Cybersecurity is no longer viewed as a purely technical function within Moroccan companies. It has become a matter of governance, business continuity and competitiveness. That is the main finding of the 2026 AUSIMètre, a study carried out by AUSIM, the Association of Information Systems Users in Morocco, in partnership with PwC among 62 organizations between January 4 and March 31, 2026.
According to the report, Morocco’s overall cyber maturity index rose from 49% in 2025 to 56% in 2026, an increase of 14%. Companies surveyed have moved from what is described as a “developing” stage to a “defined” level, characterized by more structured strategies and clearer responsibilities.
Progress was recorded across several areas. Compliance reached a maturity level of 80%, up from 70% in 2025. Budget allocation increased from 46% to 59%, while strategy improved from 50% to 58%. Governance also strengthened, rising from 44% to 52%, while preparedness for emerging risks jumped from 36% to 48%.
Read also : Morocco steps up efforts against phishing and online financial fraud
The improvement is largely driven by greater involvement from senior management in cybersecurity matters. The study found that 74% of executive teams now actively participate in cyber-related decisions, compared with 55% a year earlier. At the same time, 61% of cybersecurity leaders report directly to top management rather than solely to IT departments.
However, the report notes that this involvement still needs to be formalized. Although cybersecurity is increasingly handled at the highest levels of organizations, only 45% of companies have formally defined their acceptable level of cyber risk. According to the report’s authors, the next challenge is to turn executive commitment into lasting procedures for decision-making, oversight and crisis management.
The strengthening of governance has been accompanied by significant financial efforts. The report estimates that 56% of companies now allocate more than 5% of their IT budgets to cybersecurity, while 37% spend more than 7%. Data protection has become the top budget priority for 68% of respondents, up from 33% in 2025.
The AUSIMètre nevertheless highlights disparities across organizations. Around 14% invest less than 3% of their IT budgets in cybersecurity, while 16% still lack a clearly identified cyber budget. This reflects differences in size, sector and levels of digital transformation across the economy.
Regulation becomes a driver of trust
The regulatory framework is playing a decisive role in this growing maturity. Compliance is no longer seen solely as an obligation. According to the study, 29% of companies view it as a strategic lever and 27% as a source of trust, although 32% still approach it primarily as a minimum requirement.
The report also notes that 44% of respondents have adjusted their governance structures in response to regulatory developments. Standards and compliance requirements are helping clarify responsibilities, structure procedures and better integrate digital risks into business decisions.
As a result, investments are increasingly focused on operational threats. Data protection is cited as a priority by 67% of companies, followed by resilience against cyberattacks at 58%, while compliance ranks third at 37%.
The shortage of talent remains the biggest challenge. According to the report, 84% of surveyed organizations are affected by a lack of cybersecurity skills, with 29% describing the impact as critical and 55% as moderate. Only 8% report no difficulties in this area.
Read also : Royal Air Maroc to receive another Boeing 787 Dreamliner by end of July
To address the issue, 57% of companies prioritize training and upskilling their teams. This strategy is gradually expanding the national talent pool beyond highly specialized technical profiles.
Outsourcing also plays a role. Around 93% of organizations delegate at least one cybersecurity function to external providers, particularly continuous system monitoring, cited by 29%, and penetration testing, mentioned by 27%. The report nonetheless recommends keeping strategy, risk assessment and decision-making capabilities in-house.
Digital sovereignty is another area requiring attention. According to the AUSIMètre, 60% of companies report moderate to very high dependence on cloud service providers. While 30% already have a formal exit strategy in place, 32% are developing one and 38% have yet to do so.
The report does not challenge the adoption of cloud technologies, which have become essential to digital transformation. Instead, it emphasizes the need to map dependencies, classify data according to sensitivity and prepare for the possibility of switching providers.
Artificial intelligence reflects the same trend of rapid adoption. Nearly 87% of companies consider AI an asset for cybersecurity. Threat detection is cited by 48% of respondents, while 45% point to predictive analytics. However, only 30% have formalized rules governing its use, and 18% have yet to appoint an AI officer.
Meanwhile, phishing remains the most widespread threat, identified by one in two companies (50%). It is followed by cyberattacks carried out through service providers or partners (34%), and malicious uses of artificial intelligence (31%).
