IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →

#CyberLearn Updates

Stay up to date with new guides and improvements

10 September 2026

New

Does the Cyber Resilience Act apply to what I sell?

New plain-language guide, because the Cyber Resilience Act mechanics were only on the manufacturing page and a software vendor, a webshop badging own-brand goods or an MSP shipping branded hardware would never open that page. Two questions decide it: does what you sell contain software or connect to a device or a network (Article 2(1)), and do you sell it under your own name or logo (Article 3(13)). The own-branding case is the one people miss, and it is Article 3(13) when you had the product made for you or Article 21 when you resell it as importer or distributor, never Article 22, which is about substantial modification and is the mix-up doing the rounds. The guide carries the clocks from 11 September 2026 (24 hours early warning, 72 hours notification, 14 days final report, one month for a severe incident), notes that Article 69(3) applies the reporting duty to products already on the market, and states the penalty carve-out precisely, corrigendum included: Article 64(10)(a) removes the fine for a micro or small enterprise that misses the 24-hour deadline but not the duty to report, and it only reaches the Article 64(2) fine because a corrigendum of 2 July 2025 changed "paragraphs 3 to 9" to "paragraphs 2 to 9". Several free copies of the regulation still show the uncorrected wording. The four Cyber Resilience Act bullets moved off the manufacturing page, which keeps one line and a link. Every article read in Regulation (EU) 2024/2847 on 10 September 2026. EN/NL/FR.

Read article
Updated

Manufacturing: the size threshold decides NIS2 only, and the CRA duty starts 11 September 2026

The page answered "does this apply to me?" with the NIS2 size test alone, so a manufacturer under the threshold could read it, conclude they were out of scope, and stop there. It now says the threshold decides NIS2 only. If you sell a product with digital elements under your own name, the Cyber Resilience Act reaches you because of what you sell rather than because of a staff or turnover threshold, and its reporting duty starts on 11 September 2026. The mechanics that first landed in the "NIS2 Classification for Manufacturing" section, the reporting clocks, where you file, the products already in customers' hands and the fine carve-out for the smallest firms, now live in their own guide, "Does the Cyber Resilience Act apply to what I sell?", because a software vendor or a webshop selling own-brand goods was never going to open a page filed under manufacturing. This page keeps one line and a link. Article numbers read in Regulation (EU) 2024/2847 on 10 September 2026. EN/NL/FR.

Read article
Updated

Belgium: what to do now the 18 April 2026 deadline has passed

The page now opens with what happens if you missed the self-assessment deadline of 18 April 2026. The next date is unchanged: 18 April 2027, for an Essential-equivalent conformity assessment. No CAB is authorised for CyFun Essential certification yet, so the CCB Inspection Service asks essential entities that cannot get there in time to file a remediation plan: proof of compliance at CyFun Important level plus the measures planned to reach Essential-equivalent by 18 April 2028 (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). The page links straight to the four remediation paths. EN/NL/FR.

Read article
Updated

IT partners: your RMM is Tier-0, and the vendor page is not the whole disclosure

The RMM answer now works through a live case. CISA added N-able N-central CVE-2026-86218 to its Known Exploited Vulnerabilities catalogue on 8 September 2026. It scores 10 out of 10 on CVSS 4.0 and needs no login, and N-able fixed it on 5 September 2026 in Hotfix 4, build 2026.3.1.14. The lesson is where the vendor said what: the public advisory reported no confirmed exploitation, while the urgent notice sent to customers called the same flaw a zero-day observed being exploited in the wild. So read the mail as well as the status page, and hunt for unfamiliar sessions from before the fix shipped. EN/NL/FR.

Read article
Updated

Patch management: is the flawed part even switched on?

Two steps of the response routine carry new guidance. Assessing exposure now means asking whether the affected component is actually enabled: Zimbra CVE-2026-73570 only allows remote code execution when the optional SNMP package is installed and SNMP notifications are on, and the Citrix NetScaler flaw only bites when the appliance is set up as a SAML identity provider. That answer can move a case from emergency to routine, or the other way round. Monitoring now means searching your logs back past the fix date rather than forward from it, because N-able N-central CVE-2026-86218 was exploited as a zero-day before Hotfix 4 shipped on 5 September 2026. EN/NL/FR.

Read article
Updated

Retail: your shop platform is patchable software too

The line about keeping software updated now names a live case: CVE-2026-75650 in Adobe Commerce and Magento let attackers run code through the template engine, and it was already being exploited when CISA added it to its Known Exploited Vulnerabilities catalogue on 8 September 2026. If your shop runs on Adobe Commerce or Magento, the version of your shop platform is the thing to check. EN/NL/FR.

Read article
Updated

CyFun audit prep: evidence has a date, and a quiet integration is a gap

The evidence-collection week now warns about evidence that has gone stale. A screenshot taken four months ago is plainly old. An integration that quietly stopped feeding four months ago still looks current, and it is not. Neither one tells you what the control looks like today. Check the date on every item before you file it, and treat a feed that has gone quiet as a gap rather than a pass. EN/NL/FR.

Read article

9 September 2026

Updated

The MSP guide now reads in Dutch and French

The free practical guide for MSP owners, on offering NIS2 and CyFun compliance as a recurring service, now reads in Belgian Dutch and in French. The page copy, the cover text and the "Look inside the guide" section are all translated. The guide file itself is still one English PDF, so the Dutch and French pages say so before you hand over an email address. The English page carries no such line, and the line disappears on its own once a translated PDF ships. EN/NL/FR.

Read article

3 September 2026

Updated

CyFun auditors: a fifth verification body, and still none for Essential

The CCB refreshed its authorised-CAB list on 25 August 2026. Five bodies are now authorised for CyFun verification at Basic and Important level, up from four: Brand Compliance Belgie, CertUp, DNV Business Assurance, Vinçotte and What a Work SRL (Trust CHECK). One caveat on the newcomer: DNV is authorised against CyFun 2023 only, not CyFun 2025, so an assessment against the current framework version still means choosing between the same four names as last month. The number that matters most has not moved: zero bodies are authorised to certify CyFun at Essential level, and all five CyFun rows are scoped Basic to Important. One diary note: Brand Compliance Belgie's CyFun authorisation expires on 8 November 2026, so check it is renewed before booking anything past that date. Every page carrying the old figure has been updated, and the 22 July stamp is gone. EN/NL/FR.

Read article

24 August 2026

New

ECP vs BIO2, and what the Cyberbeveiligingswet actually says

New comparison page for BIO2 (Baseline Informatiebeveiliging Overheid), the Dutch government information-security baseline, now anchored in the Cyberbeveiligingswet. It is honest that the two are not head-to-head: BIO2 is public sector only, ECP is private-sector MSP delivery, and the overlap is cross-border MSPs and suppliers to Dutch government. The page also states the Cbw precisely, because most coverage does not. Reporting compressed it to "directors are now personally liable", but the statute never uses the word aansprakelijk. Article 80 fines the entity up to EUR 10,000,000 or 2% of worldwide turnover and article 87 up to EUR 7,000,000 or 1.4%, while a board member personally risks at most EUR 25,000 under article 93 for failing the article 24 competence duty. The obligation with a date on it is article 24 lid 5: every board member holds a training certificate, kept current, by 15 August 2028. Every article number read from the consolidated text as at 15 August 2026. EN/NL/FR.

Read article

20 August 2026

New

A fourth route if you will not reach CyFun Essential by April 2027

The CCB Inspection Service has named what an essential entity does when it cannot hold an Essential-equivalent conformity assessment by 18 April 2027: submit a remediation plan, proof of compliance at CyFun Important-equivalent level plus the measures planned to reach Essential-equivalent by 18 April 2028. The 18 April 2027 legal deadline is unchanged, and no plan is needed if you are already Essential-equivalent by then, or if your own risk analysis under Art. 7 of the NIS2 Royal Decree justifies a lower assurance level and you demonstrate by that date that you meet it. Source: CCB Inspection Service communication ref. NCCA/JK/INS/2026-002 of 11 August 2026, published 18 August 2026. Written into the missed-deadline page as a fourth remediation path, and reflected across the deadline, audit, certification and CAB-cost pages. Worth knowing why it exists: no conformity assessment body is authorised for CyFun Essential certification today, so that level currently runs through ISO/IEC 27001 or a CCB inspection. EN/NL/FR.

Read article

17 August 2026

New

ECP vs BSI IT-Grundschutz: CyFun next to the German standard

New comparison page for Germany's BSI IT-Grundschutz. IT-Grundschutz is the standard to follow if your clients are German entities subject to NIS2: the BSI references it in section 44 BSIG, ISO 27001 certification on its basis is well established, and the Grundschutz++ reform rolling out from 2026 cuts requirements from roughly 6,567 to roughly 985 in a machine-readable OSCAL format. CyFun and ECP are the right path for Belgian clients, since CyFun is the CCB's official NIS2 route. The two share NIS2 Article 21 DNA but are not interchangeable across borders. EN/NL/FR.

Read article

13 August 2026

Updated

Remote work: the company gateway you log in through is a device too

The page told you to use the company VPN but said nothing about the box at the company that accepts that login. Added a tenth tip on the remote-access gateway: it is one of the few devices deliberately left open to the internet, nobody at home can patch it, and somebody has to ask who does. Anchored on SonicWall SMA1000 (flaws CVE-2026-15409 and CVE-2026-15410, exploited from 22 June 2026, fixed mid-July 2026, both flaws flagged by CISA as used in ransomware attacks, and more than 380 of these devices tracked as exposed on the internet, though some may already have been secured, per BleepingComputer, 10 August 2026). Includes the three questions to put to your IT partner and a new checklist line. EN/NL/FR.

Read article
Updated

Passwords: hashed is not the same as safe

New section explaining, without jargon, why a breach notice saying your password was "hashed" is not an all-clear. Hashing works in one direction only and protects nothing more than a password that was already hard to guess; hackers take the scrambled list offline and grind through common and previously leaked passwords with nobody watching and no lock-out. Anchored on the Drukland notice of 10 August 2026, which covered email addresses and hashed passwords (ITdaily, 10 August 2026) plus card details for a small group (Security.NL, 11 August 2026). Ends where it should: change it, change it everywhere you reused it, turn on two-factor authentication. EN/NL/FR.

Read article
Updated

CyFun Basic effort study: dated note added, measured figures untouched

The study measures one implementation that ran 30 March to 17 June 2026, and two things in it now understate the product: the "writing policies and procedures" row of 64 manual actions, and the takeaway that most of the real effort happens off the platform. Since August 2026 the CyFun Basic procedure and policy documents come out of the platform already written in English, Dutch and French. Both places now carry a dated note saying the measurement predates that change. The measured numbers are deliberately not edited: it is a dated record of what happened. EN/NL/FR.

Read article

11 August 2026

Updated

CyFun auditors: corrected to four verification bodies, none yet for Essential

Our pages said there were only two BELAC-accredited CyFun audit bodies. The CCB list dated 22 July 2026 shows four authorised for verification at Basic and Important level: Brand Compliance Belgie, CertUp, Vinçotte and What a Work SRL (Trust CHECK). Two things the old wording missed: those four do verification, and no body is yet accredited to certify at Essential level, so Essential entities currently reach presumption of conformity through ISO 27001, where 15 authorised certification bodies are available. We have also dropped the "prepare now and you get audited first" framing, which rested on the two-auditor number. EN/NL/FR.

Read article
Updated

Scope broadened: CyFun is now the national scheme in five countries

CyberFundamentals is no longer Belgium-only. Belgium, Ireland, Romania, Malta and Cyprus are members of the CyFun Scheme Owner Group. Ireland's NCSC states it "will be adopting CyFun as its national assessment and certification scheme", with certification expected in 2027 and CyFun named a preferred method for the public administration sector. France recognises CyFun and is exploring adoption, but uses its own ReCyF framework. Our comparison and NIS2 guides now speak to SMEs and MSPs across the CyFun countries rather than to Belgium alone, while the CyberFundamentals section stays Belgium-specific where the subject is the CCB and its framework. EN/NL/FR.

Read article

23 July 2026

Updated

2FA setup: passkeys and phishing-resistant MFA section

Added a section on going beyond app codes. App-based codes can still be phished or talked out of someone in real time; passkeys, FIDO2 hardware keys and platform sign-in (Windows Hello) are bound to the real site and refuse to work on a fake one. Covers when to prioritise each and the NIS2/CyberFundamentals angle: phishing-resistant MFA on privileged accounts is what turns a stolen password into a dead end. EN/NL/FR.

Read article

16 July 2026

New

Shadow AI governance for SMEs, with a free policy template

New guide on governing the AI tools your staff already use: how to discover shadow AI (survey plus network signals), decide per tool (approve, replace or block), and keep the list alive with a quarterly review and one named owner. Includes a free, editable acceptable-AI-use policy template you can download in English, Dutch or French and adapt in an afternoon. EN/NL/FR.

Read article
Updated

Patch management: record July 2026 Patch Tuesday added to the timeline

The advisory-volume timeline now includes 14 July 2026, the largest Microsoft Patch Tuesday on record: 570 fixes (569 by CVE count), 56 critical, two actively exploited zero-days (ADFS CVE-2026-56155, KEV deadline 28 July; SharePoint CVE-2026-56164, KEV deadline 17 July) and the publicly disclosed BitLocker bypass CVE-2026-50661. It replaces June's 206 as the flagship volume stat. EN/NL/FR.

Read article
Updated

Social engineering: the Belgian financial-software vishing wave

Added the July 2026 vishing variant the Limburg public prosecutor warned about: callers pose as support staff of the company's own financial-software platform and pressure finance staff into transfers or into installing remote-access tools. New real-world example plus the rule that matters: real support never calls you, never install remote tools for a caller, verify out-of-band on a number you already have. EN/NL/FR.

Read article

12 July 2026

New

CyFun Basic, by the numbers: how much documentation and evidence it really needs

New data article measuring one real, anonymised CyFun Basic implementation: about 38 documents (~7,000 words, revised close to 950 times) and 123 pieces of evidence across 11 types, tied to the 34 controls by 294 links, with about half the evidence collected automatically. The point: producing it is only half the job; knowing what is done, what is missing and what has gone stale is the other half, which is what the platform tracks. EN/NL/FR.

Read article

9 July 2026

Updated

Incident response: Fraudstop 078 170 170 added to who-to-contact

Added Belgium's central online-fraud emergency number, announced by the CCB on 23 June 2026 and folded into Card Stop: 078 170 170, available 24/7. Call it for an unauthorised transaction, a leaked card number or security code, or an itsme approval you were talked into; the first minutes decide whether the bank can still block or recall the funds. Added as a contact entry plus callout, EN/NL/FR.

Read article
Updated

Phishing: fraud in progress goes to Fraudstop 078 170 170

Added a pointer next to the Safeonweb reporting section: suspicious messages go to verdacht@safeonweb.be, but fraud in progress is a call to Fraudstop on 078 170 170 (24/7, folded into Card Stop), because the first minutes decide whether the bank can block or recall the money. EN/NL/FR.

Read article
Updated

Patch management: July 2026 CVE refresh (ColdFusion, SharePoint, LiteLLM)

Refreshed the zero-day examples: Adobe patched 11 ColdFusion flaws on 30 June 2026, six rated CVSS 10.0, led by unauthenticated file-upload RCE CVE-2026-48276; sibling CVE-2026-48282 was exploited within 2 hours and hit CISA KEV on 7 July 2026 with a 3-day deadline. Also added actively exploited SharePoint CVE-2026-45659 (CISA KEV 1 July 2026) and LiteLLM CVE-2026-42208, a pre-auth SQL injection (CVSS 9.3) in a popular AI proxy, exploited within 36 hours with a CCB patch-immediately advisory. Retired the 2025 Oracle WebLogic and March 2026 SQL Server entries. EN/NL/FR.

Read article
Updated

Acceptable AI use: KnowBe4 numbers on how widespread shadow AI is

Added the KnowBe4 survey of Dutch organisations (report "From Agentic Risk to Human Wins", June 2026): 50% have no clear AI-use rules, 58% already run autonomous AI agents, 27% of employees use unapproved AI tools when official ones are missing, and 81% know pasted data may be stored or misused. No Belgian split was published. EN/NL/FR.

Read article
Updated

AI threats: shadow AI infrastructure as attack surface (LiteLLM)

Added a callout on AI tooling itself as a target: LiteLLM CVE-2026-42208, a pre-authentication SQL injection (CVSS 9.3) in a popular proxy that routes company traffic to AI models, exploited within 36 hours and subject of a CCB patch-immediately advisory. Takeaway: every AI tool belongs in the software inventory and patch schedule. EN/NL/FR.

Read article

2 July 2026

Updated

Remote work: public WiFi hygiene added as tip 9

New section grounded in the CCB webinar "Is your Wi-Fi an open door?" (June 2026): avoid open hotspots, confirm the exact network name with staff, watch for "evil twin" hotspots (the fake airport networks in Australia, April 2024, led to a 7+ year sentence in November 2025), remove the network afterwards, and prefer your phone's 4G/5G hotspot. Hook: researchers near 400 employees captured 166 passwords in 40 minutes, unnoticed. Added in EN/NL/FR.

Read article

20 June 2026

Updated

CyFun now cited in the EU cross-framework NIS2 mapping

Four articles now reference the reference document the EU NIS Cooperation Group published on 17 June 2026, tied to Implementing Regulation 2024/2690, which maps NIS2 security measures across frameworks and places Belgium's CyberFundamentals alongside ISO/IEC 27001, IEC 62443 and NIST CSF 2.0. Added to What is CyberFundamentals, CyberFundamentals vs ISO 27001, What is NIS2, and the NIS2 Directive explainer, EN/NL/FR.

Read article

12 June 2026

New

Acceptable AI use at work: a practical policy for SMEs

New guide on shadow AI: what happens when staff use unsanctioned AI chatbots with company or client data, and how to get ahead of it in five steps ending in a one-page acceptable-use policy. Covers data classification, an approved-tool list, the EU labelling duties that apply from 2 August 2026, and the MSP angle: offer the policy as a deliverable that maps to classification and policy controls you already manage.

Read article
New

AI-generated content: the EU labelling rules explained

New plain-language guide to Article 50 of the EU AI Act: who counts as provider versus deployer, what must be labelled from 2 August 2026, and what the European Commission's Code of Practice of 10 June 2026 adds as the voluntary low-risk path. The Munich Regional Court ruling of 28 May 2026 (AI Overviews are Google's own content) frames the liability backdrop: AI's words are your words.

Read article
Updated

Phishing: ClickFix, the attack that asks you to paste a command

Added a section on ClickFix lures: fake human-verification and fake-update pages that talk you into pasting a malicious command into your own machine, with the March 2026 breach of the Dutch municipality of Epe (871 GB exfiltrated, investigation published 5 June 2026) as the case study. The rule: no legitimate check ever asks you to paste a command.

Read article
Updated

Two-factor authentication: when MFA itself is attacked

Added a section on attacks against multi-factor authentication: Tycoon 2FA proxy phishing (dismantled by Europol and Microsoft in March 2026), helpdesk-reset social engineering (April 2026 UK retail attacks), and the Epe lesson that break-glass emergency accounts need MFA too. Defenses: phishing-resistant MFA, strict callback verification, no MFA-exempt accounts.

Read article
Updated

Patch management: what a real month looks like

Added a concrete example block: the Centre for Cybersecurity Belgium issued a critical advisory every weekday from 4 to 7 May 2026, and the week of 9 June 2026 brought a 206-fix Patch Tuesday, a critical Veeam backup-server flaw and an actively exploited Check Point VPN flaw. The takeaway: this volume is normal, so patching needs a standing weekly rhythm plus a 48-hour fast lane for actively exploited flaws.

Read article
Updated

Backup: patch your backup software first

Added a section on the backup server as the highest-value patch target, using Veeam CVE-2026-44963 (disclosed 9 June 2026, CCB warning 10 June 2026, rated 9.4 out of 10): any signed-in domain user could run code on a domain-joined backup server. Ransomware crews destroy backups first; patch within 48 hours, consider workgroup mode, keep one copy offline or immutable.

Read article
Updated

AI threats: AI output is now a legal matter

Added a section on the Munich Regional Court decision of 28 May 2026 (case 26 O 869/26): AI Overviews are Google's own content and the search-engine liability shield does not apply, plus the EU AI Act labelling obligations that apply from 2 August 2026. The flip side for businesses: AI's words are your words. Also added links to the new acceptable-AI-use and AI-content-labelling guides.

Read article
Updated

Why AI alone can't reach compliance: the shadow-AI gap

Added a section on shadow AI as a compliance gap nobody scoped: unsanctioned chatbot use with company or client data, why an inventory of the AI tools actually in use is the first step and itself evidence, and the Article 50 labelling duties from 2 August 2026 that you cannot meet for AI output you do not know exists.

Read article

4 June 2026

New

NIS2 Compliance Software Pricing: what you actually pay

New comparison guide that breaks down the four pricing models for NIS2 compliance software (per-organisation, per-client MSP, enterprise GRC, consultancy plus tooling), explains what drives the cost, and publishes Easy Cyber Protection's full MSP tiers and per-client brackets in the open. Most platforms hide pricing behind "contact sales"; this page shows the numbers and walks through total cost of ownership, including internal time and the separate CAB audit fee.

Read article
Updated

Patch Management: added June 2026 Palo Alto and FreePBX zero-days

Added two current examples to the Recent Zero-Day Examples section: Palo Alto PAN-OS GlobalProtect CVE-2026-0257 (CVSS 7.8 authentication bypass, actively exploited, CCB advisory and CISA deadline 1 June 2026) and FreePBX CVE-2026-46376 (CVSS 9.1 hard-coded credentials, CCB advisory 1 June 2026, fixed in 16.0.45 / 17.0.7).

Read article

Looking for something older?

Read the archive of earlier updates