#CyberLearn Updates Archive
Earlier changes to the learning center, oldest still on file
24 September 2026
Email security: SPF, DKIM and DMARC explained, and the rule check after a break-in
A new tip explains, in plain terms, the three domain settings that stop others sending mail with your address as the sender. SPF lists who may send, DKIM signs the message, DMARC tells the receiver what to do with a fake. Only a DMARC policy of quarantine or reject asks the receiver to keep a fake out of the inbox. The "suspect a breach" answer adds two checks from Safeonweb's invoice-fraud warning of 23 September 2026: automatic forwarding rules and unusual filters. We explain why they matter: such a rule keeps working after a password change. The tip it replaces, on keeping mail apps updated, now sits as one line under attachments. EN/NL/FR.
Read articleTwo-factor authentication: legacy sign-in protocols bypass MFA
"When MFA itself is attacked" gets a fourth entry. Older ways of signing in, such as mail apps on IMAP, POP3 or SMTP and clients like Office 2010, do not support MFA, so a stolen password gets straight in through them. Microsoft states that most compromising sign-in attempts come from legacy authentication. The defense now includes blocking these protocols, which security defaults does in Microsoft 365. EN/NL/FR.
Read articleWhat to ask your MSP: remote-access tools and edge devices
One new question in the protection section: which firewall, VPN and remote support tools do we run, which version does each run, and were the logs from before the last critical patch checked? These systems face the internet, and a patch does not remove anyone who got in before it: the CCB's WordPress warning of 23 September 2026 says patching "does not remediate historic compromise", and the page links it. EN/NL/FR.
Read articlePatch management: your website's CMS belongs in the inventory
Step 1 now lists your website's CMS and plugins, for example WordPress, even when an agency hosts the site. EN/NL/FR.
Read articleSetting up 2FA: Microsoft 365 steps now follow the Entra admin center
The Microsoft 365 steps still pointed at Azure Active Directory menus that no longer exist. They now follow the current Microsoft Entra admin center: Entra ID > Authentication methods > Policies for the Authenticator app, and Entra ID > Overview > Properties > Manage security defaults. Step 1 names the minimum roles Microsoft Learn lists for each step. EN/NL/FR.
Read articleControl categories: level table and FAQ now match the 22 categories
The level table said Basic covers all categories, and the FAQ still named categories from the older CSF 1.1 set (Access Control, Protective Technology, Maintenance). Both now follow the page's own 22-category table: Basic has controls in 17 categories, Important in 20, Essential in all 22. The FAQ names the five that start later and points to where Basic puts most of its 34 controls. EN/NL/FR.
Read articleHealthcare: essential or important entity, and which CyFun level
The summary said healthcare typically needs Important or Essential, called healthcare an "Essential" sector, and quoted an average breach cost without a source. The page now says most healthcare activities sit in a high-criticality sector (NIS2 Annex I), and that size as well as sector decides whether you are an essential or an important entity. An essential entity defaults to CyFun Essential: a certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028. It may go lower only when its own risk assessment justifies it, at its own responsibility (Art. 7). The 2-minute self-check is described as what it is: a rough estimate of scope, entity class and level. The unsourced figure is gone. Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. "Health IT providers" is gone from the scope line; it now lists the Annex I health activities, such as pharmaceutical manufacturing and R&D of medicinal products. EN/NL/FR.
Read articleCompliance roadmap: when to go beyond Basic, by NIS2 class and risk assessment
Several parts of the roadmap tied the move to Important or Essential to your sector. They now follow the CCB rule and the Royal Decree. An essential entity defaults to CyFun Essential: a certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028. It may go lower only when its own risk assessment justifies it, at its own responsibility (Art. 7). An important entity picks its level with the CCB Selection Tool; a voluntary CyFun assessment is at least at Important level (Art. 11). The timeline scenarios are titled by outcome, and the essential-entity scenario shows the legal dates. The Important scenario no longer says you cannot start at Important: the Royal Decree allows a CAB verification at Important at the first step (Art. 22 §1). Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. The size threshold now follows Recommendation 2003/361/EC: at least medium-sized means 50+ staff, or both turnover and balance sheet total above €10 million, not 50+ staff or €10M+ turnover. The Basic-Important-Essential path no longer puts Essential in year 3: an Important verification is allowed at the first step (Royal Decree, Art. 22 §1). Essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. Certification now goes through CCB-authorised auditors, not just "accredited" ones. EN/NL/FR.
Read articleAI threats: the LiteLLM example is now the September 2026 flaw
The shadow-AI paragraph used an earlier LiteLLM flaw from May 2026. It now names CVE-2026-59822, an authentication bypass in LiteLLM's MCP endpoint that CISA added to its catalogue of actively exploited flaws on 2 September 2026, fixed in version 1.84.0. The point stands: an AI gateway a team runs holds API keys and prompts, and needs patching like any other server. The page now links the NVD entry and the CISA catalogue for this CVE. EN/NL/FR.
Read articleCyberFundamentals levels: the CCB rule for which level applies
The page said your NIS2 class never sets your level, and matched Important to medium businesses and Essential to critical infrastructure. It now states the rule. An essential entity defaults to CyFun Essential: a certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028. It may go lower only when its own risk assessment justifies it, at its own responsibility (Art. 7). An important entity picks its level with the CCB Selection Tool; a voluntary CyFun assessment is at least at Important level (Art. 11). Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. The certification FAQ now follows the CCB list of 7 September 2026 and no longer calls certification optional for essential entities. The identification-date rule now covers the 2027 date only, not the 2028 date from the CCB letter. The summary and intro no longer tie the tier to company size; it follows from the NIS2 class and your own risk assessment. EN/NL/FR.
Read articleNIS2 implementation steps: target level by NIS2 class and risk assessment
Step 4 and the level table told readers to pick their level from their sector. They now say the level follows the NIS2 class and the entity's own risk assessment: essential entities default to Essential, and important entities pick their level with the CCB Selection Tool. Source: CCB FAQ on NIS2 and CyberFundamentals. The size threshold now follows Recommendation 2003/361/EC: at least medium-sized means 50+ staff, or both turnover and balance sheet total above €10 million, not 50+ staff or €10M+ turnover. The timing note no longer says an Important audit can only come in year 2: the Royal Decree allows an Important verification at the first step (Art. 22 §1). The Basic-Important-Essential path no longer puts Essential in year 3: an Important verification is allowed at the first step (Royal Decree, Art. 22 §1). Essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. The FAQ on timing adds that essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. EN/NL/FR.
Read articleNIS2 deadlines: the April 2026 step per route, and the lower-level option
The title, summary and timeline said essential entities had to submit a self-assessment by April 2026. What April 2026 required is now stated per route. Essential entities needed a CyFun Basic or Important verification from an authorised CAB, a self-assessment only if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability. A lower level is possible when the entity's own risk assessment justifies it, if it shows by 18 April 2027 that it meets that level. The remediation plan is now the CCB Inspection Service's request, preferably proof of compliance at Important level plus the measures to reach Essential by 18 April 2028. The dates run from the law's entry into force, or from a later identification date, and the page says so next to those dates. The registration figures now cite the CCB's one-year update of November 2025: about 1,500 essential and 2,500 important entities. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The July 2026 entry now describes the CER identification of critical entities and its NIS2 effect. The unsourced 84% readiness figure is gone, and the CAB card follows the list of 7 September 2026. The April 2027 entries now say what each route owes: an Essential-equivalent assessment on the CAB and ISO routes, a progress report on the CCB-inspection route (Art. 22 and 23). The intro no longer says audits are underway, which we could not source. EN/NL/FR.
Read articleWhat is NIS2: sectors by annex, size by the SME definition, April 2026 per route
The sector headings now follow the directive: sectors of high criticality (Annex I) and other critical sectors (Annex II), with essential or important depending on sector and size (Art. 3). The size threshold follows Recommendation 2003/361/EC: 50+ staff, or both turnover and balance sheet above €10 million. What April 2026 required is now stated per route. Essential entities needed a CyFun Basic or Important verification from an authorised CAB, a self-assessment only if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability. Important entities had no administrative formality. The level table and "build gradually" step follow the CCB rule. The dates are corrected: the directive entered into force on 16 January 2023, the transposition deadline was 17 October 2024, and the Belgian law applies since 18 October 2024. The intro no longer calls NIS2 the most significant EU cybersecurity law or cites an unsourced 160,000 organisations. It says what the directive requires and gives the CCB's Belgian registration figure. The annex lists now include ICT service management (business-to-business) in Annex I and chemicals in Annex II. The unsourced "160,000+ organisations" figure is gone; the page gives the 18 sectors instead. The Basic-Important-Essential path no longer puts Essential in year 3: an Important verification is allowed at the first step (Royal Decree, Art. 22 §1). Essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. EN/NL/FR.
Read articleNIS2 in Belgium: the April 2026 step per route, and the lower-level option
The page called April 2026 a self-assessment deadline for everyone. What April 2026 required is now stated per route. Essential entities needed a CyFun Basic or Important verification from an authorised CAB, a self-assessment only if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability. The level table now says what each level covers, and that essential entities default to Essential. A lower level is possible when the entity's own risk assessment justifies it, if it shows by 18 April 2027 that it meets that level. The remediation plan is now the CCB Inspection Service's request, preferably proof of compliance at Important level plus the measures to reach Essential by 18 April 2028. The dates run from the law's entry into force, or from a later identification date, and the page says so next to those dates. The registration figures now cite the CCB's one-year update of November 2025: about 1,500 essential and 2,500 important entities. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The Dutch text now spells België and essentiële correctly. The card on CAB accreditation now says no CAB is authorised for CyFun Essential yet (CCB list of 7 September 2026). The critical-entities line now says that an entity identified as critical under the CER Directive is essential under NIS2 (Art. 3(1)(f)). The April 2027 entries now say what each route owes: an Essential-equivalent assessment on the CAB and ISO routes, a progress report on the CCB-inspection route (Art. 22 and 23). The FAQ on getting audit-ready no longer picks the tier from the entity class alone. EN/NL/FR.
Read articleNIS2 audit: who needs which assessment, in 2026 and 2027
The page said important entities owed a Basic self-assessment and that self-assessment suffices at Basic. Important entities have no mandatory assessment; a voluntary CyFun one is CAB-verified at Important or higher (Royal Decree, Art. 11). What April 2026 required is now stated per route. Essential entities needed a CyFun Basic or Important verification from an authorised CAB, a self-assessment only if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability. Important entities had no administrative formality. The 2027 box names CyFun certification, ISO/IEC 27001 and CCB inspection. A lower level is possible when the entity's own risk assessment justifies it, if it shows by 18 April 2027 that it meets that level. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The 2027 entry now says what each route owes by then; on the CCB-inspection route that is a progress report (Art. 23 §2). The page now lists its sources, including the CCB letter. The timing note no longer says an Important audit can only come in year 2: the Royal Decree allows an Important verification at the first step (Art. 22 §1). The FAQ on timing adds that essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. EN/NL/FR.
Read articleNIS2 certification: the April 2026 step per route, and the lower-level option
The tier table and the self-assessment block treated Basic as a self-assessment for important entities. Important entities have no mandatory assessment. What April 2026 required of essential entities is now stated per route. Essential entities needed a CyFun Basic or Important verification from an authorised CAB, a self-assessment only if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability. The tier table names the CAB verification or certification per level. The costs now include the CCB's inspection fee on the CCB-inspection route: €150 an hour, indexed yearly (Royal Decree, Art. 20). The FAQ on a missed April 2026 step now says the sources describe no late procedure, grace period or fine, and points to the CCB inspection service. A lower level is possible when the entity's own risk assessment justifies it, if it shows by 18 April 2027 that it meets that level. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The unsourced "25% choose ISO 27001" is replaced by the CCB figure: 75% had selected a framework, most of them CyFun (November 2025). The fee exemption now follows Art. 20 §5, the CAB FAQ follows the list of 7 September 2026, and the page lists its sources. The Basic-Important-Essential path no longer puts Essential in year 3: an Important verification is allowed at the first step (Royal Decree, Art. 22 §1). Essential entities need Essential by 18 April 2027, or Important plus a plan to 18 April 2028. The CAB FAQ notes that BELAC accredits the CyFun CABs, while the ISO 27001 CABs on the list are accredited by several national bodies. The Dutch and French audit section no longer says CAB accreditation ends in April 2026; like the English, it says the CCB publishes the current list of authorised bodies. EN/NL/FR.
Read articleSupply chain: the April 2027 milestone applies to essential entities
The timeline said full CyFun certification or ISO 27001 is required for all NIS2 entities in April 2027. It now says the milestone applies to essential entities, with the 2028 remediation route and the lower-level option. The April 2026 timeline entry and FAQ now say, in the past tense, what that step required on each route. The registration figure cites the CCB's one-year update: about 4,000 entities by November 2025. The summary no longer ends with "get ahead of it or risk losing contracts"; it names the reason customers ask: Article 21(3) makes them take their suppliers' cybersecurity practices into account. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB, One year of NIS2 in Belgium; CCB NIS2 page; NIS2 Directive, Art. 21; Royal Decree of 9 June 2024. The CCB advice to suppliers now uses the CCB's wording and links its NIS2 page. The April 2027 entry adds the CCB-inspection route, where the Royal Decree asks for a progress report (Art. 23 §2). EN/NL/FR.
Read articleCyberFundamentals overview: level cards describe what each level covers
The cards said Basic is for SMEs, Important is required for important entities and Essential is for critical infrastructure. They now say what each level adds, and name Essential as the default for essential NIS2 entities. The NIS2 mapping now says essential entities default to Essential, lower only where their risk assessment justifies it (Art. 7), and that important entities opting for an assessment do so at Important or higher (Art. 11). Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. The FAQ on which tier you need no longer maps important entities to Important and essential entities to Essential; it states the same rule (Royal Decree, Art. 7 and 11). Certification now goes through CCB-authorised auditors, not just "accredited" ones. The controls link now says 22 categories, and the certification FAQ names essential entities, not sectors, as the case where it is required. EN/NL/FR.
Read articleThe CCB: levels described by their controls, not by who they are for
The page described Essential as "for critical infrastructure" and Basic as "designed for SMEs". It now gives the control counts and says each level builds on the one below. The category card now says 22 control categories, and certification goes through CCB-authorised auditors. The quick facts also say 22 control categories. EN/NL/FR.
Read articleWhat is CyberFundamentals: the intro describes three levels, not three audiences
The intro said CyberFundamentals runs from basic measures for small companies to controls for critical infrastructure. It now says three levels that build on each other, from 34 to 218 controls. The NIS2 mapping now says essential entities default to Essential, lower only where their risk assessment justifies it (Art. 7), and that important entities opting for an assessment do so at Important or higher (Art. 11). The sentence under the level list no longer says the level depends on sector and company size; it follows from the NIS2 class and the risk assessment. Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. Certification now goes through CCB-authorised auditors, not just "accredited" ones. EN/NL/FR.
Read articleCAB audit cost: what internal CyFun work does and does not count for
The page presented a Basic self-assessment as a valid way to meet April 2026 for important entities. Important entities had no formality then; a voluntary CyFun assessment is CAB-verified at Important or higher (Royal Decree, Art. 11). Working through CyFun internally counts as the formal step only for essential entities under CCB inspection (Art. 23). An important entity that becomes essential moves to CyFun Essential by default, unless its risk assessment justifies a lower level that it then shows it meets. The summary and footnote now name the CCB's fee on the CCB-inspection route: €150 an hour, indexed (Art. 20). The FAQ no longer mentions submission through a Safeonweb portal, and the budget advice for essential entities now says to start now. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The page no longer quotes a CAB price for ESSENTIAL: no CAB is authorised for ESSENTIAL certification yet (CCB list of 7 September 2026). The April 2027 entries now say what each route owes: an Essential-equivalent assessment on the CAB and ISO routes, a progress report on the CCB-inspection route (Art. 22 and 23). The CABs are described as accredited by BELAC for CyFun and authorised by the CCB. EN/NL/FR.
Read articleTalking to your IT partner about a CAB audit: the routes and the lower-level option
The guide framed April 2026 as a self-assessment deadline and said the CCB accepts CyFun Basic as the minimum NIS2 self-assessment. It now describes the April 2026 step per route and names the three conformity routes in the email template. The template says the CCB Inspection Service requests a remediation plan, and adds the lower-level option: a level the entity's risk assessment justifies, if it shows by 18 April 2027 that it meets it. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The unsourced 84% readiness figure is gone. EN/NL/FR.
Read articleCyFun for MSPs: which level a client needs
The FAQ said Basic is designed for SMEs and Important applies to important entities, typically larger organisations in regulated sectors. It now states the rule: essential entities default to CyFun Essential and may go lower only when their own risk assessment justifies it. Important entities pick their level with the CCB Selection Tool, and a voluntary CyFun assessment is at least Important. The page now links its sources. Sources: CCB FAQ on NIS2 and CyberFundamentals; Royal Decree of 9 June 2024. The CAB paragraph now follows the CCB list of 7 September 2026: five bodies for CyFun verification at Basic and Important (DNV for CyFun 2023 only), none listed for Essential, fifteen for ISO 27001. It no longer says essential entities therefore go through ISO 27001; it names all three routes, including CCB inspection. The registration figure is now about 4,000 entities by November 2025 (CCB), with a link, and the CAB count cites the list of 7 September 2026. The audit is described as done by a CAB that BELAC accredited for CyFun and the CCB authorised. EN/NL/FR.
Read articleManufacturing: most manufacturers in scope are important entities
The summary said some manufacturing sectors (chemicals, food) are classified as essential, and that CyberFundamentals Important is typically required. Manufacturing, chemicals and food are "other critical sectors" (NIS2 Annex II), so most manufacturers in scope are important entities. The class depends on sector and size, and an entity can still be designated essential. Essential entities default to Essential; important entities pick their level with the CCB Selection Tool. Sources: NIS2 Directive, Art. 3 and Annex II; CCB FAQ. The size threshold now follows Recommendation 2003/361/EC, and the FAQ lists the Annex II manufacturing subsectors instead of "general manufacturing". The subsector list adds optical products, and the unsourced downtime cost of €5,000-50,000 per hour is gone. EN/NL/FR.
Read articleFirst 30 days: what the Royal Decree ties to your risk analysis
Week 3 said the CyFun level you are assessed at follows from your risk analysis under Article 22 of the Royal Decree. It now says what the article does: for an essential entity it ties the level of the first verification (basic or important) to that analysis. Article 7 lets the same analysis justify a level below essential, and the 2027 line now names that exception. Source: Royal Decree of 9 June 2024. Certification now goes through CCB-authorised auditors, not just "accredited" ones. EN/NL/FR.
Read articleMissed the April 2026 NIS2 deadline: rewritten to what the sources say
The page said important entities owed a Basic self-assessment through the Safeonweb portal and that late submission is accepted. The April 2026 step applied to essential entities: a CAB verification, a self-assessment under CCB inspection, or the ISO scope and Statement of Applicability. Important entities had no formality. The sources describe no late procedure, grace period or fine for this step, so the page now says so and points to the CCB inspection service. It then sets out the April 2027 date, the lower-level option and the remediation plan. The CAB route notes that the Essential certificate is due by 18 April 2027 and that the CCB list of 7 September 2026 names no body for CyFun Essential yet. Sources: CCB FAQ; CCB Inspection Service letter of 11 August 2026; Royal Decree of 9 June 2024. The remediation plan now quotes the letter per route. The ISO route adds the most recent internal audit the CCB FAQ asks for, and the supply-chain FAQ follows the CCB's advice to suppliers. EN/NL/FR.
Read articleCyFun audit preparation: what the workbook is for, per entity class
The page said important entities owe a Basic self-assessment and that the portal accepts late submissions. Important entities had no formality by April 2026; a voluntary CyFun assessment is CAB-verified at Important or higher (Royal Decree, Art. 11). Week 8 and the FAQ now say what the workbook is for: a CAB hand-off, a self-assessment under CCB inspection, or evidence when the CCB asks. The unsourced claims about CCB penalties and a no-CAB route are gone. The Safeonweb submission line is gone. The 2027 paragraph now calls the remediation plan the Inspection Service's request and adds the lower-level option (Art. 7). Sources: CCB FAQ; Royal Decree of 9 June 2024. The remediation plan is now worded as the CCB Inspection Service's request, as in its letter. The 2027 paragraph says what each route owes by then, and the related link names the 22 control categories. EN/NL/FR.
Read articleCyberFundamentals certification: the authorised bodies per level, as the CCB lists them
The page said no body was accredited for Essential and that essential entities therefore reach conformity through ISO 27001. It now follows the CCB list of 7 September 2026: five bodies for CyFun verification at Basic and Important (DNV for CyFun 2023 only), none listed for Essential, fifteen for ISO 27001. It names all three routes for essential entities, including supervision by the CCB inspection service (Royal Decree, Art. 23). The FAQ no longer calls certification voluntary for everyone: an essential entity needs an Essential-level conformity assessment by 18 April 2027, or a lower level its risk assessment justifies. The CCB figures are dated November 2025, and the page now lists its sources. The summary now states the same rule and names a CCB-authorised CAB. The cost table shows no Essential price, because no CAB is authorised for it yet (CCB list, 7 September 2026), and its Important range matches the CAB audit cost guide, labelled an estimate. The Basic price is labelled an estimate too. EN/NL/FR.
Read articleNIS2 overview: the right dates for the directive and the Belgian law
The intro said NIS2 came into effect in 2024. The directive entered into force on 16 January 2023; the Belgian law that transposes it applies since 18 October 2024 (EUR-Lex; CCB). The card for the missed-deadline page now describes what the April 2026 step required of essential entities, their three routes and the 2027 remediation plan. The size threshold now follows Recommendation 2003/361/EC: at least medium-sized means 50+ staff, or both turnover and balance sheet total above €10 million, not 50+ staff or €10M+ turnover. The unsourced "160,000+ organisations" figure is gone; the page gives the 18 sectors instead. EN/NL/FR.
Read articleNIS2 requirements: the April 2026 callout per route
The callout said essential entities must submit a CyFun Basic or Important self-assessment to the CCB by April 18, 2026, and the French text gave a different registration figure. It now says what that step required on each route and points to 18 April 2027. All three languages cite the CCB's figures of November 2025. Sources: CCB FAQ on NIS2 and CyberFundamentals; CCB, One year of NIS2 in Belgium; Royal Decree of 9 June 2024. The sources list now links the CCB FAQ, the CCB's one-year update and the Royal Decree. EN/NL/FR.
Read articleNIS2 penalties: an unsourced readiness figure removed
The Belgian enforcement paragraph called April 2026 a self-assessment deadline and said 84% of in-scope Belgian organisations were not ready, citing a D3 Security survey. We could not trace that figure to a Belgian source, so the sentence is gone. The incident figure now cites the CCB news item of 26 March 2026 (635 notifications, nearly 70% more than in 2024) without calling them all mandatory, and the unsourced remediation-first claim is gone. EN/NL/FR.
Read articleNIS2 Directive: scope figure and dates corrected
The intro and quick facts said NIS2 covers 160,000+ organisations, a figure we could not trace to a primary source. The quick facts now give the CCB's Belgian figure: about 4,000 registered entities (November 2025). The intro now says the directive entered into force in January 2023 and replaced the first NIS Directive from 18 October 2024 (Art. 44). Sources: NIS2 Directive; CCB, One year of NIS2 in Belgium. EN/NL/FR.
Read articleWho must comply: dates, the April 2026 step and registration figures corrected
The FAQ said NIS2 came into force on October 17, 2024, that essential entities had to submit a self-assessment, and that about 2,000 entities were registered. The directive entered into force on 16 January 2023 and the Belgian law applies since 18 October 2024. The April 2026 step is now stated per route. About 1,500 essential and 2,500 important entities were registered one year after the law took effect (CCB, November 2025). The size threshold now follows Recommendation 2003/361/EC: at least medium-sized means 50+ staff, or both turnover and balance sheet total above €10 million, not 50+ staff or €10M+ turnover. The self-check question now asks whether both turnover and balance sheet total exceed €10 million. The quick facts now read about 1,500 essential and about 4,000 registered entities (CCB, November 2025); the unsourced 160,000 EU figure and the January 2026 date are gone. EN/NL/FR.
Read article22 September 2026
ECP vs AGID Misure Minime: CyFun next to Italy's public-sector baseline
New comparison page. AGID Misure Minime (Circular 2/2017, 20 ABSC controls over three levels) binds Italian public administrations and is self-assessed at no cost, so it does not compete with ECP, which serves private-sector SMEs through MSPs. The page says so plainly, and names the split that does matter to a cross-border MSP: AGID does not satisfy Italian NIS2, which falls under D.Lgs. 138/2024 and the ACN, in force since 16 October 2024.
Read article18 September 2026
Supply chain: advisers are high risk, because they hold originals rather than copies
The professional-services row sat at medium risk and described the exposure as contract paperwork. That reads the risk backwards for the firms it names. A notary, a bookkeeper or a payroll office holds deeds, contracts and filings that exist nowhere else, so losing them is not a privacy incident you notify and move past. The row is now high, the description leads with the loss rather than the contract clause, and the named list adds notary and payroll. EN/NL/FR.
Read articleCost of a breach: the "too small to be targeted" answer now cites measured Belgian cases
The FAQ backed its answer with a global vendor statistic and then an abstraction about automated attacks not discriminating by size. The abstraction was true and carried nothing a reader could check. It is replaced with what was counted: six Belgian organisations were added to ransomware leak sites between 1 and 16 August 2026, and five of the six sit in no NIS2-regulated sector, being a standards body, an investment firm, an architecture practice, a travel agency and a furniture chain. They were reachable, not important. The BlackFog figure and its attribution stay, and the companies are not named. EN/NL/FR.
Read article17 September 2026
Healthcare: the claim that the sector is targeted now carries a dated case
The page asserted that healthcare is heavily targeted and listed six reasons why, but gave no instance a reader could check, and nothing on it was newer than its January 2026 launch. It now carries one dated, sourced case directly under those reasons. A GP practice in Gouda, Huisartsencentrum Klein Iterson, had patient files stolen: names, dates of birth, addresses, phone numbers and parts of medical files, and for some patients the Dutch BSN, which is the same kind of number as the Belgian rijksregisternummer and is useful for identity fraud for years. LockBit 5.0 claimed the attack and had already published stolen documents. The case is deliberately a small practice rather than a hospital, because the page's advice is read by practices with a handful of staff and one shared system, and most breach stories are about organisations ten times their size. The practice did not disclose how the attackers got in and said the extent was still unknown, so neither is asserted here, and no patient count is given because none was published. Read in security.nl on 17 September 2026, reporting of 11 September 2026. EN/NL/FR.
Read article10 September 2026
Does the Cyber Resilience Act apply to what I sell?
New plain-language guide, because the Cyber Resilience Act mechanics were only on the manufacturing page and a software vendor, a webshop badging own-brand goods or an MSP shipping branded hardware would never open that page. Two questions decide it: does what you sell contain software or connect to a device or a network (Article 2(1)), and do you sell it under your own name or logo (Article 3(13)). The own-branding case is the one people miss, and it is Article 3(13) when you had the product made for you or Article 21 when you resell it as importer or distributor, never Article 22, which is about substantial modification and is the mix-up doing the rounds. The guide carries the clocks from 11 September 2026 (24 hours early warning, 72 hours notification, 14 days final report, one month for a severe incident), notes that Article 69(3) applies the reporting duty to products already on the market, and states the penalty carve-out precisely, corrigendum included: Article 64(10)(a) removes the fine for a micro or small enterprise that misses the 24-hour deadline but not the duty to report, and it only reaches the Article 64(2) fine because a corrigendum of 2 July 2025 changed "paragraphs 3 to 9" to "paragraphs 2 to 9". Several free copies of the regulation still show the uncorrected wording. The four Cyber Resilience Act bullets moved off the manufacturing page, which keeps one line and a link. Every article read in Regulation (EU) 2024/2847 on 10 September 2026. EN/NL/FR.
Read articleManufacturing: the size threshold decides NIS2 only, and the CRA duty starts 11 September 2026
The page answered "does this apply to me?" with the NIS2 size test alone, so a manufacturer under the threshold could read it, conclude they were out of scope, and stop there. It now says the threshold decides NIS2 only. If you sell a product with digital elements under your own name, the Cyber Resilience Act reaches you because of what you sell rather than because of a staff or turnover threshold, and its reporting duty starts on 11 September 2026. The mechanics that first landed in the "NIS2 Classification for Manufacturing" section, the reporting clocks, where you file, the products already in customers' hands and the fine carve-out for the smallest firms, now live in their own guide, "Does the Cyber Resilience Act apply to what I sell?", because a software vendor or a webshop selling own-brand goods was never going to open a page filed under manufacturing. This page keeps one line and a link. Article numbers read in Regulation (EU) 2024/2847 on 10 September 2026. EN/NL/FR.
Read articleBelgium: what to do now the 18 April 2026 deadline has passed
The page now opens with what happens if you missed the self-assessment deadline of 18 April 2026. The next date is unchanged: 18 April 2027, for an Essential-equivalent conformity assessment. No CAB is authorised for CyFun Essential certification yet, so the CCB Inspection Service asks essential entities that cannot get there in time to file a remediation plan: proof of compliance at CyFun Important level plus the measures planned to reach Essential-equivalent by 18 April 2028 (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). The page links straight to the four remediation paths. EN/NL/FR.
Read articleIT partners: your RMM is Tier-0, and the vendor page is not the whole disclosure
The RMM answer now works through a live case. CISA added N-able N-central CVE-2026-86218 to its Known Exploited Vulnerabilities catalogue on 8 September 2026. It scores 10 out of 10 on CVSS 4.0 and needs no login, and N-able fixed it on 5 September 2026 in Hotfix 4, build 2026.3.1.14. The lesson is where the vendor said what: the public advisory reported no confirmed exploitation, while the urgent notice sent to customers called the same flaw a zero-day observed being exploited in the wild. So read the mail as well as the status page, and hunt for unfamiliar sessions from before the fix shipped. EN/NL/FR.
Read articlePatch management: is the flawed part even switched on?
Two steps of the response routine carry new guidance. Assessing exposure now means asking whether the affected component is actually enabled: Zimbra CVE-2026-73570 only allows remote code execution when the optional SNMP package is installed and SNMP notifications are on, and the Citrix NetScaler flaw only bites when the appliance is set up as a SAML identity provider. That answer can move a case from emergency to routine, or the other way round. Monitoring now means searching your logs back past the fix date rather than forward from it, because N-able N-central CVE-2026-86218 was exploited as a zero-day before Hotfix 4 shipped on 5 September 2026. EN/NL/FR.
Read articleRetail: your shop platform is patchable software too
The line about keeping software updated now names a live case: CVE-2026-75650 in Adobe Commerce and Magento let attackers run code through the template engine, and it was already being exploited when CISA added it to its Known Exploited Vulnerabilities catalogue on 8 September 2026. If your shop runs on Adobe Commerce or Magento, the version of your shop platform is the thing to check. EN/NL/FR.
Read articleCyFun audit prep: evidence has a date, and a quiet integration is a gap
The evidence-collection week now warns about evidence that has gone stale. A screenshot taken four months ago is plainly old. An integration that quietly stopped feeding four months ago still looks current, and it is not. Neither one tells you what the control looks like today. Check the date on every item before you file it, and treat a feed that has gone quiet as a gap rather than a pass. EN/NL/FR.
Read article9 September 2026
The MSP guide now reads in Dutch and French
The free practical guide for MSP owners, on offering NIS2 and CyFun compliance as a recurring service, now reads in Belgian Dutch and in French. The page copy, the cover text and the "Look inside the guide" section are all translated. The guide file itself is still one English PDF, so the Dutch and French pages say so before you hand over an email address. The English page carries no such line, and the line disappears on its own once a translated PDF ships. EN/NL/FR.
Read article3 September 2026
CyFun auditors: a fifth verification body, and still none for Essential
The CCB refreshed its authorised-CAB list on 25 August 2026. Five bodies are now authorised for CyFun verification at Basic and Important level, up from four: Brand Compliance Belgie, CertUp, DNV Business Assurance, Vinçotte and What a Work SRL (Trust CHECK). One caveat on the newcomer: DNV is authorised against CyFun 2023 only, not CyFun 2025, so an assessment against the current framework version still means choosing between the same four names as last month. The number that matters most has not moved: zero bodies are authorised to certify CyFun at Essential level, and all five CyFun rows are scoped Basic to Important. Correction: an earlier version of this note said Brand Compliance Belgie's CyFun authorisation expires on 8 November 2026. That was wrong. It runs to 3 September 2028; the November date belongs to another body's ISO 27001 row on the same list. Every page carrying the old figure has been updated, and the 22 July stamp is gone. EN/NL/FR.
Read article24 August 2026
ECP vs BIO2, and what the Cyberbeveiligingswet actually says
New comparison page for BIO2 (Baseline Informatiebeveiliging Overheid), the Dutch government information-security baseline, now anchored in the Cyberbeveiligingswet. It is honest that the two are not head-to-head: BIO2 is public sector only, ECP is private-sector MSP delivery, and the overlap is cross-border MSPs and suppliers to Dutch government. The page also states the Cbw precisely, because most coverage does not. Reporting compressed it to "directors are now personally liable", but the statute never uses the word aansprakelijk. Article 80 fines the entity up to EUR 10,000,000 or 2% of worldwide turnover and article 87 up to EUR 7,000,000 or 1.4%, while a board member personally risks at most EUR 25,000 under article 93 for failing the article 24 competence duty. The obligation with a date on it is article 24 lid 5: every board member holds a training certificate, kept current, by 15 August 2028. Every article number read from the consolidated text as at 15 August 2026. EN/NL/FR.
Read article20 August 2026
A fourth route if you will not reach CyFun Essential by April 2027
The CCB Inspection Service has named what an essential entity does when it cannot hold an Essential-equivalent conformity assessment by 18 April 2027: submit a remediation plan, proof of compliance at CyFun Important-equivalent level plus the measures planned to reach Essential-equivalent by 18 April 2028. The 18 April 2027 legal deadline is unchanged, and no plan is needed if you are already Essential-equivalent by then, or if your own risk analysis under Art. 7 of the NIS2 Royal Decree justifies a lower assurance level and you demonstrate by that date that you meet it. Source: CCB Inspection Service communication ref. NCCA/JK/INS/2026-002 of 11 August 2026, published 18 August 2026. Written into the missed-deadline page as a fourth remediation path, and reflected across the deadline, audit, certification and CAB-cost pages. Worth knowing why it exists: no conformity assessment body is authorised for CyFun Essential certification today, so that level currently runs through ISO/IEC 27001 or a CCB inspection. EN/NL/FR.
Read article17 August 2026
ECP vs BSI IT-Grundschutz: CyFun next to the German standard
New comparison page for Germany's BSI IT-Grundschutz. IT-Grundschutz is the standard to follow if your clients are German entities subject to NIS2: the BSI references it in section 44 BSIG, ISO 27001 certification on its basis is well established, and the Grundschutz++ reform rolling out from 2026 cuts requirements from roughly 6,567 to roughly 985 in a machine-readable OSCAL format. CyFun and ECP are the right path for Belgian clients, since CyFun is the CCB's official NIS2 route. The two share NIS2 Article 21 DNA but are not interchangeable across borders. EN/NL/FR.
Read article13 August 2026
Remote work: the company gateway you log in through is a device too
The page told you to use the company VPN but said nothing about the box at the company that accepts that login. Added a tenth tip on the remote-access gateway: it is one of the few devices deliberately left open to the internet, nobody at home can patch it, and somebody has to ask who does. Anchored on SonicWall SMA1000 (flaws CVE-2026-15409 and CVE-2026-15410, exploited from 22 June 2026, fixed mid-July 2026, both flaws flagged by CISA as used in ransomware attacks, and more than 380 of these devices tracked as exposed on the internet, though some may already have been secured, per BleepingComputer, 10 August 2026). Includes the three questions to put to your IT partner and a new checklist line. EN/NL/FR.
Read articlePasswords: hashed is not the same as safe
New section explaining, without jargon, why a breach notice saying your password was "hashed" is not an all-clear. Hashing works in one direction only and protects nothing more than a password that was already hard to guess; hackers take the scrambled list offline and grind through common and previously leaked passwords with nobody watching and no lock-out. Anchored on the Drukland notice of 10 August 2026, which covered email addresses and hashed passwords (ITdaily, 10 August 2026) plus card details for a small group (Security.NL, 11 August 2026). Ends where it should: change it, change it everywhere you reused it, turn on two-factor authentication. EN/NL/FR.
Read articleCyFun Basic effort study: dated note added, measured figures untouched
The study measures one implementation that ran 30 March to 17 June 2026, and two things in it now understate the product: the "writing policies and procedures" row of 64 manual actions, and the takeaway that most of the real effort happens off the platform. Since August 2026 the CyFun Basic procedure and policy documents come out of the platform already written in English, Dutch and French. Both places now carry a dated note saying the measurement predates that change. The measured numbers are deliberately not edited: it is a dated record of what happened. EN/NL/FR.
Read article11 August 2026
CyFun auditors: corrected to four verification bodies, none yet for Essential
Our pages said there were only two BELAC-accredited CyFun audit bodies. The CCB list dated 22 July 2026 shows four authorised for verification at Basic and Important level: Brand Compliance Belgie, CertUp, Vinçotte and What a Work SRL (Trust CHECK). Two things the old wording missed: those four do verification, and no body is yet accredited to certify at Essential level, so Essential entities currently reach presumption of conformity through ISO 27001, where 15 authorised certification bodies are available. We have also dropped the "prepare now and you get audited first" framing, which rested on the two-auditor number. EN/NL/FR.
Read articleScope broadened: CyFun is now the national scheme in five countries
CyberFundamentals is no longer Belgium-only. Belgium, Ireland, Romania, Malta and Cyprus are members of the CyFun Scheme Owner Group. Ireland's NCSC states it "will be adopting CyFun as its national assessment and certification scheme", with certification expected in 2027 and CyFun named a preferred method for the public administration sector. France recognises CyFun and is exploring adoption, but uses its own ReCyF framework. Our comparison and NIS2 guides now speak to SMEs and MSPs across the CyFun countries rather than to Belgium alone, while the CyberFundamentals section stays Belgium-specific where the subject is the CCB and its framework. EN/NL/FR.
Read article23 July 2026
2FA setup: passkeys and phishing-resistant MFA section
Added a section on going beyond app codes. App-based codes can still be phished or talked out of someone in real time; passkeys, FIDO2 hardware keys and platform sign-in (Windows Hello) are bound to the real site and refuse to work on a fake one. Covers when to prioritise each and the NIS2/CyberFundamentals angle: phishing-resistant MFA on privileged accounts is what turns a stolen password into a dead end. EN/NL/FR.
Read article16 July 2026
Shadow AI governance for SMEs, with a free policy template
New guide on governing the AI tools your staff already use: how to discover shadow AI (survey plus network signals), decide per tool (approve, replace or block), and keep the list alive with a quarterly review and one named owner. Includes a free, editable acceptable-AI-use policy template you can download in English, Dutch or French and adapt in an afternoon. EN/NL/FR.
Read articlePatch management: record July 2026 Patch Tuesday added to the timeline
The advisory-volume timeline now includes 14 July 2026, the largest Microsoft Patch Tuesday on record: 570 fixes (569 by CVE count), 56 critical, two actively exploited zero-days (ADFS CVE-2026-56155, KEV deadline 28 July; SharePoint CVE-2026-56164, KEV deadline 17 July) and the publicly disclosed BitLocker bypass CVE-2026-50661. It replaces June's 206 as the flagship volume stat. EN/NL/FR.
Read articleSocial engineering: the Belgian financial-software vishing wave
Added the July 2026 vishing variant the Limburg public prosecutor warned about: callers pose as support staff of the company's own financial-software platform and pressure finance staff into transfers or into installing remote-access tools. New real-world example plus the rule that matters: real support never calls you, never install remote tools for a caller, verify out-of-band on a number you already have. EN/NL/FR.
Read article12 July 2026
CyFun Basic, by the numbers: how much documentation and evidence it really needs
New data article measuring one real, anonymised CyFun Basic implementation: about 38 documents (~7,000 words, revised close to 950 times) and 123 pieces of evidence across 11 types, tied to the 34 controls by 294 links, with about half the evidence collected automatically. The point: producing it is only half the job; knowing what is done, what is missing and what has gone stale is the other half, which is what the platform tracks. EN/NL/FR.
Read article9 July 2026
Incident response: Fraudstop 078 170 170 added to who-to-contact
Added Belgium's central online-fraud emergency number, announced by the CCB on 23 June 2026 and folded into Card Stop: 078 170 170, available 24/7. Call it for an unauthorised transaction, a leaked card number or security code, or an itsme approval you were talked into; the first minutes decide whether the bank can still block or recall the funds. Added as a contact entry plus callout, EN/NL/FR.
Read articlePhishing: fraud in progress goes to Fraudstop 078 170 170
Added a pointer next to the Safeonweb reporting section: suspicious messages go to verdacht@safeonweb.be, but fraud in progress is a call to Fraudstop on 078 170 170 (24/7, folded into Card Stop), because the first minutes decide whether the bank can block or recall the money. EN/NL/FR.
Read articlePatch management: July 2026 CVE refresh (ColdFusion, SharePoint, LiteLLM)
Refreshed the zero-day examples: Adobe patched 11 ColdFusion flaws on 30 June 2026, six rated CVSS 10.0, led by unauthenticated file-upload RCE CVE-2026-48276; sibling CVE-2026-48282 was exploited within 2 hours and hit CISA KEV on 7 July 2026 with a 3-day deadline. Also added actively exploited SharePoint CVE-2026-45659 (CISA KEV 1 July 2026) and LiteLLM CVE-2026-42208, a pre-auth SQL injection (CVSS 9.3) in a popular AI proxy, exploited within 36 hours with a CCB patch-immediately advisory. Retired the 2025 Oracle WebLogic and March 2026 SQL Server entries. EN/NL/FR.
Read articleAcceptable AI use: KnowBe4 numbers on how widespread shadow AI is
Added the KnowBe4 survey of Dutch organisations (report "From Agentic Risk to Human Wins", June 2026): 50% have no clear AI-use rules, 58% already run autonomous AI agents, 27% of employees use unapproved AI tools when official ones are missing, and 81% know pasted data may be stored or misused. No Belgian split was published. EN/NL/FR.
Read articleAI threats: shadow AI infrastructure as attack surface (LiteLLM)
Added a callout on AI tooling itself as a target: LiteLLM CVE-2026-42208, a pre-authentication SQL injection (CVSS 9.3) in a popular proxy that routes company traffic to AI models, exploited within 36 hours and subject of a CCB patch-immediately advisory. Takeaway: every AI tool belongs in the software inventory and patch schedule. EN/NL/FR.
Read article2 July 2026
Remote work: public WiFi hygiene added as tip 9
New section grounded in the CCB webinar "Is your Wi-Fi an open door?" (June 2026): avoid open hotspots, confirm the exact network name with staff, watch for "evil twin" hotspots (the fake airport networks in Australia, April 2024, led to a 7+ year sentence in November 2025), remove the network afterwards, and prefer your phone's 4G/5G hotspot. Hook: researchers near 400 employees captured 166 passwords in 40 minutes, unnoticed. Added in EN/NL/FR.
Read article20 June 2026
CyFun now cited in the EU cross-framework NIS2 mapping
Four articles now reference the reference document the EU NIS Cooperation Group published on 17 June 2026, tied to Implementing Regulation 2024/2690, which maps NIS2 security measures across frameworks and places Belgium's CyberFundamentals alongside ISO/IEC 27001, IEC 62443 and NIST CSF 2.0. Added to What is CyberFundamentals, CyberFundamentals vs ISO 27001, What is NIS2, and the NIS2 Directive explainer, EN/NL/FR.
Read article12 June 2026
Acceptable AI use at work: a practical policy for SMEs
New guide on shadow AI: what happens when staff use unsanctioned AI chatbots with company or client data, and how to get ahead of it in five steps ending in a one-page acceptable-use policy. Covers data classification, an approved-tool list, the EU labelling duties that apply from 2 August 2026, and the MSP angle: offer the policy as a deliverable that maps to classification and policy controls you already manage.
Read articleAI-generated content: the EU labelling rules explained
New plain-language guide to Article 50 of the EU AI Act: who counts as provider versus deployer, what must be labelled from 2 August 2026, and what the European Commission's Code of Practice of 10 June 2026 adds as the voluntary low-risk path. The Munich Regional Court ruling of 28 May 2026 (AI Overviews are Google's own content) frames the liability backdrop: AI's words are your words.
Read articlePhishing: ClickFix, the attack that asks you to paste a command
Added a section on ClickFix lures: fake human-verification and fake-update pages that talk you into pasting a malicious command into your own machine, with the March 2026 breach of the Dutch municipality of Epe (871 GB exfiltrated, investigation published 5 June 2026) as the case study. The rule: no legitimate check ever asks you to paste a command.
Read articleTwo-factor authentication: when MFA itself is attacked
Added a section on attacks against multi-factor authentication: Tycoon 2FA proxy phishing (dismantled by Europol and Microsoft in March 2026), helpdesk-reset social engineering (April 2026 UK retail attacks), and the Epe lesson that break-glass emergency accounts need MFA too. Defenses: phishing-resistant MFA, strict callback verification, no MFA-exempt accounts.
Read articlePatch management: what a real month looks like
Added a concrete example block: the Centre for Cybersecurity Belgium issued a critical advisory every weekday from 4 to 7 May 2026, and the week of 9 June 2026 brought a 206-fix Patch Tuesday, a critical Veeam backup-server flaw and an actively exploited Check Point VPN flaw. The takeaway: this volume is normal, so patching needs a standing weekly rhythm plus a 48-hour fast lane for actively exploited flaws.
Read articleBackup: patch your backup software first
Added a section on the backup server as the highest-value patch target, using Veeam CVE-2026-44963 (disclosed 9 June 2026, CCB warning 10 June 2026, rated 9.4 out of 10): any signed-in domain user could run code on a domain-joined backup server. Ransomware crews destroy backups first; patch within 48 hours, consider workgroup mode, keep one copy offline or immutable.
Read articleAI threats: AI output is now a legal matter
Added a section on the Munich Regional Court decision of 28 May 2026 (case 26 O 869/26): AI Overviews are Google's own content and the search-engine liability shield does not apply, plus the EU AI Act labelling obligations that apply from 2 August 2026. The flip side for businesses: AI's words are your words. Also added links to the new acceptable-AI-use and AI-content-labelling guides.
Read articleWhy AI alone can't reach compliance: the shadow-AI gap
Added a section on shadow AI as a compliance gap nobody scoped: unsanctioned chatbot use with company or client data, why an inventory of the AI tools actually in use is the first step and itself evidence, and the Article 50 labelling duties from 2 August 2026 that you cannot meet for AI output you do not know exists.
Read article4 June 2026
NIS2 Compliance Software Pricing: what you actually pay
New comparison guide that breaks down the four pricing models for NIS2 compliance software (per-organisation, per-client MSP, enterprise GRC, consultancy plus tooling), explains what drives the cost, and publishes Easy Cyber Protection's full per-client price table in the open. Most platforms hide pricing behind "contact sales"; this page shows the numbers and walks through total cost of ownership, including internal time and the separate CAB audit fee.
Read articlePatch Management: added June 2026 Palo Alto and FreePBX zero-days
Added two current examples to the Recent Zero-Day Examples section: Palo Alto PAN-OS GlobalProtect CVE-2026-0257 (CVSS 7.8 authentication bypass, actively exploited, CCB advisory and CISA deadline 1 June 2026) and FreePBX CVE-2026-46376 (CVSS 9.1 hard-coded credentials, CCB advisory 1 June 2026, fixed in 16.0.45 / 17.0.7).
Read article28 May 2026
Antivirus Comparison: when the security tool is the target
Added an EDR-section callout for the May 2026 wave where the security software itself was attacked: Trend Micro Apex One (CVE-2026-34926, on CISA's Known Exploited Vulnerabilities catalogue from 21 May 2026) was abused to turn the management server into a malware-delivery channel, and Microsoft fixed two Defender flaws granting full system rights (CVE-2026-41091) or silently blocking antivirus definition updates (CVE-2026-45498). The lesson: patch the security tool itself, protect its management console with multi-factor authentication, and confirm updates reach every device.
Read articleSupplier Security: Belgian waste-authority supply-chain case
Added a 2026 Belgian case to the supply-chain breach examples: in May 2026 the Beerse and Merksplas recycling parks (run by the Kempen inter-municipal waste authority IOK) were knocked offline by an attack on an external IT supplier, while IOK's own systems stayed intact. A concrete local illustration of why NIS2 treats supply-chain risk management as an explicit obligation.
Read article27 May 2026
Done-For-You NIS2 Scope link added to 17 articles
Contextual inbound links to the new Done-For-You NIS2 Scope & Baseline Report (€395 flat, 48-hour turnaround, ex VAT) added in-content to 12 new NIS2 / CyberFundamentals / getting-started / industry / compare articles, on top of the 5 NIS2 cluster pages already wired. Anchors vary by page (NIS2 Scope & Baseline Report, Done-For-You scope assessment, €395 scope report, scope-determination service, written scope read) to avoid anchor-text over-optimisation. Each link sits where the reader is most likely to ask "do I need this for my own company?": for example after the CyFun tiers table, after a Phase 1 scope checklist, or after a sector classification breakdown.
Read article22 May 2026
Why AI alone can't reach full NIS2 / CyFun compliance
New guide for MSPs and SME owners evaluating "AI compliance" vendors. Names what AI can do (control mapping, evidence templates, regulatory tracking, audit-pack structuring) and what it cannot (decide scope, physically verify reality, judgment calls, take responsibility). Includes a red-flag checklist for spotting vendors selling a demo, and the right division of labour between AI, the MSP and the CAB auditor.
Read article14 May 2026
ECP vs ReCyF (France): CyFun vs the French NIS2 Framework
New head-to-head comparison with ANSSI's Référentiel Cyber France (ReCyF v2.5, March 2026). Covers legal status (binding once Loi Résilience is enacted, expected H2 2026), structure (15 objectives EI / 20 EE), entity coverage (10k-15k French entities), and compliance cost (€100-200K direct vs €100-400/month via ECP MSP service). Fact-check table cites 6 ANSSI / cyber.gouv.fr / SPAC Alliance / CCB sources.
Read article7 May 2026
What is Ransomware?
Added a 5th exfiltration-attack case: SafePay + ETTP (May 6, 2026). SafePay explicitly disavows the ransomware-as-a-service model, runs every operation in-house, and openly targets SMBs, MSPs and organisations with downstream partner networks across the US and Western Europe (active since September 2024). ETTP is the fourth named Belgian victim in five weeks: Fountain (DragonForce, w15), Anderlues (TheGentlemen, w17), Van Heyghen + ISoSL (APT73, w18), now ETTP, making "one named Belgian victim per week" a documented 2026 pattern.
Read articlePatch Management: Protect Against Zero-Days
Added a 6th zero-day case: the CCB patch wave of May 4-7, 2026. Belgium's Centre for Cybersecurity issued a critical "patch immediately" advisory every weekday for four consecutive days: MOVEit Automation CVE-2026-4670 (auth bypass, CVSS 9.8, same product family as Clop 2023), n8n critical, Apache HTTP Server multi-RCE, and Ivanti EPMM authenticated RCE actively exploited. Concrete textbook example for the 48-hour-response rule the article already advocates.
Read articleWhat is the CCB?
Added a 2025 entry to the CCB history timeline: 635 incident notifications recorded, up 70% year on year. 556 cyber-related, 144 account-compromise cases (top category), 105 ransomware. Public administration and healthcare are the most-targeted sectors. Sourced from the CCB's own 2025 figures release.
Read articleIncident Response: Recovery Playbook
Extended the Temse vs Anderlues "fast-detection-wins" case with a Belgian baseline bookend: the CCB recorded 635 incident notifications in 2025 (+70% YoY), 144 account-compromise cases as the top category and 105 ransomware. Frames detection capability as the only variable that bends the recovery curve as the threat baseline shifts.
Read article30 April 2026
Two-Factor Authentication (2FA) Explained
Real Impact callout extended with the second 2026 MFA-bypass pattern: helpdesk vishing. Names Scattered Spider / DragonForce hitting Marks & Spencer, the Co-op and Harrods in April 2026 by phoning the IT helpdesk impersonating an employee and asking for an MFA reset. Defence is now framed as procedural ("never reset MFA without an out-of-band callback to a verified phone number") plus the technical (FIDO2/passkeys).
Read articleSocial Engineering Attacks
Vishing entry expanded to cover the 2026 helpdesk-vishing escalation: the same English-speaking Scattered Spider / DragonForce affiliate behind the M&S, Co-op and Harrods incidents (April 2026, UK Cyber Monitoring Centre Category-2 event, £270M-£440M projected losses). Defence framed as a strict callback rule, not a security-awareness poster.
Read articleCybersecurity for Retail
Added a 5th common-threat entry: Helpdesk Vishing & Identity-Provider Attacks. Frames the M&S (April 22) + Co-op (April 30) + Harrods 9-day cyber-hurricane in April 2026 with the DragonForce / Scattered Spider playbook. Includes UK Cyber Monitoring Centre Category-2 classification (£270M-£440M projected losses) and the M&S online-store closure of nearly seven weeks.
Read articleWhat is Ransomware?
Added a 2nd "How does ransomware spread?" method: bought infostealer credentials. Frames the 2026 reality that ransomware operators do not earn the front door, they buy it. Uses the APT73 / Bashe leak site, where Belgian victims Van Heyghen Staal and ISoSL were listed on April 27, 2026, as the example. References the LeakBase market that Belgium and Europol dismantled in March 2026 (142,000 users).
Read articleCybersecurity for IT Partners
New FAQ entry on RMM-tool urgency: "My RMM tool just got a critical CVE. Should I patch it tonight?" Names ConnectWise ScreenConnect CVE-2024-1708 added to the CISA Known Exploited Vulnerabilities catalogue on April 28, 2026. Frames RMM, remote-access agents and any tool with admin privileges across multiple tenants as Tier-0 infrastructure: same-day patching, credential rotation, and session hunt back to February.
Read articleEmployee Security Training Guide
New training topic added (Critical priority): Helpdesk Vishing & MFA Reset Drills. Includes the 2026 attack pattern, the strict callback rule, a drill scenario ("IT calls and asks for your MFA code. What do you do?"), and the M&S / Co-op / Harrods April 2026 anchor.
Read articleThe Real Cost of a Data Breach
New problem-section bullet on the enterprise scale-up: Marks & Spencer projects ~£376M in profit losses from its April 2026 incident; UK Cyber Monitoring Centre put the combined M&S + Co-op damage at £270M-£440M. Frames the damage-to-defence-spend ratio as the same at every business size: only the absolute number scales with revenue.
Read article29 April 2026
Missed the Belgian NIS2 Deadline? What Changes on April 18, 2026
New pillar article on the urgency arc. Covers what the April 18, 2026 self-assessment deadline actually required, three concrete remediation paths (late CyFun BASIC self-assessment, CAB audit at IMPORTANT or ESSENTIAL tier, ISO 27001 with a NIS2 SoA), and the CCB enforcement posture sourced from public guidance.
Read articleCyFun Audit Preparation: The 8-Week Plan
New flagship guide. Week-by-week plan to be CAB-audit ready in CyFun BASIC: scope (W1), risk register (W2), policies (W3-4), evidence collection (W5-6), mock self-assessment run (W7), submission (W8). Each week ends with the common pitfall the workbook flags and how ECP automates it. HowTo schema with all 8 steps.
Read articleCyFun CAB Audit Cost: What a Belgian NIS2 Audit Actually Costs
New money-keyword article. Honest cost ranges for the four buckets (CCB framework €0, preparation 2-6 months internal time, CAB audit fees €5K-€25K industry-reported, optional consultancy €15K-€60K), three-path comparison table, and the pricing ECP publishes. Disclosure callout up front: cost ranges are industry-reported, not CAB-published rate cards.
Read articleHow to Run a CyFun Mock Audit on Your Own
New 5-phase DIY self-check using the same CCB workbook + 1-5 maturity rubric a real CAB audit uses: evidence prep (Day 1-2), score Documentation maturity (Day 3-4), score Implementation maturity (Day 5-6), gap list + roadmap (Day 7), second-reviewer challenge (Day 8). Honesty rubric callout for self-scoring.
Read articleHow to Talk to Your IT Partner About a CyFun CAB Audit
New bridge article for SME owners. Pre-filled email template with 5 specific questions (familiarity with CyFun, scoping a BASIC self-assessment, evidence collection, tooling vs Excel, IMPORTANT-tier prep), plus 3 signals to read in the partner's reply. Slots into the existing /partner referral pattern.
Read articleNIS2 Audit Preparation Guide
Apr 2026 refresh. The forward-tense "April 2026: deadline approaching" callout is now a past-tense "April 18 deadline passed" with a link to the missed-deadline remediation paths. Timeline section updated to past tense. Voice rewrite of the "what auditors look for" section: now framed around what the CCB CyberFundamentals workbook expects (GV-PO, GV-RM, RS-IR, RC-BA, GV-SC, PR-AT control families), sourced framing, not auditor preferences. EN/NL/FR.
Read articleNIS2 Penalties
New Apr 2026 enforcement-context callout sourcing CCB 635 mandatory incident notifications in 2025 (+70% YoY per the CCB 2025 annual activity report) and the D3 Security April 2026 readiness gap (84% not fully ready, ~25% not started). Frames CCB enforcement posture as remediation-first per published guidance, not automatic sanctions for a missed date. EN/NL/FR.
Read article23 April 2026
Incident Response
Added a dated "fast detection wins" example in the Signs section: Temse (East Flanders, April 16-23, 2026, VRT NWS) caught unauthorised remote-monitoring software and contained it in 5 days with CCB + Polis support. Contrast with Anderlues (Hainaut, April 20, 2026, RTBF) where slower detection ended on the TheGentlemen leak site.
Read articleWhat is Ransomware?
Added TheGentlemen + Anderlues (April 20, 2026, RTBF) to the exfiltration-only examples and named the 2026 pattern: Belgian communes and gemeentes are a preferred target because IT staff and budget are limited while public-facing services cannot simply go offline. Checkpoint Research published a full TheGentlemen DFIR writeup in April 2026 including the SystemBC backdoor chain.
Read articleWhat is Phishing?
New section added: Fake-Breach Extortion. Covers the April 21, 2026 Bol.com case (Security.NL, RetailDetail) where a crime-forum seller listed 400,000 fabricated "customer records" padded with AI-generated rows and stitched onto older breach data. Bol confirmed no incident. Playbook: validate sample data against your schema before you deny, because denying fast on bad data is nearly as damaging as confirming fast.
Read articlePatch Management
Added Cisco Webex CVE-2026-20184 (CVSS 9.8, April 17, 2026) to the Recent Zero-Day Examples: SAML assertion forging in Control Hub / SSO lets an unauthenticated attacker impersonate any Webex user including admins. CCB issued a Yellow/High advisory. Remediation: apply Cisco patch, re-upload the SAML certificate in Control Hub to invalidate pre-patch sessions, review admin audit logs.
Read article22 April 2026
ECP vs Cynomi: Which Fits Your MSP?
New head-to-head comparison with the global vCISO platform. Covers pricing shape, framework focus, MSP multi-tenancy, CyFun recognition (Belgium, Ireland, other EU), and four honest FAQs including "can I use both?" and "what if I'm not Belgian-focused?"
Read articleECP vs Cyberday: Which Fits Your MSP?
New head-to-head comparison with the Finnish ISMS platform. Concrete pricing math (Cyberday €250–€1,990/mo tiered by employee count vs ECP one fee per client site by employee count), framework coverage table (Cyberday 70+ frameworks vs ECP CyFun-native), and honest answers on "why is ECP cheaper?" and white-labelling.
Read article20 April 2026
What to Expect from Your MSP's NIS2 Audit-Readiness Program
New client-facing explainer for SMEs. Walks through the four phases, realistic timelines (1-3 months for well-equipped clients, 4-6 months with gaps, 6-9+ months greenfield), what you do versus what your MSP does, and what "audit-ready" actually means.
Read articleHow to Scope an NIS2 Audit-Readiness Engagement
New MSP-facing scoping guide. Covers the platform-work versus engagement-work split (the #1 missed scoping item), three client-profile timelines, how to price the monthly subscription separately from one-off implementation work, and scope warnings that prevent expectation breaches.
Read article13 April 2026
Policies vs Standards vs Procedures vs Guidelines
New guide explaining the 4-tier document hierarchy every compliance programme needs. Covers the difference between policies (what & why), standards (how much), procedures (how to), and guidelines (recommended approach), with a CyFun/NIS2 mapping table and SME examples.
Read article9 April 2026
NIS2 Supply Chain Security
Added Vivaticket breach (April 2026) as a concrete supply chain multiplier example: one shared ticketing vendor compromised → 3,500 European cultural sites disrupted (Louvre, Eiffel Tower, Notre-Dame). Added to Cloud and SaaS providers tier in all three languages.
Read articleWhat is Ransomware?
Added Dragonforce + Fountain Belgium (April 2026) to the exfiltration-only examples: Malaysia-based RaaS cartel (white-label affiliate model) hits a publicly-listed Belgian workplace services company. Reinforces the "no sector is too ordinary" message.
Read article2 April 2026
Patch Management
Replaced stale Citrix Bleed (2023) example with Citrix NetScaler CVE-2026-3055 (CVSS 9.3, April 2026): memory overread in SAML IDP configuration leaks authenticated session tokens to unauthenticated attackers. Actively exploited since March 27; added to CISA KEV April 1.
Read articleWhat is NIS2?
Added April 18, 2026 hard deadline: Belgian entities must submit CyFun Basic/Important self-assessment or ISO 27001 SoA to the CCB. 2,410 critical-sector organizations had registered by March 2025 (CCB). After April 18, CCB can begin enforcement and fines.
Read articleCompliance Roadmap
Added April 18, 2026 CCB submission deadline to Phase 1 tip: shifts the timeline from vague "start now" to a concrete legal deadline requiring immediate action.
Read articleEmail Security
Added DKIM signing key compromise as a new threat vector in tip 3: even emails from trusted official domains can be forged if the sender's DKIM keys are stolen in a breach (e.g. European Commission, March 2026). Always verify unexpected urgent requests by phone.
Read article26 March 2026
Two-Factor Authentication
Added adversary-in-the-middle (AITM) caveat to the "99.9% blocked" stat: Tycoon 2FA (dismantled by Europol, March 2026) proved standard MFA can be bypassed via session-proxy. FIDO2/passkeys highlighted as the only AITM-resistant method.
Read articlePhishing
Added Phishing-as-a-Service (PaaS) as a new attack type: Tycoon 2FA ran 96,000 attacks globally including 500 Belgian victims, dismantled by Europol and Microsoft in March 2026.
Read articleSocial Engineering
Added real-world example of phishing panel real-time victim control via Telegram bot, documented by Belgian ethical hacker Inti De Ceukelaire (March 2026) against Argenta, Belfius, KBC, ING, and CBC.
Read article23 March 2026
CyberFundamentals vs ISO 27001
Clarified that the CCB explicitly accepts ISO/IEC 27001:2022 as a valid NIS2 conformity path (same legal presumption as CyFun), with SoA requirement. Added new FAQ: Microsoft 365, Purview and Secure Score do not cover CyFun compliance.
Read articleCyberFundamentals Framework Guide
Updated FAQ: both CyFun and ISO 27001 are accepted by CCB for NIS2 conformity. ISO 27001 requires a Statement of Applicability showing equivalence to the relevant CyFun level.
Read article15 March 2026
NIS2 in Belgium
New article covering Belgian NIS2 law, CCB role, CyberFundamentals framework tiers, registration statistics, and Belgian-specific deadlines.
Read articleThe NIS2 Directive Explained
New article explaining EU Directive 2022/2555: legal background, NIS1 vs NIS2 comparison, key articles (21, 23, 32-33), and Belgian transposition.
Read articleNIS2 Certification
New article comparing CyberFundamentals and ISO 27001 certification paths, tier requirements, audit process, and cost considerations.
Read articleNIS2 Audit Preparation
New article on what auditors look for, self-assessment vs external audit, 5-step preparation guide, and MSP audit support angle.
Read article12 March 2026
Ransomware
Added wiper malware section: Stryker attack claimed by Handala (March 2026).
Read articleIncident Response
Added MDM/device management tools as attack vector warning with detection signs.
Read articlePasswords
Added credential marketplace context: LeakBase takedown (142K users, Europol, March 2026).
Read articlePatch Management
Added SQL Server CVE-2026-21262 (CVSS 8.8) and Microsoft Patch Tuesday monitoring guidance.
Read articleAccess Control
Added management console warning: cloud admin portals as highest-value targets (Stryker MDM example).
Read article5 March 2026
NIS2 Deadlines
Added the CCB framework-adoption figure: three quarters of registered entities have chosen a security framework, most of them CyFun (CCB, quoted in ICT Magazine, January 2026).
Read article26 February 2026
Social Engineering
Added AI voice cloning warning to vishing section, citing WEF Global Cybersecurity Outlook 2026.
Read articleNIS2 Supply Chain
Added Qilin ransomware as concrete example of MSP-targeted supply chain attacks.
Read articleCybersecurity for IT Partners
Added warning that MSPs are primary ransomware targets (Qilin) with NIS2 supply chain implications.
Read articleSelf-Service vs Managed
Added data sovereignty FAQ: where compliance data lives matters. It contains your security blueprint.
Read articleWhy MSPs Should Offer Compliance
Updated deadline stat from vague "2026" to specific "April 18, 2026" self-assessment deadline.
Read article24 February 2026
NIS2 Supply Chain Compliance
New article explaining how NIS2 reaches organisations not directly regulated, through supply chain obligations in Article 21(2)(d). What your clients will ask and how to prepare.
Read articleHow to Talk to Your IT Partner About NIS2
Practical conversation guide for SME owners who need to discuss NIS2 readiness with their IT partner. Includes key questions and what answers to expect.
Read articleWhat to Ask Your MSP About Cybersecurity
Evaluation checklist for SMEs working with a managed service provider. Know what to ask about incident response, compliance support, and security monitoring.
Read articleNIS2 Readiness: What Your IT Partner Needs to Know
Designed to be forwarded to your IT partner. Covers the compliance framework, timeline, and specific technical capabilities needed to support NIS2 clients.
Read articleWhy Your MSP Should Offer Compliance Services
For IT partners exploring the compliance opportunity. How NIS2 creates recurring revenue and stronger client relationships through audit-readiness services.
Read article19 February 2026
NIS2 Deadlines Belgium
Updated registration numbers: 2,410 critical-sector organizations registered with CCB (CCB, March 2025; previously ~2,000). About 4,000 across all sectors. Self-assessment deadline now 8 weeks away.
Read articleWho Must Comply with NIS2?
Updated Belgian entity registration stat from ~2,000 to 2,410 critical-sector organizations (CCB announcement, March 2025).
Read article13 February 2026
Access Control Guide
New guide on least privilege, role-based access control, and credential hygiene. Practical steps for SMEs to limit who gets in and what they can do.
Read article5 February 2026
NIS2 Deadlines Belgium
Updated with critical April 18, 2026 self-assessment deadline (10 weeks away), new CAB accreditation timeline, and July 2026/April 2027 milestones. ~2,000 entities now registered.
Read articleWho Must Comply with NIS2?
Added EU "small mid-cap" category (proposed Jan 2026), updated Belgian entity registration numbers (~2,000), and April 18 self-assessment deadline.
Read articleNIS2 for SMEs
Updated with expanding scope through "small mid-cap" category and growing supply chain obligations. Belgium now has ~2,000 registered entities.
Read articleNIS2 Compliance Checklist
Added April 18, 2026 self-assessment deadline warning. Essential entities must submit CyFun or ISO 27001 documentation to the CCB.
Read articleNIS2 Penalties & Fines
Added new ransomware-specific reporting requirements: attack vector, mitigation measures, and ransom payment disclosure obligations.
Read articleCyberFundamentals Certification
Updated: three quarters of registered entities have chosen a security framework, most of them CyFun (CCB, quoted in ICT Magazine, January 2026). CAB accreditation concluding April 2026.
Read article29 January 2026
AI-Driven Cyber Threats
Learn how hackers use AI to create better phishing emails, clone voices, and automate attacks. Practical tips to defend your business.
Read articlePatch Management Guide
Keep your software up-to-date without the headache. A simple 6-step process for SMEs to handle updates and respond to critical vulnerabilities.
Read articleWhat is Ransomware?
Added new section on data exfiltration attacks - the shift from encrypting files to stealing data and threatening to publish it.
Read articleVendor Security Assessment
Added real-world supply chain breach case studies (Ledger, Clop, ESA) to show why supplier security matters.
Read articleLooking for what changed recently?
Go to the current updates