The landscape of cybersecurity in Moroccan companies has evolved significantly, transitioning from a purely technical function to a critical aspect of governance, business continuity, and competitive strategy. This insight is drawn from the AUSIMètre 2026, a comprehensive report conducted by the Association of Information Systems and Management (AUSIM) in collaboration with PwC, which surveyed 62 organizations between January 4 and March 31, 2026. The findings reveal a noteworthy increase in the overall cybersecurity maturity index in Morocco, which rose from 49% in 2025 to 56% in 2026, marking a substantial 14% improvement. This transition indicates that surveyed organizations are progressing from a developmental stage to a defined phase characterized by more structured strategies and clearly identified responsibilities.
The enhancement in cybersecurity maturity is reflected across multiple dimensions. Notably, compliance levels have reached an impressive 80%, up from 70% in 2025. Budget planning has also seen progress, increasing from 46% to 59%, and the overall strategy improved from 50% to 58%. Governance has advanced from 44% to 52%, alongside the organizations' ability to anticipate emerging risks, which rose from 36% to 48%. This upward trajectory can be attributed, in large part, to increased involvement from senior management in cybersecurity matters. According to the study, 74% of executive management now actively participates in decision-making processes related to cybersecurity, a significant increase from the 55% reported the previous year. Concurrently, 61% of cybersecurity leaders now report directly to executive management rather than solely to the information systems department.
Despite these advancements, the report emphasizes the need for formalization of this executive involvement. While cybersecurity considerations have reached the highest levels of management, only 45% of organizations have documented their acceptable level of cyber risk. The authors of the study argue that the current challenge lies in converting this executive commitment into permanent decision-making procedures, oversight, and crisis management protocols.
Strengthened governance is accompanied by significant financial commitment, with the report estimating that 56% of companies currently allocate over 5% of their IT budget to cybersecurity, while 37% exceed the 7% threshold. Data protection has emerged as the primary budgetary priority for 68% of respondents, a notable increase from the 33% reported in 2025. However, the AUSIMètre also highlights a concerning disparity within the sector; around 14% of organizations invest less than 3% of their IT budget in cybersecurity, and 16% do not even have a dedicated budget for this area. This heterogeneity reflects various factors, including differences in company size, industry sector, and levels of digital transformation across the Moroccan business landscape.
Regulatory frameworks are increasingly recognized as a pivotal factor in building trust and enhancing maturity levels. Compliance is no longer seen merely as a legal obligation; 29% of businesses view it as a strategic element, while 27% consider it a trust factor, although 32% still treat it primarily as a minimum requirement. The report also reveals that 44% of respondents have adapted their governance models in response to evolving regulatory frameworks. New rules and obligations have thus clarified responsibilities, structured procedures, and better integrated digital risks into business decision-making processes.
This evolution has also facilitated a redirection of investments towards operational threats. Data protection is cited as the top priority for 67% of companies, followed by enhancing resilience against cyberattacks (58%) and compliance (37%). However, the availability of specialized professionals remains the foremost challenge, with 84% of organizations experiencing a shortage of cybersecurity talent: 29% facing this issue critically and 55% moderately. Only 8% report no difficulties in recruiting such talent. To address this shortage, 57% of companies are investing in the training and development of their internal teams, progressively expanding the national base of professionals beyond highly specialized technical profiles. Outsourcing complements this model, with 93% of organizations subcontracting at least one cybersecurity-related function, particularly continuous system monitoring (29%) and penetration testing (27%). Nevertheless, the report recommends retaining strategy, risk knowledge, and decision-making capabilities internally.
Digital sovereignty is another key area of focus, with the AUSIMètre indicating that 60% of companies report a medium to high reliance on cloud service providers. While 30% have a formalized reversibility strategy, 32% are in the process of developing one, and 38% have yet to establish any. The report does not challenge the adoption of cloud technology, which has become an essential tool for digital transformation; instead, it emphasizes the need to identify existing dependencies, classify data by sensitivity levels, and anticipate conditions for potential vendor changes.
Artificial intelligence is experiencing a similar trend of rapid adoption, with nearly 87% of companies viewing this technology as an ally in bolstering cybersecurity. Threat detection is mentioned by 48% of respondents, while predictive analysis is cited by 45%. However, only 30% have established formal usage guidelines, and 18% have yet to appoint a specific individual responsible for AI. Concurrently, phishing remains the most prevalent threat, reported by one in two companies (50%), followed by cyberattacks through vendors or partners (34%) and malicious uses of artificial intelligence (31%).
As reported by es.le360.ma.