Responsibility Model

Cloud providers like Microsoft operate on a shared responsibility model: the provider secures the infrastructure underneath the cloud, and you’re responsible for what you put on top of it. That means your data, your identities and your access policies. Your ERP vendor operates inside that same model one layer up, and the split doesn’t disappear just because the product looks polished.

ResponsibilitySaaS ERP (Xero, NetSuite)Self-hosted ERP on cloud VMs
Platform uptime & patchingVendorYou or your provider
Point-in-time data recoveryUsually you (check the fine print)You or your provider
User access & MFAYouYou
Data residency choiceVendor decides, sometimes selectableYou choose the region

Does Cloud ERP Meet Australian Data Residency Requirements?

Not automatically. Some ERP platforms let you pin your data to an Australian region; others default to wherever’s cheapest for the vendor unless you specifically request otherwise. If your ERP holds employee or customer personal information, that’s a question worth resolving against the Australian Privacy Principles before you commit, not after an auditor asks.

This is the same question to ask about Microsoft 365 and Azure environments generally. Data residency is a setting, not a guarantee, and it only counts if someone has checked it.

Who Should Manage This?

If you’re running a SaaS ERP, you don’t need someone hosting servers. You need someone managing the identity and access layer that connects your team to it: enforcing MFA, reviewing who has access after someone leaves, and making sure the ERP isn’t the weak link in an otherwise secure environment.

If you’re running self-hosted ERP on cloud infrastructure, you need that plus someone accountable for the servers themselves. That covers patching, backups that are tested (not just scheduled), and a real recovery plan rather than an assumption that one exists.

Either way, this isn’t a separate project from the rest of your IT. It’s the same managed cloud and security work that covers the rest of your environment, applied to the system that happens to run your finances. Book a discovery call if you want a second opinion on what your current setup is actually covering.

Frequently asked questions

Is cloud ERP automatically backed up?
Usually not in the way you'd assume. Most SaaS ERP vendors protect against their own outages, not against your mistakes. An accidental deletion or bad import often isn't recoverable from vendor backups alone, so ask specifically about point-in-time recovery as well as uptime.
Does moving ERP to the cloud meet Australian data residency requirements?
It depends entirely on the vendor and the plan you're on. Many major ERP platforms let you choose an Australian hosting region, but it's rarely the default. Confirm the region in writing before you sign.
Who's responsible for ERP security in a SaaS model?
It's shared. The vendor secures the platform itself: patching, infrastructure and uptime. You're responsible for who has access, whether MFA is enforced, and what other systems are allowed to connect to it.
If I use a SaaS ERP like Xero, do I still need a cloud infrastructure provider?
Not for hosting the ERP itself. The vendor does that. You'll still usually need someone managing the identity, device and network side that connects your team to it, especially once you're relying on it for anything financial.
What's the real difference between self-hosted and SaaS ERP here?
Self-hosted ERP means you (or your provider) provision and secure the actual servers it runs on. SaaS ERP removes that layer entirely, but shifts the remaining responsibility onto access control and the integrations you connect to it.

Get the infrastructure layer right

Cloud modernisation and identity security across Microsoft 365 and Azure, covering the layer underneath whatever ERP you choose.