More than half of companies now dedicate over 5 percent of their IT budget to security, with a growing share exceeding 7 percent. Nonetheless, close to 30 percent of organizations remain under-invested or lack any dedicated budget, creating a significant disparity in resilience capacity across the corporate landscape. National regulation, notably Law 05-20, plays a structuring role: 44 percent of companies cite it as a reference framework that strengthens governance even ahead of increased investment. Facing difficulty recruiting qualified profiles, organizations are prioritizing internal training and upskilling, with more than half investing in developing existing staff. AI-related incidents are already being observed — 40 percent of companies report social engineering attacks amplified by these technologies, and 25 percent cite data leaks.