Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity for the Public Sector

Public administrations and institutions manage personal data at scale (civil records, health, taxation) and ensure the continuity of services whose disruption has a direct impact on citizens. This combination — sensitive data and essential services — makes the sector a recurring target for both opportunistic cybercrime and hacktivism, even as the resources allocated to information security often remain lower than in the private sector for a comparable, or higher, level of exposure.

Last updatedAugust 22, 2026

Sector-specific considerations

ENISA's annual Threat Landscape report has consistently ranked public administration among the most frequently targeted sectors in Europe, particularly by hacktivist actors and ransomware groups.

ENISA, Threat Landscape (annual report)

Budget constraints specific to the public sector frequently lead to underinvestment in information security, even though the volume and sensitivity of the data processed (identity, health, taxation) is comparable to that of better-resourced private organizations.

In Morocco, the information systems of public administrations fall directly under law 05-20 and DGSSI directives, which notably require periodic security audits and a formalized governance framework.

Frequently asked questions

Is a Moroccan public administration required to carry out a security audit?

Sensitive information systems of public administrations are subject to law 05-20 and DGSSI directives, which notably provide for a periodic security audit.

Can a public institution without a dedicated IT department benefit from a virtual CISO?

Yes — this is one of the most common use cases for a virtual CISO: gaining a security governance function without hiring a full-time position.

Is staff awareness really a priority in the public sector?

A significant share of incidents in the public sector originate from human error (phishing, mishandling) rather than a technical flaw — awareness training therefore remains a direct lever for reducing risk.

Which compliance frameworks apply to Moroccan administrations?

Mainly law 05-20, decree 2-21-406, DGSSI's DNSSI, and, depending on the data processed, law 09-08 on the protection of personal data.