#CyberLearn Updates
Stay up to date with new guides and improvements
29 September 2026
Course lesson: What NIS2 asks you to do
Who counts as the board now follows the CCB NIS2 FAQ. That is whoever runs and represents the company, takes binding decisions for it, or controls it.
Read articleCourse lesson: The board’s own duty
The CCB FAQ’s reading of who counts as the board replaces the interim wording, including the quiz on an advisory committee.
Read articleCourse lesson: Judging the risk
The training step now cites the CCB: each company sets the content and duration of its training, and the CCB recommends no specific programme.
Read articleCourse lesson: Reporting a significant incident
Adds the CCB Notification Guide’s concrete cases of a significant incident and when you count as aware of one.
Read articleCourse lesson: Your NIS2 calendar
The deadlines start when a company falls into scope, per the CCB FAQ; a change of size counts after two accounting periods.
Read articleCourse lesson: Your own house first
Who counts as your MSP’s board now follows the CCB FAQ. The significant-incident test adds the EU regulation’s common and recurring cases.
Read articleCourse lesson: Reporting a significant incident
Per the CCB guide, the company files its own notification. Can your IT partner file it for you? The guide does not say, and the lesson now says so.
Read articleCourse lesson: Price it, contract it, limit it
The notification clause now quotes the CCB guide: your client files its own notification. Whether you may file it for them is not in the guide.
Read article28 September 2026
ECP vs KSC (Poland): CyFun next to Poland's national cybersecurity framework
New comparison page for Poland's Krajowy System Cyberbezpieczeństwa (KSC), the NIS2 transposition amendment signed February 2026, in force 3 April 2026. Registration deadline is 3 October 2026; full implementation by 3 April 2027. Covers the 18+ regulated sectors, 50+ employee / €10M+ turnover threshold, three national CSIRTs (NASK/GOV/MON), biennial ISMS audit requirement with ISO 27001 explicitly recognised, and fines up to €10M/2% (essential entities) or €7M/1.4% (important). MSPs are regulated important entities — no multi-tenant compliance track. EN/NL/FR, 10 cited sources.
Read article25 September 2026
Phishing: two figures corrected
Belgians forwarded more than 9 million suspicious messages to verdacht@safeonweb.be in 2024, not 10 million; 10 million was the 2023 record. With those reports the CCB redirected 1,644,732 suspicious links. Tycoon 2FA reached about 96,000 victims worldwide according to Microsoft, nearly 500 of them in Belgium; we had written 96,000 attacks. Sources added: Safeonweb, The Hacker News, The Brussels Times. The CCB article's timeline gets the same 2024 correction. EN/NL/FR.
Read articleLooking for something older?
Read the archive of earlier updates