Expertise, Policy Brief|

Morocco has achieved real strategic milestones in cybersecurity, but high-profile attacks in 2024 and 2025 exposed a critical vulnerability — the April 2025 breach of the National Social Security Fund (CNSS), the country’s most significant cyber-attack to date. GGSF Policy Brief N°05 reads Morocco cybersecurity through that wake-up call and the digital sovereignty agenda it has accelerated.

What follows are the brief’s key takeaways. The full analysis — the options, the points of vigilance and the recommendations — is in the document.

Key takeaways on Morocco cybersecurity

  • The CNSS breach is the wake-up call. The April 2025 attack on the National Social Security Fund exposed the data of nearly two million people from approximately 500,000 companies. It came despite Morocco’s Tier 1 ranking in the ITU’s 2024 Global Cybersecurity Index.
  • The DGSSI anchors the national response. The General Directorate of Information Systems Security runs the national cybersecurity strategy under the National Defense Administration. Brigadier General Abdellah Boutrig’s appointment as Director General by King Mohammed VI makes cybersecurity a matter of defence and sovereignty.
  • maCERT is the operational hub. Within the DGSSI, the Moroccan Computer Emergency Response Team monitors, detects and responds to attacks, with reactive services (incident management, alerts, breach support) and proactive ones (technological watch, security assessments). Its reach depends on the ecosystem’s readiness to report.
  • The gap is maturity, not money. Budgets under the 2012 National Cybersecurity Strategy and its 2024 updates have not closed it: Kaspersky counted 12.6 million web threats in 2024, third in Africa, and a SecureWeb report found 53% of businesses “do not care about cybersecurity” while 78% act only after a breach.
  • Enforcement is moving to carrot and stick. The CNDP, the national data protection authority, is issuing formal notices and stands ready to penalise companies that fail to comply with Law 09.08 on data privacy, with fines from €1,000 to €20,000.
  • Structural vulnerabilities persist. Specialised cybersecurity skills are scarce and budgets tight, especially for small and medium-sized companies, and 40% of businesses rely on a single IT staff member. The human factor remains the most significant vulnerability, with no “secure by design” reflex.
  • AFCON 2025 and the 2030 World Cup are a stress test. Hosting both puts Morocco in the global spotlight as a primary target for threat actors, from geopolitical rivals to financially motivated cybercriminals — and as a stage to project a secure, resilient nation.
  • Partnerships and a homegrown industry are the levers. Morocco signed cybersecurity memoranda with the United States in October 2023, with the UAE that October and India in September 2025, and cooperates with Europol. Nucleon Security raised €3 million at home.

What to hold in view

Two risks frame the next phase: reliance on outdated systems in vital sectors, with limited budgets for upgrading digital infrastructure and advanced monitoring, and a threat landscape growing faster and more complex as technologies proliferate. Stolen CNSS records will feed phishing and identity theft for years.

Dive deeper into the strategic details.

Comments are closed.