On 22 September 2026, KPMG and the Belgian Cyber Security Coalition published the second edition of their study Cybersecurity in Belgium, supported by the Centre for Cybersecurity Belgium (CCB) and Agoria. This year's title says it all: Every link matters.
The study surveys Belgian organisations, a large share of which already fall under NIS2. Even so, it contains figures that apply just as much to smaller companies, because the pressure travels down the chain. Below are the five findings that matter to you, and what you can do about them this month.
1. A data breach remains the number one risk
Asked to name the five risks that matter most, Belgian organisations put data breach and data theft first, at 56 per cent. That is the second year running. Next come CEO and invoice fraud (49 per cent) and supply chain attacks (48 per cent).
Attack volumes keep rising: 53 per cent report an increase, the second year above fifty per cent, and barely 2 per cent report a decline. Roughly one in six organisations (18 per cent) suffered a successful attack causing damage or disruption in the past year. A further 10 per cent do not know whether it happened.
2. The most expensive bill is the privacy bill
This is the figure we found most striking. Organisations that were actually hit were asked where the costs sat. The answer:
- 50 per cent: costs of informing customers and meeting data protection obligations
- 40 per cent: investigation and remediation
- 30 per cent: reputational damage
- 20 per cent: failure, theft or damage of systems
The largest cost item is therefore not the technical repair, but handling the breach correctly. The study puts it this way: "In a GDPR-driven environment, the response to a breach can be as costly as the breach itself."
Whoever has their record of processing activities, their notification procedure and their communications ready in advance pays that bill far more cheaply.
3. Every link matters, and you are someone else's link
The single biggest shift in the whole study is in the supply chain. Attacks via suppliers ranked eleventh in last year's risk list. This year they rank third.
The numbers behind it:
- 57 per cent of surveyed organisations saw or suspected that a supplier in their ecosystem had been hit, against 50 per cent a year earlier.
- For more than one in four of them, that led to an interruption of their own service.
- 84 per cent are concerned that an attack on a service provider will affect them.
- 51 per cent therefore request certificates or attestations from suppliers.
That last figure is the most important one for small and medium-sized businesses. You may never be attacked directly, but you are the supplier of someone who is in scope. That customer will ask how you have arranged things. Today with a questionnaire, tomorrow with an attestation.
4. The 72-hour clock is rarely tested
Reporting a data breach is no longer good practice, it is a legal duty: within 72 hours to the Data Protection Authority under the GDPR, and for organisations in NIS2 scope an early warning within 24 hours.
How well is that arranged? Of the organisations in NIS2 scope:
- 28 per cent have a notification process that is fully documented and tested
- 44 per cent have a process that exists but has never been tested
- 22 per cent have no more than a draft
- 6 per cent have nothing at all
Seven in ten have therefore never rehearsed a procedure that has to work under time pressure, on a day nobody chooses. And the clock starts when you become aware of the breach, not when you are ready.
There is good news too: the share of organisations reporting an incident to nobody halved, from 31 to 15 per cent. CERT.be and the CCB are now the first port of call for 62 per cent, double last year. The Data Protection Authority stands at 23 per cent, eight points higher than a year ago.
5. The bottleneck is capacity, not technology
What is holding organisations back? Not the technology.
- 61 per cent name a lack of internal people and time as the biggest obstacle
- 42 per cent struggle with supplier dependencies
- 39 per cent with budget
- 22 per cent have no separate cybersecurity budget, and another 26 per cent cannot say whether one exists
- 36 per cent run cybersecurity with one or two people, 29 per cent have nobody
One complaint recurs throughout the open answers: the documentation burden, combined with a shortage of usable templates. Organisations spend disproportionate effort producing paper instead of actually making their operations safer.
The study is sharp about this: the work is not in writing documents, but in translating policy into daily practice, with evidence that you are doing it.
And people remain the first door
Two causes share first place among successful attacks, each at 46 per cent: incorrect behaviour by employees through insufficient awareness, and failure to close known vulnerabilities in time. At the same time, those same employees have become the leading detection channel: in 46 per cent of incidents an employee was the first to notice something was wrong, against 27 per cent a year earlier.
A short, understandable training session for your whole team is therefore not a formality. It is your best-performing detection system.
What to do with this, this month
You do not need a security department to apply the main conclusions. Five concrete steps:
- Write down which data you hold and why. A record of processing activities is the foundation everything else rests on, and during an incident it is the first thing you need.
- Write out your notification procedure and rehearse it once. Who calls whom, who decides, what information you need, and how you notify within 72 hours. A one-hour tabletop exercise already puts you in the better 28 per cent.
- List the suppliers who can reach your data or systems. Accountant, IT partner, web shop builder, newsletter tool. Set out what you expect from them and ask for it.
- Give your team thirty minutes on phishing, invoice fraud and what to do when in doubt. Your biggest risk and your best detector are the same person.
- Make sure you can demonstrate what you do. Not because an inspector is coming, but because your customer will soon ask.
How Konforma helps
Konforma is built for precisely the problem this study exposes: the rules are clear, but the capacity to carry them out is missing. You do not get a folder of templates, you get a guided path:
- A record of processing activities tailored to your type of organisation, which writes itself from what you fill in. No article numbers, plain language.
- A breach wizard with 24-hour and 72-hour clocks, so that during an incident you are not working out what has to happen when.
- A supplier register with model clauses, where your suppliers answer through an ordinary link. Exactly the evidence your customers will soon request.
- The CyFun hub, which follows the CCB's official framework and explains every measure in plain words, with export in the official CCB format. CyFun has become the Belgian default route: 61 per cent of organisations in NIS2 scope choose it, against 36 per cent for ISO 27001.
- Short training for your whole team, closed with a quiz, so awareness becomes demonstrable.
- A request wizard with deadline tracking for access requests and other data subject rights.
Not sure where you stand? Take the free GDPR check or the NIS2 check. In a few minutes you will know what applies to your organisation and what still needs doing.
Source: KPMG and Cyber Security Coalition, "Cybersecurity in Belgium 2026 — Every link matters", September 2026, supported by the CCB and Agoria. The study surveys Belgian organisations; the figures above come directly from the report. The translation into what it means for smaller businesses is our interpretation.
This blog post is informative and not legal advice. For your specific situation, consult a DPO or lawyer.