Main Logo Aspida

Leaders Roundtable Cybersecurity 2026

2026/03/25

Share this on

Cyberattacks are still too often seen as a technical IT problem. In reality, they are a strategic business risk with direct financial impact. For Belgian companies and certainly for SMEs a single incident can lead to weeks of downtime and damage running into hundreds of thousands of euros or more.

According to the Centre for Cybersecurity Belgium (CCB), phishing and account compromise remain the most common attack vectors in Belgium, with a clear year-on-year rise in incidents. Mid-sized organisations in particular are an attractive target today.

Cyberattacks are still too often seen as a technical IT problem. In reality, they are a strategic business risk with direct financial impact. For Belgian companies and certainly for SMEs a single incident can lead to weeks of downtime and damage running into hundreds of thousands of euros or more.

According to the Centre for Cybersecurity Belgium (CCB), phishing and account compromise remain the most common attack vectors in Belgium, with a clear year-on-year rise in incidents. Mid-sized organisations in particular are an attractive target today.

What does a cyberattack cost on average in Belgium?

The cost of a cyber incident never comes down to a single invoice. It is a combination of direct damage, operational downtime, and hidden losses.

Typical impact for Belgian businesses:

  • 💥 Basic incident: €50,000 – €150,000
  • 🧨 Serious ransomware attack: €250,000 – €1,500,000+
  • ⏱️ Average downtime: 2 to 4 weeks
  • 📉 Reputational and customer loss: often long-lasting and difficult to predict

According to CCB figures, phishing and account takeover remain the primary entry points for attackers in Belgian organisations.

But figures only become truly clear when we look at a realistic scenario.

Realistic scenario: a cyberattack at a Belgian company (100–500 employees)

Take a typical Belgian company with:

  • 250 employees
  • B2B services or manufacturing environment
  • Microsoft 365 + ERP + hybrid infrastructure
  • small internal IT department (2–6 people)
  • MFA not enforced everywhere
  • backups present but not systematically tested

This profile is strikingly common among organisations that fall victim to cyber incidents today.

Step 1: the attack begins with phishing (day 0)

An employee receives an email:

"Your Microsoft 365 session expires today. Please log in again."

The link leads to a fake login page.

Consequence:

  • credentials are stolen
  • the attacker gains access to the mailbox
  • internal communications are exploited to build trust

Without multi-factor authentication, an attacker can often remain active undetected for days.

Step 2: silent expansion within the network (days 3–10)

The attacker:

  • maps the network
  • gains access to shared drives
  • infiltrates ERP systems
  • copies customer data and quotes
  • plants ransomware without immediate activation

The goal is clear: maximum impact at the right moment.

Step 3: ransomware is activated (days 10–14)

On a Monday morning, the following suddenly appears:

"Your files have been encrypted. Pay €180,000 in Bitcoin."

Consequences:

  • ERP systems go offline
  • file servers become unusable
  • administration slows down or stops
  • production planning is disrupted
  • internal communication partially fails

From this point on, an IT incident becomes a business crisis.

Contact us

We will be happy to help you with all your questions. Please feel free to contact us.