Skip to content
CRYSTAL ITIT Solutions
ERP & Management

Backing Up and Securing Management Data: What Every Moroccan SME Should Have in Place

August 2, 20268 min read
Backing Up and Securing Management Data: What Every Moroccan SME Should Have in Place

Ask yourself the question coldly: if the computer hosting your management system burned down tonight — or if ransomware encrypted your files tomorrow morning —, what would remain of your company? Invoices issued and awaiting collection, the accounting of current and past financial years, the customer file built over fifteen years, stock, payroll: management data is an SME's most concentrated asset, and often its least protected. Many Moroccan companies still live with a management system installed on a single computer, a "backup" on an external drive permanently plugged in — therefore encryptable by the same ransomware —, and no idea how long it would take to start again. The good news: protecting yourself seriously requires neither a large group's budget nor rare expertise, but a few principles applied with constancy — and the choice of a suitable hosting model. This guide covers the real risks, the 3-2-1 rule, the restore test, the sharing of responsibilities under SaaS, and access rights — with what Crystal ERP (erp.crystalit.ma) takes care of for its customers.

Management data: the most concentrated and least protected asset

What makes management data critical is its dual status. It is first vital for operations: without the customer file, the balances and the invoices, activity stops — impossible to deliver, invoice, chase payment, pay. It is then required by law: accounting documents and supporting records must be kept for ten years in Morocco, and the DGI's electronic invoicing adds a requirement to archive structured invoices (Electronic invoicing in Morocco in 2026). Losing this data is therefore not only an operational problem: it is a legal and tax exposure.

Yet loss scenarios are anything but theoretical, and the most frequent is not the most spectacular. Before ransomware, there is the never-backed-up disk that fails, the laptop stolen from a car, the unfortunate deletion by a hurried user, the file overwritten with a bad version, the acrimonious departure of an employee who alone held the credentials. Each of these ordinary scenarios is enough to erase years of management. The question to ask is not "can this happen?" but "how much time and data would we lose if it happened tomorrow?" — and if the answer is "we don't know", it means "too much".

  • Vital for operations: without customers, balances and invoices, activity stops the same day.
  • Required by law: accounting documents kept for ten years, electronic invoices archived.
  • The ordinary risk first: disk failure, stolen laptop, accidental deletion, overwritten file.
  • Ransomware next: it also encrypts the external drive permanently plugged into the same computer.
  • Two figures to know: how much data lost (hours? days?) and how long to start again.

The 3-2-1 rule: the minimum standard explained simply

The 3-2-1 rule sums up decades of disasters in one formula: three copies of the data, on two different media, one of them off-site. Three copies, because a single backup can itself be faulty at the precise moment it is needed. Two different media, because one batch of disks can age the same way and one system can be compromised all at once. One off-site copy, because a fire, water damage or a burglary takes everything in the same place — the backup sitting on the server it protects protects nothing.

Two clarifications make the rule genuinely effective. The first: at least one copy must be disconnected or out of an attacker's reach — modern ransomware seeks out and encrypts backups reachable from the network; an isolated copy (unplugged medium or immutable-version storage) is the only reliable rampart. The second: backups must be automatic and monitored — the one that relies on "someone remembers to plug in the drive on Friday" stops at the first busy week, and nobody notices before the disaster. The frequency follows from the question raised above: if losing one day of entries is acceptable, a daily backup is enough; if activity is intense, tighten it.

  • 3 copies: the live data plus two backups — a single backup is a gamble.
  • 2 different media: disk and cloud, or server and removable medium — never the same basket twice.
  • 1 off-site copy: fire, flood and burglary take everything in the same place.
  • One copy out of the network's reach: ransomware encrypts any backup it can see.
  • Automatic and monitored: an alert must flag any failed backup — without waiting for the disaster.

Backing up is not enough: restoring, and proving it

The shameful secret of backups is that a significant share cannot be restored when the day comes: corrupted files, a backup incomplete for months, a lost encryption password, a format unreadable on the new hardware, a procedure known only to an unreachable service provider. A backup only has value if it is restorable, and that can only be established by trying. Hence the practice that separates protected companies from reassured ones: the periodic restore test — actually restoring, on a test environment, a recent data set, and verifying that a usable management system is recovered.

This test answers the two questions that matter, the ones every director should be able to state: the RPO — how much data is lost at most (the gap between two backups) — and the RTO — how long it takes to become operational again. An annual test is a minimum; half-yearly is reasonable for an active management system. Finally, the procedure must be documented — where the backups are, how to restore them, who knows how, which passwords — and kept somewhere other than on the system it is supposed to save. Ten pages suffice; their absence turns a technical incident into a company crisis.

SaaS or local server: who is responsible for what

The hosting model radically changes the burden on the company. With a management system installed on a local server or computer, everything above — the 3-2-1 rule, automation, the off-site copy, restore tests, security updates, the UPS, replacing ageing hardware — falls to the SME, with the skills that implies and that are precisely lacking in most small organisations. It is not impossible; it is a profession, and you must consciously decide whether to practise it or delegate it.

With a SaaS ERP, the infrastructure, backups, redundancy and security updates fall to the vendor, who industrialises them for all its customers — a level of protection an isolated SME can hardly afford on its own (SaaS ERP: why Moroccan companies are moving to the cloud to run their…). That is the architecture of Crystal ERP (Crystal ERP): management data is hosted, backed up and monitored by CRYSTAL IT, and the company accesses its ERP through a browser, including after a computer is stolen — which becomes a simple hardware replacement. The honest counterpart: SaaS does not exempt the company from its own duties — access security (see next section), protecting the workstations, and backing up what lives outside the ERP, office files and email first. The right question to put to any vendor remains: which backups, at what frequency, tested how, restorable in how long?

  • On-premise: backups, updates, hardware and tests fall to the company — it is a profession.
  • Under SaaS: the vendor industrialises backups, redundancy and security for all its customers.
  • The theft or failure of a workstation becomes a non-event: the data is not on it.
  • SaaS does not cover everything: access, workstations and files outside the ERP remain the SME's responsibility.
  • Questions for the vendor: backup frequency, restore tests, recovery time.

Access: the half of security that costs nothing

A major share of data losses comes neither from failures nor from hackers, but from poorly managed access. The single account shared by the whole team — impossible to know who did what; the password stuck to the screen or identical everywhere for years; the former employee whose access nobody revoked; the intern with the same rights as the CFO. These ordinary negligences expose the company as much as ransomware does, and can be eliminated without spending a dirham: named accounts for everyone, rights aligned with the job — the salesperson invoices but does not delete, the storekeeper moves stock but does not see payroll —, an access review at every departure and once a year, and strong, unique passwords, ideally handled by a dedicated password manager.

These practices meet a legal obligation: as soon as a company processes personal data — and a customer file is personal data —, Law 09-08 requires appropriate protection measures, under the supervision of the CNDP (Cybersecurity and law 09-08). The differentiated access rights and traceability a modern ERP offers — who created, modified, deleted what and when — are its basic building blocks; Crystal ERP provides them natively, up to multi-company profiles for groups (Managing Several Companies and Several Sites in One ERP). The security of management data is ultimately not a technical subject but a management one: deciding what must survive a disaster, verifying that you could restore it, and knowing who has control over what. Three decisions, and the company sleeps better.

  • Named accounts for everyone: a shared account makes all traceability impossible.
  • Rights aligned with the job: everyone sees and does what their role requires, nothing more.
  • Revoke access the day an employee leaves — and review all rights once a year.
  • Unique, strong passwords, managed properly — not the same one everywhere for five years.
  • Law 09-08: protecting the customer file is not optional, it is an obligation supervised by the CNDP.

An SME's management data — invoices, accounting, customers, stock, payroll — concentrates years of work and legal retention obligations; its loss is one of the rare events capable of putting a healthy company in peril over a weekend. Yet protection comes down to a few things: the 3-2-1 rule with one copy out of reach, automatic and monitored backups, a restore test that proves you could start again, named accounts with adjusted rights — and a hosting choice made consciously. It is one of the fundamental arguments for SaaS ERP: with Crystal ERP (erp.crystalit.ma), hosting, backups and infrastructure security are industrialised by CRYSTAL IT, a vendor based in Rabat for more than 20 years, while the company keeps control of its access and its usage. Ask yourself the opening question — what would remain tomorrow morning? — and if the answer leaves you in doubt, contact the CRYSTAL IT team: taking stock of your management data is the natural starting point.

Have a project or a question? Let's talk with a CRYSTAL IT expert.

Request a demo