Connect with us

Kingdom

Cybercrime: Morocco Strengthens Its Digital Shield

Since the cyberattacks of 2025, cybersecurity has become a strategic priority for the State. In less than a year, ministries and public agencies have launched a series of tenders: SOCs, audits, network infrastructures, and advanced detection solutions. A real race has begun among technology companies to secure the Kingdom’s critical digital systems. Analysis.

Published


Updated

April 8, 2025 marks a turning point. Within a few hours, the systems of the National Social Security Fund (CNSS) plunge into digital chaos. A large-scale cyberattack disrupts services, exposes sensitive data, and shakes the institution’s reputation. Two months later, the “Tawtik” platform of the National Council of Notaries is in turn affected.

These incidents, which brutally reveal the digital vulnerabilities of systems that are nonetheless critical, elevate cybersecurity from a technical concern to a strategic priority. The shock is immediate. Ministries, public institutions, and major agencies launch a race to strengthen their digital defenses.

Cybersecurity is thus emerging as one of the most dynamic segments of public procurement. Between April 2025 and February 2026, no fewer than 22 contracts, representing more than 151 million dirhams, were launched by seventeen public institutions, according to official documents we reviewed (see infographic). Of this total, 14 contracts have already been awarded, while eight are still in the process of being tendered.

The rush toward cybersecurity operations centers

Unsurprisingly, the CNSS is among the most active institutions. In June 2025, the public entity led by Hassan Boubrik entrusted the IT company Munisys with maintaining its critical reverse proxy systems and the protection of exchanged documents. At the same time, several tenders were launched to strengthen anti-intrusion systems and deploy data loss prevention (DLP) solutions.

But the most structuring project came a few months later. At the end of October, the French group Devoteam secured a 7.9 million dirham contract to set up a Security Operations Center (SOC) tasked with continuously monitoring CNSS information systems.

Planned for an initial duration of one year, renewable up to three years, the mission involves overseeing the entire IT infrastructure (servers, networks, databases, and endpoints) in order to detect and neutralize threats in real time. A true digital control tower, the SOC is gradually becoming the backbone of institutional cybersecurity.

Security audits multiply

In CNSS’s wake, several public bodies are also accelerating their investments. The latest example is the Ministry of Economy and Finance, which awarded Dataprotect, in February 2026, a contract worth 8.5 million dirhams for the implementation and operation of a SOC.

The project includes analyzing existing systems, assessing current security measures, and integrating operational procedures.

This contract adds to two other similar deals won in July and October 2025 by the company founded in 2009 by Ali El Azzouzi. The first, signed with the National Motorway Company of Morocco (ADM), concerns the protection of its critical infrastructure for 9 million dirhams. The second involves the National Road Safety Agency (Narsa), which entrusted it with setting up and managing its SOC for nearly 5 million dirhams.

The healthcare sector is not left behind. In December 2025, the Ministry of Health and Social Protection, led by Amine Tehraoui, allocated nearly 11 million dirhams to deploy its own Security Operations Center.

The objective: to protect highly sensitive data, particularly that of hospital information systems.

This project complements another contract launched two months earlier for the acquisition of a Privileged Access Management (PAM) solution, with a budget of 4.5 million dirhams. The system is intended to control and track remote access to the platforms of the ministry’s Information Systems Division, as well as to hospital systems hosted at Maroc Data Center.

Critical infrastructure under surveillance

Another rapidly expanding segment is information system vulnerability audits. Many administrations are using them to identify weaknesses in their digital infrastructure, assess performance levels, and verify compliance with security standards.

The National Agency for Land Conservation, Cadastre and Cartography (ANCFCC) is among the institutions engaged in this approach. In July 2025, the agency led by Karim Tajmouati commissioned NearSecure to carry out a comprehensive security audit of its information system.

The contract was launched in a context marked by a land data leak from the Tawfik notarial platform. Spanning thirteen months, the audit covers the central site, the Mapping Directorate, and a sample of three external offices, in order to assess all organizational, technical, and strategic dimensions of the agency’s cybersecurity.

At the same time, ANCFCC is preparing to update its Information Systems Master Plan (SDSI) as part of its digital transformation strategy looking ahead to 2030. Operators of strategic infrastructure are also strengthening their systems.

This is the case of the National Office of Electricity and Drinking Water (ONEE), whose Water branch entrusted Dataprotect with an audit aimed at securing its IT and industrial architectures.

The main challenge: protecting IT and OT systems to avoid any service interruption or resource contamination. This upgrade is also intended to secure a future centralized database fed by smart sensors and connected meters, designed to monitor distribution networks in real time.

Comprehensive security measures

Beyond SOCs and audits, several institutions are investing in advanced detection and data protection solutions. This is the case of the Ministry of the Interior, which has enlisted Maroc Data Center (MDC) to manage and host its portals. This is far from trivial, as experts consider websites to be preferred entry points for “black hat” hackers.

But the most ambitious project remains a contract worth nearly 34 million dirhams launched in September 2025 to secure the networks linking the central administration to 83 prefectures.

The program includes firewall solutions, SD-WAN technologies, vulnerability management tools, and advanced email protection. As early as July 2023, the department led by Abdelouafi Laftit had already awarded a 10.2 million dirham contract to Dataprotect to assist in setting up a SOC to secure one of the Kingdom’s most critical information systems.

The same applies to the Directorate General of Taxes (DGI), which launched a contract in early 2026 worth more than 7 million dirhams to deploy a data loss prevention (DLP) solution.

Securing digital transactions is also a major issue for Barid Al-Maghrib, which has invested more than 18 million dirhams in modernizing its cryptographic systems used for managing electronic certificates.

Other institutions, including the Ministry of Agriculture, the Ministry of Equipment and Water, the National Telecommunications Regulatory Agency (ANRT), the National Authority for Electricity Regulation (ANRE), and the Office of Vocational Training and Work Promotion (OFPPT), have also initiated several projects aimed at strengthening their digital infrastructure and protection systems.

According to the Morocco Cybersecurity Market report by Mordor Intelligence, the Moroccan digital security market is expected to reach $157 million in 2026 and rise to $238 million by 2031.

Long confined to a discreet line item in public IT budgets, cybersecurity has now been elevated to a national priority. More than a technical issue, it is becoming a strategic matter at the heart of the State’s digital sovereignty.

DGSSI, watchdog of national cybersecurity

Attached to the National Defense Administration, the General Directorate for the Security of Information Systems (DGSSI), led by Brigadier General Abdellah Boutrig, is the national authority responsible for cybersecurity and cyber defense.

It ensures the protection and resilience of public administration information systems as well as critical infrastructure, in accordance with Law No. 05-20 on cybersecurity and the National Information Systems Security Directive.

DGSSI also oversees the National Cybersecurity Strategy 2030, focused on strengthening governance, securing critical infrastructure, and training experts, including “ethical hackers.”

This represents a major challenge, as needs are estimated at more than 10,000 specialists, compared to fewer than 3,000 active professionals in 2025. To attract these scarce profiles, a draft decree adopted last October in the Council of Ministers provides for a specific HR status for the institution and incentive allowances aimed at enhancing its attractiveness.

Dataprotect vs. NearSecure: The Duel of the Leaders

Behind the scenes of public procurement in cybersecurity, two technology companies largely dominate the field: Dataprotect and NearSecure. Their names have appeared repeatedly in contract award notices in recent years. Between June 2025 and February 2026, the two companies secured nearly two-thirds of the fourteen contracts awarded.

In this duel, however, the advantage goes to the company led by Ali El Azzouzi, which has accumulated five contracts totaling 23.3 million dirhams. Among them is notably a contract won by its e-learning-focused subsidiary, Awarino, with the National Airports Office (ONDA).

For its part, NearSecure, co-founded in 2017 by Youssef Bencharhi, has secured three contracts for a total amount of 4.2 million dirhams.