Even with hardened servers, reviewed code and careful access rights, no business system is completely immune. Zero-day vulnerabilities, credential-stuffing attacks, insider threats or a simple failed upgrade can still take Odoo down or expose data.
When it happens, your preparation decides whether it is a short interruption or a business-threatening disaster. This final article in our Odoo security series brings the series together.
Key takeaways
- A backup only counts once you have restored it successfully.
- Follow 3-2-1: three copies, two kinds of storage, one encrypted copy off-site.
- Enforce two-factor authentication for administrators and privileged users.
- Write an incident playbook before you need it, with names, steps and contacts.
Common preparedness gaps
- Untested backups. Nightly backups run for years without anyone restoring one — until the day it matters.
- No audit trail. Without central logs it is impossible to tell how an attacker got in or what they touched.
- No two-factor authentication. Privileged accounts protected by a password alone are easy targets for credential theft.
- No owner. Nobody knows who decides to take the system offline, who calls the hosting provider or who informs customers.
Building resilience
- 3-2-1 encrypted backups. Back up the database and the filestore. Keep three copies on two kinds of storage, with one encrypted copy at a different location or provider.
- Scheduled restore tests. Restore to a test server every quarter and time it, so you know your real recovery time.
- Two-factor authentication. Odoo supports TOTP-based two-factor authentication; require it for administrators and anyone with access to finance or HR data.
- Logging. Keep server, proxy and Odoo logs centrally and long enough to investigate an incident.
- Least privilege. Fewer administrators means fewer accounts to compromise — see access rights and record rules.
Your incident playbook
Write it down and keep a copy outside Odoo. It should cover:
- Who is in charge and how to reach them, including your Odoo partner and hosting provider.
- Containment: how to take the instance offline or block access, disable compromised users and revoke API keys.
- Investigation: where logs live and how to preserve them before anything is changed.
- Recovery: which backup to restore, in what order, and how to check data before going live again.
- Communication: who informs staff, customers and, where required, data-protection authorities.
- Lessons learned: a short review after every incident, with fixes assigned.
How Mediod can help
Mediod helps clients plan backups and recovery, harden their set-up and respond when something goes wrong, as part of our Odoo support and maintenance service. Earlier articles in this series cover each layer: Odoo.sh, dedicated servers, custom modules, AI-generated code, access rights and APIs and webhooks.
Want to secure your custom modules, review AI-generated code or check your Odoo.sh or server set-up? Ask Mediod for a security assessment.
More from our Odoo security series
- Securing Odoo APIs, Webhooks and External Portals
- Access Rights and Record Rules: Protecting Multi-Company Odoo Data
- The AI Coding Boom: Reducing Vulnerabilities in AI-Generated Odoo Code
- Custom Modules and Security Debt: Writing Safe Odoo Apps from Scratch
- Hardening a Dedicated Odoo Server (VPS or On-Premise): An Infrastructure Blueprint
- Odoo.sh Security: What’s Handled for You and What You Still Need to Protect
See all Odoo Security articles →
Want a second pair of eyes on your Odoo security?
Mediod Consulting is an Official Odoo Partner. We review custom modules, access rights, integrations and hosting set-ups, and give you a prioritised list of fixes. Book a free discovery call or request a quotation for a security review.
Frequently Asked Questions
How often should I test Odoo backups?
Restore a backup to a separate test server at least every quarter and after major changes, and check that both the database and the filestore are complete.
Does Odoo support two-factor authentication?
Yes. Odoo supports TOTP-based two-factor authentication with an authenticator app. Administrators can require it for users.
What is the 3-2-1 backup rule?
Keep three copies of your data on two different types of storage, with at least one copy stored off-site. For Odoo, back up both the database and the filestore and encrypt off-site copies.



