Headlines Morocco Technology

Morocco’s Cyber Maturity Index Jumps to 56% as AI Adoption Outpaces Governance Controls

The third edition of the AUSIMètre barometer, published by AUSIM and PwC in July, points to a contrasted picture of cybersecurity readiness among Moroccan companies: notable governance progress and rising investment, alongside structural fragilities that continue to constrain the broader economy’s maturity. The overall maturity index rose from 49 percent in 2025 to 56 percent in 2026, marking a transition to what the study characterizes as a “defined” level — driven largely by growing engagement from top management, with 74 percent of general management now actively participating in cyber governance, up from 55 percent a year earlier.

Budget allocation is following the same trajectory. More than half of companies now dedicate over 5 percent of their IT budget to security, with a growing share exceeding 7 percent. Nonetheless, close to 30 percent of organizations remain under-invested or lack any dedicated budget, creating a significant disparity in resilience capacity across the corporate landscape. National regulation, notably Law 05-20, plays a structuring role: 44 percent of companies cite it as a reference framework that strengthens governance even ahead of increased investment.

Talent availability remains the principal obstacle to further progress. Morocco faces a particularly acute shortage, with 84 percent of companies reporting a lack of specialized talent — well above the global average of 63 percent — and 29 percent describing the situation as critical. Facing difficulty recruiting qualified profiles, organizations are prioritizing internal training and upskilling, with more than half investing in developing existing staff. Outsourcing has also become common: 93 percent of companies delegate at least one cyber function, particularly continuous monitoring and penetration testing, though experts caution that while technical operations can be outsourced, governance and decision-making must remain in-house.

The study identifies two vulnerability zones linked to rapid technology adoption. Artificial intelligence is seen as an efficiency lever by 87 percent of companies, particularly for automating incident detection, yet control mechanisms remain insufficient: only 30 percent of organizations have formalized usage rules, and 18 percent have designated no one responsible for overseeing these tools. AI-related incidents are already being observed — 40 percent of companies report social engineering attacks amplified by these technologies, and 25 percent cite data leaks. Cloud dependency compounds the risk: 60 percent of companies show medium-to-critical dependency on external providers, and 70 percent have no formalized reversibility strategy, exposing them to loss of control in the event of provider failure or major crisis.

The report also flags a lack of anticipation regarding quantum computing threats: nearly 64 percent of companies consider the risk distant, even as experts warn that sensitive data is already being intercepted under a “harvest now, decrypt later” logic, with only around 30 percent of organizations having begun crypto-agility efforts to prepare for post-quantum standards. AUSIM and PwC identify three priorities for strengthening national resilience: framing AI usage and securing cloud environments with strict usage rules and reversibility plans built into contracts from the outset; addressing the talent shortage by retraining non-technical profiles into cyber risk management roles while using AI as a support tool; and preparing for the post-quantum era by mapping cryptographic assets and embedding crypto-agility requirements into tenders.

North Africa Post
North Africa Post's news desk is composed of journalists and editors, who are constantly working to provide new and accurate stories to NAP readers.
https://northafricapost.com