Kingdom
Cybersecurity: Leveraging Human Capital to Strengthen Digital Resilience
In a context marked by the rise of cyberattacks, there is an urgent need to develop a critical mass of local skills capable of countering hackers and creating sovereign solutions. The state and businesses have recognized this and are investing heavily in it.
Like a wake-up call, the surge of hacking that shook several public entities last April—such as the National Social Security Fund (CNSS) and the Ministries of Justice, Agriculture, and Employment—exposed the vulnerability of their information systems.
This wave of cyberattacks acted as an electric shock, pushing many institutions to reinforce their computer servers and thoroughly review the protection of their digital infrastructures. This is the case for the CNSS, which two months later, in June, enlisted the services of the IT company Munisys for the maintenance of its reverse proxy solution and the protection solution for exchanged documents.
The Ministry of Agriculture is no exception. Ahmed El Bouari’s department continues to strengthen its information system to limit intrusion risks. The latest evidence: the 4.8 million dirham contract recently launched to acquire a security solution for its Active Directory, the infrastructure managing all accounts, permissions, and access for its 6,000 users.
A few days earlier, the institution had chosen the Spanish company Intelcom to deploy a combined solution for tape backup and anti-ransomware protection for its IT system.
Digital Talents to Counter Threats
Other structures, spared by “Black hat” experts, are also securing their digital systems to protect against potential attacks. Among them is the Ministry of the Interior, which budgeted 33.6 million dirhams at the end of September for the implementation of digital solutions to fortify its central headquarters and its 83 prefectures.
Before that, in July, the National Agency for Land Conservation, Cadastre, and Cartography (ANCFCC) engaged the company NearSecure for a comprehensive audit of its information system security for 2.51 million dirhams (MDH). This contract is far from trivial, as it came just weeks after the hacking of the notaries’ platform Tawtik.
But beyond strengthening digital defenses, there is an urgent need to train a critical mass of local skills to better face hyper-sophisticated “black hat” hackers who excel in innovating phishing methods. Without this qualified human capital, no cybersecurity strategy can fully succeed.
The last Council of Ministers, held on October 19, confirmed the necessity of having proven talents in technology to face these constantly evolving threats. This is evidenced by the adoption of a draft decree that establishes a special status for civil servants of the National Directorate of Information Systems Security (DGSSI), attached to the National Defense Administration.
Targeted Training to Better Equip Staff
Objective: to provide this public institution with a more flexible and attractive human resource management framework to recruit and retain civilian profiles who excel in cyber defense.
An “overall incentive allowance” will be introduced to attract these “geeks” who will lead technical and highly sensitive missions. In addition to recruiting digital talents, other institutions are increasingly investing in strengthening their employees’ capacities to better equip them in this field. The National Office of Airports (ONDA) is a case in point.
After announcing on October 8 the recruitment of its Director of Information Systems (DSI) who will lead the digital transformation of airports, the entity headed by Adel El Fakir mandated the company Awarino on October 27 to train its teams through an e-learning solution.
This subsidiary of Dataprotect, dedicated to cybersecurity training and awareness, will set up an online training platform offering various modules: from password management to physical security in the office, including data protection in accordance with Moroccan laws and international standards such as the EU’s GDPR.
International firms are joining in
Simulated phishing campaigns will be implemented to measure user reactions and generate detailed statistics through an automated dashboard, along with an employee evaluation system. This initiative is part of the national air sector modernization strategy.
“Developing specialized training has become a strategic priority. The goal is not only to equip public and private institutions with local skills capable of ensuring their systems’ resilience, but also to stimulate an entire ecosystem of service providers and experts who can support the country’s digital transformation securely,” explains Ali El Azzouzi, CEO of Dataprotect.
Aware of this crucial challenge and the shortage of qualified talent, several renowned international firms operating in Morocco are launching training centers specifically aimed at Moroccan businesses. The most recent is the British firm PwC, which inaugurated the region’s first Digital Resilience Center (DRC) in MENA on October 14.
This center of expertise and innovation is designed to support Moroccan and international companies in digital resilience, risk management, and cybersecurity. A month earlier, Deloitte established its CyberAcademy, backed by its Cybercenter based in the Kingdom. The goal is clear: to make Morocco a hub for exporting their expertise to other countries on the continent.
A Cybersecurity Innovation Center to Anticipate Digital Threats
Morocco will soon have a Cybersecurity Innovation Center (CIC) to strengthen its digital arsenal. The decision formalizing the creation of this infrastructure, which will be structured as a public interest group (GIE), was published in the Official Bulletin on May 6, 2025.
The project is led by the National Defense Administration, the delegated ministry in charge of the Budget, the Ministry of Digital Transition and Administration Reform, and Mohammed V University in Rabat.
Established for a renewable 40-year term, the CIC will be based at the National School of Computer Science and Systems Analysis (Ensias) and will carry out several activities for its members, including advanced training in cybersecurity professions, fundamental and applied research on emerging threats, technological development and innovation, and shared management of specialized equipment.
These activities will be conducted through close partnerships with academic and professional stakeholders from both the public and private sectors.
The center will also provide specialized cybersecurity startups with an environment conducive to experimentation, incubation, and the valorization of innovations.