IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →

#CyberLearn Updates

Stay up to date with new guides and improvements

20 August 2026

New

A fourth route if you will not reach CyFun Essential by April 2027

The CCB Inspection Service has named what an essential entity does when it cannot hold an Essential-equivalent conformity assessment by 18 April 2027: submit a remediation plan, proof of compliance at CyFun Important-equivalent level plus the measures planned to reach Essential-equivalent by 18 April 2028. The 18 April 2027 legal deadline is unchanged, and no plan is needed if you are already Essential-equivalent by then, or if your own risk analysis under Art. 7 of the NIS2 Royal Decree justifies a lower assurance level and you demonstrate by that date that you meet it. Source: CCB Inspection Service communication ref. NCCA/JK/INS/2026-002 of 11 August 2026, published 18 August 2026. Written into the missed-deadline page as a fourth remediation path, and reflected across the deadline, audit, certification and CAB-cost pages. Worth knowing why it exists: no conformity assessment body is authorised for CyFun Essential certification today, so that level currently runs through ISO/IEC 27001 or a CCB inspection. EN/NL/FR.

Read article

13 August 2026

Updated

Remote work: the company gateway you log in through is a device too

The page told you to use the company VPN but said nothing about the box at the company that accepts that login. Added a tenth tip on the remote-access gateway: it is one of the few devices deliberately left open to the internet, nobody at home can patch it, and somebody has to ask who does. Anchored on SonicWall SMA1000 (flaws CVE-2026-15409 and CVE-2026-15410, exploited from 22 June 2026, fixed mid-July 2026, both flaws flagged by CISA as used in ransomware attacks, and more than 380 of these devices tracked as exposed on the internet, though some may already have been secured, per BleepingComputer, 10 August 2026). Includes the three questions to put to your IT partner and a new checklist line. EN/NL/FR.

Read article
Updated

Passwords: hashed is not the same as safe

New section explaining, without jargon, why a breach notice saying your password was "hashed" is not an all-clear. Hashing works in one direction only and protects nothing more than a password that was already hard to guess; hackers take the scrambled list offline and grind through common and previously leaked passwords with nobody watching and no lock-out. Anchored on the Drukland notice of 10 August 2026, which covered email addresses and hashed passwords (ITdaily, 10 August 2026) plus card details for a small group (Security.NL, 11 August 2026). Ends where it should: change it, change it everywhere you reused it, turn on two-factor authentication. EN/NL/FR.

Read article
Updated

CyFun Basic effort study: dated note added, measured figures untouched

The study measures one implementation that ran 30 March to 17 June 2026, and two things in it now understate the product: the "writing policies and procedures" row of 64 manual actions, and the takeaway that most of the real effort happens off the platform. Since August 2026 the CyFun Basic procedure and policy documents come out of the platform already written in English, Dutch and French. Both places now carry a dated note saying the measurement predates that change. The measured numbers are deliberately not edited: it is a dated record of what happened. EN/NL/FR.

Read article

11 August 2026

Updated

CyFun auditors: corrected to four verification bodies, none yet for Essential

Our pages said there were only two BELAC-accredited CyFun audit bodies. The CCB list dated 22 July 2026 shows four authorised for verification at Basic and Important level: Brand Compliance Belgie, CertUp, Vinçotte and What a Work SRL (Trust CHECK). Two things the old wording missed: those four do verification, and no body is yet accredited to certify at Essential level, so Essential entities currently reach presumption of conformity through ISO 27001, where 15 authorised certification bodies are available. We have also dropped the "prepare now and you get audited first" framing, which rested on the two-auditor number. EN/NL/FR.

Read article
Updated

Scope broadened: CyFun is now the national scheme in five countries

CyberFundamentals is no longer Belgium-only. Belgium, Ireland, Romania, Malta and Cyprus are members of the CyFun Scheme Owner Group. Ireland's NCSC states it "will be adopting CyFun as its national assessment and certification scheme", with certification expected in 2027 and CyFun named a preferred method for the public administration sector. France recognises CyFun and is exploring adoption, but uses its own ReCyF framework. Our comparison and NIS2 guides now speak to SMEs and MSPs across the CyFun countries rather than to Belgium alone, while the CyberFundamentals section stays Belgium-specific where the subject is the CCB and its framework. EN/NL/FR.

Read article

23 July 2026

Updated

2FA setup: passkeys and phishing-resistant MFA section

Added a section on going beyond app codes. App-based codes can still be phished or talked out of someone in real time; passkeys, FIDO2 hardware keys and platform sign-in (Windows Hello) are bound to the real site and refuse to work on a fake one. Covers when to prioritise each and the NIS2/CyberFundamentals angle: phishing-resistant MFA on privileged accounts is what turns a stolen password into a dead end. EN/NL/FR.

Read article

16 July 2026

New

Shadow AI governance for SMEs, with a free policy template

New guide on governing the AI tools your staff already use: how to discover shadow AI (survey plus network signals), decide per tool (approve, replace or block), and keep the list alive with a quarterly review and one named owner. Includes a free, editable acceptable-AI-use policy template you can download in English, Dutch or French and adapt in an afternoon. EN/NL/FR.

Read article
Updated

Patch management: record July 2026 Patch Tuesday added to the timeline

The advisory-volume timeline now includes 14 July 2026, the largest Microsoft Patch Tuesday on record: 570 fixes (569 by CVE count), 56 critical, two actively exploited zero-days (ADFS CVE-2026-56155, KEV deadline 28 July; SharePoint CVE-2026-56164, KEV deadline 17 July) and the publicly disclosed BitLocker bypass CVE-2026-50661. It replaces June's 206 as the flagship volume stat. EN/NL/FR.

Read article
Updated

Social engineering: the Belgian financial-software vishing wave

Added the July 2026 vishing variant the Limburg public prosecutor warned about: callers pose as support staff of the company's own financial-software platform and pressure finance staff into transfers or into installing remote-access tools. New real-world example plus the rule that matters: real support never calls you, never install remote tools for a caller, verify out-of-band on a number you already have. EN/NL/FR.

Read article

12 July 2026

New

CyFun Basic, by the numbers: how much documentation and evidence it really needs

New data article measuring one real, anonymised CyFun Basic implementation: about 38 documents (~7,000 words, revised close to 950 times) and 123 pieces of evidence across 11 types, tied to the 34 controls by 294 links, with about half the evidence collected automatically. The point: producing it is only half the job; knowing what is done, what is missing and what has gone stale is the other half, which is what the platform tracks. EN/NL/FR.

Read article

9 July 2026

Updated

Incident response: Fraudstop 078 170 170 added to who-to-contact

Added Belgium's central online-fraud emergency number, announced by the CCB on 23 June 2026 and folded into Card Stop: 078 170 170, available 24/7. Call it for an unauthorised transaction, a leaked card number or security code, or an itsme approval you were talked into; the first minutes decide whether the bank can still block or recall the funds. Added as a contact entry plus callout, EN/NL/FR.

Read article
Updated

Phishing: fraud in progress goes to Fraudstop 078 170 170

Added a pointer next to the Safeonweb reporting section: suspicious messages go to verdacht@safeonweb.be, but fraud in progress is a call to Fraudstop on 078 170 170 (24/7, folded into Card Stop), because the first minutes decide whether the bank can block or recall the money. EN/NL/FR.

Read article
Updated

Patch management: July 2026 CVE refresh (ColdFusion, SharePoint, LiteLLM)

Refreshed the zero-day examples: Adobe patched 11 ColdFusion flaws on 30 June 2026, six rated CVSS 10.0, led by unauthenticated file-upload RCE CVE-2026-48276; sibling CVE-2026-48282 was exploited within 2 hours and hit CISA KEV on 7 July 2026 with a 3-day deadline. Also added actively exploited SharePoint CVE-2026-45659 (CISA KEV 1 July 2026) and LiteLLM CVE-2026-42208, a pre-auth SQL injection (CVSS 9.3) in a popular AI proxy, exploited within 36 hours with a CCB patch-immediately advisory. Retired the 2025 Oracle WebLogic and March 2026 SQL Server entries. EN/NL/FR.

Read article
Updated

Acceptable AI use: KnowBe4 numbers on how widespread shadow AI is

Added the KnowBe4 survey of Dutch organisations (report "From Agentic Risk to Human Wins", June 2026): 50% have no clear AI-use rules, 58% already run autonomous AI agents, 27% of employees use unapproved AI tools when official ones are missing, and 81% know pasted data may be stored or misused. No Belgian split was published. EN/NL/FR.

Read article
Updated

AI threats: shadow AI infrastructure as attack surface (LiteLLM)

Added a callout on AI tooling itself as a target: LiteLLM CVE-2026-42208, a pre-authentication SQL injection (CVSS 9.3) in a popular proxy that routes company traffic to AI models, exploited within 36 hours and subject of a CCB patch-immediately advisory. Takeaway: every AI tool belongs in the software inventory and patch schedule. EN/NL/FR.

Read article

2 July 2026

Updated

Remote work: public WiFi hygiene added as tip 9

New section grounded in the CCB webinar "Is your Wi-Fi an open door?" (June 2026): avoid open hotspots, confirm the exact network name with staff, watch for "evil twin" hotspots (the fake airport networks in Australia, April 2024, led to a 7+ year sentence in November 2025), remove the network afterwards, and prefer your phone's 4G/5G hotspot. Hook: researchers near 400 employees captured 166 passwords in 40 minutes, unnoticed. Added in EN/NL/FR.

Read article

20 June 2026

Updated

CyFun now cited in the EU cross-framework NIS2 mapping

Four articles now reference the reference document the EU NIS Cooperation Group published on 17 June 2026, tied to Implementing Regulation 2024/2690, which maps NIS2 security measures across frameworks and places Belgium's CyberFundamentals alongside ISO/IEC 27001, IEC 62443 and NIST CSF 2.0. Added to What is CyberFundamentals, CyberFundamentals vs ISO 27001, What is NIS2, and the NIS2 Directive explainer, EN/NL/FR.

Read article

12 June 2026

New

Acceptable AI use at work: a practical policy for SMEs

New guide on shadow AI: what happens when staff use unsanctioned AI chatbots with company or client data, and how to get ahead of it in five steps ending in a one-page acceptable-use policy. Covers data classification, an approved-tool list, the EU labelling duties that apply from 2 August 2026, and the MSP angle: offer the policy as a deliverable that maps to classification and policy controls you already manage.

Read article
New

AI-generated content: the EU labelling rules explained

New plain-language guide to Article 50 of the EU AI Act: who counts as provider versus deployer, what must be labelled from 2 August 2026, and what the European Commission's Code of Practice of 10 June 2026 adds as the voluntary low-risk path. The Munich Regional Court ruling of 28 May 2026 (AI Overviews are Google's own content) frames the liability backdrop: AI's words are your words.

Read article
Updated

Phishing: ClickFix, the attack that asks you to paste a command

Added a section on ClickFix lures: fake human-verification and fake-update pages that talk you into pasting a malicious command into your own machine, with the March 2026 breach of the Dutch municipality of Epe (871 GB exfiltrated, investigation published 5 June 2026) as the case study. The rule: no legitimate check ever asks you to paste a command.

Read article
Updated

Two-factor authentication: when MFA itself is attacked

Added a section on attacks against multi-factor authentication: Tycoon 2FA proxy phishing (dismantled by Europol and Microsoft in March 2026), helpdesk-reset social engineering (April 2026 UK retail attacks), and the Epe lesson that break-glass emergency accounts need MFA too. Defenses: phishing-resistant MFA, strict callback verification, no MFA-exempt accounts.

Read article
Updated

Patch management: what a real month looks like

Added a concrete example block: the Centre for Cybersecurity Belgium issued a critical advisory every weekday from 4 to 7 May 2026, and the week of 9 June 2026 brought a 206-fix Patch Tuesday, a critical Veeam backup-server flaw and an actively exploited Check Point VPN flaw. The takeaway: this volume is normal, so patching needs a standing weekly rhythm plus a 48-hour fast lane for actively exploited flaws.

Read article
Updated

Backup: patch your backup software first

Added a section on the backup server as the highest-value patch target, using Veeam CVE-2026-44963 (disclosed 9 June 2026, CCB warning 10 June 2026, rated 9.4 out of 10): any signed-in domain user could run code on a domain-joined backup server. Ransomware crews destroy backups first; patch within 48 hours, consider workgroup mode, keep one copy offline or immutable.

Read article
Updated

AI threats: AI output is now a legal matter

Added a section on the Munich Regional Court decision of 28 May 2026 (case 26 O 869/26): AI Overviews are Google's own content and the search-engine liability shield does not apply, plus the EU AI Act labelling obligations that apply from 2 August 2026. The flip side for businesses: AI's words are your words. Also added links to the new acceptable-AI-use and AI-content-labelling guides.

Read article
Updated

Why AI alone can't reach compliance: the shadow-AI gap

Added a section on shadow AI as a compliance gap nobody scoped: unsanctioned chatbot use with company or client data, why an inventory of the AI tools actually in use is the first step and itself evidence, and the Article 50 labelling duties from 2 August 2026 that you cannot meet for AI output you do not know exists.

Read article

4 June 2026

New

NIS2 Compliance Software Pricing: what you actually pay

New comparison guide that breaks down the four pricing models for NIS2 compliance software (per-organisation, per-client MSP, enterprise GRC, consultancy plus tooling), explains what drives the cost, and publishes Easy Cyber Protection's full MSP tiers and per-client brackets in the open. Most platforms hide pricing behind "contact sales"; this page shows the numbers and walks through total cost of ownership, including internal time and the separate CAB audit fee.

Read article
Updated

Patch Management: added June 2026 Palo Alto and FreePBX zero-days

Added two current examples to the Recent Zero-Day Examples section: Palo Alto PAN-OS GlobalProtect CVE-2026-0257 (CVSS 7.8 authentication bypass, actively exploited, CCB advisory and CISA deadline 1 June 2026) and FreePBX CVE-2026-46376 (CVSS 9.1 hard-coded credentials, CCB advisory 1 June 2026, fixed in 16.0.45 / 17.0.7).

Read article

28 May 2026

Updated

Antivirus Comparison: when the security tool is the target

Added an EDR-section callout for the May 2026 wave where the security software itself was attacked: Trend Micro Apex One (CVE-2026-34926, on CISA's Known Exploited Vulnerabilities catalogue from 21 May 2026) was abused to turn the management server into a malware-delivery channel, and Microsoft fixed two Defender flaws granting full system rights (CVE-2026-41091) or silently blocking antivirus definition updates (CVE-2026-45498). The lesson: patch the security tool itself, protect its management console with multi-factor authentication, and confirm updates reach every device.

Read article
Updated

Supplier Security: Belgian waste-authority supply-chain case

Added a 2026 Belgian case to the supply-chain breach examples: in May 2026 the Beerse and Merksplas recycling parks (run by the Kempen inter-municipal waste authority IOK) were knocked offline by an attack on an external IT supplier, while IOK's own systems stayed intact. A concrete local illustration of why NIS2 treats supply-chain risk management as an explicit obligation.

Read article

27 May 2026

Updated

Done-For-You NIS2 Scope link added to 17 articles

Contextual inbound links to the new Done-For-You NIS2 Scope & Baseline Report (€395 flat, 48-hour turnaround, ex VAT) added in-content to 12 new NIS2 / CyberFundamentals / getting-started / industry / compare articles, on top of the 5 NIS2 cluster pages already wired. Anchors vary by page (NIS2 Scope & Baseline Report, Done-For-You scope assessment, €395 scope report, scope-determination service, written scope read) to avoid anchor-text over-optimisation. Each link sits where the reader is most likely to ask "do I need this for my own company?": for example after the CyFun tiers table, after a Phase 1 scope checklist, or after a sector classification breakdown.

Read article

22 May 2026

New

Why AI alone can't reach full NIS2 / CyFun compliance

New guide for MSPs and SME owners evaluating "AI compliance" vendors. Names what AI can do (control mapping, evidence templates, regulatory tracking, audit-pack structuring) and what it cannot (decide scope, physically verify reality, judgment calls, take responsibility). Includes a red-flag checklist for spotting vendors selling a demo, and the right division of labour between AI, the MSP and the CAB auditor.

Read article

14 May 2026

New

ECP vs ReCyF (France): CyFun vs the French NIS2 Framework

New head-to-head comparison with ANSSI's Référentiel Cyber France (ReCyF v2.5, March 2026). Covers legal status (binding once Loi Résilience is enacted, expected H2 2026), structure (15 objectives EI / 20 EE), entity coverage (10k-15k French entities), and compliance cost (€100-200K direct vs €100-400/month via ECP MSP service). Fact-check table cites 6 ANSSI / cyber.gouv.fr / SPAC Alliance / CCB sources.

Read article

7 May 2026

Updated

What is Ransomware?

Added a 5th exfiltration-attack case: SafePay + ETTP (May 6, 2026). SafePay explicitly disavows the ransomware-as-a-service model, runs every operation in-house, and openly targets SMBs, MSPs and organisations with downstream partner networks across the US and Western Europe (400+ claimed victims since September 2024). ETTP is the fourth named Belgian victim in five weeks: Fountain (DragonForce, w15), Anderlues (TheGentlemen, w17), Van Heyghen + ISoSL (APT73, w18), now ETTP, making "one named Belgian victim per week" a documented 2026 pattern.

Read article
Updated

Patch Management: Protect Against Zero-Days

Added a 6th zero-day case: the CCB patch wave of May 4-7, 2026. Belgium's Centre for Cybersecurity issued a critical "patch immediately" advisory every weekday for four consecutive days: MOVEit Automation CVE-2026-4670 (auth bypass, CVSS 9.8, same product family as Clop 2023), n8n critical, Apache HTTP Server multi-RCE, and Ivanti EPMM authenticated RCE actively exploited. Concrete textbook example for the 48-hour-response rule the article already advocates.

Read article
Updated

What is the CCB?

Added a 2025 entry to the CCB history timeline: 635 incident notifications recorded, up 70% year on year. 556 cyber-related, 144 account-compromise cases (top category), 105 ransomware. Public administration and healthcare are the most-targeted sectors. Sourced from the CCB's own 2025 figures release.

Read article
Updated

Incident Response: Recovery Playbook

Extended the Temse vs Anderlues "fast-detection-wins" case with a Belgian baseline bookend: the CCB recorded 635 incident notifications in 2025 (+70% YoY), 144 account-compromise cases as the top category and 105 ransomware. Frames detection capability as the only variable that bends the recovery curve as the threat baseline shifts.

Read article

Looking for something older?

Read the archive of earlier updates