
Cybersecurity · 6 September 2026 · 7 min read
Morocco's Law 09-08 and the CNDP: what companies must put in place
Declaring processing, securing data, contractors, transfers abroad: the concrete obligations of Law 09-08 and how IT answers them.
Industry
Secure, traceable IT worthy of the trust your clients place in you.
Lenders, brokers, insurance agencies and wealth managers handle sensitive personal and financial data every day. A poorly controlled login, a fraudulent e-mail or lost data can cost far more than the incident itself: the trust of your clients and your partners.
We build IT where every access is authenticated, every action is logged and every piece of data is backed up out of reach. We help you document these controls to meet Morocco’s Law 09-08 requirements and answer questions from partners or auditors.

01
ID documents, statements, contracts: a leak can create liability under Law 09-08 and damages your reputation for the long term.
02
Fake payment orders and impersonation of executives or clients: finance teams are a favourite target for attackers.
03
Who opened which file, from which device, at what time? Without reliable logs, you cannot answer an audit or investigate an incident.
04
Advice, policy sales and complaints often happen by phone. Without recording and archiving, disputes are settled with no evidence.
Financial services company
3CX IP telephony for a financial services company
Modern telephony usable anywhere, delivered on time and certified by the client as compliant with the specifications.
Read the case studyPrivate institution
Access control: doors, locks and lift
Controlled, traceable access managed from a single point, with no hassle for authorised users.
Read the case study
Cybersecurity · 6 September 2026 · 7 min read
Declaring processing, securing data, contractors, transfers abroad: the concrete obligations of Law 09-08 and how IT answers them.

Cybersecurity · 14 September 2026 · 1 min read
Multi-factor authentication blocks most intrusions through stolen passwords. Where to start, what to protect first, and how to avoid a user revolt.

Cybersecurity · 16 September 2026 · 3 min read
Fake supplier bank details, fake DHL, fake Microsoft, CEO fraud: the 8 phishing scenarios we see every week at our clients, and the habits that stop them.
Law 09-08 governs the processing of personal data and is overseen by the CNDP. Among other things, it requires client data to be kept secure. We implement the technical controls (access, encryption, logging, backup) and help you document them; the legal side should be confirmed with your counsel.
We combine MFA on e-mail, anti-phishing filtering, alerts on suspicious forwarding rules and staff awareness training. We also help you set up an out-of-band double check for any change to bank details.
Yes. 3CX can record calls per extension or per queue, archive them and restrict access to authorised people only. We also set up the caller notice and the retention period you choose.
We enable and centralise access logs across Microsoft 365, file servers and compatible applications, with named accounts protected by MFA. After an audit request or an incident, you can see who did what and when.
We audit the security and traceability of your IT systems free of charge.
Reply within one business day · Free initial audit · No commitment