Skip to content

Häufig gestellte Fragen

Is cloud ERP fundamentally more secure than on-premises?
A blanket answer falls short, because security is split according to the shared responsibility model: the cloud provider is responsible for the physical infrastructure and platform, while the customer remains responsible for permissions, identity management and data classification. Large hyperscalers employ several hundred security specialists, operate data centres attested to standards such as ISO 27001, SOC 2 and the German BSI C5 catalogue, and often patch vulnerabilities very quickly — something a small internal IT department rarely matches. The most common cause of cloud security incidents, however, is not gaps on the provider's side but customer configuration errors such as excessive permissions or unsecured API endpoints, the avoidance of which, according to Gartner, lies predominantly with the customer. What matters is therefore less the deployment model than a consistent security architecture with zero-trust principles and a tested disaster recovery strategy.
Which industries should lean towards on-premises or private cloud?
Typically companies with deep OT integration such as machinery manufacturing, metalworking or the process industry, whose ERP is tightly interlinked with MES, SCADA or PLM systems, as well as regulated industries such as pharmaceuticals, medical technology or defence with strict data residency and auditability requirements. Organisations with very deep customisation or in-house developments that cannot be reproduced in standardised public cloud versions are also often better served by private cloud or on-premises. Service providers, e-commerce companies and skilled trades businesses with largely standardisable processes, by contrast, usually benefit from public cloud SaaS. In practice, the private cloud is frequently the pragmatic middle ground, because it combines customisation depth with outsourced operations and EU data residency.
When is on-premises more economical than cloud ERP?
Over very long investment cycles, classically licensed on-premises software can pay off, because the ongoing subscription costs of the cloud, summed over ten to fifteen years, can exceed the one-off capital costs. The prerequisite, however, is that a largely depreciated data centre is available and an experienced internal IT team sustainably carries security, high availability and patch management. In addition, on-premises incurs annual maintenance and software support fees of typically around 18 to 22 percent of the licence total, which belong in every TCO calculation. The comparison only becomes reliable through TCO modelling over five to seven years that fully accounts for licences, implementation, internal effort, hosting and release upgrades.
What does a switch from on-premises to cloud ERP cost?
The costs depend heavily on the state of customisation and the chosen migration path, and can reach a substantial share of the original implementation costs. A greenfield migration, i.e. a clean re-implementation in the cloud, causes higher initial effort than a brownfield approach, which largely carries over existing structures, but in return it clears out outdated customisations and focuses on the standard, which is often cheaper and more stable in the long run. Brownfield approaches are cheaper and less disruptive in the short term, but carry technical legacy into the new environment. A reliable figure can only be determined per project after taking stock of interfaces, workflows and special logic, which is why a proof of concept on two to three critical processes is advisable before the budget is approved.
What GDPR and CLOUD Act risks exist with US cloud providers?
Public cloud providers with a US parent company are subject to the US CLOUD Act, which under certain circumstances grants American authorities access to data even when it is stored in European data centres. The EU-US Data Privacy Framework, whose adequacy decision was issued in July 2023, does regulate the adequacy of commercial data transfers, but it does not remove the governmental access rights arising from the CLOUD Act and FISA 702, and following the Schrems II ruling of 2020, the legal situation remains in flux due to a pending challenge to the framework before the CJEU. For particularly sensitive data categories such as HR, health or trade secret data, EU sovereign cloud options or European providers are therefore recommended, along with technical measures such as customer-managed encryption keys, with which the provider itself cannot decrypt the data. A systematic data classification and a proper data processing agreement, including scrutiny of sub-processors, are the foundation for this.
How do we prevent vendor lock-in with cloud ERP?
The most important lever is an exit strategy anchored in the contract from the start, with clear clauses on data export, interface openness and transition support in the event of termination. Make sure you can export data in standardised formats such as CSV, JSON or XML, use standard APIs, and anchor customisation in separate layers or microservices rather than in the core system wherever possible. A minimum transition support period of twelve to eighteen months after termination provides realistic room for an orderly migration, and vendor-independent documentation of configurations, workflows and permissions is the basis for re-implementation in an alternative system. An annual test export ensures that the exported data is actually complete and interpretable when it counts, because an exit plan that has never been tested is of no help in a crisis.