RMG Solutions
//
Guide

Cybersecurity for Moroccan SMEs: 2026 Complete Guide

Cyberattacks, real costs in MAD, Law 05-20 legal obligations and a 30-60-90 day action plan: the complete cybersecurity guide for Moroccan SMEs in 2026.

RMG SolutionsApril 30, 202614 min read

What Happened on April 8, 2025

On April 8, 2025, a group calling itself "Jabaroot DZ" published 53,000 files extracted from the databases of Morocco's National Social Security Fund (CNSS). The files contained the names, national ID numbers, bank account details, and salary information of nearly 2 million Moroccan employees. The data of approximately 500,000 companies was exposed: HR records, corporate bank account details, and information about company directors.

This is not an incident that concerns CNSS alone. If you run an SME in Morocco, your data was potentially in those files. Your employees received calls, SMS messages, and scam attempts exploiting that information. Several business owners reported attempted fraudulent wire transfers in the weeks that followed.

The CNSS breach made concrete, for tens of thousands of Moroccan executives, a risk they knew existed in theory. This guide answers the question many have been asking since: where do I start?


Why Moroccan SMEs Are Prime Targets

The Myth of Small Size as Protection

Many SME directors sincerely believe their company is too small to interest hackers. That logic may have held ten years ago. It does not hold today.

According to DGSSI (Morocco's General Directorate of Information Systems Security) data, 60% of cyberattacks in Morocco target very small and small-to-medium businesses. The reason is straightforward: large companies have invested in their security, and their systems are harder to compromise. SMEs, by contrast, often remain accessible with basic tools. Ransomware-as-a-service (RaaS) has democratized cybercrime: individuals with no technical skills now rent attack toolkits for a few hundred dollars and target the least protected organizations. Your 30-employee SME in Casablanca is an easier target than a publicly listed group.

In the first half of 2025, 21 million cyber threats were detected in Morocco, according to data presented at the Kaspersky/KNext Forum in Rabat. That number does not concern only large institutions.

A 2025 CGEM (Confederation of Moroccan Enterprises) survey reveals that 62% of Moroccan companies report having experienced at least one attempted attack. Among those that suffered a serious attack, more than half experienced multi-day business interruptions.

The 2025 Ausimètre barometer (PwC/AUSIM) confirms this awareness: 73% of Moroccan companies place cyber risk at the top of their priorities for the next 12 months, and 78% allocate up to 25% of their technology investment to it. The Moroccan cybersecurity market reached USD 157 million in 2026 (Mordor Intelligence), with 15.67% annual growth in the SME segment, twice the rate of the overall market. Morocco scored 97.5/100 on the ITU's 2024 Global Cybersecurity Index, placing it in Tier 1 alongside global leaders. The institutional framework is in place, but its application remains the responsibility of each individual business.

21M

Cyber threats detected (H1 2025)

60%

SMEs targeted by attacks

1.2M MAD

Average cost of an attack

62%

Moroccan companies attacked

Who Gets Attacked, and Why

Some sectors are over-represented in Moroccan incident statistics:

SectorPrimary vulnerability
Trade and distributionCustomer data, banking access, online payments
Construction and real estateSensitive financial data, large wire transfers
Professional services (lawyers, accountants)Confidential third-party data, high ransom potential
Textile and agro-food manufacturingSupply chain access, supplier credentials
Hospitality and restaurantsCard data, reservations, point-of-sale systems
IT servicesSupply-chain attacks targeting their clients

Distribution, construction, and professional services see the highest incident rates, not because they are careless, but because they handle large financial flows with reduced or non-existent IT teams.


The Cost of an Attack vs. the Cost of Protection

What an Incident Really Costs

SME directors almost always underestimate the real cost of a cyberattack. They think of the potential ransom, but forget everything else.

Cost itemEstimated range (MAD)
System and data restoration50,000 - 200,000 MAD
Lost revenue during interruption100,000 - 500,000 MAD
Legal fees and CNDP notification costs20,000 - 80,000 MAD
Regulatory fines (CNDP, Law 09-08)100,000 - 300,000 MAD
Potential ransom (if ransomware)50,000 - 300,000 MAD
Crisis communications and lost contractsVariable
Estimated average total cost1.2 million MAD

This 1.2 million MAD figure is cited by the DGSSI as the average impact of a ransomware attack on a Moroccan SME. It reflects a reality that local experts confirm: a 40-person company paralyzed for a week, with compromised customer data and a regulatory notification obligation, quickly reaches that level of loss.

There is another number worth knowing: 60% of SMEs that suffer a major attack cease operations within 18 months. Not because of the ransom itself, but because the loss of customer trust, reconstruction costs, and operational disruption accumulate to the point where the business is no longer viable.

What Protection Costs by Company Size

Protection is not reserved for large enterprises. SME-accessible solutions exist, and their cost is incomparable with that of an incident.

Company sizeRecommended cybersecurity budgetWhat it covers
1-10 employees1,500 - 4,000 MAD/monthEDR antivirus, password manager, cloud backups, MFA
10-50 employees4,000 - 15,000 MAD/monthCentralized EDR, managed firewall, basic monitoring, training
50-200 employees15,000 - 50,000 MAD/monthOutsourced SOC, SIEM, incident response, regular audits
200+ employeesFrom 50,000 MAD/monthIn-house or hybrid SOC, red team, full compliance program

These figures include both tools and, where relevant, the services of a specialized partner like RMG Solutions. Threat protection services can be rolled out progressively, without locking up an entire annual budget on day one.

The Return on Investment

The math is direct. For a 30-person SME, a protection budget of 6,000 MAD per month represents 72,000 MAD per year. Against an incident with an average cost above 1.2 million MAD (not counting customer churn) the question is not "can we afford to spend on cybersecurity," but "can we afford not to?"

Less than 15% of Moroccan SMEs have a dedicated cybersecurity budget (CGEM, 2025). That is precisely why attackers target SMEs first.

To estimate your current exposure level quickly without commitment, our cybersecurity self-diagnostic assesses your posture in 5 minutes across the ten key domains (governance, access, backups, training, etc.).


The 5 Threats Facing Moroccan SMEs in 2026

1. Phishing: and Its WhatsApp Variant

Phishing remains the primary entry point into Moroccan SME systems. In 2024, 47% of attacks against Moroccan SMEs originated from fraudulent emails impersonating banks, government agencies, or commercial partners (DGSSI).

The Morocco-specific variant deserves particular attention: WhatsApp phishing. Moroccan SMEs use WhatsApp Business intensively for customer and supplier communications. Attackers know this. They send messages from numbers resembling those of suppliers or partners ("Your invoice pending validation, click here"), fake DGI tax notices, or urgency-driven messages ("Your bank account will be blocked in 24 hours").

These messages are often written in fluent Darija or French, and rely on information harvested from previous breaches, including the CNSS leak.

What you can do now: Train every employee to never click a link received via WhatsApp or email without a direct voice verification with the supposed sender. This simple protocol blocks the vast majority of attempts.

2. Ransomware

Ransomware encrypts your files and demands a ransom to recover them. The average demand exceeds 500,000 MAD for Moroccan SMEs, according to data collected by local cybersecurity providers.

What changed in the past two years: attackers no longer just encrypt your data. They first exfiltrate it, then threaten to publish it if you do not pay. This "double extortion" has become standard practice and makes simple backup restoration insufficient.

The most frequent vectors for Moroccan SMEs: email with infected attachment, exposed and poorly secured RDP (remote desktop) access, and compromise of an external IT service provider.

3. Credential Theft

This vector is underestimated. Millions of username/password combinations from Moroccan businesses circulate on underground forums, often originating from leaks of unrelated services (social networks, e-commerce platforms).

If your employees reuse the same passwords for personal email and professional accounts (and that is very common) an attacker who buys a leaked credential database can access your systems directly with no technical effort.

The protection is simple and nearly free: two-factor authentication (2FA/MFA) on all professional accounts, plus a password manager. It is the cybersecurity investment with the best cost-to-effectiveness ratio.

4. Cloud Misconfiguration

The shift to cloud (Microsoft 365, Google Workspace, Azure or AWS storage) has brought real benefits to Moroccan SMEs. It has also created new risks, often invisible.

Cloud storage buckets accidentally made public, overly broad access rights in Microsoft 365, administrator accounts without MFA: these errors expose sensitive data without an attack even being necessary. The data is simply accessible to anyone who knows where to look.

Automated scanning tools continuously crawl the internet looking for these exposed configurations. An SME that migrated to the cloud without a configuration audit is often more vulnerable than before the migration.

5. Supply Chain Attacks

If your IT provider, your accounting firm, or your software vendor is compromised, attackers can reach your network through that trust relationship. That is what happened with CNSS: the affected companies had done nothing wrong, but their data was stored at an entity that was compromised.

For SMEs, the concrete risk is this: your IT provider has access to your systems for maintenance. If their infrastructure is compromised, an attacker has the same access as your technician. Asking your provider for guarantees on their own security is not paranoia: it is risk management.


Law 09-08 and the CNDP Turning Point

Law 09-08 on the protection of personal data has existed since 2009. For fifteen years, the CNDP (Morocco's National Commission for the Protection of Personal Data) ran an awareness phase and did not actively sanction.

That changed in February 2025. The CNDP officially announced the end of its awareness phase and the start of an active enforcement phase. In 2024, 27 million MAD in fines were already issued against Moroccan companies for Law 09-08 violations. The pace will accelerate.

Your concrete obligations under Law 09-08:

  • Declare your personal data processing activities to the CNDP
  • Inform your customers, employees, and partners of the collection and use of their data
  • Secure the data you process technically and organizationally
  • Restrict data access to the strict minimum (data minimization principle)
  • Do not transfer personal data abroad without CNDP authorization
Type of violationAdministrative sanction
Failure to declare to CNDP10,000 - 100,000 MAD
Failure to inform data subjects10,000 - 100,000 MAD
Violation of security measures100,000 - 300,000 MAD
Illicit collection of sensitive data100,000 - 300,000 MAD
Refusal to cooperate with CNDP100,000 - 300,000 MAD
Unauthorized international transferUp to 300,000 MAD + criminal sanctions

Sanctions are cumulative per violation. An SME that has not declared its processing, does not inform its customers, and has not secured its data can face more than 600,000 MAD in simultaneous fines.

Law 05-20: For Critical Infrastructure

Law 05-20 on cybersecurity, published in 2020, applies primarily to public administrations, public institutions, and operators of vital infrastructure (energy, water, transport, banks, telecoms). If your SME operates in these sectors or supplies services to such entities, you may be subject to its requirements.

Its obligations include compliance with the National Information Systems Security Directive (DNSSI), incident reporting to the DGSSI within strict deadlines, and security audits performed by certified PASSI providers.

For a complete analysis of your DGSSI obligations, see our complete DGSSI compliance guide for Morocco, which covers the full DNSSI requirements, the Law 05-20 implementing decree, and the practical compliance roadmap.

What This Means in Practice for Your SME

Even if your sector is not directly targeted by Law 05-20, Law 09-08 applies to you as soon as you process personal data, which is the case for every business that has employees, customers, or suppliers.

CNDP compliance and cybersecurity are not two separate topics. A security incident that exposes personal data automatically creates a regulatory problem. Investing in technical security is also investing in legal compliance.


30-60-90 Day Action Plan

This plan is designed for an SME starting from scratch or nearly so. It is realistic, sequenced, and calibrated for a constrained budget. The first 30 days require no external provider.

Cybersecurity 30-60-90 day action plan for SMEs

Phase 1: First 30 Days: Audit and Immediate Protection

Weeks 1-2: Inventory and Audit

Before deploying tools, you need to know what you have. List all your digital assets: computers, servers, professional mobile devices, cloud services, applications in use. Identify who has access to what.

Ask yourself these questions:

  • Who has administrator rights on your network? Are they all necessary?
  • Are your backups tested regularly? Where are they stored?
  • What software runs on your machines, and is it up to date?
  • Do all your Microsoft 365 or Google Workspace accounts have MFA enabled?

Weeks 2-4: Immediate Near-Zero-Cost Actions

ActionCostImpact
Enable MFA on all professional accounts0 MADBlocks ~99% of credential theft attempts
Update all operating systems and software0 MADCloses the most exploited vulnerabilities
Change all default passwords (routers, NAS, etc.)0 MADEliminates a frequent entry vector
Disable internet-exposed RDP access0 MADDrastically reduces ransomware risk
Test your backups (restore one file)0 MADYou'll know whether they actually work
Deploy a password manager (Bitwarden Teams)~1,500 MAD/yearEliminates password reuse

Phase 2: Days 30-60: Tools and Processes

Deploying Protection Tools

A traditional antivirus is no longer enough. Moroccan SMEs should move to an EDR solution (Endpoint Detection and Response), which detects suspicious behavior in addition to known virus signatures.

Realistic options for Moroccan SMEs:

SolutionTypeMonthly budget (30 endpoints)Strengths
Microsoft Defender for BusinessEDR~2,500 MADMicrosoft 365 integration, simple to deploy
Bitdefender GravityZoneEDR~2,000 MADExcellent price/protection ratio, local support
SentinelOne SingularityEDR/XDR~5,000 MADAdvanced behavioral detection
Sophos Intercept XEDR~3,000 MADStrong ransomware protection

3-2-1 Backup Strategy

The 3-2-1 rule is the minimum: 3 copies of your data, on 2 different media, with 1 offsite (cloud or remote location). For a Moroccan SME, this might look like:

  • Local backup on NAS (daily)
  • Cloud backup on Azure or Backblaze B2 (daily)
  • Monthly archive backup stored separately

Written Security Policy

A security policy doesn't need to be 50 pages. For an SME, a one-to-two-page document covering the essential rules is enough: use of professional devices, password rules, procedure for suspicious emails or messages, incident reporting.

Phase 3: Days 60-90: Monitoring and Resilience

Monitoring and Detection

By this stage, you have protected your endpoints and organized your backups. The next step is to see what is happening on your network. Continuous security monitoring detects abnormal behavior before it becomes an incident.

For SMEs of fewer than 50 people, the most cost-effective solution is often an outsourced managed SOC service. Rather than hiring a security analyst (cost: 15,000 to 25,000 MAD/month), you pay for access to a full team for a fraction of that budget. RMG Solutions offers this through its continuous monitoring service, with certified consultants who understand the Moroccan regulatory context.

Incident Response Plan

78% of Moroccan SMEs do not have an incident response plan (CGEM, 2025). When an attack occurs, the absence of a plan turns a bad situation into a catastrophe.

A minimal plan must answer these questions:

  • Who decides to isolate a compromised system, and how?
  • Who notifies customers, authorities, the CNDP?
  • Who contacts the cybersecurity provider, and what is the emergency number?
  • How do you document the incident for legal reasons?

Our incident response team can help you build that plan and test it.

Team Training

Most incidents start with human error. A two-hour annual training session on current threats (phishing, WhatsApp, passwords) statistically divides the incident risk by three. This is not a boring PowerPoint training: practical phishing simulations and concrete Moroccan case studies are far more effective.


Need expert guidance?

Leave your details and an RMG Solutions expert will contact you within 24h.

Your data stays confidential

How to Choose the Right Solutions

Antivirus, EDR, XDR, Managed SOC: What These Acronyms Actually Mean

These acronyms create confusion. Here is what each level actually delivers:

SolutionWhat it doesWhat it doesn't doMonthly budget (30-endpoint SME)
Traditional antivirusDetects known viruses by signatureMisses novel attacks, no automatic response500 - 1,000 MAD
EDRDetects by behavior, isolates infected machines, generates alertsRequires someone to analyze the alerts2,000 - 5,000 MAD
XDREDR + correlation across network, email, cloud in a unified consoleMore complex to deploy, requires expertise5,000 - 15,000 MAD
Managed SOC24/7 monitoring by human experts, incident response includedNo direct control over the tools10,000 - 30,000 MAD

For most Moroccan SMEs between 10 and 100 employees, the pragmatic recommendation is: properly configured EDR + backup rules + employee training. Add a managed SOC when the budget allows, or when your sector (finance, healthcare, critical industry) justifies continuous monitoring.

When to Outsource, When to Keep In-House

SituationRecommendation
SME with no dedicated IT teamFully outsource to an MSSP provider
SME with 1-2 IT techniciansOutsource monitoring and incident response, keep day-to-day in-house
SME with 3+ IT staffKeep operational in-house, outsource audits and advanced SOC
Regulated sector (banking, healthcare)Hybrid SOC: in-house team + certified provider for regulatory obligations

Certifications to Demand from Your Provider

Not all cybersecurity providers are equal. Here is what to verify before signing:

PASSI (Information Systems Security Audit Provider): qualification issued by ANSSI in France, recognized in Morocco. Indicates that the provider can conduct audits aligned with international standards.

ISO 27001: certification of the information security management standard. A provider certified ISO 27001 applies to its own organization the processes it recommends to clients.

Vendor partnerships: an official partnership with Microsoft, Palo Alto, CrowdStrike, or SentinelOne indicates competence verified by these vendors.

For managed security services, systematically request client references in your sector and certifications of the technical staff, not just of the company.

If your sector exposes you to regulatory obligations, a security audit by a qualified provider is the first step to identifying your gaps precisely before investing in tools.

Cyber Insurance in Morocco

Cyber insurance exists in Morocco, but the market is still nascent. Among insurers offering specific cyber coverage: Allianz Morocco (Cyber Assurances product), AFMA, and Howden Morocco. Finance Minister Nadia Fettah announced in 2025 the development of a dedicated cyber insurance product at the Casablanca Insurance Meeting.

Coverage typically includes:

  • System restoration costs
  • Business interruption losses
  • Third-party liability for data breaches
  • Notification and crisis communication costs

Premiums range from 5,000 to 30,000 MAD per year for an SME, depending on sector and data volume. Cyber insurance does not replace technical protection: most contracts exclude incidents resulting from obvious negligence (no updates, no backups). It complements a healthy security posture, it does not substitute for one.


Where to Start, Concretely

If you read this guide to here, you know three things: your SME is a target, the cost of inaction exceeds the cost of protection, and the legal obligations are now actively enforced.

Your next step: a cybersecurity audit of your current situation. Not a tool, not a contract. A diagnostic. Where do you stand? What are your priority gaps? What budget is realistic for your size and sector?

RMG Solutions supports Moroccan SMEs from the initial audit to the rollout of protection and monitoring solutions. Contact us for an initial free assessment.


The RMG Solutions Approach to SME Cybersecurity

Complete protection, not just an audit. Most cybersecurity providers in Morocco sell isolated services: a one-time audit, an antivirus, a firewall. At RMG Solutions, we cover the full protection chain because we are the only multi-service IT partner in the Moroccan market: security posture audit and gap analysis, EDR rollout across all your endpoints, managed SOC with continuous 24/7 monitoring, incident response when an attack hits, and CNDP/DGSSI regulatory compliance. When we identify a flaw in your infrastructure during the audit, we fix it ourselves, no need to find another provider for network, server, or cloud work. Based in Hay Riad (Rabat), we intervene on-site the same day in Rabat and within the hour in Casablanca, which makes the difference when ransomware hits on a Monday morning. Every engagement starts with a free 30-minute initial assessment, no commitment, with a costed action plan adapted to your real budget.

Contact us to schedule your assessment.


Frequently Asked Questions

Does a 10-person Moroccan SME really need cybersecurity?

Yes. Size is not a protective factor: 60% of attack targets in Morocco are very small and small-to-medium businesses. Attackers specifically target small organizations because they are less protected. A 10-person SME that processes customer data, uses online banking, and communicates by email faces the same threats as a large enterprise, with fewer resources to recover from an incident.

What should I do if my company is hit by a cyberattack?

First step: isolate the affected systems from the rest of the network to limit propagation. Do not power off the machines (you'll lose forensic evidence). Immediately contact a specialist incident response provider. If personal data is compromised, you have a legal obligation to notify the CNDP within the deadlines defined by Law 09-08. Document everything from the start for insurance and legal purposes.

What sanctions apply if I am not Law 09-08 compliant?

Administrative fines range from 10,000 MAD for minor infractions (no CNDP declaration) up to 300,000 MAD per violation for serious infractions (no security measures, illicit collection). Sanctions are cumulative: multiple simultaneous violations result in multiple fines. The most serious infractions can also lead to criminal proceedings. Since February 2025, the CNDP has been in active enforcement mode.

Is MFA (two-factor authentication) enough to protect my professional accounts?

MFA is the most effective single measure to prevent account takeover via credential stuffing or classic phishing. It statistically blocks more than 99% of automated attempts. But it doesn't protect against everything: an employee approving a fraudulent MFA prompt ("MFA fatigue" attack), malware bypassing authentication, or unauthorized physical access are different vectors. MFA is necessary but not sufficient. It must be paired with EDR, backups, and team training.

How do I know if my current IT provider actually secures my company?

Ask them four direct questions: Do you have ISO 27001 certification or PASSI qualification? Can you provide a security audit report of my systems? Do you have an incident response plan for my infrastructure? What happens if you yourself are attacked? If the answers are vague or these questions seem new to them, your security is probably not in good hands. A serious provider anticipates these questions and can answer with concrete documentation.

By RMG Solutions

Certified Odoo Partner | Cybersecurity | Infrastructure | GRC

Last updated : April 30, 2026

Protect Your Business

Security audits, SOC, endpoint protection, our experts secure your information systems.