
Spain cyberwar Morocco: defence analysis southern flank
Real capabilities, structural gaps and plausible scenarios in a context of sustained tension with Morocco.
TL;DR for executives
Spain has a formal cyberdefence architecture in line with the NATO average and in full expansion, but carries structural weaknesses —delayed regulation, institutional fragmentation, dependence on the private sector and talent shortage— that a hostile actor with modest capabilities like Morocco can exploit without needing a decisive attack. The real risk is not the digital Pearl Harbor of the headlines, but sustained attrition in the grey zone.
1. Why the popular question is wrongly framed
The popular narrative about cyberwar is built on a Hollywood-inherited imaginary: one country switches on its digital weapons and another goes dark in hours. That mental frame produces two simultaneous errors: it overestimates the real offensive capability of most state actors and underestimates the damage that can be inflicted without firing a single decisive exploit.
Contemporary doctrine —both NATO and EU— works with a different concept: the continuum of confrontation, also known as the grey zone. A sustained space below the threshold of conventional armed conflict where cyber operations, espionage, informational pressure, migratory manipulation, economic coercion and hostile diplomacy combine. The commander of the Spanish Joint Cyberspace Command described it in February 2026 as a permanent situation of 'hot peace'.
The right question is not whether Morocco can take down the Spanish power grid. It is what operational, informational and coercive advantages Morocco can accumulate against Spain on a sustained basis without ever crossing the NATO threshold —and whether Spain is prepared to detect, attribute and respond to that continuous pressure.
2. The formal architecture of Spanish cyberdefence
Spain has built a reasonably complete institutional architecture over the past fifteen years: the Joint Cyberspace Command (MCCE), the National Cryptologic Centre (CCN-CERT), the National Cybersecurity Institute (INCIBE-CERT), the National Centre for Critical Infrastructure Protection (CNPIC) and the National Security Department (DSN).
MCCE is undergoing the largest transformation in its history: it currently has around 500 personnel and plans to triple its workforce to 1,500 by 2030, with a 100,000 sqm complex planned for 2029 and associated investment exceeding 100 million euros. Add SCOMCE as the cyber domain weapons system, the Military School of Cyberoperations (EMCO) that trained 449 specialists in 2025, an AI Reference Centre (CRIA) and Spain's designation as host nation of the NATO Cyber Range.
The 2025 Defence Plan allocated 3.262 billion euros to technology and cybersecurity, plus an additional 1.157 billion specifically for cybersecurity and cyberdefence. Significant figures, although Spain remains below the 2% of GDP NATO defence commitment. Operationally, MCCE participates in Locked Shields 2026, the largest real-time cyberdefence exercise in the world.
3. The structural cracks the official discourse doesn't emphasise
Serious regulatory delay. The NIS2 Directive (EU 2022/2555) had a transposition deadline of 17 October 2024 and, by mid-2026, the final law has still not been published in the official gazette. Meanwhile, critical sectors operate with a framework designed in 2019 for a threat that has completely mutated.
Institutional fragmentation. Five actors with different organic dependencies, operational cultures and chains of command. It works reasonably well in peacetime thanks to personal relationships and committees. In acute crisis, that coordination is a known failure point.
Dependence on the private sector for critical infrastructure. Around 80% of Spanish critical infrastructure is privately owned. The 28 April 2025 blackout was the free dress rehearsal: the final report ruled out cyberattack but identified digital vulnerabilities and proved that a non-malicious failure paralysed the peninsula for hours. A hostile actor with prior preparation could deliberately replicate a similar collapse.
Talent shortage and brain drain. The MCCE chief himself acknowledges that around 20% of military personnel trained in cyberoperations end up captured by the private sector, where salaries can reach 200,000 euros per year.
Volume and professionalisation of the threat. In 2025 INCIBE handled 122,223 incidents, 26% more than in 2024. Check Point documented an average of 1,968 weekly cyberattacks per organisation in Spain, 70% more than in 2023. Any geopolitically motivated targeted operation hides in that noise.
4. The actor in question: Morocco, real capabilities
Morocco operates two main services relevant to Spain: DGED (foreign and military intelligence, around 4,000 agents and an estimated budget of 100 million euros, with around thirty agents accredited in Spain) and DGST (interior intelligence with growing external capability). Internal CNI reports classify Moroccan espionage as the most aggressive after the Russian one, although tactically more elementary.
Morocco is not in the first division of cyber powers. Its own offensive capability is modest and is compensated through two routes: turnkey capability purchase —mainly commercial spyware, with around 200 Pegasus licences contracted for surveillance in Spain, including the Prime Minister and ministers— and contracting external operators for specific operations.
The Pegasus case is the most solid evidence available: the technique used against the Spanish PM was a zero-click infection identical to the method previously used against critical Moroccan journalists, and the forensic footprint reinforces attribution to Rabat. Add, on the hybrid plane, the Ceuta crisis of May 2021 and sustained pressure on the Western Sahara dispute.
What Morocco cannot do today without support from a major actor: take down the electrical, financial or telecommunications grid in a sustained way; maintain advanced cyber operations on critical infrastructure with sufficient OPSEC persistence; sustain a prolonged offensive campaign that triggers a NATO casus belli.
5. Plausible scenarios: the realistic matrix
Scenario A — Baseline (high probability, ongoing). Sustained espionage on political, military, business and media profiles via commercial spyware. Information and disinformation operations on social networks in Spanish, Arabic and Catalan. Recruitment of informants and harassment of resident dissidents. This scenario is already operational.
Scenario B — Tactical escalation with trigger (medium probability). Activatable by incident in Ceuta/Melilla or Spanish decision perceived as hostile: DDoS campaigns against government portals, symbolic defacements, controlled leaks of previously exfiltrated data, activation of hacktivist proxies and informational intensification for 7-21 days.
Scenario C — Prolonged low-intensity harassment (medium-low probability). Cyber pressure on non-critical sectors over months, selective targeting of SMEs and consultancies in sensitive sectors (defence, energy, telecommunications, specialised legal), combined with migratory and economic coercion. Objective: erode the Spanish negotiating position.
Scenario D — Attack on critical infrastructure (low probability, high impact). Requires external support or exceptional opportunity window. Morocco has strong incentives not to reach here except in a very serious crisis. Most likely, if it occurred, it would be through a proxy with plausible deniability and damage calibrated to stay below NATO thresholds.
6. Operational implications by audience
For CEOs and boards: the risk is neither theoretical nor distant. If the organisation operates in banking, energy, telecommunications, transport, health, water, food, defence or professional services with political exposure, it is within the plausible targeting perimeter. Regulatory compliance lags behind the threat: do not wait for NIS2 transposition to audit and reinforce. The supply chain is the most underestimated vector.
For compliance and legal officers: review cyberinsurance coverages (war exclusion and hostile state actor clauses are being redefined), document due diligence on supply chain, anticipate NIS2 obligations without waiting for the official gazette and prepare notification protocols with aggressive deadlines (24 hours for early warning, 72 hours for initial notification).
For SMEs and professionals: SMEs are the weakest link in the Spanish economic fabric. 50% suffer some cyberattack per year and ransomware was present in 88% of breaches in 2025. Minimums: multi-factor authentication on critical services, immutable and disconnected backups, recurring training in phishing and social engineering, written and tested incident response plan, and updated inventory of external exposure.
7. Strategic lessons
Spain is not defenceless against Morocco alone. The combination of expanding MCCE, NATO umbrella, European depth and interconnection with allied networks makes a decisive single-blow Moroccan attack highly improbable.
Spain is not well prepared for sustained attrition in the grey zone. The structural weaknesses —delayed regulation, fragmentation, private dependence, talent drain, gap in the SME fabric— are what an intelligent actor will exploit for years without crossing red lines.
The real battlefield is informational and intelligence, not critical infrastructure. Whoever accumulates better information, better attribution and better narrative response capability will have an advantage in every bilateral crisis.
Preparation is measured in detection and response speed, not in walls. Assume the attacker is already inside and design to detect and contain. And assume that the private sector is indistinguishable from the State for national security purposes: an SME supplying an essential operator is, de facto, part of the national defence chain. And it rarely knows it.
Frequently asked questions
Related articles
Are you making corporate decisions without all the information?
Request a confidential strategic evaluation. We analyze your specific situation and indicate whether we can help — and how.
Response within 24-48 hours. Confidentiality guaranteed.