Cybersecurity for Moroccan SMEs: 2026 Complete Guide
Cyberattacks, real costs in MAD, Law 05-20 legal obligations and a 30-60-90 day action plan: the complete cybersecurity guide for Moroccan SMEs in 2026.
What Happened on April 8, 2025
On April 8, 2025, a group calling itself "Jabaroot DZ" published 53,000 files extracted from the databases of Morocco's National Social Security Fund (CNSS). The files contained the names, national ID numbers, bank account details, and salary information of nearly 2 million Moroccan employees. The data of approximately 500,000 companies was exposed: HR records, corporate bank account details, and information about company directors.
This is not an incident that concerns CNSS alone. If you run an SME in Morocco, your data was potentially in those files. Your employees received calls, SMS messages, and scam attempts exploiting that information. Several business owners reported attempted fraudulent wire transfers in the weeks that followed.
The CNSS breach made concrete, for tens of thousands of Moroccan executives, a risk they knew existed in theory. This guide answers the question many have been asking since: where do I start?
Why Moroccan SMEs Are Prime Targets
The Myth of Small Size as Protection
Many SME directors sincerely believe their company is too small to interest hackers. That logic may have held ten years ago. It does not hold today.
According to DGSSI (Morocco's General Directorate of Information Systems Security) data, 60% of cyberattacks in Morocco target very small and small-to-medium businesses. The reason is straightforward: large companies have invested in their security, and their systems are harder to compromise. SMEs, by contrast, often remain accessible with basic tools. Ransomware-as-a-service (RaaS) has democratized cybercrime: individuals with no technical skills now rent attack toolkits for a few hundred dollars and target the least protected organizations. Your 30-employee SME in Casablanca is an easier target than a publicly listed group.
In the first half of 2025, 21 million cyber threats were detected in Morocco, according to data presented at the Kaspersky/KNext Forum in Rabat. That number does not concern only large institutions.
A 2025 CGEM (Confederation of Moroccan Enterprises) survey reveals that 62% of Moroccan companies report having experienced at least one attempted attack. Among those that suffered a serious attack, more than half experienced multi-day business interruptions.
The 2025 Ausimètre barometer (PwC/AUSIM) confirms this awareness: 73% of Moroccan companies place cyber risk at the top of their priorities for the next 12 months, and 78% allocate up to 25% of their technology investment to it. The Moroccan cybersecurity market reached USD 157 million in 2026 (Mordor Intelligence), with 15.67% annual growth in the SME segment, twice the rate of the overall market. Morocco scored 97.5/100 on the ITU's 2024 Global Cybersecurity Index, placing it in Tier 1 alongside global leaders. The institutional framework is in place, but its application remains the responsibility of each individual business.
21M
Cyber threats detected (H1 2025)
60%
SMEs targeted by attacks
1.2M MAD
Average cost of an attack
62%
Moroccan companies attacked
Who Gets Attacked, and Why
Some sectors are over-represented in Moroccan incident statistics:
| Sector | Primary vulnerability |
|---|---|
| Trade and distribution | Customer data, banking access, online payments |
| Construction and real estate | Sensitive financial data, large wire transfers |
| Professional services (lawyers, accountants) | Confidential third-party data, high ransom potential |
| Textile and agro-food manufacturing | Supply chain access, supplier credentials |
| Hospitality and restaurants | Card data, reservations, point-of-sale systems |
| IT services | Supply-chain attacks targeting their clients |
Distribution, construction, and professional services see the highest incident rates, not because they are careless, but because they handle large financial flows with reduced or non-existent IT teams.
The Cost of an Attack vs. the Cost of Protection
What an Incident Really Costs
SME directors almost always underestimate the real cost of a cyberattack. They think of the potential ransom, but forget everything else.
| Cost item | Estimated range (MAD) |
|---|---|
| System and data restoration | 50,000 - 200,000 MAD |
| Lost revenue during interruption | 100,000 - 500,000 MAD |
| Legal fees and CNDP notification costs | 20,000 - 80,000 MAD |
| Regulatory fines (CNDP, Law 09-08) | 100,000 - 300,000 MAD |
| Potential ransom (if ransomware) | 50,000 - 300,000 MAD |
| Crisis communications and lost contracts | Variable |
| Estimated average total cost | 1.2 million MAD |
This 1.2 million MAD figure is cited by the DGSSI as the average impact of a ransomware attack on a Moroccan SME. It reflects a reality that local experts confirm: a 40-person company paralyzed for a week, with compromised customer data and a regulatory notification obligation, quickly reaches that level of loss.
There is another number worth knowing: 60% of SMEs that suffer a major attack cease operations within 18 months. Not because of the ransom itself, but because the loss of customer trust, reconstruction costs, and operational disruption accumulate to the point where the business is no longer viable.
What Protection Costs by Company Size
Protection is not reserved for large enterprises. SME-accessible solutions exist, and their cost is incomparable with that of an incident.
| Company size | Recommended cybersecurity budget | What it covers |
|---|---|---|
| 1-10 employees | 1,500 - 4,000 MAD/month | EDR antivirus, password manager, cloud backups, MFA |
| 10-50 employees | 4,000 - 15,000 MAD/month | Centralized EDR, managed firewall, basic monitoring, training |
| 50-200 employees | 15,000 - 50,000 MAD/month | Outsourced SOC, SIEM, incident response, regular audits |
| 200+ employees | From 50,000 MAD/month | In-house or hybrid SOC, red team, full compliance program |
These figures include both tools and, where relevant, the services of a specialized partner like RMG Solutions. Threat protection services can be rolled out progressively, without locking up an entire annual budget on day one.
The Return on Investment
The math is direct. For a 30-person SME, a protection budget of 6,000 MAD per month represents 72,000 MAD per year. Against an incident with an average cost above 1.2 million MAD (not counting customer churn) the question is not "can we afford to spend on cybersecurity," but "can we afford not to?"
Less than 15% of Moroccan SMEs have a dedicated cybersecurity budget (CGEM, 2025). That is precisely why attackers target SMEs first.
To estimate your current exposure level quickly without commitment, our cybersecurity self-diagnostic assesses your posture in 5 minutes across the ten key domains (governance, access, backups, training, etc.).
The 5 Threats Facing Moroccan SMEs in 2026
1. Phishing: and Its WhatsApp Variant
Phishing remains the primary entry point into Moroccan SME systems. In 2024, 47% of attacks against Moroccan SMEs originated from fraudulent emails impersonating banks, government agencies, or commercial partners (DGSSI).
The Morocco-specific variant deserves particular attention: WhatsApp phishing. Moroccan SMEs use WhatsApp Business intensively for customer and supplier communications. Attackers know this. They send messages from numbers resembling those of suppliers or partners ("Your invoice pending validation, click here"), fake DGI tax notices, or urgency-driven messages ("Your bank account will be blocked in 24 hours").
These messages are often written in fluent Darija or French, and rely on information harvested from previous breaches, including the CNSS leak.
What you can do now: Train every employee to never click a link received via WhatsApp or email without a direct voice verification with the supposed sender. This simple protocol blocks the vast majority of attempts.
2. Ransomware
Ransomware encrypts your files and demands a ransom to recover them. The average demand exceeds 500,000 MAD for Moroccan SMEs, according to data collected by local cybersecurity providers.
What changed in the past two years: attackers no longer just encrypt your data. They first exfiltrate it, then threaten to publish it if you do not pay. This "double extortion" has become standard practice and makes simple backup restoration insufficient.
The most frequent vectors for Moroccan SMEs: email with infected attachment, exposed and poorly secured RDP (remote desktop) access, and compromise of an external IT service provider.
3. Credential Theft
This vector is underestimated. Millions of username/password combinations from Moroccan businesses circulate on underground forums, often originating from leaks of unrelated services (social networks, e-commerce platforms).
If your employees reuse the same passwords for personal email and professional accounts (and that is very common) an attacker who buys a leaked credential database can access your systems directly with no technical effort.
The protection is simple and nearly free: two-factor authentication (2FA/MFA) on all professional accounts, plus a password manager. It is the cybersecurity investment with the best cost-to-effectiveness ratio.
4. Cloud Misconfiguration
The shift to cloud (Microsoft 365, Google Workspace, Azure or AWS storage) has brought real benefits to Moroccan SMEs. It has also created new risks, often invisible.
Cloud storage buckets accidentally made public, overly broad access rights in Microsoft 365, administrator accounts without MFA: these errors expose sensitive data without an attack even being necessary. The data is simply accessible to anyone who knows where to look.
Automated scanning tools continuously crawl the internet looking for these exposed configurations. An SME that migrated to the cloud without a configuration audit is often more vulnerable than before the migration.
5. Supply Chain Attacks
If your IT provider, your accounting firm, or your software vendor is compromised, attackers can reach your network through that trust relationship. That is what happened with CNSS: the affected companies had done nothing wrong, but their data was stored at an entity that was compromised.
For SMEs, the concrete risk is this: your IT provider has access to your systems for maintenance. If their infrastructure is compromised, an attacker has the same access as your technician. Asking your provider for guarantees on their own security is not paranoia: it is risk management.
The Legal Framework: What Your SME Must Comply With
Law 09-08 and the CNDP Turning Point
Law 09-08 on the protection of personal data has existed since 2009. For fifteen years, the CNDP (Morocco's National Commission for the Protection of Personal Data) ran an awareness phase and did not actively sanction.
That changed in February 2025. The CNDP officially announced the end of its awareness phase and the start of an active enforcement phase. In 2024, 27 million MAD in fines were already issued against Moroccan companies for Law 09-08 violations. The pace will accelerate.
Your concrete obligations under Law 09-08:
- Declare your personal data processing activities to the CNDP
- Inform your customers, employees, and partners of the collection and use of their data
- Secure the data you process technically and organizationally
- Restrict data access to the strict minimum (data minimization principle)
- Do not transfer personal data abroad without CNDP authorization
| Type of violation | Administrative sanction |
|---|---|
| Failure to declare to CNDP | 10,000 - 100,000 MAD |
| Failure to inform data subjects | 10,000 - 100,000 MAD |
| Violation of security measures | 100,000 - 300,000 MAD |
| Illicit collection of sensitive data | 100,000 - 300,000 MAD |
| Refusal to cooperate with CNDP | 100,000 - 300,000 MAD |
| Unauthorized international transfer | Up to 300,000 MAD + criminal sanctions |
Sanctions are cumulative per violation. An SME that has not declared its processing, does not inform its customers, and has not secured its data can face more than 600,000 MAD in simultaneous fines.
Law 05-20: For Critical Infrastructure
Law 05-20 on cybersecurity, published in 2020, applies primarily to public administrations, public institutions, and operators of vital infrastructure (energy, water, transport, banks, telecoms). If your SME operates in these sectors or supplies services to such entities, you may be subject to its requirements.
Its obligations include compliance with the National Information Systems Security Directive (DNSSI), incident reporting to the DGSSI within strict deadlines, and security audits performed by certified PASSI providers.
For a complete analysis of your DGSSI obligations, see our complete DGSSI compliance guide for Morocco, which covers the full DNSSI requirements, the Law 05-20 implementing decree, and the practical compliance roadmap.
What This Means in Practice for Your SME
Even if your sector is not directly targeted by Law 05-20, Law 09-08 applies to you as soon as you process personal data, which is the case for every business that has employees, customers, or suppliers.
CNDP compliance and cybersecurity are not two separate topics. A security incident that exposes personal data automatically creates a regulatory problem. Investing in technical security is also investing in legal compliance.
30-60-90 Day Action Plan
This plan is designed for an SME starting from scratch or nearly so. It is realistic, sequenced, and calibrated for a constrained budget. The first 30 days require no external provider.
Phase 1: First 30 Days: Audit and Immediate Protection
Weeks 1-2: Inventory and Audit
Before deploying tools, you need to know what you have. List all your digital assets: computers, servers, professional mobile devices, cloud services, applications in use. Identify who has access to what.
Ask yourself these questions:
- Who has administrator rights on your network? Are they all necessary?
- Are your backups tested regularly? Where are they stored?
- What software runs on your machines, and is it up to date?
- Do all your Microsoft 365 or Google Workspace accounts have MFA enabled?
Weeks 2-4: Immediate Near-Zero-Cost Actions
| Action | Cost | Impact |
|---|---|---|
| Enable MFA on all professional accounts | 0 MAD | Blocks ~99% of credential theft attempts |
| Update all operating systems and software | 0 MAD | Closes the most exploited vulnerabilities |
| Change all default passwords (routers, NAS, etc.) | 0 MAD | Eliminates a frequent entry vector |
| Disable internet-exposed RDP access | 0 MAD | Drastically reduces ransomware risk |
| Test your backups (restore one file) | 0 MAD | You'll know whether they actually work |
| Deploy a password manager (Bitwarden Teams) | ~1,500 MAD/year | Eliminates password reuse |
Phase 2: Days 30-60: Tools and Processes
Deploying Protection Tools
A traditional antivirus is no longer enough. Moroccan SMEs should move to an EDR solution (Endpoint Detection and Response), which detects suspicious behavior in addition to known virus signatures.
Realistic options for Moroccan SMEs:
| Solution | Type | Monthly budget (30 endpoints) | Strengths |
|---|---|---|---|
| Microsoft Defender for Business | EDR | ~2,500 MAD | Microsoft 365 integration, simple to deploy |
| Bitdefender GravityZone | EDR | ~2,000 MAD | Excellent price/protection ratio, local support |
| SentinelOne Singularity | EDR/XDR | ~5,000 MAD | Advanced behavioral detection |
| Sophos Intercept X | EDR | ~3,000 MAD | Strong ransomware protection |
3-2-1 Backup Strategy
The 3-2-1 rule is the minimum: 3 copies of your data, on 2 different media, with 1 offsite (cloud or remote location). For a Moroccan SME, this might look like:
- Local backup on NAS (daily)
- Cloud backup on Azure or Backblaze B2 (daily)
- Monthly archive backup stored separately
Written Security Policy
A security policy doesn't need to be 50 pages. For an SME, a one-to-two-page document covering the essential rules is enough: use of professional devices, password rules, procedure for suspicious emails or messages, incident reporting.
Phase 3: Days 60-90: Monitoring and Resilience
Monitoring and Detection
By this stage, you have protected your endpoints and organized your backups. The next step is to see what is happening on your network. Continuous security monitoring detects abnormal behavior before it becomes an incident.
For SMEs of fewer than 50 people, the most cost-effective solution is often an outsourced managed SOC service. Rather than hiring a security analyst (cost: 15,000 to 25,000 MAD/month), you pay for access to a full team for a fraction of that budget. RMG Solutions offers this through its continuous monitoring service, with certified consultants who understand the Moroccan regulatory context.
Incident Response Plan
78% of Moroccan SMEs do not have an incident response plan (CGEM, 2025). When an attack occurs, the absence of a plan turns a bad situation into a catastrophe.
A minimal plan must answer these questions:
- Who decides to isolate a compromised system, and how?
- Who notifies customers, authorities, the CNDP?
- Who contacts the cybersecurity provider, and what is the emergency number?
- How do you document the incident for legal reasons?
Our incident response team can help you build that plan and test it.
Team Training
Most incidents start with human error. A two-hour annual training session on current threats (phishing, WhatsApp, passwords) statistically divides the incident risk by three. This is not a boring PowerPoint training: practical phishing simulations and concrete Moroccan case studies are far more effective.
Need expert guidance?
Leave your details and an RMG Solutions expert will contact you within 24h.
How to Choose the Right Solutions
Antivirus, EDR, XDR, Managed SOC: What These Acronyms Actually Mean
These acronyms create confusion. Here is what each level actually delivers:
| Solution | What it does | What it doesn't do | Monthly budget (30-endpoint SME) |
|---|---|---|---|
| Traditional antivirus | Detects known viruses by signature | Misses novel attacks, no automatic response | 500 - 1,000 MAD |
| EDR | Detects by behavior, isolates infected machines, generates alerts | Requires someone to analyze the alerts | 2,000 - 5,000 MAD |
| XDR | EDR + correlation across network, email, cloud in a unified console | More complex to deploy, requires expertise | 5,000 - 15,000 MAD |
| Managed SOC | 24/7 monitoring by human experts, incident response included | No direct control over the tools | 10,000 - 30,000 MAD |
For most Moroccan SMEs between 10 and 100 employees, the pragmatic recommendation is: properly configured EDR + backup rules + employee training. Add a managed SOC when the budget allows, or when your sector (finance, healthcare, critical industry) justifies continuous monitoring.
When to Outsource, When to Keep In-House
| Situation | Recommendation |
|---|---|
| SME with no dedicated IT team | Fully outsource to an MSSP provider |
| SME with 1-2 IT technicians | Outsource monitoring and incident response, keep day-to-day in-house |
| SME with 3+ IT staff | Keep operational in-house, outsource audits and advanced SOC |
| Regulated sector (banking, healthcare) | Hybrid SOC: in-house team + certified provider for regulatory obligations |
Certifications to Demand from Your Provider
Not all cybersecurity providers are equal. Here is what to verify before signing:
PASSI (Information Systems Security Audit Provider): qualification issued by ANSSI in France, recognized in Morocco. Indicates that the provider can conduct audits aligned with international standards.
ISO 27001: certification of the information security management standard. A provider certified ISO 27001 applies to its own organization the processes it recommends to clients.
Vendor partnerships: an official partnership with Microsoft, Palo Alto, CrowdStrike, or SentinelOne indicates competence verified by these vendors.
For managed security services, systematically request client references in your sector and certifications of the technical staff, not just of the company.
If your sector exposes you to regulatory obligations, a security audit by a qualified provider is the first step to identifying your gaps precisely before investing in tools.
Cyber Insurance in Morocco
Cyber insurance exists in Morocco, but the market is still nascent. Among insurers offering specific cyber coverage: Allianz Morocco (Cyber Assurances product), AFMA, and Howden Morocco. Finance Minister Nadia Fettah announced in 2025 the development of a dedicated cyber insurance product at the Casablanca Insurance Meeting.
Coverage typically includes:
- System restoration costs
- Business interruption losses
- Third-party liability for data breaches
- Notification and crisis communication costs
Premiums range from 5,000 to 30,000 MAD per year for an SME, depending on sector and data volume. Cyber insurance does not replace technical protection: most contracts exclude incidents resulting from obvious negligence (no updates, no backups). It complements a healthy security posture, it does not substitute for one.
Where to Start, Concretely
If you read this guide to here, you know three things: your SME is a target, the cost of inaction exceeds the cost of protection, and the legal obligations are now actively enforced.
Your next step: a cybersecurity audit of your current situation. Not a tool, not a contract. A diagnostic. Where do you stand? What are your priority gaps? What budget is realistic for your size and sector?
RMG Solutions supports Moroccan SMEs from the initial audit to the rollout of protection and monitoring solutions. Contact us for an initial free assessment.
The RMG Solutions Approach to SME Cybersecurity
Complete protection, not just an audit. Most cybersecurity providers in Morocco sell isolated services: a one-time audit, an antivirus, a firewall. At RMG Solutions, we cover the full protection chain because we are the only multi-service IT partner in the Moroccan market: security posture audit and gap analysis, EDR rollout across all your endpoints, managed SOC with continuous 24/7 monitoring, incident response when an attack hits, and CNDP/DGSSI regulatory compliance. When we identify a flaw in your infrastructure during the audit, we fix it ourselves, no need to find another provider for network, server, or cloud work. Based in Hay Riad (Rabat), we intervene on-site the same day in Rabat and within the hour in Casablanca, which makes the difference when ransomware hits on a Monday morning. Every engagement starts with a free 30-minute initial assessment, no commitment, with a costed action plan adapted to your real budget.
Contact us to schedule your assessment.
Frequently Asked Questions
Does a 10-person Moroccan SME really need cybersecurity?
Yes. Size is not a protective factor: 60% of attack targets in Morocco are very small and small-to-medium businesses. Attackers specifically target small organizations because they are less protected. A 10-person SME that processes customer data, uses online banking, and communicates by email faces the same threats as a large enterprise, with fewer resources to recover from an incident.
What should I do if my company is hit by a cyberattack?
First step: isolate the affected systems from the rest of the network to limit propagation. Do not power off the machines (you'll lose forensic evidence). Immediately contact a specialist incident response provider. If personal data is compromised, you have a legal obligation to notify the CNDP within the deadlines defined by Law 09-08. Document everything from the start for insurance and legal purposes.
What sanctions apply if I am not Law 09-08 compliant?
Administrative fines range from 10,000 MAD for minor infractions (no CNDP declaration) up to 300,000 MAD per violation for serious infractions (no security measures, illicit collection). Sanctions are cumulative: multiple simultaneous violations result in multiple fines. The most serious infractions can also lead to criminal proceedings. Since February 2025, the CNDP has been in active enforcement mode.
Is MFA (two-factor authentication) enough to protect my professional accounts?
MFA is the most effective single measure to prevent account takeover via credential stuffing or classic phishing. It statistically blocks more than 99% of automated attempts. But it doesn't protect against everything: an employee approving a fraudulent MFA prompt ("MFA fatigue" attack), malware bypassing authentication, or unauthorized physical access are different vectors. MFA is necessary but not sufficient. It must be paired with EDR, backups, and team training.
How do I know if my current IT provider actually secures my company?
Ask them four direct questions: Do you have ISO 27001 certification or PASSI qualification? Can you provide a security audit report of my systems? Do you have an incident response plan for my infrastructure? What happens if you yourself are attacked? If the answers are vague or these questions seem new to them, your security is probably not in good hands. A serious provider anticipates these questions and can answer with concrete documentation.
By RMG Solutions
Certified Odoo Partner | Cybersecurity | Infrastructure | GRC
Last updated : April 30, 2026