Skip to content

Industry

Finance & insurance

Secure, traceable IT worthy of the trust your clients place in you.

Lenders, brokers, insurance agencies and wealth managers handle sensitive personal and financial data every day. A poorly controlled login, a fraudulent e-mail or lost data can cost far more than the incident itself: the trust of your clients and your partners.

We build IT where every access is authenticated, every action is logged and every piece of data is backed up out of reach. We help you document these controls to meet Morocco’s Law 09-08 requirements and answer questions from partners or auditors.

Finance & insurance

The challenges in your industry

01

Highly sensitive client data

ID documents, statements, contracts: a leak can create liability under Law 09-08 and damages your reputation for the long term.

02

Payment fraud and phishing

Fake payment orders and impersonation of executives or clients: finance teams are a favourite target for attackers.

03

Traceability of access and actions

Who opened which file, from which device, at what time? Without reliable logs, you cannot answer an audit or investigate an incident.

04

Evidence of client conversations

Advice, policy sales and complaints often happen by phone. Without recording and archiving, disputes are settled with no evidence.

Useful guides for you

Secured server room

Cybersecurity · 14 September 2026 · 1 min read

Rolling out MFA in an SMB: the five-step guide

Multi-factor authentication blocks most intrusions through stolen passwords. Where to start, what to protect first, and how to avoid a user revolt.

Frequently asked questions

What does Morocco’s Law 09-08 require from a financial firm?

Law 09-08 governs the processing of personal data and is overseen by the CNDP. Among other things, it requires client data to be kept secure. We implement the technical controls (access, encryption, logging, backup) and help you document them; the legal side should be confirmed with your counsel.

How do we protect ourselves against payment fraud?

We combine MFA on e-mail, anti-phishing filtering, alerts on suspicious forwarding rules and staff awareness training. We also help you set up an out-of-band double check for any change to bank details.

Can client calls be recorded on an IP phone system?

Yes. 3CX can record calls per extension or per queue, archive them and restrict access to authorised people only. We also set up the caller notice and the retention period you choose.

How can we prove who accessed a client file?

We enable and centralise access logs across Microsoft 365, file servers and compatible applications, with named accounts protected by MFA. After an audit request or an incident, you can see who did what and when.

Is every access to your data really traced?

We audit the security and traceability of your IT systems free of charge.

Reply within one business day · Free initial audit · No commitment

Request my free audit
CallWhatsAppFree audit