TUNIS — The number of security incidents reported to Tunisia's national computer security agency has risen by more than 48 percent between 2024 and 2026, according to figures published on Friday by L'Économiste Maghrébin, which also reported that the document setting out a National Cybersecurity Strategy for 2026–2030 has been finalised.

The same account, citing the Interior Ministry, puts the number of cyberattacks recorded in the country at 57,430 for the first half of 2025, and reports that criminal groups operating internationally — LockBit, BlackCat and Cl0p among them — now actively target the Middle East and North Africa, Tunisia included.

The trend is not new. Incidents reported to the agency rose by more than 146 percent in 2022, from around 63,000 the previous year to more than 155,000. Ransomware cases, according to a report relayed by the specialist outlet Tunisie Haut Débit, went from 15,411 in 2023 to 37,076 in 2024.

What the numbers do and do not measure

These counts describe reports, not attacks. An incident enters the statistics when someone notices it and tells the agency. That makes the curve a joint measure of two things — how much hostile activity there is, and how much of it gets detected and declared.

In a market where most firms are small, the second factor is the weaker one. A rise in declarations can therefore mean the threat is growing, that reporting habits are improving, or both; and a plateau would not be reassuring. The published series cannot separate these, which is why the raw totals should be read as a floor rather than a measurement.

Why ransomware in particular

Ransomware is the business model that industrialised cybercrime. Affiliates rent the malware, the operators take a cut, and access to a victim's network is bought and sold as a commodity. The economics reward volume, so targeting follows the path of least resistance rather than the value of the target — a mid-sized industrial firm in Sousse with an unpatched remote-access server is a better proposition than a hardened bank.

Two features of the Tunisian economy fit that profile. The productive base is dominated by small and medium firms, for whom a full-time security function is an expense with no visible return until the day it is needed. And a large share of them are subcontractors to European clients, which makes them an entry point into a longer supply chain — a reason to attack them that has nothing to do with what they themselves are worth.

The strategy, and what a strategy cannot do

The 2026–2030 document is built, per L'Économiste Maghrébin, around resilient protection of national infrastructure and the strengthening of human skills. It succeeds the 2020–2025 strategy published by the agency, whose broad architecture — a national CERT, sector coordination, awareness campaigns — is already in place. Tunisia's tunCERT monitors threats, issues alerts and provides free technical assistance to organisations that have been attacked.

The honest criticism is not that the strategy is wrong but that the binding constraint sits elsewhere. Skilled staff are the scarcest input in this field worldwide, and Tunisia trains engineers who are recruited abroad at salaries no local SME can match. A strategy that promises to strengthen human skills without addressing where those people end up working will produce trained people and undefended companies.

What is proposed elsewhere

The measures with the best evidence behind them are unglamorous. Mandatory incident reporting with legal protection for the reporting firm, as introduced in the European Union's NIS2 framework, converts a reputational risk into an administrative obligation and improves the data everyone depends on. Pooled security services — a shared operations centre serving an industrial zone or a sector federation — spread the cost of expertise across firms that cannot each hire an analyst. Insurance underwriting has, in several markets, done more to raise baseline hygiene than regulation, because insurers price backups and multi-factor authentication directly.

None of this is exotic, and some of it falls to industry bodies rather than the state. The measure of the 2026–2030 strategy will be whether, four years from now, the reported-incident curve has flattened because attacks are being stopped — and not because they have stopped being reported.