Back to overview
February 10, 2025

NIS2: new legislation forces businesses to tighten up cyber security

What do auxiliary party liability, mobility, solar panels and cyber have in common? They are four factors that affect your company’s risk profile. In the latest episode of our video podcast Succes Verzekerd, a panel of in-house experts discusses how you can successfully include new risks in your company’s risk management approach. Tom Van Britsom explains the legal requirements that companies must meet in the fight against cyber crime.

Every company and every working environment is becoming increasingly digital. This trend has many advantages, including increased efficiency and speed, and has been confirmed by the adoption of working from home at many organisations. The downside of digitisation is that cyber risks are growing. With legislators tightening the requirements in the area of cyber security, businesses are obliged to step up their efforts

Digital risks affect cyber security

The way many businesses work has changed significantly in recent years. Production lines that are now controlled almost entirely by digital means or administrative processes that are taken care of using a digital accounting package are examples of this.

As a result of this wave of digitisation, most businesses have to some extent become IT businesses. This makes them more attractive to criminals, who have not stood idly by, but are eagerly making use on a huge scale of phishing emails that lead to ransomware attacks all over the world.

If a haulage business is hacked, it may not be possible to deliver a product to the supermarket for days as a result.

NIS2: new legislation since 2024

In 2024, the NIS2 Law was introduced in Europe. This stricter and more extensive version of the initial NIS legislation from 2016 aims to beef up businesses’ efforts in the area of cyber security, specifying the approach they must take to their security policy. The scope of businesses and sectors covered by the legislation has been extended: the focus was previously on crucial sectors such as hospitals, banks, energy and the water supply, but NIS2 now also relates to sectors such as food, production and transport.

CCB Infographic1 NIS2 E crop
*source: Centre for Cybersecurity Belgium (CCB)

Penalties for non-compliance

The NIS2 legislation is managed in Belgium by the Centre for Cybersecurity (CCB). Companies in breach of the legislation may face a range of measures, from advice, instructions, bans, inspections and fines all the way through to the removal of directors from their position.

Looking to the future

Both businesses and private individuals will increasingly face digital risks. Alongside current legislation such as GDPR (focusing on data protection and privacy) and NIS and NIS2 (focusing on cyber security), new legislation is being developed all the time to increase resilience to digital risks.

The next piece of legislation to come out is the Cyber Resilience Act, focusing on the products that businesses make. It will seek to ensure that the software in smartphones, for example, is safe.

Our advice

We advise companies to manage cyber risks optimally, with the help of their broker, by focusing on three aspects:

  1. Arranging an insurance solution that provides support in the event of incidents and offers a financial safety net.
  2. Providing training so that employees can spot phishing emails and respond appropriately.
  3. Holding workshops to prepare for a cyber incident on the basis of a realistic case study and to develop an action plan.

Related posts

U7353792727 Photorealistic image man with glasses on a video ca f4b25fc1 d39c 4912 8c94 22f675ab7cd0

Part 2: From awareness to action, boosting your cyber resilience

Cyber & fraud
19.11.2025

How do you convert an understanding of the cyber threat into concrete action? Vanbreda supports companies with interactive workshops and realistic simulations that systematically boost cyber resilience. Davy Heremans, a cyber risk expert who works daily with the service specialising in Phishing as a Service and with cyber workshops at Vanbreda, explains how companies can strengthen their human firewall.

Read more
Read more about Part 2: From awareness to action, boosting your cyber resilience
EBBF04338

Part 1: The human firewall — the key to a cyber secure company

Cyber & fraud
19.11.2025

Cyber security is no longer a trifling concern: it’s a real and constant threat to every company. While the technology is evolving, the human factor often remains the weak link. Davy Heremans, cyber risk expert at Vanbreda, explains why prevention is the only way forward.

Read more
Read more about Part 1: The human firewall - the key to a cyber secure company
U7353792727 Photorealistic image close up of hands typing on a c7db082e c71e 4659 9fb2 79ee0dc0ce29

Our company doesn’t need cyber insurance’: four misconceptions debunked

Cyber & fraud
01.10.2025

Cyber risks are now part and parcel of running a business. Despite this, some companies are clearly still sceptical about cyber insurance. Their doubts are unwarranted, because insurance of this kind is more than just a financial safety net: it also enables you to bring in professional IT support immediately in the event of a cyber incident, giving it double value. In this article, we discuss four arguments often put forward by companies for not taking out cyber insurance, and explain why it makes sense to give it serious consideration.

Read more
Read more about ‘Our company doesn’t need cyber insurance’: four misconceptions debunked
Afbeelding multi masters group3

We appreciate the smooth and prompt interaction.

Testimonial
12.06.2025

Multi Masters Group offers a wide range of facility services to companies and organizations throughout Belgium. Thanks to their total solutions – from cleaning and technical maintenance to security, safety, mobility, and catering – clients can fully focus on their core activities.

Read more
Read more about We appreciate the smooth and prompt interaction.