Cybersecurity for SMEs, without scaremongering or jargon.

An SME does not need a multinational’s SOC. It needs measures proportionate to its real exposure, teams who know what to look for — and a partner able to actually act when an incident happens.

The context

What Belgium actually went through in 2025.

Three public figures, published by the Centre for Cybersecurity Belgium. They are not there to alarm you: they simply say that the most frequent threat is not the most spectacular.

Notifications to the CCB

0

Reporting has become the norm

The Centre for Cybersecurity Belgium received 635 incident notifications in 2025, 556 of them cyber-related — nearly 70% more than in 2024. Any company can report an incident to the CCB, even when it is under no obligation to do so.

Compromised accounts

0

The number one threat makes no noise

Account compromises doubled in a year, to 144 cases: they are now the most reported threat in Belgium, ahead of ransomware (105 cases). A stolen password shows no ransom note — it signs in, reads, waits, and invoices in your name.

Suspicious messages reported

0M

Your teams are the front line

Close to ten million suspicious messages were forwarded to suspicious@safeonweb.be in 2025 by Belgian citizens and employees. The country’s best sensor is human — which is why awareness counts as much as tooling.

Centre for Cybersecurity Belgium — key figures 2025.

The approach

Before, during, after.

Three phases, one requirement: measures proportionate to your real exposure, never a catalogue sold on fear.

Before the incident

Reducing exposure, methodically.

Most of the incidents we have handled exploited weaknesses that were known and fixable. Prevention is the best security investment an SME can make.

  • Security posture assessment: a factual picture of your exposure
  • Microsoft 365 hardening: MFA everywhere, conditional access, mail protection
  • Backups tested regularly — a backup never restored is not a backup
  • Staff awareness: phishing, CEO fraud, everyday good practice

During the incident

A structured response, not panic.

We have handled business email compromise (BEC) cases and led a full rebuild after a ransomware attack. When an incident happens, every hour counts and every action has to come in the right order.

  • Immediate containment: isolate what must be isolated, preserve what can be preserved
  • Analysis of sign-in logs to reconstruct what happened
  • Evicting the attacker: revoking access, resetting credentials, closing the way in
  • Controlled communication to your teams, clients and partners

After the incident

Coming out stronger than before.

An incident handled well becomes a turning point: the chance to rebuild on sound foundations and bring the organisation up to standard for good.

  • A full resilience plan, prioritised by impact
  • Architecture reviewed and corrected on the points that were exploited
  • Stronger monitoring on the signals that were missed
  • Follow-up over time: posture is maintained, not declared

The baseline

Six measures cover the essentials. Start with them.

An SME does not need to do everything. Six measures cover the vast majority of what we meet in the field. They can be put in place in a few weeks, without changing your tools — and often by switching on what your licences already include.
  1. 01

    Two-factor authentication, everywhere, no exceptions

    On email, remote access and administrator accounts. It is the measure that stops the most incidents for the least effort. Exceptions granted “just for this one person” are exactly the doors we find open afterwards.

  2. 02

    A backup out of reach, and restored for real

    A copy the network can neither change nor erase, and at least one genuine restore carried out in front of you, stopwatch in hand. The same goes for Microsoft 365: Microsoft guarantees the availability of its service and keeps your deleted items for a limited time, but recovering your data after encryption or human error remains your responsibility. A backup never restored is not a backup: it is an intention.

  3. 03

    Administrator accounts, counted

    Who can do everything, on what, from where, and since when. In most SMEs the answer surprises the business owner: former providers, forgotten service accounts, permanent access that should have been temporary.

  4. 04

    Updates kept up, not assumed

    Workstations, servers, firewalls, network equipment: planned, applied, verified. Most of the intrusions we have analysed came through a flaw that had been known and patched for months.

  5. 05

    A hardened mail system

    Filtering, authentication of your domain (SPF, DKIM, DMARC) so nobody can write to your clients in your name, and blocking of auto-forwarding rules created without your knowledge. Your email is your first attack surface: it is where everything begins.

  6. 06

    Teams warned, never blamed

    One hour to learn to spot a fake sign-in page and an unusual payment request. And one clear rule: when in doubt, pick up the phone. Never any blame for one alert too many — a team that fears being wrong is a team that says nothing.

This baseline is the same for everyone. It is also, almost word for word, the list your cyber insurer will ask you to tick — and will check on the day of the claim. What comes next — network segmentation, endpoint detection, monitoring, continuity planning — depends on your real exposure. That is decided after the assessment, not before.

Obligations

You are probably not covered by NIS2. Your clients are.

Many providers wave regulation about as a sales argument. Let us keep it simple: here is what applies to you, and what does not.
What does not apply to you

NIS2 covers around 4,000 organisations in Belgium.

The Belgian law of 26 April 2024 transposes the European NIS2 directive. It covers designated sectors — energy, health, transport, public administration, finance, critical industry — above a certain size. Around 4,000 organisations have registered on that basis with the Centre for Cybersecurity Belgium. An SME of 10 to 100 people operating outside those sectors is very unlikely to fall within its direct scope. We would rather tell you that plainly than turn it into a sales lever.

Your clients, though, are subject to it. And they pass it on to you.

NIS2 makes the entities concerned responsible for the security of their supply chain: their suppliers, their subcontractors, their providers. If you supply a hospital, a local authority, an energy operator, a bank or a large manufacturer, the security questionnaire turns up in tenders and at framework contract renewal. For an SME subcontractor the risk is not the fine: it is losing a contract on a vague answer.

CyberFundamentals: the Belgian framework, free and tiered.

The CCB publishes CyberFundamentals — CyFun — a public framework with four levels: Small, Basic, Important, Essential. The Small level is self-assessed online, with no consultant. This is not one more standard: it is the common vocabulary your client will use to put questions to you. And the timetable has already started: the requirements on the entities concerned are moving down their supply chain now, not in two years.

GDPR, on the other hand, already applies to everyone.

It does not address cybersecurity as such, but it requires measures appropriate to the risk and the notification of data breaches. If an incident affects personal data — clients, patients, employees — and is likely to result in a risk to the people concerned, the breach must be notified to the Data Protection Authority within 72 hours. Seventy-two calendar hours: the weekend counts. It is the one obligation that applies to absolutely every company, whatever its size — and the one most often forgotten while everyone talks about NIS2.

We do not issue certification: that is the role of accredited bodies, and we would not be both judge and jury. What we do is put you in a position to answer — the current position against the framework, the gaps ranked in order, and the evidence file your client will ask you for.

Budget

How it is costed.

The question always comes up, and rightly so. Here is how we cost things — before we have even met.

The security posture assessment: a fixed fee, known before we start.

The scope is defined together, and the price is fixed and stated before the first day of work. It is counted in days, not months. At the end you receive a written report that belongs to you: findings, priorities, costing. You can act on it with us, with your current provider, or on your own. That is our definition of independence.

The baseline: a one-off piece of work, costed line by line.

Each measure has its cost and its expected benefit, written side by side. You decide what happens now and what waits for the next budget. And we say this before selling anything: depending on your Microsoft 365 plan, part of this baseline is already included in the licences you pay for. Turning it on costs working time, not necessarily extra licences.

Keeping it up: a monthly figure you can read.

Monitoring, updates, verified backups, awareness, regular posture reviews. A figure per user and per device, with no surprise adjustment at year end. Security is not a project you finish: it is a posture you maintain.

You are never shown a line on a quote without knowing what it buys. If a measure is not justified in your case, it is not there. And we give you the order of magnitude from the first conversation — not after three meetings.

Our code of practice

“We do not sell fear. Every recommendation is justified by your real exposure and ranked by impact. If a measure is not justified in your situation, we tell you so.”

Think you are protected? Let’s check.

Request a security posture assessment

A factual assessment, with no commitment.