Cybersecurity

Cybersecurity for SMEs in Morocco is not just about targeted attacks. Most attacks are simply looking for open doors: a reused password, a workstation never updated, a backup never tested.

SADIS, a Moroccan company based in Laâyoune and Casablanca, secures what it already installs: the network and infrastructure, Microsoft 365, workstations and management software. Security is not a product added at the end; it is a way of configuring everything.

The threats that matter

Audit and vulnerability assessment

The IT security audit begins with an inventory: workstations, servers, accounts, data and access rights. It then checks backups, the firewall, administrator accounts, email, updates and remote access.

The vulnerability assessment covers three scopes: exposed websites, the network and systems. Each finding receives a proportionate action, ranked by priority. Effort goes first to the flaws that can actually be exploited.

The audit also reviews Law 09-08, which requires the protection of the personal data of customers, employees and suppliers, under the oversight of the CNDP. The recommendations and alerts of the DGSSI serve as a reference. SADIS helps apply these rules in your tools, but issues neither certification nor accreditation.

Accounts and access

Most incidents start with an account that has been stolen, guessed or reused. This is the first area to address.

At an industrial company near Casablanca, SADIS unified the on-premises directory and Microsoft 365 with Microsoft Entra Connect. A departure is now handled in a single operation, email included. The engagement is detailed on the Microsoft 365 migration case study page.

Securing firewalls and VPNs

In many SMEs, the operator's router serves as the firewall, with its factory settings. SADIS installs a next-generation firewall (Fortinet, Sophos or pfSense, depending on what is already in place). It filters traffic by application, inspects traffic and logs events.

Remote access and links between sites go through IPsec or WireGuard VPNs, combined with MFA, never through ports open on the Internet. The visitors' Wi-Fi stays separate from the file server.

Hardening completes the setup: unnecessary services disabled, default passwords changed, administration restricted to dedicated accounts.

Workstations, EDR and monitoring

Monitoring relies on Zabbix for equipment status and on Wazuh for security events. A full disk, a failed backup or an abnormal login triggers a centralised alert. Day-to-day follow-up falls under IT fleet maintenance.

Cloud backup and business recovery

A backup that has never been restored is an assumption, not protection. The 3-2-1 rule sets the course: three copies, on two different media, one of them off site.

The disaster recovery plan (DRP) specifies what to restore, in what order and by whom. In the event of an incident, it avoids improvisation:

  1. Isolate the affected workstations from the network.
  2. Alert the right people, with contact details kept off the server.
  3. Assess what is affected and what is not.
  4. Restore in the agreed order: management software, email, files, then the rest.
  5. Fix the entry point and document the incident.

Training teams

No tool can stop a user who types their password into a fake page. Awareness training teaches people to recognise phishing and to verify by phone any change of bank details.

Above all, it builds a reflex: report it right away. A click reported within the minute is easy to handle; hidden for a week, it becomes an incident.

Your access stays yours

Before founding SADIS in Morocco, its founders spent six years on freelance assignments within large French industrial groups. Configurations are documented and administrator accounts belong to your company. A free audit of your existing setup comes before any quote. Our other services are presented on the SADIS Digital page.

Frequently asked questions

Is a small business really a target?

Yes. Most attacks are not aimed at anyone in particular: they look for poorly protected accounts and systems that have not been updated.

Where should we start on a limited budget?

With three measures: MFA on Microsoft 365, tested 3-2-1 backups and updates applied everywhere. The audit then ranks the rest by priority.

Does SADIS issue a compliance certification?

No. SADIS helps apply good practice and Law 09-08 in your tools, without issuing any certification or taking the place of the CNDP or the DGSSI.

What should you do after clicking on a phishing email?

Report it immediately and change the account password. The person in charge of IT then checks MFA, recent sign-ins and email forwarding rules.

How do you cut off access for an employee who is leaving?

In a single operation, thanks to a directory unified between on-premises accounts and Microsoft 365. Any shared passwords they knew must also be changed.

Talk to us about your project

Describe your email setup, your current backups, the number of workstations and what worries you most. Write to contact@sadis.ma, call +212 661 396 943 or use the contact page.