
Introduction
In 2026, cyberattacks are the number one threat facing Belgian SMEs. According to the Centre for Cybersecurity Belgium (CCB), 68% of Belgian SMEs have suffered at least one cybersecurity incident in the past 12 months. The average cost of a cyberattack for a Belgian SME is estimated at EUR 50,000, and in 60% of cases the affected business goes bankrupt within six months of a major attack.
Yet many SMEs still see cybersecurity as a concern reserved for large companies. That is a fatal mistake: cybercriminals increasingly target small businesses, precisely because they are less protected. SMEs account for more than 70% of ransomware victims in Belgium.
With the European NIS2 directive now transposed into Belgian law, many SMEs face new cybersecurity obligations. This guide details the 10 essential measures every Belgian SME should implement to protect itself effectively.
The Belgian Cybersecurity Landscape
The Most Common Threats in Belgium
According to CCB and CERT.be reports, the most common threats facing Belgian SMEs are:
| Threat Type | Share of SMEs Affected | Average Cost per Incident |
|---|---|---|
| Phishing / spear phishing | 72% | EUR 5,000–25,000 |
| Ransomware | 28% | EUR 30,000–250,000 |
| CEO fraud / BEC | 18% | EUR 15,000–100,000 |
| Denial-of-service (DDoS) attack | 12% | EUR 10,000–50,000 |
| Data theft / data breach | 15% | EUR 20,000–500,000 |
| Various malware | 35% | EUR 5,000–30,000 |
Key Belgian Institutions
- Centre for Cybersecurity Belgium (CCB): the national cybersecurity authority, attached to the Prime Minister's office. The CCB coordinates national policy, issues alerts and offers free tools such as the CyberFundamentals Framework.
- CERT.be: the national Computer Emergency Response Team, which handles IT security incidents. In 2025, CERT.be processed more than 10 million reports.
- Safeonweb: the CCB's awareness platform for citizens and small businesses, offering free security-check tools.
- Data Protection Authority (APD/GBA): responsible for enforcing the GDPR in Belgium, with the power to impose fines for data breaches.
The Legal Framework: NIS2 and GDPR
The NIS2 Directive (Network and Information Security Directive 2), transposed into Belgian law, considerably widens the range of companies subject to cybersecurity obligations. It now covers:
- Companies with more than 50 employees or turnover above EUR 10 million in "essential" and "important" sectors (energy, transport, health, banking, digital infrastructure, wastewater management, public administration, space, food, manufacturing, postal services, waste management, chemicals, research).
- Providers of digital services (cloud, search engines, marketplaces).
Key NIS2 obligations for Belgian SMEs:
- Implementing cybersecurity risk-management measures
- Reporting significant incidents to the CCB within 24 hours (early warning) and 72 hours (full notification)
- Direct management liability (executives can be held personally responsible)
- Securing the supply chain
- Fines of up to EUR 10 million or 2% of global turnover for essential entities
The GDPR also requires the protection of personal data, with fines of up to EUR 20 million or 4% of global turnover. The Belgian APD has already imposed significant fines on Belgian companies.
The 10 Essential SME Cybersecurity Measures
Measure 1: Adopt the CCB's CyberFundamentals Framework
The CyberFundamentals Framework is the cybersecurity standard developed by the CCB specifically for Belgian companies. It offers four maturity levels:
| Level | Description | Target |
|---|---|---|
| Small | Essential baseline measures | Micro-businesses, self-employed |
| Basic | Security fundamentals | SMEs with fewer than 50 employees |
| Important | Advanced security | SMEs with more than 50 employees, "important" NIS2 entities |
| Essential | Maximum security | Large companies, "essential" NIS2 entities |
This framework is free and available on the CCB website. It is the ideal starting point for any Belgian SME wanting to structure its cybersecurity approach.
Practical actions:
- Download the CyberFundamentals Framework from ccb.belgium.be
- Complete the online self-assessment to determine your current level
- Identify the gaps between your situation and your target level
- Draw up a prioritised action plan over 6 to 12 months
- Consider CyberFundamentals certification with a BELAC-accredited body
Measure 2: Set Up a Strong Password Policy and MFA
Weak or reused passwords are responsible for more than 80% of data breaches. Here are the rules to apply in your SME:
Password policy:
- Minimum 14 characters (uppercase, lowercase, numbers, special characters)
- No reusing passwords across services
- Mandatory change only if compromise is suspected (no arbitrary periodic changes, in line with current NIST recommendations)
- Use of a business password manager
Recommended password managers:
- Bitwarden (Teams plan from USD 4/user/month, open source)
- 1Password Business (USD 7.99/user/month)
- Keeper Business (EUR 3.75/user/month)
Multi-factor authentication (MFA):
MFA is the most effective security measure after strong passwords. Enable it on:
- All business email accounts (Microsoft 365, Google Workspace)
- Management tools (accounting, CRM, ERP)
- VPN and remote-desktop access
- Cloud accounts (AWS, Azure, GCP)
- Online banking accounts
Recommended MFA solutions:
- Microsoft Authenticator (free, built into Microsoft 365)
- Google Authenticator or Authy (free)
- YubiKey physical keys (from EUR 50/key, recommended for administrators)
Measure 3: Back Up Using the 3-2-1-1-0 Rule
Backup is your last line of defence against ransomware. Apply the 3-2-1-1-0 rule:
- 3 copies of your data
- 2 different types of media (e.g. local hard drive plus cloud)
- 1 off-site copy (remote data centre or cloud)
- 1 offline copy (disconnected from the network, out of ransomware's reach)
- 0 errors after verification (test restoration regularly)
Backup solutions suited to Belgian SMEs:
| Solution | Type | Indicative Price | Data Location |
|---|---|---|---|
| Veeam Backup | Software | From EUR 2/VM/month | Your choice |
| Acronis Cyber Protect | Cloud + local | From EUR 5/workstation/month | EU data centres |
| Datto / Kaseya | Cloud + local | On quote | EU data centres |
| Backblaze B2 | Cloud | USD 6/TB/month | USA/EU |
| Combell Backup | Cloud | From EUR 10/month | Belgian data centres |
| NRB Cloud Backup | Cloud | On quote | Belgian data centres (Herstal) |
Practical tip: Test restoring your backups at least once a quarter. Many companies discover too late that their backups are corrupted or incomplete.
Measure 4: Keep Your Systems Up to Date (Patch Management)
Unpatched software vulnerabilities are cybercriminals' favourite entry point. The WannaCry ransomware, for example, exploited a Windows flaw for which a patch had existed for two months.
Patch management best practices:
- Enable automatic updates on all workstations (Windows Update, macOS)
- Update your servers within 48 hours of a critical patch being released
- Keep all your software up to date (browsers, Adobe, Java, etc.)
- Replace end-of-life systems (Windows Server 2012/2016, Windows 10 after October 2025)
- Use a centralised management tool
Patch management tools for SMEs:
- Microsoft Intune (included in Microsoft 365 Business Premium, around EUR 20/user/month)
- ManageEngine Patch Manager Plus (from EUR 300/year for 50 devices)
- NinjaRMM / Atera: remote management solutions with built-in patch management (from EUR 3/endpoint/month)
Measure 5: Protect Your Email and Train Your Employees
Phishing is the number one attack vector in Belgium. 92% of cyberattacks start with a malicious email.
Technical email protection:
- Deploy an advanced anti-spam/anti-phishing filter (Microsoft Defender for Office 365, Barracuda, Proofpoint)
- Configure email authentication protocols: SPF, DKIM and DMARC on your domain
- Enable real-time scanning of attachments and links
- Block automatic macro execution in Office documents
Employee training and awareness:
Employee training is crucial. According to the CCB, a well-run awareness campaign cuts clicks on phishing emails by 75% within six months.
Practical actions:
- Hold quarterly awareness sessions (30 minutes)
- Run simulated phishing campaigns to test your employees
- Display best practices in offices and on your intranet
- Appoint "cybersecurity ambassadors" in each department
Awareness and phishing-simulation tools:
- KnowBe4 (global leader, from EUR 15/user/year)
- Phished (Belgian startup based in Leuven, specialising in AI-driven phishing simulations, from EUR 2.50/user/month)
- CCB's Safeonweb: free awareness and testing tools
Measure 6: Secure Your Corporate Network
Firewall and network segmentation:
- Deploy a next-generation firewall (NGFW) at the entry point of your network
- Segment your network: separate guest Wi-Fi from the internal network, isolate critical systems
- Use a VPN for remote access
Firewall solutions for SMEs:
- Fortinet FortiGate (from EUR 400 plus annual subscription, very popular in Belgium)
- Sophos XGS (from EUR 500 plus subscription)
- WatchGuard Firebox (from EUR 600)
- pfSense (open source, free, but requires technical skills)
Wi-Fi security:
- Use the WPA3 protocol (or WPA2-Enterprise at minimum)
- Change your router/access point's default password
- Create a separate Wi-Fi network for visitors
- Disable WPS (Wi-Fi Protected Setup)
Measure 7: Protect Workstations and Mobile Devices (Endpoint Security)
Every workstation, laptop and smartphone is a potential entry point for cybercriminals.
Endpoint Detection and Response (EDR) solutions for SMEs:
| Solution | Indicative Price | Strengths |
|---|---|---|
| Microsoft Defender for Business | Included in M365 Business Premium (~EUR 20/user/month) | Native Windows integration, EDR included |
| Bitdefender GravityZone | From EUR 3/device/month | Excellent detection rate, cloud management |
| ESET PROTECT | From EUR 3.50/device/month | Lightweight, high-performing, support based in Belgium |
| SentinelOne | From EUR 5/device/month | Advanced AI, automated response |
| CrowdStrike Falcon Go | From EUR 8/device/month | Market leader, cloud-native |
Mobile device management (MDM):
- Deploy an MDM solution for business smartphones and tablets
- Microsoft Intune (included in M365 Business Premium) or Jamf (for Apple environments)
- Enforce mobile device encryption
- Configure remote wipe in case of loss or theft
- Separate business data from personal data (containerisation)
Measure 8: Manage Access and Privileges (IAM)
The principle of least privilege is fundamental: each employee should only access the resources their job requires.
Access management best practices:
- Assign named accounts to each employee (never shared accounts)
- Remove departing employees' access on their last day
- Limit the number of administrators (ideally 2-3 people maximum)
- Carry out a quarterly access review
- Use separate administrative accounts for admin tasks
Identity management solutions for SMEs:
- Microsoft Entra ID (formerly Azure AD, included in Microsoft 365)
- JumpCloud (from USD 7/user/month, multi-OS management)
- Okta (from USD 2/user/month for SSO)
Measure 9: Develop an Incident Response Plan
Even with the best protection, an incident can still occur. A well-prepared response plan makes the difference between a minor disruption and a disaster.
Components of an incident response plan:
- Response team: designate internal leads and external contacts (IT provider, specialist lawyer, insurer, CCB/CERT.be)
- Detection procedures: how to identify an incident (SIEM/EDR alerts, employee reports, external notification)
- Containment procedures: immediate actions to limit impact (isolate compromised systems, disconnect from the network)
- Communication procedures: who to inform and within what timeframe (management, employees, customers, the APD if personal data is involved, the CCB under NIS2)
- Recovery procedures: restoring systems and data from backups
- Post-incident analysis: understanding what happened and how to prevent it recurring
Notification obligations:
- GDPR: notify the APD within 72 hours of a personal data breach
- NIS2: early warning to the CCB within 24 hours, full notification within 72 hours
- Cyber insurance: notify your insurer within the timeframe set out in your contract
Emergency contacts in Belgium:
- CERT.be: cert@cert.be / +32 2 501 05 60
- Safeonweb: suspect@safeonweb.be (to report suspicious emails)
- APD: contact@apd-gba.be (for personal data breaches)
- Federal police (FCCU): report cybercrime via ecops.be
Measure 10: Take Out Cyber Insurance
Cyber insurance has become essential for Belgian SMEs. It covers the costs of a security incident that your business could not absorb alone.
What cyber insurance typically covers:
- Crisis management and incident response costs
- Data and system restoration costs
- Operating losses linked to business interruption
- Legal costs and regulatory fines
- Notification costs for affected individuals (GDPR)
- Third-party liability
- Crisis communication and reputation management costs
Insurers offering cyber cover in Belgium:
| Insurer | Product | Indicative SME Premium |
|---|---|---|
| AXA Belgium | Cyber Secure | From EUR 500/year |
| AG Insurance | CyberEdge | From EUR 600/year |
| Ethias | Cyber Protection | From EUR 450/year |
| Hiscox | Cyber Clear | From EUR 400/year |
| Allianz | Cyber Protect | From EUR 550/year |
| Zurich | Cyber & Data Protection | On quote |
Tip: Premiums have risen by 30 to 50% in recent years. Insurers now require a minimum level of security (MFA, backups, a response plan) before granting cover. Implement the first 9 measures in this guide to secure the best terms.
Cybersecurity Budget: How Much Should You Invest?
Benchmarks for Belgian SMEs
The CCB's general recommendation is to allocate 5 to 10% of your total IT budget to cybersecurity. Here are estimates by company size:
| Company Size | Estimated Annual IT Budget | Recommended Cybersecurity Budget |
|---|---|---|
| Micro-business (1-9 employees) | EUR 5,000–20,000 | EUR 500–2,000/year |
| Small business (10-49 employees) | EUR 20,000–100,000 | EUR 2,000–10,000/year |
| Medium business (50-249 employees) | EUR 100,000–500,000 | EUR 10,000–50,000/year |
Example Cybersecurity Budget for a 25-Employee SME
| Item | Annual Cost |
|---|---|
| Microsoft 365 Business Premium (includes Defender, Intune, MFA) | EUR 6,000 (EUR 20 x 25 x 12 months) |
| Cloud backup (Acronis or equivalent) | EUR 1,500 |
| Fortinet FortiGate firewall + subscription | EUR 1,200 |
| Training and awareness (Phished) | EUR 750 |
| Password manager (Bitwarden Teams) | EUR 1,200 |
| Cyber insurance | EUR 800 |
| Annual security audit | EUR 3,000 |
| Total | EUR 14,450/year |
This budget of under EUR 600/month delivers solid protection for a 25-person SME.
Cybersecurity Grants and Subsidies in Belgium
Business Vouchers in Wallonia
The Walloon Region offers business vouchers ("chèques-entreprises") covering up to 75% of the cost of cybersecurity consulting (capped at EUR 60,000 per year). These vouchers can be used for:
- A cybersecurity audit
- Setting up a security policy
- Support towards CyberFundamentals certification
- Staff training
KMO-portefeuille in Flanders
VLAIO's KMO-portefeuille (SME wallet) lets Flemish SMEs recover 20 to 30% of cybersecurity consulting costs, with an annual cap of EUR 7,500.
Brussels Grants
Hub.brussels offers dedicated cybersecurity support through its digital transformation programmes. Innoviris also funds cybersecurity-related R&D projects.
Cybersecurity Providers in Belgium
For SMEs without in-house expertise, using a specialist provider is often the best solution:
Belgian companies specialising in cybersecurity:
- NVISO (Brussels): penetration testing, managed SOC, consulting
- Toreon (Antwerp): application security, DevSecOps, training
- Approach (Brussels): consulting, audit, managed SOC
- Davinsi Labs (Proximus group): managed SOC, detection and response
- e-BO Enterprises (Ostend): IT security, infrastructure, cloud
- Secutec (Mechelen): security solutions, EDR, firewalls
- SecureLink (Antwerp, Orange group): managed SOC, SIEM, consulting
Tip: Check that your provider holds recognised certifications (ISO 27001, CREST, OSCP for pentesters) and ideally CCB CyberFundamentals labelling.
Cybersecurity Checklist for Belgian SMEs
Use this checklist to assess your level of preparedness:
- CyberFundamentals Framework adopted and self-assessment completed
- Strong password policy in place
- MFA enabled on all critical accounts
- Automated backups following the 3-2-1-1-0 rule
- Backup restoration tested within the last 3 months
- All systems up to date (OS, software, firmware)
- Anti-phishing solution deployed on email
- Employee awareness campaign run in the last 6 months
- Firewall configured and network segmented
- EDR solution deployed on all endpoints
- Access and privilege management in place
- Incident response plan documented and tested
- Cyber insurance taken out
- NIS2 compliance assessed (if applicable)
- GDPR compliance ensured (records of processing activities, DPO if required)
Conclusion
Cybersecurity is no longer optional for Belgian SMEs: it is a legal necessity (NIS2, GDPR) and a condition of economic survival. The 10 measures presented in this guide form a solid foundation that will let your SME defend itself effectively against the vast majority of threats.
The recommended approach is pragmatic: start with the highest-impact measures (MFA, backups, updates), then progress towards a higher maturity level with the CCB's CyberFundamentals Framework. Don't hesitate to use specialist providers and take advantage of the regional grants available to fund your approach.
Cybersecurity is an investment, not a cost. Every euro invested in prevention represents a potential saving of 10 to 50 euros in remediation costs. Protect your business, your employees and your customers — start today.
This article was written by the Espero-Soft team for the blog dedicated to entrepreneurs in Belgium. For a personalised cybersecurity audit or support implementing these measures, contact our experts.


