Skip to content
Cybersecurity

Security audit or penetration test: which one for an SMB in Morocco?

IT security audit or penetration test in Morocco: differences, scopes, deliverables, how to read the report and the right order for an SMB.

By the ALLSAFE SOLUTIONS engineering team1 October 20266 min read
Secured server room

“We need a pentest.” The request often comes after an incident at a peer company, a customer requirement or an article about ransomware. Yet for most SMBs it is not the first thing to do. Short answer: a security audit checks all your protections and practices and produces an action plan; a penetration test simulates an attack on a precise scope to prove what can actually be exploited. The first tells you where you stand, the second shows how far an attacker would get. In the vast majority of cases, the audit comes first.

This guide is for SMB owners and IT managers in Morocco who want to know what to order, from whom, and how to read the report. It complements our article on the IT audit of an SMB, which is broader and also covers hardware, costs and continuity.

Security audit vs penetration test: the differences

Criterion Security audit Penetration test
Question asked Which protections are missing or misconfigured? Can an attacker get in, and how far?
Method Interviews, configuration review, technical checks Simulated, authorised and controlled attack
Scope Broad: organisation, accounts, network, backups, endpoints Narrow and defined: an address, an application, a network
Output Prioritised action plan List of exploited vulnerabilities, with evidence
Who does it Security and systems engineer Offensive specialist, ideally qualified
Best timing First, then regularly After the audit’s fixes, on exposed areas

They are not opposites: they follow one another. A penetration test run on a network without MFA, with former employees’ accounts still active and an over-permissive firewall, is an expensive way to confirm what an audit would have listed in a day.

What a security audit covers

A useful security audit for an SMB looks at what attackers exploit first:

  • Identities: admin accounts, former employees, shared passwords, MFA on email and remote access.
  • The perimeter: firewall rules, services exposed to the internet, VPN, up-to-date firmware.
  • Email and cloud: Microsoft 365 or Google Workspace security settings, anti-spoofing, external sharing. See secure Microsoft 365 in 10 settings.
  • Endpoints: antivirus or EDR, patching, local admin rights, laptop encryption.
  • Backups: offsite copy, immutability, restore test.
  • Segmentation: separation of endpoints, servers, cameras and guest Wi-Fi.

The result is an assessment and an action plan ranked by priority. It is the basis on which a penetration test, if needed, can be targeted.

Possible scopes for a penetration test

A penetration test is ordered on a precise scope. The four most common for an SMB:

  1. External: what an attacker sees from the internet. Public IP addresses, VPN, portals, email, forgotten services. This is the most relevant scope to start with.
  2. Internal: the tester starts from a device plugged into your network, like a compromised employee or a visitor. It measures whether a compromised endpoint can reach servers, the directory and backups.
  3. Web application: your online shop, customer extranet or exposed business application. The test targets authentication, permissions, injection and data leakage.
  4. Phishing simulation: a fake message sent to your teams to measure who clicks and who enters credentials. Useful to steer awareness training, provided management is informed and no individual is singled out. The most frequent scenarios are described in 8 phishing scams targeting SMBs in Morocco.

You also choose how much information the tester gets: black box (nothing), grey box (a standard user account) or white box (access to documentation). For an SMB, grey box often gives the best balance between realism and depth.

The framework to set before any test

A penetration test without a written framework is an attack. Unauthorised access to an information system is a criminal offence in Morocco, even with good intentions. Before starting, require:

  • a written authorisation signed by management, listing precisely the addresses, applications and accounts in scope;
  • the dates and times of the test, with a reachable contact on each side;
  • the exclusions: no denial of service, no changes to production data, immediate stop if there is an impact;
  • the agreement of the hosting provider or cloud vendor if the scope sits with them;
  • a confidentiality commitment covering the results and any data seen during the test.

Reading a report: what it must contain

Whether for an audit or a penetration test, a good report reads at two levels.

  • An executive summary: overall risk level, three to five major findings, decisions required.
  • A technical section: for each finding, the description, the evidence (screenshot, request, account obtained), the severity, often expressed with a CVSS score, and the recommended fix.
  • A remediation plan: who fixes what, in which order.
  • A retest planned after the fixes, to confirm the weaknesses are really closed.

Be wary of a report that is just the raw output of an automated scanner, with no proof of exploitation and no context: that is not a penetration test. And rank findings by your business, not only by score: a “medium” weakness on the payroll server may come before a “high” one on an isolated test machine.

Useful Moroccan references

The DGSSI publishes an information systems security audit guide (in French), written to help public administrations and bodies define their audit needs against the National Information Systems Security Directive (DNSSI). The DGSSI also publishes a qualification framework for audit providers, which concerns the sensitive information systems of critical infrastructure operators. A private SMB is generally not subject to it, but these documents are a good grid to frame a request.

On personal data, law 09-08 requires security measures appropriate to the risks. A documented audit followed by fixes is a concrete way to show you have assessed them.

Common mistakes

  1. Ordering a penetration test before fixing the basics: MFA, accounts, backups, firewall.
  2. Confusing an automated vulnerability scan with a penetration test.
  3. Running a test without written authorisation or a precise scope.
  4. Forgetting to inform the host or vendor of the tested site.
  5. Filing the report away without a remediation plan or retest.
  6. Having security assessed only by the provider who installed it.

Checklist before ordering

  • Security audit done and immediate priorities fixed.
  • Test objective stated: customer requirement, exposed application, validation of fixes.
  • Scope listed: addresses, applications, networks, test accounts.
  • Level chosen: black, grey or white box.
  • Written authorisation, schedule, contacts and exclusions approved.
  • Report format and retest included in the proposal.
  • Team or provider designated to apply the fixes.

How we do it

At ALLSAFE SOLUTIONS, the initial audit is free. Our engineers check identities, the firewall, email, endpoints, backups and segmentation, and give you a prioritised action plan. We do not present ourselves as a certified penetration testing firm: when your situation justifies a targeted penetration test, we help you define its scope and specifications, refer you to a specialised provider, then apply the fixes, notably on firewalls from our partners Fortinet and WatchGuard.

The fixes then become part of our business cybersecurity offering, with 24/7 monitoring and critical incidents handled in under 15 minutes, for example through managed EDR. Anonymised examples are available in our case studies.

To find out where your security really stands before ordering anything, request your free audit: we reply within 24 business hours.

Frequently asked questions

What is the difference between a security audit and a penetration test?

An audit compares your organisation, configurations and practices with a reference framework and produces an overall action plan. A penetration test is a simulated attack, authorised in writing, on a defined scope: it shows which weaknesses can actually be exploited and how far an attacker could go.

Where should an SMB start?

With the audit. It reveals the most common weaknesses, such as missing MFA, poorly protected backups or an over-permissive firewall. A penetration test run before these are fixed only confirms what the audit would have found.

When does a penetration test become necessary?

When you expose an application or website that handles data, when a customer or principal requires it, after a major redesign, or to check that the fixes from an audit hold up against a real attack.

Is there a Moroccan reference for security audits?

Yes. The DGSSI publishes an information systems security audit guide, aimed primarily at public administrations and bodies, as well as a qualification framework for audit providers. An SMB can use them to frame its approach.

About the editorial team

ALLSAFE SOLUTIONS

Network, security and cloud engineers

Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.

LinkedIn
← All articles
CallWhatsAppFree audit