Introduction

In 2026, cyberattacks are the number one threat facing Belgian SMEs. According to the Centre for Cybersecurity Belgium (CCB), 68% of Belgian SMEs have suffered at least one cybersecurity incident in the past 12 months. The average cost of a cyberattack for a Belgian SME is estimated at EUR 50,000, and in 60% of cases the affected business goes bankrupt within six months of a major attack.

Yet many SMEs still see cybersecurity as a concern reserved for large companies. That is a fatal mistake: cybercriminals increasingly target small businesses, precisely because they are less protected. SMEs account for more than 70% of ransomware victims in Belgium.

With the European NIS2 directive now transposed into Belgian law, many SMEs face new cybersecurity obligations. This guide details the 10 essential measures every Belgian SME should implement to protect itself effectively.

The Belgian Cybersecurity Landscape

The Most Common Threats in Belgium

According to CCB and CERT.be reports, the most common threats facing Belgian SMEs are:

Threat Type Share of SMEs Affected Average Cost per Incident
Phishing / spear phishing 72% EUR 5,000–25,000
Ransomware 28% EUR 30,000–250,000
CEO fraud / BEC 18% EUR 15,000–100,000
Denial-of-service (DDoS) attack 12% EUR 10,000–50,000
Data theft / data breach 15% EUR 20,000–500,000
Various malware 35% EUR 5,000–30,000

Key Belgian Institutions

  • Centre for Cybersecurity Belgium (CCB): the national cybersecurity authority, attached to the Prime Minister's office. The CCB coordinates national policy, issues alerts and offers free tools such as the CyberFundamentals Framework.
  • CERT.be: the national Computer Emergency Response Team, which handles IT security incidents. In 2025, CERT.be processed more than 10 million reports.
  • Safeonweb: the CCB's awareness platform for citizens and small businesses, offering free security-check tools.
  • Data Protection Authority (APD/GBA): responsible for enforcing the GDPR in Belgium, with the power to impose fines for data breaches.

The NIS2 Directive (Network and Information Security Directive 2), transposed into Belgian law, considerably widens the range of companies subject to cybersecurity obligations. It now covers:

  • Companies with more than 50 employees or turnover above EUR 10 million in "essential" and "important" sectors (energy, transport, health, banking, digital infrastructure, wastewater management, public administration, space, food, manufacturing, postal services, waste management, chemicals, research).
  • Providers of digital services (cloud, search engines, marketplaces).
  • Implementing cybersecurity risk-management measures
  • Reporting significant incidents to the CCB within 24 hours (early warning) and 72 hours (full notification)
  • Direct management liability (executives can be held personally responsible)
  • Securing the supply chain
  • Fines of up to EUR 10 million or 2% of global turnover for essential entities

The GDPR also requires the protection of personal data, with fines of up to EUR 20 million or 4% of global turnover. The Belgian APD has already imposed significant fines on Belgian companies.

The 10 Essential SME Cybersecurity Measures

Measure 1: Adopt the CCB's CyberFundamentals Framework

The CyberFundamentals Framework is the cybersecurity standard developed by the CCB specifically for Belgian companies. It offers four maturity levels:

Level Description Target
Small Essential baseline measures Micro-businesses, self-employed
Basic Security fundamentals SMEs with fewer than 50 employees
Important Advanced security SMEs with more than 50 employees, "important" NIS2 entities
Essential Maximum security Large companies, "essential" NIS2 entities

This framework is free and available on the CCB website. It is the ideal starting point for any Belgian SME wanting to structure its cybersecurity approach.

  • Download the CyberFundamentals Framework from ccb.belgium.be
  • Complete the online self-assessment to determine your current level
  • Identify the gaps between your situation and your target level
  • Draw up a prioritised action plan over 6 to 12 months
  • Consider CyberFundamentals certification with a BELAC-accredited body

Measure 2: Set Up a Strong Password Policy and MFA

Weak or reused passwords are responsible for more than 80% of data breaches. Here are the rules to apply in your SME:

  • Minimum 14 characters (uppercase, lowercase, numbers, special characters)
  • No reusing passwords across services
  • Mandatory change only if compromise is suspected (no arbitrary periodic changes, in line with current NIST recommendations)
  • Use of a business password manager
  • Bitwarden (Teams plan from USD 4/user/month, open source)
  • 1Password Business (USD 7.99/user/month)
  • Keeper Business (EUR 3.75/user/month)

Multi-factor authentication (MFA):
MFA is the most effective security measure after strong passwords. Enable it on:

  • All business email accounts (Microsoft 365, Google Workspace)
  • Management tools (accounting, CRM, ERP)
  • VPN and remote-desktop access
  • Cloud accounts (AWS, Azure, GCP)
  • Online banking accounts
  • Microsoft Authenticator (free, built into Microsoft 365)
  • Google Authenticator or Authy (free)
  • YubiKey physical keys (from EUR 50/key, recommended for administrators)

Measure 3: Back Up Using the 3-2-1-1-0 Rule

Backup is your last line of defence against ransomware. Apply the 3-2-1-1-0 rule:

  • 3 copies of your data
  • 2 different types of media (e.g. local hard drive plus cloud)
  • 1 off-site copy (remote data centre or cloud)
  • 1 offline copy (disconnected from the network, out of ransomware's reach)
  • 0 errors after verification (test restoration regularly)
Solution Type Indicative Price Data Location
Veeam Backup Software From EUR 2/VM/month Your choice
Acronis Cyber Protect Cloud + local From EUR 5/workstation/month EU data centres
Datto / Kaseya Cloud + local On quote EU data centres
Backblaze B2 Cloud USD 6/TB/month USA/EU
Combell Backup Cloud From EUR 10/month Belgian data centres
NRB Cloud Backup Cloud On quote Belgian data centres (Herstal)

Practical tip: Test restoring your backups at least once a quarter. Many companies discover too late that their backups are corrupted or incomplete.

Measure 4: Keep Your Systems Up to Date (Patch Management)

Unpatched software vulnerabilities are cybercriminals' favourite entry point. The WannaCry ransomware, for example, exploited a Windows flaw for which a patch had existed for two months.

  • Enable automatic updates on all workstations (Windows Update, macOS)
  • Update your servers within 48 hours of a critical patch being released
  • Keep all your software up to date (browsers, Adobe, Java, etc.)
  • Replace end-of-life systems (Windows Server 2012/2016, Windows 10 after October 2025)
  • Use a centralised management tool
  • Microsoft Intune (included in Microsoft 365 Business Premium, around EUR 20/user/month)
  • ManageEngine Patch Manager Plus (from EUR 300/year for 50 devices)
  • NinjaRMM / Atera: remote management solutions with built-in patch management (from EUR 3/endpoint/month)

Measure 5: Protect Your Email and Train Your Employees

Phishing is the number one attack vector in Belgium. 92% of cyberattacks start with a malicious email.

  • Deploy an advanced anti-spam/anti-phishing filter (Microsoft Defender for Office 365, Barracuda, Proofpoint)
  • Configure email authentication protocols: SPF, DKIM and DMARC on your domain
  • Enable real-time scanning of attachments and links
  • Block automatic macro execution in Office documents

Employee training and awareness:
Employee training is crucial. According to the CCB, a well-run awareness campaign cuts clicks on phishing emails by 75% within six months.

  • Hold quarterly awareness sessions (30 minutes)
  • Run simulated phishing campaigns to test your employees
  • Display best practices in offices and on your intranet
  • Appoint "cybersecurity ambassadors" in each department
  • KnowBe4 (global leader, from EUR 15/user/year)
  • Phished (Belgian startup based in Leuven, specialising in AI-driven phishing simulations, from EUR 2.50/user/month)
  • CCB's Safeonweb: free awareness and testing tools

Measure 6: Secure Your Corporate Network

  • Deploy a next-generation firewall (NGFW) at the entry point of your network
  • Segment your network: separate guest Wi-Fi from the internal network, isolate critical systems
  • Use a VPN for remote access
  • Fortinet FortiGate (from EUR 400 plus annual subscription, very popular in Belgium)
  • Sophos XGS (from EUR 500 plus subscription)
  • WatchGuard Firebox (from EUR 600)
  • pfSense (open source, free, but requires technical skills)
  • Use the WPA3 protocol (or WPA2-Enterprise at minimum)
  • Change your router/access point's default password
  • Create a separate Wi-Fi network for visitors
  • Disable WPS (Wi-Fi Protected Setup)

Measure 7: Protect Workstations and Mobile Devices (Endpoint Security)

Every workstation, laptop and smartphone is a potential entry point for cybercriminals.

Solution Indicative Price Strengths
Microsoft Defender for Business Included in M365 Business Premium (~EUR 20/user/month) Native Windows integration, EDR included
Bitdefender GravityZone From EUR 3/device/month Excellent detection rate, cloud management
ESET PROTECT From EUR 3.50/device/month Lightweight, high-performing, support based in Belgium
SentinelOne From EUR 5/device/month Advanced AI, automated response
CrowdStrike Falcon Go From EUR 8/device/month Market leader, cloud-native
  • Deploy an MDM solution for business smartphones and tablets
  • Microsoft Intune (included in M365 Business Premium) or Jamf (for Apple environments)
  • Enforce mobile device encryption
  • Configure remote wipe in case of loss or theft
  • Separate business data from personal data (containerisation)

Measure 8: Manage Access and Privileges (IAM)

The principle of least privilege is fundamental: each employee should only access the resources their job requires.

  • Assign named accounts to each employee (never shared accounts)
  • Remove departing employees' access on their last day
  • Limit the number of administrators (ideally 2-3 people maximum)
  • Carry out a quarterly access review
  • Use separate administrative accounts for admin tasks
  • Microsoft Entra ID (formerly Azure AD, included in Microsoft 365)
  • JumpCloud (from USD 7/user/month, multi-OS management)
  • Okta (from USD 2/user/month for SSO)

Measure 9: Develop an Incident Response Plan

Even with the best protection, an incident can still occur. A well-prepared response plan makes the difference between a minor disruption and a disaster.

  1. Response team: designate internal leads and external contacts (IT provider, specialist lawyer, insurer, CCB/CERT.be)
  2. Detection procedures: how to identify an incident (SIEM/EDR alerts, employee reports, external notification)
  3. Containment procedures: immediate actions to limit impact (isolate compromised systems, disconnect from the network)
  4. Communication procedures: who to inform and within what timeframe (management, employees, customers, the APD if personal data is involved, the CCB under NIS2)
  5. Recovery procedures: restoring systems and data from backups
  6. Post-incident analysis: understanding what happened and how to prevent it recurring
  • GDPR: notify the APD within 72 hours of a personal data breach
  • NIS2: early warning to the CCB within 24 hours, full notification within 72 hours
  • Cyber insurance: notify your insurer within the timeframe set out in your contract

Measure 10: Take Out Cyber Insurance

Cyber insurance has become essential for Belgian SMEs. It covers the costs of a security incident that your business could not absorb alone.

  • Crisis management and incident response costs
  • Data and system restoration costs
  • Operating losses linked to business interruption
  • Legal costs and regulatory fines
  • Notification costs for affected individuals (GDPR)
  • Third-party liability
  • Crisis communication and reputation management costs
Insurer Product Indicative SME Premium
AXA Belgium Cyber Secure From EUR 500/year
AG Insurance CyberEdge From EUR 600/year
Ethias Cyber Protection From EUR 450/year
Hiscox Cyber Clear From EUR 400/year
Allianz Cyber Protect From EUR 550/year
Zurich Cyber & Data Protection On quote

Tip: Premiums have risen by 30 to 50% in recent years. Insurers now require a minimum level of security (MFA, backups, a response plan) before granting cover. Implement the first 9 measures in this guide to secure the best terms.

Cybersecurity Budget: How Much Should You Invest?

Benchmarks for Belgian SMEs

The CCB's general recommendation is to allocate 5 to 10% of your total IT budget to cybersecurity. Here are estimates by company size:

Company Size Estimated Annual IT Budget Recommended Cybersecurity Budget
Micro-business (1-9 employees) EUR 5,000–20,000 EUR 500–2,000/year
Small business (10-49 employees) EUR 20,000–100,000 EUR 2,000–10,000/year
Medium business (50-249 employees) EUR 100,000–500,000 EUR 10,000–50,000/year

Example Cybersecurity Budget for a 25-Employee SME

Item Annual Cost
Microsoft 365 Business Premium (includes Defender, Intune, MFA) EUR 6,000 (EUR 20 x 25 x 12 months)
Cloud backup (Acronis or equivalent) EUR 1,500
Fortinet FortiGate firewall + subscription EUR 1,200
Training and awareness (Phished) EUR 750
Password manager (Bitwarden Teams) EUR 1,200
Cyber insurance EUR 800
Annual security audit EUR 3,000
Total EUR 14,450/year

This budget of under EUR 600/month delivers solid protection for a 25-person SME.

Cybersecurity Grants and Subsidies in Belgium

Business Vouchers in Wallonia

The Walloon Region offers business vouchers ("chèques-entreprises") covering up to 75% of the cost of cybersecurity consulting (capped at EUR 60,000 per year). These vouchers can be used for:

  • A cybersecurity audit
  • Setting up a security policy
  • Support towards CyberFundamentals certification
  • Staff training

KMO-portefeuille in Flanders

VLAIO's KMO-portefeuille (SME wallet) lets Flemish SMEs recover 20 to 30% of cybersecurity consulting costs, with an annual cap of EUR 7,500.

Brussels Grants

Hub.brussels offers dedicated cybersecurity support through its digital transformation programmes. Innoviris also funds cybersecurity-related R&D projects.

Cybersecurity Providers in Belgium

For SMEs without in-house expertise, using a specialist provider is often the best solution:

  • NVISO (Brussels): penetration testing, managed SOC, consulting
  • Toreon (Antwerp): application security, DevSecOps, training
  • Approach (Brussels): consulting, audit, managed SOC
  • Davinsi Labs (Proximus group): managed SOC, detection and response
  • e-BO Enterprises (Ostend): IT security, infrastructure, cloud
  • Secutec (Mechelen): security solutions, EDR, firewalls
  • SecureLink (Antwerp, Orange group): managed SOC, SIEM, consulting

Tip: Check that your provider holds recognised certifications (ISO 27001, CREST, OSCP for pentesters) and ideally CCB CyberFundamentals labelling.

Cybersecurity Checklist for Belgian SMEs

Use this checklist to assess your level of preparedness:

  • CyberFundamentals Framework adopted and self-assessment completed
  • Strong password policy in place
  • MFA enabled on all critical accounts
  • Automated backups following the 3-2-1-1-0 rule
  • Backup restoration tested within the last 3 months
  • All systems up to date (OS, software, firmware)
  • Anti-phishing solution deployed on email
  • Employee awareness campaign run in the last 6 months
  • Firewall configured and network segmented
  • EDR solution deployed on all endpoints
  • Access and privilege management in place
  • Incident response plan documented and tested
  • Cyber insurance taken out
  • NIS2 compliance assessed (if applicable)
  • GDPR compliance ensured (records of processing activities, DPO if required)

Conclusion

Cybersecurity is no longer optional for Belgian SMEs: it is a legal necessity (NIS2, GDPR) and a condition of economic survival. The 10 measures presented in this guide form a solid foundation that will let your SME defend itself effectively against the vast majority of threats.

The recommended approach is pragmatic: start with the highest-impact measures (MFA, backups, updates), then progress towards a higher maturity level with the CCB's CyberFundamentals Framework. Don't hesitate to use specialist providers and take advantage of the regional grants available to fund your approach.

Cybersecurity is an investment, not a cost. Every euro invested in prevention represents a potential saving of 10 to 50 euros in remediation costs. Protect your business, your employees and your customers — start today.


This article was written by the Espero-Soft team for the blog dedicated to entrepreneurs in Belgium. For a personalised cybersecurity audit or support implementing these measures, contact our experts.