Digital, field and data-protection intelligence for Morocco mandates.

OSINT-visible exposure, field infrastructure, informal local processes and data-handling gaps, observed on the ground.

Thirteen years of recurring fieldwork in Morocco. Collection done in person, reporting in English and Italian.

Formatted for EDD, pre-signing diligence and corporate intelligence files. Scoped by mandate, under NDA.

Rob Pinna, CTIA

Digital risk intelligence analyst

Morocco · Italy · field since 2013

Rob Pinna

Deliverables

Annex-ready inputs for due diligence, EDD, legal and corporate intelligence files.

01
Digital / cyber Visible Exposure Annex

OSINT-led outside view before deeper diligence or authorised site access.

02
Field / operating reality Field Verification Note

Ground-level observations around infrastructure, vendors and operating practice.

03
Legal / compliance Data Protection Gap Note

Assessment of data-handling gaps visible before integration or remediation planning.

04
EDD / counsel / investment file Technical Annex

Combined digital, field and data-protection layer written for insertion into a wider file.

Assessment Flow

The method joins remote visibility with field-observed operating reality.

01

OSINT

Visible exposure, domains, platforms, internet-facing services and passive technical indicators.

02

Digital Field Analysis

Wireless baseline, legacy infrastructure, visible devices, vendor marks and site-level technical conditions.

03

Informal Practices

Staff workflows, local administration, vendor access and trust-based operating patterns.

04

Data Handling

Guest, transaction and operating data flows; inherited practices; integration or legal gap indicators.

Output

Assessment Layer

Observed, inferred and unverified findings kept distinct for the receiving due diligence, EDD, counsel or corporate intelligence file.

Public Evidence

Published samples show structure, judgement style and limits. They are not client disclosures.

Assessment 01
Digital Infrastructure and Operational Risk in the Medina of Fez OSINT and field exposure assessment

Field collection on foot over four days: 1,027 unique BSSIDs, 76.3% WPS-enabled, zero enterprise-grade deployments. Confidence levels, limitations and source notes included.

Assessment 02
Hospitality Portfolio Pre-Investment Digital Risk Assessment Illustrative transaction-format assessment

District indicators, inherited technical exposure, brand abuse, staff-channel risk, compliance burden and transaction file structure.

From the ground

Short notes from ongoing fieldwork in Morocco, observed first-hand.

22 May 2026
Decisions by Kinship: Network Administration in Medina Riads

The owner of a small riad in the Marrakech medina needs to upgrade the wifi. She calls her brother-in-law.

12 April 2026
CGNAT and the Empty Map

Walking through the Fes medina I started counting.

14 March 2026
Signal Decay: Open Wireless Infrastructure in Medina Hospitality Zones

Passive signal mapping conducted across the northern sector of the medina in January 2026 identified forty-three distinct access points within a two-hundred-metre radius of the primary riad cluster.

Working Standard

Passive first. Claims stay inside the evidence.

Findings use ICD-203 style confidence language, with observed, inferred and unverified material kept separate. Analysis is framed against regional threat actor tradecraft, including access brokers, fraud operators and intelligence-adjacent collectors, with MITRE ATT&CK mapping where useful. Collection is passive: no active probing, unauthorised access or credential testing. Work can be conducted under NDA and structured to a firm's house format. Client matters are not disclosed.

Discuss a Mandate

For scoped Morocco digital risk intelligence, field verification or annex support: direct@robpinna.com