Table of Contents
Cybersecurity in Morocco: Key Statistics and Insights
Morocco has made significant strides in technology and digitalization, transforming administration services, education and government operations. That shift brought our data and privacy into the digital realm — and with it a critical question: is Morocco prepared for the challenges of cybersecurity in Morocco?
This page is a reference for journalists, researchers, businesses and IT professionals. Every figure is attributed to its original source so it can be checked and cited; where sources disagree, we explain why.
Last reviewed and updated: August 2026. Originally published July 2024.
Morocco Cybersecurity at a Glance (2026)
| Indicator | Latest figure | Source (year) |
|---|---|---|
| ITU Global Cybersecurity Index | 97.5/100 — Tier 1 “Role-modelling” | ITU GCI, 5th ed. (2024) |
| National Cyber Security Index | 79.17% — 44th | e-Governance Academy (Oct 2025) |
| Cyberattacks recorded by DGSSI | 879 in 2025, incl. 109 direct interventions | DGSSI (2025) |
| Attack attempts detected (telemetry) | 20.7 million in H1 2025 | Kaspersky Security Network (2025) |
| Cybercrime & cyber-blackmail cases | 13,643 in 2025 | DGSN annual report (Dec 2025) |
| Ransomware detections | 1,076 in 2024 (9th in Africa) | INTERPOL / Trend Micro (2025) |
| National strategy in force | National Cybersecurity Strategy 2030 | DGSSI (July 2024) |
| National cybersecurity authority | DGSSI, with maCERT as national CERT | Law 05-20 (2020) |
Each figure is sourced in the sections below.
Key Statistics for Cybersecurity in Morocco
1. Global Cybersecurity Ranking
ITU Global Cybersecurity Index — Tier 1, 97.5/100
- In the fifth Global Cybersecurity Index, published by the International Telecommunication Union (ITU) in September 2024, Morocco scored 97.5/100 and entered Tier 1 — “Role-modelling”, the highest of five tiers and the only Maghreb country there. (ITU report, PDF; DGSSI)
- What it measures: a country’s commitment to cybersecurity, via 83 indicators across five pillars — legal, technical, organizational, capacity development and cooperation. The 2024 edition assessed 194 countries, each submission independently verified. Morocco’s pillar scores: 20/20 legal, organizational and cooperation, 19.38/20 capacity development, 18.12/20 technical, against a global average overall score of 65.7/100.
- Methodology note: since this edition the ITU publishes tiers, not ranks. Tier 1 covers scores from 95 to 100 and 46 countries share it. The ITU says rankings derived from the GCI “are not endorsed by ITU” — so any source giving Morocco an “Nth in the world” 2024 position is inventing a rank.
Why you may see “50th, 82%” instead. That comes from the 2020 edition, when the GCI still produced a league table — a figure Morocco’s own National Cybersecurity Strategy 2030 cites as a 2020 achievement. The two results are four years and one methodology apart, not in conflict. As of August 2026 the 2024 edition is still the most recent GCI.
National Cyber Security Index — 79.17%, 44th
The NCSI, maintained by Estonia’s e-Governance Academy, measures something narrower: a country’s implemented capacity to prevent threats and manage incidents, verified against public evidence. It is a living database, so positions shift whenever any country is re-assessed. At its 15 October 2025 update Morocco scored 79.17%, 44th. (NCSI: Morocco)
| NCSI category | Score |
|---|---|
| Critical information infrastructure protection | 100% |
| Digital enablers security | 100% |
| Cyber threat analysis and awareness | 100% |
| Personal data protection | 100% |
| Cybersecurity research and development | 100% |
| Cybersecurity policy development | 80% |
| Global cybersecurity contribution | 67% |
| Education and professional development | 60% |
Morocco’s NCSI category scores, October 2025 update. Source: e-Governance Academy.
Reading the trend correctly. Earlier snapshots placed Morocco 30th (cited by the DGSSI) and 32nd at 70.13%. Morocco’s score rose about nine points while its rank fell, because other countries were re-assessed and the NCSI reorganised its indicators — so cite the score and update date, not the rank alone. Separately, Moroccan press reporting on the Allianz Risk Barometer 2025 placed Morocco among the 23 countries most exposed to cyberattacks and the only Arab country listed (Le360) — second-hand reporting of a commercial survey, not an official index.
Morocco’s Cybersecurity Focus Areas

This graph shows cybersecurity in Morocco focus areas by percentage, based on the 2024 NCSI assessment. For current figures see the table above. Source
2. Cybercrime Incidence
What the state records. In 2025 the DGSSI recorded 879 cyberattacks, 109 of them needing direct intervention by maCERT, the national detection and response centre (source). In 2024 Morocco blocked 644 cyberattacks, with 134 DGSSI interventions, 64 critical platforms reinforced and 16 vulnerability alerts (source) — a 36% year-on-year rise. From January to September 2025, 76 mobile applications of public bodies and critical infrastructure were audited; 20 held critical vulnerabilities.
What vendor telemetry shows. Figures in the tens of millions circulate widely and are often misattributed to the DGSSI. They come from telemetry — automated detections counting blocked attempts, not breaches. At KNext Rabat 2025, under the Ministry of Digital Transition, Kaspersky reported 20.7 million detected attack attempts against Moroccan systems in January–June 2025: ~15 million local threats and ~6 million internet-borne, plus 2.1 million RDP attacks, 800,000 exploits, 390,000 credential-stealing attempts, 230,000 spyware detections — stealers and spyware each up 22% on H1 2024 — and 8,000 backdoors. (Infomédiaire)
What the police record. In its 2025 annual report (17 December 2025) the DGSN reported 13,643 cases of modern-technology crime and cyber-blackmail, 3,131 extortive content items, 1,036 international letters rogatory and 415 people referred to the courts. Online sexual extortion fell 5% to 370 cases (89 arrests, 486 victims, 129 foreign). E-Blagh took 25,876 reports from its June 2024 launch to end-2025. (SNRT News)
Hacktivism and politically motivated attacks
Pro-Algeria hacktivist groups like Anonymous Algeria and EvilBbyte have targeted Morocco Telecom and Moroccan Airlines via DDoS, data theft and defacement. Morocco’s internet providers have suffered RDP breaches, and an attack in Agadir affected over 16,000 IP addresses. ‘Cyb3r Drag0nz’ and ‘Team 1919’ leaked credentials for 30,000 students; STORMOUS exploited vulnerabilities for network access; and ‘Starry Addax‘ phishing targeted activists in Morocco and Western Sahara. Source
Since April 2025 the dominant actor has been Jabaroot (also “JabarootDZ”), presenting itself as Algerian, which has claimed a sustained series of intrusions into Moroccan public institutions. Several claims remain unconfirmed, and Moroccan researchers caution that some published files may be recycled. Verified and disputed claims are separated in the timeline below.



3. Financial Impact
Cyberattacks impose real costs on Morocco’s economy, especially in telecoms, transport, banking and government. The most authoritative continental source is the INTERPOL Africa Cyberthreat Assessment Report 2025 (4th edition, May 2025):
- Cyber incidents across Africa caused losses exceeding USD 3 billion between 2019 and 2025, hitting finance, healthcare, energy and government hardest. (INTERPOL, PDF)
- 1,076 ransomware detections in Morocco during 2024 (Trend Micro data), ninth in Africa — behind South Africa and Egypt, which recorded 17,849 and 12,281.
- Phishing-led online scams are Africa’s most prevalent cyberthreat, at 34% of all detected cyber incidents.
- Egypt and Morocco are named among Africa’s most heavily targeted nations, given their internet penetration and economy size.
- The highest number of AI-enhanced sextortion incidents was recorded in Morocco, Mali, Egypt and Mauritania.
On the older “USD 4 billion / 8%” figures. Those came from INTERPOL’s 2024 report and remain valid for 2024. They are not comparable to the 2025 edition, which gives a cumulative 2019–2025 total rather than an annual one — a different measure, not a downward revision.
2023 Banking Cyberattack: CIH Bank fell victim to a cyberattack in 2023 in which 105 clients were deceived and 3 million Moroccan Dirhams stolen — one of several attacks on Moroccan banks in recent years.
Widely circulated figures for the average cost of a Moroccan breach, or the size of Morocco’s cybersecurity market, trace only to vendor marketing and are deliberately excluded here.
4. Government Initiatives
- The National Cybersecurity Strategy 2030, launched July 2024, replaced the 2012 strategy — see its section below. The 2012 strategy delivered the legal framework, maCERT, a critical-infrastructure mapping and qualification schemes for security and audit providers.
- UN Convention against Cybercrime: on 25 October 2025 in Hanoi, Morocco signed the first UN treaty against cybercrime alongside 70+ states including 21 African countries, Justice Minister Abdellatif Ouahbi signing for the Kingdom. It covers phishing, ransomware, child sexual abuse material and money laundering, and speeds cross-border evidence sharing. (UN News)
- E-Blagh: the DGSN’s public cybercrime reporting platform, launched June 2024, cited by INTERPOL as continental good practice.
- Regional leadership: Morocco has held the vice-presidency of the African Network of Cybersecurity Authorities (ANCA) since 2022. DGSSI Director General Brigadier General Abdellah Boutrig describes the approach as deliberately holistic — governance, law, operational capability, cooperation and skills at once. (SNRT News)
- Skills pipeline: the DGSSI ran Morocco’s first national student cybersecurity competition (16 February–8 April 2026), while Cyber Awareness Days with universities reach over 50,000 participants annually.
- Digital Morocco 2030: commits about 11 billion dirhams (USD 1.1 billion) for 2024–2026, targeting 240,000 digital jobs and 3,000 startups, with cybersecurity a named priority.
5. Moroccan Hackers
Moroccan hackers have been ranked as the most dangerous in North Africa, according to the 2024 Global Digital Fraud Index by SumSub. The report, cited by La Razón, placed Morocco third in Africa with a global rating of 3.51 points.
Notable Malicious Hacking Groups
- Storm-0539 (Atlas Lion): cloud identity exploitation and gift card fraud, stealing up to $100,000 daily through phishing, fake domains and charity impersonation.
- Moroccan Ghosts: cyber espionage and data breaches against government and private sector entities.
- Dark Atlas: a newer group conducting ransomware attacks on Moroccan businesses.
One distinction is often blurred in coverage of cybersecurity in Morocco: groups based in Morocco attacking targets abroad (Storm-0539) are a separate phenomenon from groups attacking Morocco (Jabaroot). Morocco appears in international reporting as both an origin and a destination of cybercrime.
The Rise of Ethical Hackers
While malicious hackers are a major threat, ethical hackers are stepping up to fight cybercrime and improve cybersecurity in Morocco. SecureWeb Hackers, a group of ethical hackers and bug bounty hunters, has helped secure online assets for businesses, government institutions and universities worldwide. Through Taghra.com sharing knowledge, tutorials and best practices.
Other Initiatives
- Cybersecurity Competitions: events like Akasec CTF encourage young talent, now joined by the DGSSI’s first national student competition in 2026.
- Training Programs: the top 5 places to learn cybersecurity in Morocco with certifications: read the article.
- Awareness: gauge your own exposure with our free cybersecurity awareness test.
Morocco’s National Cybersecurity Strategy 2030
Morocco’s National Cybersecurity Strategy 2030 (SNC 2030) was unveiled by the DGSSI on 22 July 2024, replacing the 2012 strategy. It defines what the Moroccan state intends to do about cybersecurity through the end of the decade, and is structured as 4 pillars → 11 strategic objectives → 26 initiatives → 60 actions.
Primary sources: DGSSI publications page · full strategy, FR (PDF) · official English summary (PDF)
“For a reliable, secure and resilient national cyberspace supporting Kingdom’s digital transformation, promoting economic prosperity and ensuring citizens’ well-being.”
National Cybersecurity Strategy 2030 — official English summary, DGSSI
Why Morocco created it
The 2012 strategy had delivered its main outcomes — a legal framework, maCERT, a critical-infrastructure mapping, training programmes and international partnerships — and Morocco’s rise to 50th in the 2020 GCI was cited as evidence it worked. But threats changed, so Morocco refreshed its posture rather than let it drift.
A national cyber-risk study conducted beforehand found Morocco’s threat picture closely matches the global one, singling out three threats by frequency and destructive potential: ransomware, capable of paralysing a company or public service; DDoS attacks, able to take services offline; and social engineering. It also flagged supply-chain security and the challenges posed by AI, the Internet of Things and Big Data.
The four pillars and eleven objectives
| Pillar | Strategic objectives |
|---|---|
| Pillar 1 National cybersecurity governance — institutional and legal framework Keep the rulebook current, and make the many bodies involved work together. |
• Maintain and strengthen the legal and normative framework (periodic review, sector-by-sector adaptation) • Improve national coordination — between critical-infrastructure protectors, between law enforcement and cyber intelligence, and with private-sector actors |
| Pillar 2 Security and resilience of national cyberspace Detect attacks, survive them, and decide on real data. |
• Support decision-making with data-driven policies (national picture, metrics, indicators) • Strengthen prevention, management and response to cyber incidents and crises, nationally and by sector • Promote standards and norms — qualification and labelling schemes for products, services and providers, plus national certification schemes • Consolidate critical infrastructure resilience — updated mapping, cross-sector dependencies, stronger audits, hardened telecom and digital operators |
| Pillar 3 Capacity building and awareness Produce enough skilled people, and make users harder to fool. |
• Develop a cybersecurity culture — citizen awareness, public and private campaigns, and awareness modules at school level • Support the national ecosystem and innovation, including university R&D • Strengthen human resources — upgraded university and vocational programmes, professional certification, continuous training for managers |
| Pillar 4 Regional and international cooperation Cyberspace has no borders, so neither can the response. |
• Strengthen active participation in international forums and reinforce the Kingdom’s positioning • Develop bilateral cooperation on information sharing and capacity building |
Source: DGSSI, National Cybersecurity Strategy 2030 — official English summary.
The role of the DGSSI, and the impact so far
The Direction Générale de la Sécurité des Systèmes d’Information (DGSSI), under the National Defence Administration, is Morocco’s national cybersecurity authority. Under Law 05-20 it coordinates the state’s cybersecurity strategy, drafts cybersecurity law and regulation, defines and verifies protection measures, qualifies audit and security providers, operates the national watch–detection–alert system through maCERT, and monitors implementation of the action plans. Evaluation is not left to the DGSSI alone: the Strategic Cybersecurity Committee (CSC), created by Law 05-20, assesses progress.
Two years in, the record is mixed. The ITU named the 2030-horizon strategy among the strengths that lifted Morocco into GCI Tier 1, and audit activity, the incident-response caseload, the first student competition and the UN convention signature all map onto specific objectives. Yet the CNSS breach of April 2025 and the OFPPT incident of April 2026 both came after the launch. Moroccan specialists argue the weakness is organizational, not technical: CISOs frequently lack a stable seat on executive committees, so they work with limited budgets and too little authority. A strategy sets direction; it does not patch systems.
Cybersecurity Laws, Regulators and Institutions in Morocco
Morocco’s framework was built incrementally over roughly a decade. For a practical, business-oriented walkthrough, see our guide to the top Moroccan cybersecurity laws.
| Instrument | Year | What it does |
|---|---|---|
| DNSSI — National Directive for Information Systems Security | 2014 updated Jan 2023 | Minimum organizational and technical security measures for public administrations and critical infrastructure — the operational text beneath the law. |
| Decree 2-15-712 | 2016 | Security rules for critical infrastructure running sensitive information systems, to guarantee continuity of operations. |
| Head of Government order on audit providers | 2018 | Accreditation criteria for providers auditing sensitive information systems, and how audits are conducted. |
| Law 05-20 on cybersecurity | 2020 | The cornerstone. Security rules for entities, critical infrastructure and operators, and creates the governance bodies: the national cybersecurity authority, the Strategic Cybersecurity Committee and the major cyber crisis management committee. |
| Decree 2-21-406 | 2021 | Brings Law 05-20 into force — composition and operation of the governance bodies, and obligations for entities, critical infrastructure and operators. |
| Law 09-08 on personal data protection | 2009 | Governs lawful processing of personal data and created the CNDP. Still the primary data protection statute. |
| Law 43-20 on trust services for electronic transactions | 2020 | Electronic signatures, digital identity and trust services — cited by the ITU among Morocco’s GCI strengths. |
| National Cybersecurity Strategy 2030 | 2024 | Policy direction rather than binding law: 4 pillars, 11 objectives, 26 initiatives, 60 actions. |
| UN Convention against Cybercrime | 2025 signed Oct | Cross-border cybercrime cooperation. Signed, pending ratification. |
Who does what
- DGSSI — national cybersecurity authority: sets protection measures, qualifies providers, audits, coordinates response.
- maCERT — national watch, detection and response centre under the DGSSI; intervened in 109 incidents in 2025.
- Strategic Cybersecurity Committee (CSC) — sets strategic direction, evaluates DGSSI activity, defines audit scope and advises on draft legislation. A separate major cyber crisis committee coordinates crisis response and can mandate measures for critical infrastructure.
- CNDP — personal data protection authority, verifying that processing is lawful and does not infringe privacy or fundamental rights. We previously reported a security issue on a CNDP-related government site.
- Cybercrime enforcement — shared between the Ministry of Justice, the Superior Council of the Judicial Power, the Public Prosecutor’s Office, the DGSN and the Royal Gendarmerie, each with dedicated units.
Data protection: from awareness to enforcement
The most consequential recent shift is not a new law but a change of posture. After roughly fifteen years of awareness work, the CNDP moved into active enforcement of Law 09-08 in 2025, running sectoral compliance campaigns with deadlines and writing to companies to demand compliance. Sanctions run from warnings and withdrawal of processing authorizations to fines and, in defined cases, three months to one year in prison; failing to declare a processing operation is itself an offence.
It also acted publicly during the CNSS breach: on 10 April 2025 it warned that leaked data circulating on unauthorized channels remains protected by Law 09-08, that using it is unlawful, and that it would investigate complaints. As of mid-2026 no bill replacing Law 09-08 had reached Parliament, though the CNDP is working with the Ministry of Digital Transition on a framework for responsible AI.
Bank Al-Maghrib, Phishing and Stronger Authentication in Banking
Banking is where cybersecurity in Morocco touches the most citizens, and where the regulator has moved most concretely. Full detail: Bank Al-Maghrib’s phishing crackdown and the new rules for banks in 2026.
The threat facing banking customers
The pattern is consistent and needs no sophisticated malware. Fraudsters send fake SMS messages or push malicious links via social media, impersonating a bank or public administration. The victim enters real credentials on a convincing fake page. The money then moves through “comptes rebonds” — mule accounts opened in third parties’ names — breaking the trail between victim and perpetrator and making recovery and prosecution far harder.
The public-sector leaks since April 2025 amplified this: national ID numbers, contact details, salaries and addresses exposed there now feed targeted fraudulent SMS campaigns impersonating banks and ministries, some run from overseas “scam farms”. Leaked identity data is what turns generic phishing into convincing, personalised fraud — see our guide on how to spot phishing emails.
What Bank Al-Maghrib has done, and what it now requires
- July 2024 — a first guidance document for banks on detecting phishing and communicating about it with customers.
- 17 July 2026 — Bank Al-Maghrib and the Autorité Nationale du Renseignement Financier (ANRF) convened banking officials in Rabat, led by ANRF President Jawhar Nfissi and BAM’s Director of Banking Supervision Nabil Badr, with input from Banco de Portugal. A second guidance document followed, on mule accounts.
- 23 July 2026 — BAM’s 2025 annual banking supervision report put non-financial risks at the heart of supervision and named cybersecurity a top priority: cyber-risk dashboards across the whole banking sector, tighter oversight of critical service providers and a ransomware-prevention guide.
The technical core: a stolen password must not be enough to move money. Three expectations are set for banks — multi-factor authentication (MFA) for account access and transaction validation, since a second factor at the moment of transfer, not just at login, is what defeats an attacker holding captured credentials; trusted-device recognition, so logins from unrecognised devices are challenged; and hardened mobile banking apps, resistant to tampering and interception.
What this means for banks, customers and the country
- For banks: anti-fraud controls move from a differentiator to a supervised expectation. Banks must demonstrate MFA coverage, device-trust logic and app hardening, monitor mule accounts and report through the new dashboards — and outsourced providers now fall within supervisory scope.
- For customers: expect more authentication prompts and transaction confirmations — friction that exists because a password alone can no longer be trusted. Never approve a code you did not initiate, never enter credentials from an SMS link, and call your bank on a number you already have.
- Nationally: one of the first cases where a Moroccan sector regulator turned a national cybersecurity objective into binding, checkable expectations for a whole industry — the “sectoral adaptation” Pillar 1 calls for — while addressing the downstream consequence of the leaks: fraud against citizens.
Timeline: Morocco’s Cybersecurity Developments, 2024–2026
The developments below changed the landscape rather than merely filling news cycles. Unconfirmed claims are labelled as such.
| Date | What happened | Why it matters |
|---|---|---|
| Jun 2024 | DGSN launches E-Blagh, a public platform for reporting online crime, at national open days in Agadir attended by 2.1 million people, 845 schools taking part. | A direct citizen reporting channel — 25,876 reports by end-2025, cited by INTERPOL as good practice. |
| 22 Jul 2024 | DGSSI unveils the National Cybersecurity Strategy 2030. Bank Al-Maghrib issues its first phishing guidance to banks. | Sets national direction to 2030, plus the first sector-specific response to consumer phishing. (DGSSI) |
| Sep 2024 | The ITU publishes the 5th Global Cybersecurity Index. Morocco scores 97.5/100 and enters Tier 1. Over the year, Morocco’s services block 644 cyberattacks. | Morocco’s strongest-ever international assessment, and the baseline for the 2025 increase. (ITU) |
| 8 Apr 2025 Confirmed | CNSS breach — the largest confirmed data leak in Moroccan history. Files published on a Telegram channel run by Jabaroot included 53,574 employee-declaration PDFs, a file covering 497,653 affiliated entities and one listing 1,945,915 employees. Affected organizations included AXA and Al Barid Bank. Two days later the CNDP warned that using the leaked data is unlawful under Law 09-08. | Exposed national ID numbers, salaries and bank details at scale, triggering a wave of downstream fraud — and the first major test of Morocco’s data protection regulator. (Médias24 · SecureWeb analysis) |
| May 2025 | INTERPOL publishes its 4th Africa Cyberthreat Assessment, naming Morocco among Africa’s most heavily targeted countries with 1,076 ransomware detections for 2024. | Puts Morocco’s threat level in verified continental context. (INTERPOL, PDF) |
| Jun 2025 Denied | Jabaroot targets the Tawthiq notarial platform and claims an intrusion into the Ministry of Justice covering some 5,000 judges and 35,000 judicial staff. The Ministry officially denied being hacked. | Shows how contested attribution has become — claim and denial belong together in any citation. |
| H1 2025 | Kaspersky telemetry records 20.7 million attack attempts against Moroccan systems. 76 public and critical-infrastructure mobile apps are audited; 20 are critically vulnerable. | Shows the automated traffic behind the smaller count of recorded incidents, and officially confirms persistent weaknesses. |
| Oct 2025 | Morocco signs the UN Convention against Cybercrime in Hanoi on 25 October. Two weeks earlier the NCSI updates Morocco to 79.17%, 44th. | Commits Morocco to the first global framework for cross-border cybercrime cooperation. (UN News · NCSI) |
| Dec 2025 | The DGSN reports 13,643 cybercrime and cyber-blackmail cases for 2025; the DGSSI records 879 cyberattacks, 109 needing maCERT intervention. | The clearest official measure of cybercrime affecting citizens, plus a ~36% rise in incidents over 2024. (SNRT · H24info) |
| Feb–Apr 2026 | The DGSSI runs Morocco’s first national cybersecurity competition for students of public and private universities and grandes écoles. | Direct implementation of Pillar 3: the domestic talent pipeline. |
| 26 Mar 2026 Unconfirmed | The Bashe group (tracked as APT73) claims to have breached 2M Maroc, exfiltrating ~30 GB of internal documents, emails and financial files. Not officially confirmed. | Financially motivated ransomware operators are now targeting Moroccan media alongside political hacktivism. |
| 8–10 Apr 2026 Unconfirmed | Jabaroot claims a breach of CNOPS, publishing a file said to hold over 3 million members’ names, registration numbers and addresses — one year to the day after CNSS. Never confirmed; researchers noted it lacked the timestamps present in the CNSS leak and could be recycled. | Landed as the CNSS and CNOPS regimes were merging, raising data-governance questions — and a case study in why unverified claims need labelling. |
| 12–14 Apr 2026 Confirmed | OFPPT confirms an incident on its “My Way” platform: a CSV on the dark web with data on ~100,000 young users — names, phones, emails and national ID numbers. Attributed to misuse of a compromised legitimate account, not direct technical compromise. | A rare case of prompt, detailed public-sector breach disclosure — the transparency standard others are now measured against. |
| Jul 2026 | Bank Al-Maghrib and the ANRF convene banks in Rabat (17 July): guidance on mule accounts, plus expectations on MFA, trusted devices and app hardening. On 23 July BAM’s supervision report generalises cyber-risk dashboards sector-wide. | Turns national cyber policy into supervised obligations for an entire sector, embedding cyber risk in prudential supervision. (SecureWeb analysis) |
Three patterns stand out. Institutional maturity and operational exposure rose together — Tier 1 recognition and the largest breach in the country’s history are seven months apart. The public sector, not private business, absorbed the highest-impact incidents. And confirmation is now the hardest part of the story: several widely reported claims were never confirmed, one was officially denied, and only OFPPT disclosed in detail on its own initiative.
Moroccan Businesses: Field Reality, Challenges and Best Practices
Secureweb Analysis in Morocco:
Our assessment of Cybersecurity in Morocco (for businesses) reveals key cybersecurity trends:
- 53% of Moroccan businesses contacted by us do not care about cybersecurity, even after we explain the risks associated with their vulnerabilities.
- 40% of businesses expect their single IT staff member to manage all security-related issues.
- 78% of businesses only begin to adopt a cybersecurity strategy after experiencing a hack or breach.
- Only 4% of businesses demonstrate strong cybersecurity practices proactively.
Methodology note: these percentages come from SecureWeb’s own outreach to Moroccan organizations during security assessment and disclosure work. They describe the organizations we contacted and are not a statistically representative national survey. They are published because comparable independent data on Moroccan SME security posture does not exist.
Challenges of Cybersecurity in Morocco
Despite ongoing efforts, cybersecurity in Morocco still faces significant challenges.
- Outdated technology: government and university websites still run ageing stacks with insufficient security practices — officially confirmed by the 2025 finding that 20 of 76 public and critical-infrastructure mobile applications carried critical vulnerabilities.
- Lack of skilled professionals: many roles stay unfilled through a mismatch between employer needs and available skills. The DGSSI’s own Director General has identified a deficit of qualified operational profiles, calling for curricula to be adapted to field needs.
- Governance, not just technology: information security directors often lack a permanent seat on executive committees, leaving them with constrained budgets and too little authority. Emphasis remains on penetration testing and products rather than durable processes and resilience.
- Breach notification and citizen recourse: no public tool lets a Moroccan citizen check whether their data appears in a compromised database, and affected institutions have often communicated late or not at all.
- Absence of Bug Bounty Programs: Morocco lacks BBPs/VDPs, which reward researchers for reporting flaws before attackers exploit them.
- No secure coding training: secure coding practices for developers are not prioritized, leaving room for vulnerabilities.
Best Practices for Individuals and Organizations
For Individuals:
- Use unique, strong passwords and enable two-factor authentication (2FA).
- Regularly update software and avoid clicking on suspicious links.
- Treat unsolicited SMS and calls quoting your real details as suspicious — after the 2025–2026 leaks, a fraudster knowing your name or ID number proves nothing. Learn to recognise phishing messages and what happens to leaked data on the dark web.
- Never approve an authentication code or banking notification you did not personally initiate.
- Not sure where you stand? Take our free cybersecurity awareness test to find your weak points.
For Organizations:
- Conduct regular security audits and penetration testing.
- Train employees against common cyber errors with phishing awareness and secure coding, and invest in cybersecurity suited to your industry.
- Enforce MFA on every externally reachable service and restrict remote access — RDP alone drew 2.1 million recorded attacks on Moroccan systems in H1 2025.
- Assess suppliers and third parties — the OFPPT incident stemmed from misuse of a legitimate account, and both the strategy and Bank Al-Maghrib now treat service-provider risk as first-order.
- If you process personal data, review Law 09-08 compliance now — the CNDP moved from awareness to enforcement in 2025.
Frequently Asked Questions
What is Morocco’s cybersecurity ranking?
On the ITU’s Global Cybersecurity Index 2024, Morocco scored 97.5/100 and sits in Tier 1 — the highest of five tiers, and the only Maghreb country there. The ITU publishes tiers, not ranks. On the separate NCSI it scored 79.17%, 44th, in October 2025.
Which body is responsible for cybersecurity in Morocco?
The DGSSI, under the National Defence Administration, with maCERT as national CERT. Cybercrime investigation sits with the DGSN and Royal Gendarmerie; personal data with the CNDP.
What was the biggest data breach in Morocco?
The CNSS breach of April 2025 — files covering 497,653 affiliated entities and 1,945,915 employees. Full analysis: the CNSS hack.
What is Morocco’s main cybersecurity law?
Law 05-20 on cybersecurity (2020), in force via decree 2-21-406 (2021), setting obligations for entities, critical infrastructure and operators and creating the governance bodies. Personal data falls under Law 09-08 (2009).
What is the biggest cyber threat facing Morocco?
Morocco’s national risk study named ransomware, DDoS and social engineering. In practice phishing dominates: INTERPOL attributes 34% of Africa’s detected cyber incidents to phishing-led scams, and Morocco’s largest recent losses to citizens came from fraud built on leaked data.
Conclusion
As Morocco advances digitally, prioritising strong cybersecurity practices is essential to reduce cybercrime and build a safer digital environment for everyone.
The 2024–2026 period makes the challenge unusually clear. Morocco has a credible national strategy, a recognised authority, a Tier 1 international assessment and, in banking, a regulator turning policy into enforceable practice. It also has the largest data breach in its history, a talent shortage the DGSSI acknowledges, and institutions that have not consistently told citizens when their data was exposed. Both are true at once, and any honest account of cybersecurity in Morocco must hold them together.
Primary Sources and Further Reading
- DGSSI — National Cybersecurity Strategy 2030 (full text, FR · summary, EN)
- ITU — Global Cybersecurity Index 2024 (5th edition) · INTERPOL — Africa Cyberthreat Assessment 2025 · NCSI — Morocco
- DGSSI · CNDP · Bank Al-Maghrib
- SecureWeb analyses: the CNSS hack · Bank Al-Maghrib’s phishing rules · Moroccan cybersecurity laws · government efforts and challenges · where to study cybersecurity in Morocco · free awareness test




