<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog (NO-INDEX)</title>
    <link>https://staging.toreon.com/en/insights/blogs</link>
    <description>Toreon Blog</description>
    <language>en</language>
    <pubDate>Tue, 25 Aug 2026 13:59:24 GMT</pubDate>
    <dc:date>2026-08-25T13:59:24Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>4 phases of an ISO27001 Information Security Management System implementation. - Toreon - Business driven cyber consulting</title>
      <link>https://staging.toreon.com/en/insights/blogs/4-phases-of-an-iso27001-information-security-management-system-implementation</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/4-phases-of-an-iso27001-information-security-management-system-implementation" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Tealpartners-1.png" alt="4 phases of an ISO27001 Information Security Management System implementation. - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;More and more companies are seeing the value of obtaining an ISO27001 certificate. After all, there are &lt;strong&gt;continuously new cyber threats and attacks&lt;/strong&gt; and more and more legislation and certain sectors require companies to implement specific security standards. A &lt;strong&gt;security certificate&lt;/strong&gt; is therefore becoming a key business enabler.&lt;/p&gt; 
       &lt;p&gt;The digital security coaches of&amp;nbsp;&lt;a href="https://www.toreon.com/"&gt;Toreon&lt;/a&gt;support you in implementing an ISO27001 Information Security Management System (ISMS) in your organization. Such a process consists of &lt;strong&gt;4 phases&lt;/strong&gt;.&lt;/p&gt; 
       &lt;ol&gt; 
        &lt;li&gt;Shaping your ISMS&lt;/li&gt; 
        &lt;li&gt;Implementing ISO27001&lt;/li&gt; 
        &lt;li&gt;Monitoring and controlling your ISMS&lt;/li&gt; 
        &lt;li&gt;Improvement and certification&lt;/li&gt; 
       &lt;/ol&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 1: Shaping your ISMS&lt;/h2&gt; 
       &lt;p&gt;With the help of our consultant, we will draw up the necessary documentation (security policy, processes, instructions) so that the requirements of the standard can be translated into a ‘&lt;strong&gt;security operating model&lt;/strong&gt;‘ tailored to your organization.&lt;/p&gt; 
       &lt;p&gt;This happens in practice in 2 steps.&lt;/p&gt; 
       &lt;ol&gt; 
        &lt;li&gt;The consultant draws up a &lt;strong&gt;first version of the documentation&lt;/strong&gt;, based on the security risk assessment results and the Toreon document database. This database contains many examples of detailed ISMS documents, which the coach can use to create efficient and qualitative documentation for you.&lt;/li&gt; 
        &lt;li&gt;Then the feedback from your stakeholders is processed, after which the coach sets up an &lt;strong&gt;ISMS&lt;/strong&gt;, with documents tailored to your company. The 80/20 rule applies here. 80% of the documentation is sector-specific, as the same measures often recur, and 20% is organization-specific.&lt;/li&gt; 
       &lt;/ol&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 2: Implementing ISO27001&lt;/h2&gt; 
       &lt;p&gt;In phase 2, your consultant coaches you to technically and operationally implement technical controls that were determined in the first phase.&lt;/p&gt; 
       &lt;p&gt;In this phase, you take charge of the &lt;strong&gt;ISO27001 implementation process&lt;/strong&gt;, applying all processes and controls.&amp;nbsp;Toreon’s&amp;nbsp;high-tech security experts are available to support you. The goal is to make your security officer self-reliant so that he can maintain the system himself. In this phase,&amp;nbsp;Toreon&amp;nbsp;also provides ‘&lt;strong&gt;security awareness&lt;/strong&gt;‘ sessions to communicate all new security requirements to all your employees.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 3: Monitoring and controlling your ISMS&lt;/h2&gt; 
       &lt;p&gt;Toreon&amp;nbsp;performs a &lt;strong&gt;first internal audit&lt;/strong&gt; to check if you are ready to obtain the ISO27001 certificate. Such an internal audit is also a hard condition to obtain your certificate. This audit is done by consultants who were not involved in the implementation of your ISMS, to ensure sufficient objectivity and neutrality.&lt;/p&gt; 
       &lt;p&gt;The consultants use the same method as external auditors, in accordance with the requirements of ISO19011. In this way, your organization is optimally prepared for an external certification audit.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Setting up an ISMS&lt;/h3&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 4: Improvement and certification&lt;/h2&gt; 
       &lt;p&gt;The non-conformities that have come to light from the internal audit&amp;nbsp;must be eliminated before your organization can be certified.&amp;nbsp;Toreon&amp;nbsp;coaches you on this and at the same time helps you to administratively plan the certification. Your consultant is also present during the external audit to talk to the auditors.&amp;nbsp;Toreon’s&amp;nbsp;consultants have experience in external audits and know very well what external auditors expect and can translate their expectations to the measures implemented by the organization.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Download our product sheet and learn more about our methodology!&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/4-phases-of-an-iso27001-information-security-management-system-implementation" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Tealpartners-1.png" alt="4 phases of an ISO27001 Information Security Management System implementation. - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;More and more companies are seeing the value of obtaining an ISO27001 certificate. After all, there are &lt;strong&gt;continuously new cyber threats and attacks&lt;/strong&gt; and more and more legislation and certain sectors require companies to implement specific security standards. A &lt;strong&gt;security certificate&lt;/strong&gt; is therefore becoming a key business enabler.&lt;/p&gt; 
       &lt;p&gt;The digital security coaches of&amp;nbsp;&lt;a href="https://www.toreon.com/"&gt;Toreon&lt;/a&gt;support you in implementing an ISO27001 Information Security Management System (ISMS) in your organization. Such a process consists of &lt;strong&gt;4 phases&lt;/strong&gt;.&lt;/p&gt; 
       &lt;ol&gt; 
        &lt;li&gt;Shaping your ISMS&lt;/li&gt; 
        &lt;li&gt;Implementing ISO27001&lt;/li&gt; 
        &lt;li&gt;Monitoring and controlling your ISMS&lt;/li&gt; 
        &lt;li&gt;Improvement and certification&lt;/li&gt; 
       &lt;/ol&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 1: Shaping your ISMS&lt;/h2&gt; 
       &lt;p&gt;With the help of our consultant, we will draw up the necessary documentation (security policy, processes, instructions) so that the requirements of the standard can be translated into a ‘&lt;strong&gt;security operating model&lt;/strong&gt;‘ tailored to your organization.&lt;/p&gt; 
       &lt;p&gt;This happens in practice in 2 steps.&lt;/p&gt; 
       &lt;ol&gt; 
        &lt;li&gt;The consultant draws up a &lt;strong&gt;first version of the documentation&lt;/strong&gt;, based on the security risk assessment results and the Toreon document database. This database contains many examples of detailed ISMS documents, which the coach can use to create efficient and qualitative documentation for you.&lt;/li&gt; 
        &lt;li&gt;Then the feedback from your stakeholders is processed, after which the coach sets up an &lt;strong&gt;ISMS&lt;/strong&gt;, with documents tailored to your company. The 80/20 rule applies here. 80% of the documentation is sector-specific, as the same measures often recur, and 20% is organization-specific.&lt;/li&gt; 
       &lt;/ol&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 2: Implementing ISO27001&lt;/h2&gt; 
       &lt;p&gt;In phase 2, your consultant coaches you to technically and operationally implement technical controls that were determined in the first phase.&lt;/p&gt; 
       &lt;p&gt;In this phase, you take charge of the &lt;strong&gt;ISO27001 implementation process&lt;/strong&gt;, applying all processes and controls.&amp;nbsp;Toreon’s&amp;nbsp;high-tech security experts are available to support you. The goal is to make your security officer self-reliant so that he can maintain the system himself. In this phase,&amp;nbsp;Toreon&amp;nbsp;also provides ‘&lt;strong&gt;security awareness&lt;/strong&gt;‘ sessions to communicate all new security requirements to all your employees.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 3: Monitoring and controlling your ISMS&lt;/h2&gt; 
       &lt;p&gt;Toreon&amp;nbsp;performs a &lt;strong&gt;first internal audit&lt;/strong&gt; to check if you are ready to obtain the ISO27001 certificate. Such an internal audit is also a hard condition to obtain your certificate. This audit is done by consultants who were not involved in the implementation of your ISMS, to ensure sufficient objectivity and neutrality.&lt;/p&gt; 
       &lt;p&gt;The consultants use the same method as external auditors, in accordance with the requirements of ISO19011. In this way, your organization is optimally prepared for an external certification audit.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Setting up an ISMS&lt;/h3&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Phase 4: Improvement and certification&lt;/h2&gt; 
       &lt;p&gt;The non-conformities that have come to light from the internal audit&amp;nbsp;must be eliminated before your organization can be certified.&amp;nbsp;Toreon&amp;nbsp;coaches you on this and at the same time helps you to administratively plan the certification. Your consultant is also present during the external audit to talk to the auditors.&amp;nbsp;Toreon’s&amp;nbsp;consultants have experience in external audits and know very well what external auditors expect and can translate their expectations to the measures implemented by the organization.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Download our product sheet and learn more about our methodology!&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2F4-phases-of-an-iso27001-information-security-management-system-implementation&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Governance risk and compliance</category>
      <category>Industrial Security and IOT</category>
      <category>Governance Risk Compliance</category>
      <category>Toreon All</category>
      <category>Industrial Security Iot</category>
      <pubDate>Tue, 05 May 2026 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/4-phases-of-an-iso27001-information-security-management-system-implementation</guid>
      <dc:date>2026-05-05T22:00:00Z</dc:date>
      <dc:creator>Laurent Dupont</dc:creator>
    </item>
    <item>
      <title>Cyber Security Challenge - Toreon - Business driven cyber consulting</title>
      <link>https://staging.toreon.com/en/insights/blogs/social-responsibility/csc-belgium</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/social-responsibility/csc-belgium" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/cybersecurity-1.png" alt="Cyber Security Challenge - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;The Cyber Security Challenge Belgium has been founded in 2015 and is co-organized by Toreon and Nviso and wants to demonstrate the potential of a career in cyber security and make students more “cyber security aware” in order to help build a more cyber secure economy and society.&lt;/p&gt; 
       &lt;p&gt;In 2020 alone, the Challenge has attracted over 700 students – a number that has increased at each edition – and has become one of the essential cyber events for the industry and the academic world.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="http://https%3A%2F%2Fwww.toreon.com%2Fsocial-responsibility%2F"&gt;More about social responsability&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/social-responsibility/csc-belgium" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/cybersecurity-1.png" alt="Cyber Security Challenge - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;The Cyber Security Challenge Belgium has been founded in 2015 and is co-organized by Toreon and Nviso and wants to demonstrate the potential of a career in cyber security and make students more “cyber security aware” in order to help build a more cyber secure economy and society.&lt;/p&gt; 
       &lt;p&gt;In 2020 alone, the Challenge has attracted over 700 students – a number that has increased at each edition – and has become one of the essential cyber events for the industry and the academic world.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="http://https%3A%2F%2Fwww.toreon.com%2Fsocial-responsibility%2F"&gt;More about social responsability&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fsocial-responsibility%2Fcsc-belgium&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 14 Apr 2026 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/social-responsibility/csc-belgium</guid>
      <dc:date>2026-04-14T22:00:00Z</dc:date>
      <dc:creator>Less than a minute</dc:creator>
    </item>
    <item>
      <title>KMO Portefeuille - Toreon - Business driven cyber consulting</title>
      <link>https://staging.toreon.com/en/insights/blogs/kmo-portefeuille</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/kmo-portefeuille" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Dienstverlener-kmo-portefeuille-400x248-1-1.png" alt="KMO Portefeuille - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Toreon is een trotse partner van VLAIO, en maakt cyberbeveiliging toegankelijker voor kleine en middelgrote ondernemingen met subsidies tot 50% 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Bent u een Vlaamse KMO? Dan komt u in aanmerking voor subsidies van de Vlaamse overheid wanneer u adviesdiensten of opleidingen van Toreon aankoopt. Toreon is een geregistreerde leverancier van adviesdiensten en opleidingen in het kader van de &lt;strong&gt;KMO-Portefeuille.&lt;/strong&gt;&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Wat is de KMO-Portefeuille?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;De KMO-Portefeuille zijn subsidies die worden toegekend door het &lt;strong&gt;Vlaams Agentschap voor Innovatie &amp;amp; Ondernemen&lt;/strong&gt;. Het doel van deze subsidie is om de &lt;strong&gt;groei van Vlaamse KMO’s te ondersteunen&lt;/strong&gt;. Deze subsidies kunnen enkel worden toegekend wanneer u diensten afneemt bij KMO-Portefeuille geregistreerde dienstverleners.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Kom ik in aanmerking?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;De volgende entiteiten komen in aanmerking voor KMO-Portefeuille subsidies. KMO’s &amp;amp; Vrije beroepen die:&lt;/p&gt; 
       &lt;ul&gt; 
        &lt;li&gt;Gevestigd zijn binnen Vlaanderen&lt;/li&gt; 
        &lt;li&gt;Deel uitmaken van de privésector (minder dan 25% is in handen van een administratieve overheid)&lt;/li&gt; 
        &lt;li&gt;Een aanvaardbare hoofdactiviteit hebben&lt;/li&gt; 
        &lt;li&gt;Voldoen aan de regelgeving van het Vlaamse Gewest&lt;/li&gt; 
       &lt;/ul&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Hoeveel subsidies kan ik krijgen?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Het bedrag van de subsidies die u kunt krijgen, hangt af van de grootte van uw organisatie.&lt;/p&gt; 
       &lt;table&gt; 
        &lt;tbody&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Grootte van de organisatie&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;b&gt;Criteria&lt;/b&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Subsidies %&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Max subsidies/jaar&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Klein&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Minder dan 50 werknemers&lt;/strong&gt;&lt;p&gt;&lt;strong&gt;Minder dan 10 miljoen jaaromzet&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Minder dan 10 miljoen op de balans&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;45%&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;€ 7.500&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Middelgroot&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Minder dan 250 werknemers&lt;/strong&gt;&lt;p&gt;&lt;strong&gt;Minder dan 50 miljoen jaaromzet&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Minder dan 43 miljoen op de balans&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;35%&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;€ 7.500&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
        &lt;/tbody&gt; 
       &lt;/table&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Hoe kan ik mijn KMO-Portefeuille subsidie aanvragen?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;U kunt uw subsidies aanvragen via een gebruiksvriendelijke webapplicatie die toegankelijk is op de volgende website: http://kmo-portefeuille.be/. De volgende informatie is nodig om een aanvraag in te dienen voor KMO-Portefeuille steun.&lt;/p&gt; 
       &lt;table&gt; 
        &lt;tbody&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Dienstverlener&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Toreon BV&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Registratienummer&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;DV.A219933&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Offertenummer&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;8022386775&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
        &lt;/tbody&gt; 
       &lt;/table&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Wil je nog meer weten over de KMO-Portefeuille?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.vlaio.be/nl/subsidies-financiering/kmo-portefeuille"&gt;VLAIO KMO-Portefeuille&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/kmo-portefeuille" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Dienstverlener-kmo-portefeuille-400x248-1-1.png" alt="KMO Portefeuille - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Toreon is een trotse partner van VLAIO, en maakt cyberbeveiliging toegankelijker voor kleine en middelgrote ondernemingen met subsidies tot 50% 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Bent u een Vlaamse KMO? Dan komt u in aanmerking voor subsidies van de Vlaamse overheid wanneer u adviesdiensten of opleidingen van Toreon aankoopt. Toreon is een geregistreerde leverancier van adviesdiensten en opleidingen in het kader van de &lt;strong&gt;KMO-Portefeuille.&lt;/strong&gt;&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Wat is de KMO-Portefeuille?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;De KMO-Portefeuille zijn subsidies die worden toegekend door het &lt;strong&gt;Vlaams Agentschap voor Innovatie &amp;amp; Ondernemen&lt;/strong&gt;. Het doel van deze subsidie is om de &lt;strong&gt;groei van Vlaamse KMO’s te ondersteunen&lt;/strong&gt;. Deze subsidies kunnen enkel worden toegekend wanneer u diensten afneemt bij KMO-Portefeuille geregistreerde dienstverleners.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Kom ik in aanmerking?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;De volgende entiteiten komen in aanmerking voor KMO-Portefeuille subsidies. KMO’s &amp;amp; Vrije beroepen die:&lt;/p&gt; 
       &lt;ul&gt; 
        &lt;li&gt;Gevestigd zijn binnen Vlaanderen&lt;/li&gt; 
        &lt;li&gt;Deel uitmaken van de privésector (minder dan 25% is in handen van een administratieve overheid)&lt;/li&gt; 
        &lt;li&gt;Een aanvaardbare hoofdactiviteit hebben&lt;/li&gt; 
        &lt;li&gt;Voldoen aan de regelgeving van het Vlaamse Gewest&lt;/li&gt; 
       &lt;/ul&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Hoeveel subsidies kan ik krijgen?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Het bedrag van de subsidies die u kunt krijgen, hangt af van de grootte van uw organisatie.&lt;/p&gt; 
       &lt;table&gt; 
        &lt;tbody&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Grootte van de organisatie&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;b&gt;Criteria&lt;/b&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Subsidies %&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Max subsidies/jaar&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Klein&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Minder dan 50 werknemers&lt;/strong&gt;&lt;p&gt;&lt;strong&gt;Minder dan 10 miljoen jaaromzet&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Minder dan 10 miljoen op de balans&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;45%&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;€ 7.500&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Middelgroot&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Minder dan 250 werknemers&lt;/strong&gt;&lt;p&gt;&lt;strong&gt;Minder dan 50 miljoen jaaromzet&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Minder dan 43 miljoen op de balans&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;35%&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;€ 7.500&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
        &lt;/tbody&gt; 
       &lt;/table&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Hoe kan ik mijn KMO-Portefeuille subsidie aanvragen?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;U kunt uw subsidies aanvragen via een gebruiksvriendelijke webapplicatie die toegankelijk is op de volgende website: http://kmo-portefeuille.be/. De volgende informatie is nodig om een aanvraag in te dienen voor KMO-Portefeuille steun.&lt;/p&gt; 
       &lt;table&gt; 
        &lt;tbody&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Dienstverlener&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;Toreon BV&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Registratienummer&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;DV.A219933&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
         &lt;tr&gt; 
          &lt;td&gt;&lt;strong&gt;Offertenummer&lt;/strong&gt;&lt;/td&gt; 
          &lt;td&gt;&lt;strong&gt;8022386775&lt;/strong&gt;&lt;/td&gt; 
         &lt;/tr&gt; 
        &lt;/tbody&gt; 
       &lt;/table&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h2&gt;Wil je nog meer weten over de KMO-Portefeuille?&lt;/h2&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.vlaio.be/nl/subsidies-financiering/kmo-portefeuille"&gt;VLAIO KMO-Portefeuille&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fkmo-portefeuille&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 07 Apr 2026 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/kmo-portefeuille</guid>
      <dc:date>2026-04-07T22:00:00Z</dc:date>
      <dc:creator>Less than a minute</dc:creator>
    </item>
    <item>
      <title>Break-Glass Access done right: Why YubiKeys are essential for secure emergency access - Toreon - Business driven cyber consulting</title>
      <link>https://staging.toreon.com/en/insights/blogs/break-glass-access-done-right</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/break-glass-access-done-right" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-thumbnail-Break-glass-access-1.webp" alt="Break-Glass Access done right: Why YubiKeys are essential for secure emergency access - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026.&amp;nbsp; Toreon can configure &amp;nbsp;break-glass accounts to be protected by YubiKeys.&amp;nbsp; These keys are becoming a best practice for resilient, audit-ready organizations.&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;When security meets reality: The Break-Glass dilemma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every organization plans for continuity. Yet when a real incident hits — ransomware, identity system failure, or privileged account lockout — theory meets reality fast.&lt;/p&gt; 
     &lt;p&gt;Emergency or &lt;em&gt;break-glass&lt;/em&gt; accounts are designed for exactly these moments. But here’s the uncomfortable truth:&lt;/p&gt; 
     &lt;p&gt;many break-glass setups today are either &lt;strong&gt;too weak to be secure&lt;/strong&gt; or &lt;strong&gt;too risky to ever use confidently&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;Also, Microsoft has defined July 1st, 2026 as end date for customers to postpone the MFA enforcement of Phase 2 for their tenants.&amp;nbsp; This implies that Brek the Glass accounts will have to be onboarded in MFA as well.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why traditional Break-Glass Accounts fall short&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Security vs. accessibility is a false trade-off&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Legacy emergency access models were built around convenience, not threat reality. Common issues include:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Password-based access that can be stolen, reused, or leaked&lt;/li&gt; 
      &lt;li&gt;Emergency accounts quietly becoming backdoors&lt;/li&gt; 
      &lt;li&gt;No clear ownership, audit trail, or activation workflow&lt;/li&gt; 
      &lt;li&gt;MFA being disabled “temporarily” — and never re-enabled&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In modern threat landscapes, these weaknesses are no longer theoretical. They are actively exploited.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The shift to hardware-based emergency access&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Security teams are increasingly aligning emergency access with the same zero-trust principles applied elsewhere — &lt;em&gt;without sacrificing availability&lt;/em&gt;.&lt;/p&gt; 
     &lt;p&gt;At the center of this shift: &lt;strong&gt;hardware-backed authentication&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;By protecting break-glass accounts with &lt;strong&gt;dedicated YubiKeys&lt;/strong&gt;, organizations eliminate entire classes of risk that passwords and software-based MFA simply can’t address.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Break the Glass with YubiKeys: A secure-by-design approach&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Emergency Access without everyday risk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A YubiKey-based break-glass solution is designed around one principle:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;privileged access must exist — but only when absolutely necessary&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;Key characteristics include:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Dedicated emergency-only accounts&lt;/strong&gt;, fully isolated from daily operations&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;One YubiKey per account&lt;/strong&gt;, enforcing phishing-resistant authentication&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Offline, tamper-evident storage&lt;/strong&gt; to prevent silent misuse&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Clear activation procedures&lt;/strong&gt; that remove ambiguity during incidents&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This ensures emergency access is &lt;em&gt;available, controlled, and auditable&lt;/em&gt; — all at once.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Phishing resistance where it matters most&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Why FIDO2 changes the game&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Break-glass accounts are high-value targets. That’s why protecting them with &lt;strong&gt;FIDO2-based YubiKeys&lt;/strong&gt; matters:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;No passwords to steal&lt;/li&gt; 
      &lt;li&gt;No credentials to phish&lt;/li&gt; 
      &lt;li&gt;No replay attacks&lt;/li&gt; 
      &lt;li&gt;Physical presence required&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Even during chaos, access can only be activated by &lt;strong&gt;authorized individuals holding the actual hardware key&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;That’s not just stronger authentication — it’s enforced intent.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Governance, compliance, and audit readiness built in&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Security teams need Proof, not promises&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Emergency access must stand up to audits, regulators, and internal governance — especially after an incident.&lt;/p&gt; 
     &lt;p&gt;A well-designed YubiKey break-glass setup supports this by default:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Every activation is logged and reviewable&lt;/li&gt; 
      &lt;li&gt;Dual custody and approval workflows are clearly defined&lt;/li&gt; 
      &lt;li&gt;Regular validation ensures readiness without exposure&lt;/li&gt; 
      &lt;li&gt;Optional monitoring and alerting integrate with existing security tooling&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The result: &lt;strong&gt;confidence before, during, and after an incident&lt;/strong&gt;.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;From Theory to Practice: How Secure Break-Glass Works&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;A Structured, Tested, and Documented Process&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A mature approach to break-glass access includes:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Provisioning&lt;/strong&gt; Hardened emergency accounts, each protected by a dedicated YubiKey.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Secure custody&lt;/strong&gt; Clear guidance on offline storage, sealing, and audit procedures.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Ongoing assurance&lt;/strong&gt; Periodic testing and validation without increasing risk exposure.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Incident response&lt;/strong&gt; A defined workflow for activation, alerting, and post-incident review.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;This turns emergency access from an uncomfortable necessity into a &lt;strong&gt;controlled security capability&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;The Toreon fixed price offering&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Break‑glass account credentials package&lt;/li&gt; 
      &lt;li&gt;One YubiKey per account&lt;/li&gt; 
      &lt;li&gt;Operational runbook for emergency activation&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;€ 1950,00&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Lorem Ipsum …&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Ready to see how your company can benefit?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/vincent-haerinck"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/break-glass-access-done-right" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-thumbnail-Break-glass-access-1.webp" alt="Break-Glass Access done right: Why YubiKeys are essential for secure emergency access - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Microsoft allows customers with complex environments or technical barriers to postpone the enforcement of Phase 2 for their tenants until July 1st, 2026.&amp;nbsp; Toreon can configure &amp;nbsp;break-glass accounts to be protected by YubiKeys.&amp;nbsp; These keys are becoming a best practice for resilient, audit-ready organizations.&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;When security meets reality: The Break-Glass dilemma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every organization plans for continuity. Yet when a real incident hits — ransomware, identity system failure, or privileged account lockout — theory meets reality fast.&lt;/p&gt; 
     &lt;p&gt;Emergency or &lt;em&gt;break-glass&lt;/em&gt; accounts are designed for exactly these moments. But here’s the uncomfortable truth:&lt;/p&gt; 
     &lt;p&gt;many break-glass setups today are either &lt;strong&gt;too weak to be secure&lt;/strong&gt; or &lt;strong&gt;too risky to ever use confidently&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;Also, Microsoft has defined July 1st, 2026 as end date for customers to postpone the MFA enforcement of Phase 2 for their tenants.&amp;nbsp; This implies that Brek the Glass accounts will have to be onboarded in MFA as well.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why traditional Break-Glass Accounts fall short&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Security vs. accessibility is a false trade-off&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Legacy emergency access models were built around convenience, not threat reality. Common issues include:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Password-based access that can be stolen, reused, or leaked&lt;/li&gt; 
      &lt;li&gt;Emergency accounts quietly becoming backdoors&lt;/li&gt; 
      &lt;li&gt;No clear ownership, audit trail, or activation workflow&lt;/li&gt; 
      &lt;li&gt;MFA being disabled “temporarily” — and never re-enabled&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In modern threat landscapes, these weaknesses are no longer theoretical. They are actively exploited.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The shift to hardware-based emergency access&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Security teams are increasingly aligning emergency access with the same zero-trust principles applied elsewhere — &lt;em&gt;without sacrificing availability&lt;/em&gt;.&lt;/p&gt; 
     &lt;p&gt;At the center of this shift: &lt;strong&gt;hardware-backed authentication&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;By protecting break-glass accounts with &lt;strong&gt;dedicated YubiKeys&lt;/strong&gt;, organizations eliminate entire classes of risk that passwords and software-based MFA simply can’t address.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Break the Glass with YubiKeys: A secure-by-design approach&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Emergency Access without everyday risk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A YubiKey-based break-glass solution is designed around one principle:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;privileged access must exist — but only when absolutely necessary&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;Key characteristics include:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Dedicated emergency-only accounts&lt;/strong&gt;, fully isolated from daily operations&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;One YubiKey per account&lt;/strong&gt;, enforcing phishing-resistant authentication&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Offline, tamper-evident storage&lt;/strong&gt; to prevent silent misuse&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Clear activation procedures&lt;/strong&gt; that remove ambiguity during incidents&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This ensures emergency access is &lt;em&gt;available, controlled, and auditable&lt;/em&gt; — all at once.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Phishing resistance where it matters most&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Why FIDO2 changes the game&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Break-glass accounts are high-value targets. That’s why protecting them with &lt;strong&gt;FIDO2-based YubiKeys&lt;/strong&gt; matters:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;No passwords to steal&lt;/li&gt; 
      &lt;li&gt;No credentials to phish&lt;/li&gt; 
      &lt;li&gt;No replay attacks&lt;/li&gt; 
      &lt;li&gt;Physical presence required&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Even during chaos, access can only be activated by &lt;strong&gt;authorized individuals holding the actual hardware key&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;That’s not just stronger authentication — it’s enforced intent.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Governance, compliance, and audit readiness built in&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Security teams need Proof, not promises&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Emergency access must stand up to audits, regulators, and internal governance — especially after an incident.&lt;/p&gt; 
     &lt;p&gt;A well-designed YubiKey break-glass setup supports this by default:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Every activation is logged and reviewable&lt;/li&gt; 
      &lt;li&gt;Dual custody and approval workflows are clearly defined&lt;/li&gt; 
      &lt;li&gt;Regular validation ensures readiness without exposure&lt;/li&gt; 
      &lt;li&gt;Optional monitoring and alerting integrate with existing security tooling&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The result: &lt;strong&gt;confidence before, during, and after an incident&lt;/strong&gt;.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;From Theory to Practice: How Secure Break-Glass Works&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;A Structured, Tested, and Documented Process&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A mature approach to break-glass access includes:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Provisioning&lt;/strong&gt; Hardened emergency accounts, each protected by a dedicated YubiKey.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Secure custody&lt;/strong&gt; Clear guidance on offline storage, sealing, and audit procedures.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Ongoing assurance&lt;/strong&gt; Periodic testing and validation without increasing risk exposure.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Incident response&lt;/strong&gt; A defined workflow for activation, alerting, and post-incident review.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;This turns emergency access from an uncomfortable necessity into a &lt;strong&gt;controlled security capability&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;The Toreon fixed price offering&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Break‑glass account credentials package&lt;/li&gt; 
      &lt;li&gt;One YubiKey per account&lt;/li&gt; 
      &lt;li&gt;Operational runbook for emergency activation&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;€ 1950,00&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Lorem Ipsum …&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Ready to see how your company can benefit?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/vincent-haerinck"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fbreak-glass-access-done-right&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <category>Cloud</category>
      <category>Toreon Cyber Insights</category>
      <pubDate>Wed, 18 Mar 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/break-glass-access-done-right</guid>
      <dc:date>2026-03-18T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>2026: The Year Cyber Compliance Becomes Mandatory - Toreon - Business driven cyber consulting</title>
      <link>https://staging.toreon.com/en/insights/blogs/2026-the-year-cyber-compliance-becomes-mandatory</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/2026-the-year-cyber-compliance-becomes-mandatory" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-thumbnail-2026-Compliance-becomes-mandatory-1.webp" alt="2026: The Year Cyber Compliance Becomes Mandatory - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For many Belgian organizations, 2026 is the year where cybersecurity compliance moves from “important topic” to “non‑negotiable business requirement.” NIS2 and the Cyber Resilience Act (CRA) sit at the center of this shift, with other EU regulations tightening the pressure around them.&lt;/p&gt; 
     &lt;p&gt;This article zooms in on NIS2 and CRA—their deadlines, scope, and impact on Belgian companies—while briefly highlighting DORA, the AI Act and GDPR where they intersect. Where we see unclear or conflicting information in public sources, we call it out explicitly so you can plan with eyes wide open.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;h4&gt;Table of Contents&lt;/h4&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. NIS2 in Belgium: 2026 is the first big test&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Belgium is one of the few EU countries that fully transposed NIS2 on time. The Belgian NIS2 law (Law of 26 April 2024) entered into force on 18 October 2024 and replaces the former NIS1 Act. From that date, in‑scope entities must implement minimum security measures and report significant incidents to the Centre for Cybersecurity Belgium (CCB).&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.1 Key NIS2 dates in Belgium&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Milestone&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;What it means for you&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Law in force&lt;/td&gt; 
        &lt;td&gt;18 Oct 2024&lt;/td&gt; 
        &lt;td&gt;NIS2 obligations apply; incident reporting to CCB becomes mandatory.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Registration (most entities)&lt;/td&gt; 
        &lt;td&gt;18 Mar 2025&lt;/td&gt; 
        &lt;td&gt;Essential and important entities registered via Safeonweb@Work.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Registration (digital providers)&lt;/td&gt; 
        &lt;td&gt;18 Dec 2024&lt;/td&gt; 
        &lt;td&gt;Cloud, data centres, MSP/MSSP, online platforms register earlier.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;First verification deadline&lt;/td&gt; 
        &lt;td&gt;18 Apr 2026&lt;/td&gt; 
        &lt;td&gt;Basic/Important CyFun verification or equivalent ISO 27001 progress.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Certification for essential entities&lt;/td&gt; 
        &lt;td&gt;18 Apr 2027&lt;/td&gt; 
        &lt;td&gt;Essential entities must hold full certification (in case of CyFun Essential assurance level or ISO 27001).&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.2 Who falls under NIS2 in Belgium?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;NIS2 applies to companies active in “highly critical” and “critical” sectors. Whether you are an “important” or “essential” entity depends on a combination of the sector you’re in and the size of the company, from a headcount or financial perspective.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Sector &amp;amp; size logic (Belgium)&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Large company: Staff headcount of at least 250 FTEs OR (&amp;gt; € 50 m annual turnover AND &amp;gt; €43 m annual balance sheet total).&lt;/p&gt; 
     &lt;p&gt;Medium-sized company: Staff headcount of at least 50 FTEs OR (&amp;gt; € 10 m annual turnover AND &amp;gt; € 10 m annual balance sheet total).&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Sector&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Size&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Category&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Highly Critical&lt;/strong&gt;&lt;br&gt; Energy, healthcare, drinking/waste water, digital infrastructure, public admin, transport infrastructure, banking &amp;amp; FMIs, space.&lt;/td&gt; 
        &lt;td&gt;Large company&lt;/td&gt; 
        &lt;td&gt;ESSENTIAL&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Medium-sized company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Critical&lt;/strong&gt;&lt;br&gt; Postal/courier, waste management, chemicals, food production, manufacturing (incl. medical devices &amp;amp; electronics), digital providers, research.&lt;/td&gt; 
        &lt;td&gt;Large company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Medium-sized company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Directly named sectors in the Belgian law include energy, banking, healthcare, water treatment, digital infrastructure, public administrations and operators of transport infrastructure such as ports, airports and rail infrastructure—not every individual transporter.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Remark:&lt;/strong&gt; Micro and small entities can still be scoped in if they are the sole provider of an essential service in each Member State or play a key role in critical supply chains.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.3 What NIS2 actually expects by April 2026&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;By &lt;strong&gt;18 April 2026&lt;/strong&gt;, Belgian NIS2 &lt;strong&gt;Essential&lt;/strong&gt; entities must be able to &lt;strong&gt;prove&lt;/strong&gt; that they have implemented a baseline of security controls and governance. The CCB recognizes several routes: whether you choose the ISO- or CyFun route, companies need to demonstrate they have taken the CyFun Controls into account.&lt;/p&gt; 
     &lt;p&gt;The CyFun controls you must implement are based on the CyFun assurance level you need to reach and this is determined based on a risk assessment. The CCB has prepared a risk assessment tool which contains the initial risk analysis per sector, based on relevant incident and threat information. This spreadsheet can be downloaded from the Safeonweb at work portal. In case you alter the default values and receive a lower CyFun assurance level, you must provide substantial evidence validated by management to support your case. It is the assurance level based on this risk assessment that determines the next steps.&lt;/p&gt; 
     &lt;p&gt;The CyberFundamentals levels referred to in the table below reference the target CyFun, not the NIS2 entity level. As an example: you may be a NIS2 Essential entity, but have a CyFun assurance level of important. As an essential entity, you must submit evidence by April 18th 2026 and 2027, but the assurance level is considered to determine whether you need a CyFun “verification” or “certification”. NIS2 important entities do not need to provide evidence by these two dates, but do need to comply with the law, of course. Verification or certification is voluntary for these entities.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Route&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;2026 requirement&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;2027 requirement&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Basic&lt;/td&gt; 
        &lt;td&gt;Basic verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Maintain verification; may need to step up to Important/Essential later.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Important&lt;/td&gt; 
        &lt;td&gt;Basic or Important verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Important verification by 18 Apr 2027 if not already obtained.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Essential&lt;/td&gt; 
        &lt;td&gt;At least Basic/Important verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Essential certification by 18 Apr 2027.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;ISO 27001&lt;/td&gt; 
        &lt;td&gt;Submit scope (must be entire company) + Statement of Applicability (SoA) of future certification + internal audit report to show compliance with at least CyFun Basic to CCB by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Achieve full ISO 27001 certification by 18 Apr 2027.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CCB / sector inspection&lt;/td&gt; 
        &lt;td&gt;Demonstrate compliance during inspection (more bespoke approach).&lt;/td&gt; 
        &lt;td&gt;Follow inspection findings and possible follow‑up audits.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;All verifications and certifications need to be executed by a CAB (Conformity Assessment Body) accredited by the CCB.&lt;/strong&gt; The list of accredited CABs can also be found on the Safeonweb at work portal.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Core obligations behind the badges&lt;/strong&gt; (simplified):&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Governance: board accountability, risk management, security policy, cyber KPIs.&lt;/li&gt; 
      &lt;li&gt;Protection: access control, network segmentation, secure configuration, awareness.&lt;/li&gt; 
      &lt;li&gt;Detection &amp;amp; response: incident detection, playbooks, crisis management, reporting within 24h/72h/30 days using CCB templates.&lt;/li&gt; 
      &lt;li&gt;Supply chain security: demonstrable security expectations for suppliers and MSPs.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The &lt;strong&gt;CyFun® framework&lt;/strong&gt; is now explicitly embedded in Belgian law as a way to “assume, until proven otherwise,” NIS2 compliance when the required level is achieved. Directors are personally liable in case of serious failures and can face significant fines.[4][6][5]&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.4 Penalties and management liability&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The Belgian NIS2 regime foresees serious sanctions for persistent non‑compliance:[6][28]&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Essential entities&lt;/strong&gt;: up to €10 million or 2% of global annual turnover, whichever is higher.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Important entities&lt;/strong&gt;: up to €7 million or 1.4% of global annual turnover.&lt;/li&gt; 
      &lt;li&gt;Management can be temporarily banned from exercising managerial functions in serious cases.[28][4][6]&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For many boards, NIS2 is the first time cyber risk has been translated directly into personal legal exposure.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. The Cyber Resilience Act: product security becomes a legal obligation&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Where NIS2 focuses on organizational resilience, the Cyber Resilience Act (CRA) targets the security of products with digital elements—from software and IoT to connected industrial systems.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.1 CRA timeline: 2026 is about reporting&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The CRA entered into force in December 2024 but applies in phases.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;CRA milestone&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;What changes&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Entry into force&lt;/td&gt; 
        &lt;td&gt;10–11 Dec 2024&lt;/td&gt; 
        &lt;td&gt;CRA is on the books; transitional period starts.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Reporting obligations (Article 14) apply&lt;/td&gt; 
        &lt;td&gt;11 Sep 2026&lt;/td&gt; 
        &lt;td&gt;Mandatory vulnerability &amp;amp; incident reporting for manufacturers.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Full CRA applicability&lt;/td&gt; 
        &lt;td&gt;11 Dec 2027&lt;/td&gt; 
        &lt;td&gt;All CRA obligations enforceable; non‑compliant products cannot be placed on EU market.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.2 Who must care about CRA?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The CRA applies to &lt;strong&gt;manufacturers, importers and distributors&lt;/strong&gt; that place “products with digital elements” on the EU market. This includes:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Software vendors that create mobile or desktop applications .&lt;/li&gt; 
      &lt;li&gt;Manufacturers or vendors of embedded devices, such as consumer IoT, toys with bluetooth connectivity, industrial control systems or sensors or network appliances. ).&lt;/li&gt; 
      &lt;li&gt;Unlike NIS2, CRA does &lt;strong&gt;not&lt;/strong&gt; use size thresholds—small vendors are still in scope if their products fall under the definition.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.3 CRA reporting from September 2026: new operational pressure&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;From 11 September 2026, CRA introduces strict, non‑negotiable reporting timelines once a manufacturer becomes aware of an actively exploited vulnerability or serious incident affecting their product.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;CRA reporting obligation&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Timeline after awareness&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Scope&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Early warning to ENISA &amp;amp; national CSIRT&lt;/td&gt; 
        &lt;td&gt;Within 24 hours&lt;/td&gt; 
        &lt;td&gt;Actively exploited vulnerability or severe incident affecting product security.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Detailed notification&lt;/td&gt; 
        &lt;td&gt;Within 72 hours&lt;/td&gt; 
        &lt;td&gt;Technical details, affected products, mitigation measures, impact assessment.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Final report – vulnerabilities&lt;/td&gt; 
        &lt;td&gt;Within 14 days after fix/mitigation&lt;/td&gt; 
        &lt;td&gt;Root cause, remediation, deployed updates, lessons learned.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Final report – severe incidents&lt;/td&gt; 
        &lt;td&gt;Within 1 month after resolution&lt;/td&gt; 
        &lt;td&gt;Broader impact analysis and improvements.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Importantly, this obligation covers all in‑market products, including legacy solutions. There is no “grandfathering” of older software or devices.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.4 CRA: security by design, SBOMs and documentation&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Beyond reporting, CRA pushes three major long‑term shifts in how products are built and maintained:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Security by design &amp;amp; by default&lt;/strong&gt; across the full product lifecycle (from design through updates and end‑of‑life).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Vulnerability handling process&lt;/strong&gt;: proactive discovery, timely fixes, secure updates, and clear communication to users.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Technical documentation&lt;/strong&gt;: including risk assessments, update policies, and often a &lt;strong&gt;Software Bill of Materials (SBOM)&lt;/strong&gt; to support transparency and vulnerability management.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For many Belgian software and hardware vendors, CRA is the first regulation that explicitly connects engineering practices, product management, and legal compliance.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. NIS2 vs CRA: complementary, not competing&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;NIS2 and CRA are often mentioned in the same breath. They are indeed part of the same EU strategy but solve different problems.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Aspect&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;NIS2 (Belgium)&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Cyber Resilience Act (CRA)&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Primary focus&lt;/td&gt; 
        &lt;td&gt;Organizational cybersecurity &amp;amp; service continuity.&lt;/td&gt; 
        &lt;td&gt;Security of products with digital elements.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Main addressees&lt;/td&gt; 
        &lt;td&gt;Operators of essential and important services (entities).&lt;/td&gt; 
        &lt;td&gt;Manufacturers, importers, distributors of digital products.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Scope logic&lt;/td&gt; 
        &lt;td&gt;Sector + size thresholds; some exceptions for critical players.&lt;/td&gt; 
        &lt;td&gt;Product classification (criticality, use, connectivity).&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Key 2026 trigger&lt;/td&gt; 
        &lt;td&gt;18 Apr 2026: CyFun/ISO verification deadline.&lt;/td&gt; 
        &lt;td&gt;11 Jun 2026 + 11 Sep 2026: CAB notification &amp;amp; reporting duties.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Reporting destination&lt;/td&gt; 
        &lt;td&gt;National CCB (Safeonweb@Work).&lt;/td&gt; 
        &lt;td&gt;ENISA + national CSIRTs.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Typical Belgian examples&lt;/td&gt; 
        &lt;td&gt;Hospitals, utilities, banks, public administrations, large logistics hubs, cloud-providers.&lt;/td&gt; 
        &lt;td&gt;Software vendors, IoT manufacturers, industrial equipment makers, connected consumer products.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For many mid‑sized Belgian tech companies, both will apply. Example:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A SaaS vendor operating a cloud platform &lt;strong&gt;that processes data from products with digital elements&lt;/strong&gt; may be in scope under NIS2 (digital provider + supply chain) and CRA (product with digital elements).&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In that case, NIS2 shapes &lt;strong&gt;how you secure your organization&lt;/strong&gt;, while CRA shapes &lt;strong&gt;how you design, maintain and support your product&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Other 2026 regulations in the background&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While NIS2 and CRA take center stage for most Belgian organizations, three other regulations deserve a place on your 2026 radar.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.1 DORA – for financial services and their ICT suppliers&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;strong&gt;Digital Operational Resilience Act (DORA)&lt;/strong&gt; has applied since &lt;strong&gt;17 January 2025&lt;/strong&gt; and sets uniform rules for ICT risk management, incident reporting, resilience testing and third‑party risk in financial services.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Scope includes banks, insurers, payment institutions, investment firms, funds and &lt;strong&gt;critical ICT third‑party providers&lt;/strong&gt;.&lt;/li&gt; 
      &lt;li&gt;Belgian entities are supervised mainly by the NBB and FSMA.&lt;/li&gt; 
      &lt;li&gt;DORA penalties in several EU countries go up to the higher of €5–10 million or a percentage of turnover; Belgium sits mid‑pack with significant, but proportionate, fines.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For Belgian FinTech’s and ICT providers with financial clients, DORA and NIS2 will increasingly be discussed in the same RFPs and audits.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.2 AI Act – 2026 is go‑live for high‑risk AI&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;strong&gt;AI Act&lt;/strong&gt; entered into force in 2024; most obligations for &lt;strong&gt;high‑risk AI systems&lt;/strong&gt; (e.g. credit scoring, certain HR tools, remote biometric identification) will apply &lt;strong&gt;from August 2026&lt;/strong&gt;.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;High‑risk systems must meet requirements on risk management, data governance, transparency, human oversight, and robustness.&lt;/li&gt; 
      &lt;li&gt;Fines can reach up to €35 million or 7% of global turnover for prohibited practices.&lt;/li&gt; 
      &lt;li&gt;For Belgian organizations, the DPA and sector regulators are expected to share enforcement, but the exact institutional set‑up is still emerging.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.3 GDPR – faster procedures, focused actions&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;GDPR itself doesn’t change in 2026, but &lt;strong&gt;enforcement dynamics&lt;/strong&gt; do:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A new &lt;strong&gt;GDPR Procedural Regulation&lt;/strong&gt; streamlines cross‑border enforcement with indicative 15‑month resolution timelines (extendable for complex cases).&lt;/li&gt; 
      &lt;li&gt;The 2026 coordinated enforcement action at EU level focuses on transparency obligations (Articles 12–14), which will impact how Belgian organizations draft notices and communicate with data subjects.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In practice, this means GDPR investigations should become faster and more predictable—while still potentially costly.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.4 CER-Law&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;On 18 December 2025, Belgium adopted the CER Law, implementing the European CER Directive to strengthen the resilience of critical entities and essential services. The law establishes a harmonized framework to protect against natural, accidental, and intentional threats. It requires&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;risk assessments at both sectoral and entity level;&lt;/li&gt; 
      &lt;li&gt;identification of critical entities and infrastructure;&lt;/li&gt; 
      &lt;li&gt;resilience planning;&lt;/li&gt; 
      &lt;li&gt;and information-sharing procedures.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The&amp;nbsp;National Crisis Center&amp;nbsp;coordinates its implementation. The NIS2 Directive stipulates that all critical entities falling under the CER Directive are automatically designated as essential entities under NIS2. This means that if you are currently classified as an important entity under NIS2, you could still become an essential entity if you meet the criteria of the CER framework.&lt;/p&gt; 
     &lt;p&gt;However, CER excludes obligations that are already covered under NIS2 and does not apply to the digital infrastructure or the financial sector.&lt;/p&gt; 
     &lt;p&gt;It is expected that the list of companies which need to comply with the CER law will be drawn up by July 2026.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. How Belgian organizations can move from “reaction” to “strategy”&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Given the overlapping timelines, the key is to avoid treating each regulation as a separate project. The most effective Belgian organizations are doing three things:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Scope once, use many times&lt;br&gt; &lt;br&gt;&lt;/strong&gt;Map your business against NIS2, CRA, DORA, AI Act and GDPR in a single exercise. Identify which entities, products and processes sit at the intersection (e.g. a SaaS product used by a bank and classified as high‑risk AI).&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Build on a strong backbone (CyFun &amp;amp; ISO 27001)&lt;br&gt; &lt;br&gt;&lt;/strong&gt;Use &lt;strong&gt;CyberFundamentals&lt;/strong&gt; and/or &lt;strong&gt;ISO 27001&lt;/strong&gt; as your common governance backbone. Both align closely with NIS2, support DORA and CRA preparation, and give you a consistent way to show your board and regulators that you’re in control. But if you are working in an international context, the ISO-route is certainly preferrable.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Integrate product security early&lt;br&gt; &lt;br&gt;&lt;/strong&gt;For CRA‑relevant companies, &lt;strong&gt;assess your development practices using OWASP SAMM and build a roadmap towards a secure development lifecycle.&lt;/strong&gt; This will allow you to gradually bring threat modeling, SBOMs and secure development practices into the SDLC now, not in late 2026, making CRA compliance a natural outcome of your engineering processes rather than a bolt‑on.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Use available support&lt;br&gt; &lt;br&gt;&lt;/strong&gt;In Flanders, VLAIO subsidies—and specific programs developed with partners like Toreon—can cover a significant portion of the cost of your NIS2‑driven security improvement trajectory. Sectoral initiatives like the CYSSDE EU pentesting program further help critical entities strengthen their posture at reduced cost.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;If you’re unsure whether NIS2, CRA—or both—apply to your organization, the worst option in 2026 is to wait. Determining your scope, mapping your gaps and building a realistic roadmap now will cost far less than rushing to catch up under regulatory pressure later. &lt;strong&gt;Toreon is a selected partner of VLAIO to support these trajectories and has already accumulated over 100 projects subsidized by VLAIO.&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Learn more about the VLAIO-subidies&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/2026-the-year-cyber-compliance-becomes-mandatory" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-thumbnail-2026-Compliance-becomes-mandatory-1.webp" alt="2026: The Year Cyber Compliance Becomes Mandatory - Toreon - Business driven cyber consulting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For many Belgian organizations, 2026 is the year where cybersecurity compliance moves from “important topic” to “non‑negotiable business requirement.” NIS2 and the Cyber Resilience Act (CRA) sit at the center of this shift, with other EU regulations tightening the pressure around them.&lt;/p&gt; 
     &lt;p&gt;This article zooms in on NIS2 and CRA—their deadlines, scope, and impact on Belgian companies—while briefly highlighting DORA, the AI Act and GDPR where they intersect. Where we see unclear or conflicting information in public sources, we call it out explicitly so you can plan with eyes wide open.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;h4&gt;Table of Contents&lt;/h4&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. NIS2 in Belgium: 2026 is the first big test&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Belgium is one of the few EU countries that fully transposed NIS2 on time. The Belgian NIS2 law (Law of 26 April 2024) entered into force on 18 October 2024 and replaces the former NIS1 Act. From that date, in‑scope entities must implement minimum security measures and report significant incidents to the Centre for Cybersecurity Belgium (CCB).&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.1 Key NIS2 dates in Belgium&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Milestone&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;What it means for you&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Law in force&lt;/td&gt; 
        &lt;td&gt;18 Oct 2024&lt;/td&gt; 
        &lt;td&gt;NIS2 obligations apply; incident reporting to CCB becomes mandatory.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Registration (most entities)&lt;/td&gt; 
        &lt;td&gt;18 Mar 2025&lt;/td&gt; 
        &lt;td&gt;Essential and important entities registered via Safeonweb@Work.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Registration (digital providers)&lt;/td&gt; 
        &lt;td&gt;18 Dec 2024&lt;/td&gt; 
        &lt;td&gt;Cloud, data centres, MSP/MSSP, online platforms register earlier.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;First verification deadline&lt;/td&gt; 
        &lt;td&gt;18 Apr 2026&lt;/td&gt; 
        &lt;td&gt;Basic/Important CyFun verification or equivalent ISO 27001 progress.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Certification for essential entities&lt;/td&gt; 
        &lt;td&gt;18 Apr 2027&lt;/td&gt; 
        &lt;td&gt;Essential entities must hold full certification (in case of CyFun Essential assurance level or ISO 27001).&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.2 Who falls under NIS2 in Belgium?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;NIS2 applies to companies active in “highly critical” and “critical” sectors. Whether you are an “important” or “essential” entity depends on a combination of the sector you’re in and the size of the company, from a headcount or financial perspective.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Sector &amp;amp; size logic (Belgium)&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Large company: Staff headcount of at least 250 FTEs OR (&amp;gt; € 50 m annual turnover AND &amp;gt; €43 m annual balance sheet total).&lt;/p&gt; 
     &lt;p&gt;Medium-sized company: Staff headcount of at least 50 FTEs OR (&amp;gt; € 10 m annual turnover AND &amp;gt; € 10 m annual balance sheet total).&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Sector&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Size&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Category&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Highly Critical&lt;/strong&gt;&lt;br&gt; Energy, healthcare, drinking/waste water, digital infrastructure, public admin, transport infrastructure, banking &amp;amp; FMIs, space.&lt;/td&gt; 
        &lt;td&gt;Large company&lt;/td&gt; 
        &lt;td&gt;ESSENTIAL&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Medium-sized company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Critical&lt;/strong&gt;&lt;br&gt; Postal/courier, waste management, chemicals, food production, manufacturing (incl. medical devices &amp;amp; electronics), digital providers, research.&lt;/td&gt; 
        &lt;td&gt;Large company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Medium-sized company&lt;/td&gt; 
        &lt;td&gt;IMPORTANT&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Directly named sectors in the Belgian law include energy, banking, healthcare, water treatment, digital infrastructure, public administrations and operators of transport infrastructure such as ports, airports and rail infrastructure—not every individual transporter.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Remark:&lt;/strong&gt; Micro and small entities can still be scoped in if they are the sole provider of an essential service in each Member State or play a key role in critical supply chains.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.3 What NIS2 actually expects by April 2026&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;By &lt;strong&gt;18 April 2026&lt;/strong&gt;, Belgian NIS2 &lt;strong&gt;Essential&lt;/strong&gt; entities must be able to &lt;strong&gt;prove&lt;/strong&gt; that they have implemented a baseline of security controls and governance. The CCB recognizes several routes: whether you choose the ISO- or CyFun route, companies need to demonstrate they have taken the CyFun Controls into account.&lt;/p&gt; 
     &lt;p&gt;The CyFun controls you must implement are based on the CyFun assurance level you need to reach and this is determined based on a risk assessment. The CCB has prepared a risk assessment tool which contains the initial risk analysis per sector, based on relevant incident and threat information. This spreadsheet can be downloaded from the Safeonweb at work portal. In case you alter the default values and receive a lower CyFun assurance level, you must provide substantial evidence validated by management to support your case. It is the assurance level based on this risk assessment that determines the next steps.&lt;/p&gt; 
     &lt;p&gt;The CyberFundamentals levels referred to in the table below reference the target CyFun, not the NIS2 entity level. As an example: you may be a NIS2 Essential entity, but have a CyFun assurance level of important. As an essential entity, you must submit evidence by April 18th 2026 and 2027, but the assurance level is considered to determine whether you need a CyFun “verification” or “certification”. NIS2 important entities do not need to provide evidence by these two dates, but do need to comply with the law, of course. Verification or certification is voluntary for these entities.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Route&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;2026 requirement&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;2027 requirement&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Basic&lt;/td&gt; 
        &lt;td&gt;Basic verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Maintain verification; may need to step up to Important/Essential later.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Important&lt;/td&gt; 
        &lt;td&gt;Basic or Important verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Important verification by 18 Apr 2027 if not already obtained.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CyberFundamentals – Essential&lt;/td&gt; 
        &lt;td&gt;At least Basic/Important verification by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Essential certification by 18 Apr 2027.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;ISO 27001&lt;/td&gt; 
        &lt;td&gt;Submit scope (must be entire company) + Statement of Applicability (SoA) of future certification + internal audit report to show compliance with at least CyFun Basic to CCB by 18 Apr 2026.&lt;/td&gt; 
        &lt;td&gt;Achieve full ISO 27001 certification by 18 Apr 2027.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;CCB / sector inspection&lt;/td&gt; 
        &lt;td&gt;Demonstrate compliance during inspection (more bespoke approach).&lt;/td&gt; 
        &lt;td&gt;Follow inspection findings and possible follow‑up audits.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;All verifications and certifications need to be executed by a CAB (Conformity Assessment Body) accredited by the CCB.&lt;/strong&gt; The list of accredited CABs can also be found on the Safeonweb at work portal.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Core obligations behind the badges&lt;/strong&gt; (simplified):&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Governance: board accountability, risk management, security policy, cyber KPIs.&lt;/li&gt; 
      &lt;li&gt;Protection: access control, network segmentation, secure configuration, awareness.&lt;/li&gt; 
      &lt;li&gt;Detection &amp;amp; response: incident detection, playbooks, crisis management, reporting within 24h/72h/30 days using CCB templates.&lt;/li&gt; 
      &lt;li&gt;Supply chain security: demonstrable security expectations for suppliers and MSPs.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The &lt;strong&gt;CyFun® framework&lt;/strong&gt; is now explicitly embedded in Belgian law as a way to “assume, until proven otherwise,” NIS2 compliance when the required level is achieved. Directors are personally liable in case of serious failures and can face significant fines.[4][6][5]&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;1.4 Penalties and management liability&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The Belgian NIS2 regime foresees serious sanctions for persistent non‑compliance:[6][28]&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Essential entities&lt;/strong&gt;: up to €10 million or 2% of global annual turnover, whichever is higher.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Important entities&lt;/strong&gt;: up to €7 million or 1.4% of global annual turnover.&lt;/li&gt; 
      &lt;li&gt;Management can be temporarily banned from exercising managerial functions in serious cases.[28][4][6]&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For many boards, NIS2 is the first time cyber risk has been translated directly into personal legal exposure.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. The Cyber Resilience Act: product security becomes a legal obligation&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Where NIS2 focuses on organizational resilience, the Cyber Resilience Act (CRA) targets the security of products with digital elements—from software and IoT to connected industrial systems.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.1 CRA timeline: 2026 is about reporting&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The CRA entered into force in December 2024 but applies in phases.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;CRA milestone&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Date&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;What changes&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Entry into force&lt;/td&gt; 
        &lt;td&gt;10–11 Dec 2024&lt;/td&gt; 
        &lt;td&gt;CRA is on the books; transitional period starts.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Reporting obligations (Article 14) apply&lt;/td&gt; 
        &lt;td&gt;11 Sep 2026&lt;/td&gt; 
        &lt;td&gt;Mandatory vulnerability &amp;amp; incident reporting for manufacturers.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Full CRA applicability&lt;/td&gt; 
        &lt;td&gt;11 Dec 2027&lt;/td&gt; 
        &lt;td&gt;All CRA obligations enforceable; non‑compliant products cannot be placed on EU market.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.2 Who must care about CRA?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The CRA applies to &lt;strong&gt;manufacturers, importers and distributors&lt;/strong&gt; that place “products with digital elements” on the EU market. This includes:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Software vendors that create mobile or desktop applications .&lt;/li&gt; 
      &lt;li&gt;Manufacturers or vendors of embedded devices, such as consumer IoT, toys with bluetooth connectivity, industrial control systems or sensors or network appliances. ).&lt;/li&gt; 
      &lt;li&gt;Unlike NIS2, CRA does &lt;strong&gt;not&lt;/strong&gt; use size thresholds—small vendors are still in scope if their products fall under the definition.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.3 CRA reporting from September 2026: new operational pressure&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;From 11 September 2026, CRA introduces strict, non‑negotiable reporting timelines once a manufacturer becomes aware of an actively exploited vulnerability or serious incident affecting their product.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;CRA reporting obligation&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Timeline after awareness&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Scope&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Early warning to ENISA &amp;amp; national CSIRT&lt;/td&gt; 
        &lt;td&gt;Within 24 hours&lt;/td&gt; 
        &lt;td&gt;Actively exploited vulnerability or severe incident affecting product security.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Detailed notification&lt;/td&gt; 
        &lt;td&gt;Within 72 hours&lt;/td&gt; 
        &lt;td&gt;Technical details, affected products, mitigation measures, impact assessment.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Final report – vulnerabilities&lt;/td&gt; 
        &lt;td&gt;Within 14 days after fix/mitigation&lt;/td&gt; 
        &lt;td&gt;Root cause, remediation, deployed updates, lessons learned.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Final report – severe incidents&lt;/td&gt; 
        &lt;td&gt;Within 1 month after resolution&lt;/td&gt; 
        &lt;td&gt;Broader impact analysis and improvements.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Importantly, this obligation covers all in‑market products, including legacy solutions. There is no “grandfathering” of older software or devices.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;2.4 CRA: security by design, SBOMs and documentation&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Beyond reporting, CRA pushes three major long‑term shifts in how products are built and maintained:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Security by design &amp;amp; by default&lt;/strong&gt; across the full product lifecycle (from design through updates and end‑of‑life).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Vulnerability handling process&lt;/strong&gt;: proactive discovery, timely fixes, secure updates, and clear communication to users.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Technical documentation&lt;/strong&gt;: including risk assessments, update policies, and often a &lt;strong&gt;Software Bill of Materials (SBOM)&lt;/strong&gt; to support transparency and vulnerability management.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For many Belgian software and hardware vendors, CRA is the first regulation that explicitly connects engineering practices, product management, and legal compliance.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. NIS2 vs CRA: complementary, not competing&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;NIS2 and CRA are often mentioned in the same breath. They are indeed part of the same EU strategy but solve different problems.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Aspect&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;NIS2 (Belgium)&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Cyber Resilience Act (CRA)&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Primary focus&lt;/td&gt; 
        &lt;td&gt;Organizational cybersecurity &amp;amp; service continuity.&lt;/td&gt; 
        &lt;td&gt;Security of products with digital elements.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Main addressees&lt;/td&gt; 
        &lt;td&gt;Operators of essential and important services (entities).&lt;/td&gt; 
        &lt;td&gt;Manufacturers, importers, distributors of digital products.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Scope logic&lt;/td&gt; 
        &lt;td&gt;Sector + size thresholds; some exceptions for critical players.&lt;/td&gt; 
        &lt;td&gt;Product classification (criticality, use, connectivity).&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Key 2026 trigger&lt;/td&gt; 
        &lt;td&gt;18 Apr 2026: CyFun/ISO verification deadline.&lt;/td&gt; 
        &lt;td&gt;11 Jun 2026 + 11 Sep 2026: CAB notification &amp;amp; reporting duties.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Reporting destination&lt;/td&gt; 
        &lt;td&gt;National CCB (Safeonweb@Work).&lt;/td&gt; 
        &lt;td&gt;ENISA + national CSIRTs.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Typical Belgian examples&lt;/td&gt; 
        &lt;td&gt;Hospitals, utilities, banks, public administrations, large logistics hubs, cloud-providers.&lt;/td&gt; 
        &lt;td&gt;Software vendors, IoT manufacturers, industrial equipment makers, connected consumer products.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For many mid‑sized Belgian tech companies, both will apply. Example:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A SaaS vendor operating a cloud platform &lt;strong&gt;that processes data from products with digital elements&lt;/strong&gt; may be in scope under NIS2 (digital provider + supply chain) and CRA (product with digital elements).&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In that case, NIS2 shapes &lt;strong&gt;how you secure your organization&lt;/strong&gt;, while CRA shapes &lt;strong&gt;how you design, maintain and support your product&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Other 2026 regulations in the background&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While NIS2 and CRA take center stage for most Belgian organizations, three other regulations deserve a place on your 2026 radar.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.1 DORA – for financial services and their ICT suppliers&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;strong&gt;Digital Operational Resilience Act (DORA)&lt;/strong&gt; has applied since &lt;strong&gt;17 January 2025&lt;/strong&gt; and sets uniform rules for ICT risk management, incident reporting, resilience testing and third‑party risk in financial services.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Scope includes banks, insurers, payment institutions, investment firms, funds and &lt;strong&gt;critical ICT third‑party providers&lt;/strong&gt;.&lt;/li&gt; 
      &lt;li&gt;Belgian entities are supervised mainly by the NBB and FSMA.&lt;/li&gt; 
      &lt;li&gt;DORA penalties in several EU countries go up to the higher of €5–10 million or a percentage of turnover; Belgium sits mid‑pack with significant, but proportionate, fines.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;For Belgian FinTech’s and ICT providers with financial clients, DORA and NIS2 will increasingly be discussed in the same RFPs and audits.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.2 AI Act – 2026 is go‑live for high‑risk AI&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;strong&gt;AI Act&lt;/strong&gt; entered into force in 2024; most obligations for &lt;strong&gt;high‑risk AI systems&lt;/strong&gt; (e.g. credit scoring, certain HR tools, remote biometric identification) will apply &lt;strong&gt;from August 2026&lt;/strong&gt;.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;High‑risk systems must meet requirements on risk management, data governance, transparency, human oversight, and robustness.&lt;/li&gt; 
      &lt;li&gt;Fines can reach up to €35 million or 7% of global turnover for prohibited practices.&lt;/li&gt; 
      &lt;li&gt;For Belgian organizations, the DPA and sector regulators are expected to share enforcement, but the exact institutional set‑up is still emerging.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.3 GDPR – faster procedures, focused actions&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;GDPR itself doesn’t change in 2026, but &lt;strong&gt;enforcement dynamics&lt;/strong&gt; do:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A new &lt;strong&gt;GDPR Procedural Regulation&lt;/strong&gt; streamlines cross‑border enforcement with indicative 15‑month resolution timelines (extendable for complex cases).&lt;/li&gt; 
      &lt;li&gt;The 2026 coordinated enforcement action at EU level focuses on transparency obligations (Articles 12–14), which will impact how Belgian organizations draft notices and communicate with data subjects.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;In practice, this means GDPR investigations should become faster and more predictable—while still potentially costly.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;4.4 CER-Law&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;On 18 December 2025, Belgium adopted the CER Law, implementing the European CER Directive to strengthen the resilience of critical entities and essential services. The law establishes a harmonized framework to protect against natural, accidental, and intentional threats. It requires&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;risk assessments at both sectoral and entity level;&lt;/li&gt; 
      &lt;li&gt;identification of critical entities and infrastructure;&lt;/li&gt; 
      &lt;li&gt;resilience planning;&lt;/li&gt; 
      &lt;li&gt;and information-sharing procedures.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The&amp;nbsp;National Crisis Center&amp;nbsp;coordinates its implementation. The NIS2 Directive stipulates that all critical entities falling under the CER Directive are automatically designated as essential entities under NIS2. This means that if you are currently classified as an important entity under NIS2, you could still become an essential entity if you meet the criteria of the CER framework.&lt;/p&gt; 
     &lt;p&gt;However, CER excludes obligations that are already covered under NIS2 and does not apply to the digital infrastructure or the financial sector.&lt;/p&gt; 
     &lt;p&gt;It is expected that the list of companies which need to comply with the CER law will be drawn up by July 2026.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. How Belgian organizations can move from “reaction” to “strategy”&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Given the overlapping timelines, the key is to avoid treating each regulation as a separate project. The most effective Belgian organizations are doing three things:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Scope once, use many times&lt;br&gt; &lt;br&gt;&lt;/strong&gt;Map your business against NIS2, CRA, DORA, AI Act and GDPR in a single exercise. Identify which entities, products and processes sit at the intersection (e.g. a SaaS product used by a bank and classified as high‑risk AI).&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Build on a strong backbone (CyFun &amp;amp; ISO 27001)&lt;br&gt; &lt;br&gt;&lt;/strong&gt;Use &lt;strong&gt;CyberFundamentals&lt;/strong&gt; and/or &lt;strong&gt;ISO 27001&lt;/strong&gt; as your common governance backbone. Both align closely with NIS2, support DORA and CRA preparation, and give you a consistent way to show your board and regulators that you’re in control. But if you are working in an international context, the ISO-route is certainly preferrable.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Integrate product security early&lt;br&gt; &lt;br&gt;&lt;/strong&gt;For CRA‑relevant companies, &lt;strong&gt;assess your development practices using OWASP SAMM and build a roadmap towards a secure development lifecycle.&lt;/strong&gt; This will allow you to gradually bring threat modeling, SBOMs and secure development practices into the SDLC now, not in late 2026, making CRA compliance a natural outcome of your engineering processes rather than a bolt‑on.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Use available support&lt;br&gt; &lt;br&gt;&lt;/strong&gt;In Flanders, VLAIO subsidies—and specific programs developed with partners like Toreon—can cover a significant portion of the cost of your NIS2‑driven security improvement trajectory. Sectoral initiatives like the CYSSDE EU pentesting program further help critical entities strengthen their posture at reduced cost.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;If you’re unsure whether NIS2, CRA—or both—apply to your organization, the worst option in 2026 is to wait. Determining your scope, mapping your gaps and building a realistic roadmap now will cost far less than rushing to catch up under regulatory pressure later. &lt;strong&gt;Toreon is a selected partner of VLAIO to support these trajectories and has already accumulated over 100 projects subsidized by VLAIO.&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Learn more about the VLAIO-subidies&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2F2026-the-year-cyber-compliance-becomes-mandatory&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>CRA</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <category>Compliance</category>
      <category>NIS2</category>
      <category>Toreon Cyber Insights</category>
      <pubDate>Thu, 19 Feb 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/2026-the-year-cyber-compliance-becomes-mandatory</guid>
      <dc:date>2026-02-19T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Grid Congestion, Risk Assessment &amp; Resilience: How Governance Secures Business Continuity</title>
      <link>https://staging.toreon.com/en/insights/blogs/grid-congestion-risk-assessment-and-resilience-why-governance-matters</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/grid-congestion-risk-assessment-and-resilience-why-governance-matters" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-3-1.png" alt="Grid Congestion, Risk Assessment &amp;amp; Resilience: How Governance Secures Business Continuity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The recent meeting with Flux50 members on grid congestion, risk assessment, and building resilient energy systems shows that these themes are inextricably linked. The challenges in the Flemish (and broader European) energy landscape are no longer hypothetical: grid congestion is no longer a question of “if,” but of “when.” Companies are facing a rapidly changing grid, growing electrification, an increase in renewable energy, and aging infrastructure. The consequences of these developments affect not only business continuity, but also economic growth and the competitiveness of entire regions. Our Business Area Lead Consultant, &lt;a href="https://www.linkedin.com/in/vincenthaerinck/"&gt;Vincent Haerinck&lt;/a&gt;, represented Toreon at the meeting.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://flux50.com/"&gt;&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;The Link Between Grid Congestion and Risk&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grid congestion means that, at peak times, the electricity grid can no longer cope with demand or supply. This leads to waiting times for new connections, limitations on expansions, and potential production losses. As the speakers pointed out, this has a direct economic impact: companies that cannot expand or produce lose revenue and competitive strength. Examples from the Netherlands clearly show that Flanders is not immune to this issue.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Building Resilience: Practical Solutions&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The use of batteries, smart control systems, and hybrid solutions was discussed as a way to protect business processes against grid outages or peak loads. However, technology is only one side of the story. Properly sizing backup systems, identifying critical assets, and anticipating future energy needs require a well-thought-out approach. This is where governance comes into play.&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Importance of Governance in Risk Assessment&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The core message from the risk assessment segment is that solid governance is essential not only to identify risks, but also to manage them structurally. This means:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Working with formal or semi-formal risk management systems (for example, in line with ISO standards)&lt;/li&gt; 
      &lt;li&gt;Periodically evaluating risks and adjusting plans to changing circumstances&lt;/li&gt; 
      &lt;li&gt;Risks are not limited to cybersecurity alone; due to the increasing digitalization of platforms and control systems across all components of production equipment, this can no longer be overlooked when safeguarding production capacity and overall business operations&lt;/li&gt; 
      &lt;li&gt;Involving all stakeholders: from CEO to plant manager, each with their own risk profile and priorities&lt;/li&gt; 
      &lt;li&gt;Assigning clear roles, responsibilities, and resources&lt;/li&gt; 
      &lt;li&gt;Striving not only for compliance, but also for trust and resilience&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Risk management is not a one-off exercise, but a continuous, iterative process that enables companies to remain flexible and resilient. Without this governance, even the best technology is insufficient to guarantee business continuity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion: From Reactive to Proactive&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The common thread throughout the meeting? Successful companies do not wait for things to go wrong; they invest in governance, risk management, and resilience before it becomes necessary. By addressing grid congestion, risk, and resilience in an integrated way and embedding them in business operations, organizations can not only absorb disruptions, but also gain strategic advantage from the energy transition.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Want to know how to concretely embed governance and risk assessment in your organization?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/vincent-haerinck"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Speaker: Vincent Haerinck&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Vincent Haerinck is a Principal Consultant at Toreon, an Antwerp-based cyberconsulting firm. With a deep focus on industrial cybersecurity, Vincent specializes in bridging the gap between Operational Technology (OT) and Information Technology (IT). He helps organizations navigate complex security challenges, ranging from supply chain security to compliance with emerging European regulations like NIS2 and the &lt;a href="https://www.toreon.com/our-services/cra-compliance/"&gt;Cyber Resilience Act&lt;/a&gt; (CRA).&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/grid-congestion-risk-assessment-and-resilience-why-governance-matters" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-3-1.png" alt="Grid Congestion, Risk Assessment &amp;amp; Resilience: How Governance Secures Business Continuity" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The recent meeting with Flux50 members on grid congestion, risk assessment, and building resilient energy systems shows that these themes are inextricably linked. The challenges in the Flemish (and broader European) energy landscape are no longer hypothetical: grid congestion is no longer a question of “if,” but of “when.” Companies are facing a rapidly changing grid, growing electrification, an increase in renewable energy, and aging infrastructure. The consequences of these developments affect not only business continuity, but also economic growth and the competitiveness of entire regions. Our Business Area Lead Consultant, &lt;a href="https://www.linkedin.com/in/vincenthaerinck/"&gt;Vincent Haerinck&lt;/a&gt;, represented Toreon at the meeting.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://flux50.com/"&gt;&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;The Link Between Grid Congestion and Risk&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grid congestion means that, at peak times, the electricity grid can no longer cope with demand or supply. This leads to waiting times for new connections, limitations on expansions, and potential production losses. As the speakers pointed out, this has a direct economic impact: companies that cannot expand or produce lose revenue and competitive strength. Examples from the Netherlands clearly show that Flanders is not immune to this issue.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Building Resilience: Practical Solutions&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The use of batteries, smart control systems, and hybrid solutions was discussed as a way to protect business processes against grid outages or peak loads. However, technology is only one side of the story. Properly sizing backup systems, identifying critical assets, and anticipating future energy needs require a well-thought-out approach. This is where governance comes into play.&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Importance of Governance in Risk Assessment&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The core message from the risk assessment segment is that solid governance is essential not only to identify risks, but also to manage them structurally. This means:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Working with formal or semi-formal risk management systems (for example, in line with ISO standards)&lt;/li&gt; 
      &lt;li&gt;Periodically evaluating risks and adjusting plans to changing circumstances&lt;/li&gt; 
      &lt;li&gt;Risks are not limited to cybersecurity alone; due to the increasing digitalization of platforms and control systems across all components of production equipment, this can no longer be overlooked when safeguarding production capacity and overall business operations&lt;/li&gt; 
      &lt;li&gt;Involving all stakeholders: from CEO to plant manager, each with their own risk profile and priorities&lt;/li&gt; 
      &lt;li&gt;Assigning clear roles, responsibilities, and resources&lt;/li&gt; 
      &lt;li&gt;Striving not only for compliance, but also for trust and resilience&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Risk management is not a one-off exercise, but a continuous, iterative process that enables companies to remain flexible and resilient. Without this governance, even the best technology is insufficient to guarantee business continuity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion: From Reactive to Proactive&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The common thread throughout the meeting? Successful companies do not wait for things to go wrong; they invest in governance, risk management, and resilience before it becomes necessary. By addressing grid congestion, risk, and resilience in an integrated way and embedding them in business operations, organizations can not only absorb disruptions, but also gain strategic advantage from the energy transition.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Want to know how to concretely embed governance and risk assessment in your organization?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/vincent-haerinck"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Speaker: Vincent Haerinck&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Vincent Haerinck is a Principal Consultant at Toreon, an Antwerp-based cyberconsulting firm. With a deep focus on industrial cybersecurity, Vincent specializes in bridging the gap between Operational Technology (OT) and Information Technology (IT). He helps organizations navigate complex security challenges, ranging from supply chain security to compliance with emerging European regulations like NIS2 and the &lt;a href="https://www.toreon.com/our-services/cra-compliance/"&gt;Cyber Resilience Act&lt;/a&gt; (CRA).&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fgrid-congestion-risk-assessment-and-resilience-why-governance-matters&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Tue, 27 Jan 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/grid-congestion-risk-assessment-and-resilience-why-governance-matters</guid>
      <dc:date>2026-01-27T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Artes Group Boosts Cyber Resilience with Red Teaming | Toreon</title>
      <link>https://staging.toreon.com/en/insights/blogs/artes-group-red-teaming-with-toreon</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/artes-group-red-teaming-with-toreon" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-2-1.png" alt="Artes Group Boosts Cyber Resilience with Red Teaming | Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;a href="https://artesgroup.be/"&gt;Artes Group&lt;/a&gt; is a construction consortium that includes various sister companies covering all key domains, from civil engineering, hydraulic engineering to petrochemistry, buildings and restoration. The group prides itself on challenging construction assignments and unique construction sites, requiring both creativity and ingenuity. Its many realizations and yards include the famous Brussels Palace of Justice, The Oosterweel Link, landmark bridges, train stations and many more.&lt;/p&gt; 
     &lt;p&gt;Heavily relying on IT to support its complex projects, Artes Group wanted an assessment to validate its investments in cyber security and identify any significant gaps in its security posture. Feeling that traditional security audits no longer shed enough light on their risks, the company chose to have its systems ethically tested and selected Toreon for a red team engagement.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Check out the latest Toreon Cyber Insights articles&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;IT as a backbone for a diverse construction group&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Artes Group’s internal IT department supports all group entities and sister companies, respecting their unique needs and identities. From workstation provisioning and support for tender calculation to financial systems and technology for logistics coordination and yard collaboration, the IT team is responsible for a wide range of services.&lt;/p&gt; 
     &lt;p&gt;Bjorn Lagace, IT manager at Artes Group: “Each construction yard is like a small company… sometimes up to more than 100 people need to work together seamlessly on one project. And it’s our job to provide and support technology that enables them to do their job.”&lt;/p&gt; 
     &lt;p&gt;Despite being a relatively small team, the IT department led by Bjorn combines system engineering, application expertise, and service desk operations. The team is forward-looking, investing in training and exploring the practical use of modern technology like AI to improve business effectiveness. Their work over the past years has significantly strengthened the company’s IT foundation.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;From best-practice security to resilience testing&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;After years of building and refining their IT landscape, Artes Group reached a point where deeper insights were needed to steer their long-term cybersecurity roadmap. Traditional audits had helped but felt incomplete. “Although you learn from audits, you’re left with the feeling that they’ve overlooked something. That’s why we decided to put ourselves really to the test by having ourselves ethically hacked,” Bjorn Lagace explained.&lt;/p&gt; 
     &lt;p&gt;Artes Group wanted to simulate realistic attack scenarios that would challenge both their cloud and on-premise environments. The goal: identify blind spots, validate strengths, and gain tangible input for strategic planning. In short, they wanted to measure their resilience, not just check compliance boxes.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;A red teaming partner offering expertise, transparency and cultural fit&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Artes Group approached several specialized companies to propose this red team engagement, leading to a shortlist of three. The final choice fell on &lt;a href="https://www.toreon.com/"&gt;Toreon&lt;/a&gt;, which ultimately stood out because of their transparent communication, demonstrated expertise, well-substantiated and correctly priced proposal, and a detailed explanation of the work they would perform.&lt;/p&gt; 
     &lt;p&gt;Bjorn Lagace: “&lt;em&gt;The maturity of Toreon’s consultants played a decisive role. Their professionalism convinced us we had found the right partner. Toreon’s approach resonated with our own mindset: ambitious, practical, and grounded. This cultural fit helped guide our choice.&lt;/em&gt;”&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Purpose-built testing backed by structured, transparent communication&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Toreon kicked off the assignment by thoroughly reviewing Artes Group’s environment and tailoring the test scenarios accordingly. They focused efforts only where meaningful improvements could be uncovered, adjusting the scope based on Artes Group’s infrastructure and business realities.&lt;/p&gt; 
     &lt;p&gt;Communication and planning proved to be key strengths in the approach. Every step was prepared, communicated, and executed with discipline while remaining flexible to Artes Group’s availability. Agreements were clear, timelines were respected, and expectations were consistently managed.&lt;/p&gt; 
     &lt;p&gt;“&lt;em&gt;All findings were documented in reports that were both detailed and accessible. Toreon explained how each incident was discovered, why it mattered, and how it could be remediated. During follow-up sessions, Toreon consultants explored the reports in depth. This transparent dialogue contributed strongly to a positive collaboration and outcome&lt;/em&gt;,” Bjorn Lagace clarified.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Actionable results with rapid follow-through&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Toreon’s method categorizes incidents and risks based on severity. Artes Group and Toreon agreed in advance that any critical incident would trigger immediate contact. During the exercise, two critical findings were uncovered in connection with one of Artes Group’s external partners. These were escalated right away and swiftly resolved, issues Artes Group acknowledges would have been difficult to detect themselves. Beyond the few critical issues, all other observations were neatly categorized, documented, and explained.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Strategic value through insight, planning and partner alignment&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The ethical hacking exercise yielded a level of visibility far exceeding that of traditional audits. It provided Artes Group with a facts-based foundation to refine both short- and long-term security plans. It also surfaced lessons about supplier management. With some incidents tied to partners, Artes Group initiated constructive conversations with two of them – supported by the documentation Toreon had provided.“The exercise helped us engage in dialogue with our partners and support them. If a supplier has a problem, we also have a problem,” Bjorn Lagace added.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Ethical hacking as an essential complement to traditional audits&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For Artes Group, the read teaming engagement led by Toreon demonstrated the tangible value of testing, not just implementing, security measures. It reinforced the idea that resilience requires putting systems, processes, as well as people to the test.&lt;/p&gt; 
     &lt;p&gt;As Bjorn Lagace put it: “&lt;em&gt;To measure is to know. You can only be sure by testing, and what better way to do that than through ethical hacking? A cybersecurity audit alone is not waterproof. Therefore, I advise every company to do a red teaming exercise at some point.&lt;/em&gt;”&lt;/p&gt; 
     &lt;p&gt;By deliberately allowing themselves to be attacked under controlled conditions, Artes Group achieved a realistic assessment of their readiness and gained insights that traditional audits could not provide. The collaboration with Toreon resulted in improved plans, better partner engagement, and a stronger overall security posture.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Contact us!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/artes-group-red-teaming-with-toreon" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-2-1.png" alt="Artes Group Boosts Cyber Resilience with Red Teaming | Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;a href="https://artesgroup.be/"&gt;Artes Group&lt;/a&gt; is a construction consortium that includes various sister companies covering all key domains, from civil engineering, hydraulic engineering to petrochemistry, buildings and restoration. The group prides itself on challenging construction assignments and unique construction sites, requiring both creativity and ingenuity. Its many realizations and yards include the famous Brussels Palace of Justice, The Oosterweel Link, landmark bridges, train stations and many more.&lt;/p&gt; 
     &lt;p&gt;Heavily relying on IT to support its complex projects, Artes Group wanted an assessment to validate its investments in cyber security and identify any significant gaps in its security posture. Feeling that traditional security audits no longer shed enough light on their risks, the company chose to have its systems ethically tested and selected Toreon for a red team engagement.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Check out the latest Toreon Cyber Insights articles&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/designing-cyber-governance-board-structures-and-practices-for-effective-oversight/"&gt;Board Structures and Practices for Effective Oversight&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;IT as a backbone for a diverse construction group&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Artes Group’s internal IT department supports all group entities and sister companies, respecting their unique needs and identities. From workstation provisioning and support for tender calculation to financial systems and technology for logistics coordination and yard collaboration, the IT team is responsible for a wide range of services.&lt;/p&gt; 
     &lt;p&gt;Bjorn Lagace, IT manager at Artes Group: “Each construction yard is like a small company… sometimes up to more than 100 people need to work together seamlessly on one project. And it’s our job to provide and support technology that enables them to do their job.”&lt;/p&gt; 
     &lt;p&gt;Despite being a relatively small team, the IT department led by Bjorn combines system engineering, application expertise, and service desk operations. The team is forward-looking, investing in training and exploring the practical use of modern technology like AI to improve business effectiveness. Their work over the past years has significantly strengthened the company’s IT foundation.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;From best-practice security to resilience testing&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;After years of building and refining their IT landscape, Artes Group reached a point where deeper insights were needed to steer their long-term cybersecurity roadmap. Traditional audits had helped but felt incomplete. “Although you learn from audits, you’re left with the feeling that they’ve overlooked something. That’s why we decided to put ourselves really to the test by having ourselves ethically hacked,” Bjorn Lagace explained.&lt;/p&gt; 
     &lt;p&gt;Artes Group wanted to simulate realistic attack scenarios that would challenge both their cloud and on-premise environments. The goal: identify blind spots, validate strengths, and gain tangible input for strategic planning. In short, they wanted to measure their resilience, not just check compliance boxes.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;A red teaming partner offering expertise, transparency and cultural fit&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Artes Group approached several specialized companies to propose this red team engagement, leading to a shortlist of three. The final choice fell on &lt;a href="https://www.toreon.com/"&gt;Toreon&lt;/a&gt;, which ultimately stood out because of their transparent communication, demonstrated expertise, well-substantiated and correctly priced proposal, and a detailed explanation of the work they would perform.&lt;/p&gt; 
     &lt;p&gt;Bjorn Lagace: “&lt;em&gt;The maturity of Toreon’s consultants played a decisive role. Their professionalism convinced us we had found the right partner. Toreon’s approach resonated with our own mindset: ambitious, practical, and grounded. This cultural fit helped guide our choice.&lt;/em&gt;”&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Purpose-built testing backed by structured, transparent communication&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Toreon kicked off the assignment by thoroughly reviewing Artes Group’s environment and tailoring the test scenarios accordingly. They focused efforts only where meaningful improvements could be uncovered, adjusting the scope based on Artes Group’s infrastructure and business realities.&lt;/p&gt; 
     &lt;p&gt;Communication and planning proved to be key strengths in the approach. Every step was prepared, communicated, and executed with discipline while remaining flexible to Artes Group’s availability. Agreements were clear, timelines were respected, and expectations were consistently managed.&lt;/p&gt; 
     &lt;p&gt;“&lt;em&gt;All findings were documented in reports that were both detailed and accessible. Toreon explained how each incident was discovered, why it mattered, and how it could be remediated. During follow-up sessions, Toreon consultants explored the reports in depth. This transparent dialogue contributed strongly to a positive collaboration and outcome&lt;/em&gt;,” Bjorn Lagace clarified.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Actionable results with rapid follow-through&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Toreon’s method categorizes incidents and risks based on severity. Artes Group and Toreon agreed in advance that any critical incident would trigger immediate contact. During the exercise, two critical findings were uncovered in connection with one of Artes Group’s external partners. These were escalated right away and swiftly resolved, issues Artes Group acknowledges would have been difficult to detect themselves. Beyond the few critical issues, all other observations were neatly categorized, documented, and explained.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Strategic value through insight, planning and partner alignment&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The ethical hacking exercise yielded a level of visibility far exceeding that of traditional audits. It provided Artes Group with a facts-based foundation to refine both short- and long-term security plans. It also surfaced lessons about supplier management. With some incidents tied to partners, Artes Group initiated constructive conversations with two of them – supported by the documentation Toreon had provided.“The exercise helped us engage in dialogue with our partners and support them. If a supplier has a problem, we also have a problem,” Bjorn Lagace added.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Ethical hacking as an essential complement to traditional audits&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For Artes Group, the read teaming engagement led by Toreon demonstrated the tangible value of testing, not just implementing, security measures. It reinforced the idea that resilience requires putting systems, processes, as well as people to the test.&lt;/p&gt; 
     &lt;p&gt;As Bjorn Lagace put it: “&lt;em&gt;To measure is to know. You can only be sure by testing, and what better way to do that than through ethical hacking? A cybersecurity audit alone is not waterproof. Therefore, I advise every company to do a red teaming exercise at some point.&lt;/em&gt;”&lt;/p&gt; 
     &lt;p&gt;By deliberately allowing themselves to be attacked under controlled conditions, Artes Group achieved a realistic assessment of their readiness and gained insights that traditional audits could not provide. The collaboration with Toreon resulted in improved plans, better partner engagement, and a stronger overall security posture.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Contact us!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fartes-group-red-teaming-with-toreon&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Customer Stories</category>
      <category>Toreon News</category>
      <category>Toreon Cyber Insights</category>
      <pubDate>Sun, 18 Jan 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/artes-group-red-teaming-with-toreon</guid>
      <dc:date>2026-01-18T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>VLAIO Cybersecurity: 50% Subsidie &amp; Expertbegeleiding Toreon</title>
      <link>https://staging.toreon.com/en/insights/blogs/cybersecurity-groei-met-vlaio-en-toreon</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/cybersecurity-groei-met-vlaio-en-toreon" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/toreon-opgeknipt-3.png" alt="VLAIO Cybersecurity: 50% Subsidie &amp;amp; Expertbegeleiding Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Tot 50% gesubsidieerd via VLAIO&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Bent u een Vlaamse KMO en wilt u uw bedrijf beter beschermen tegen cyberdreigingen?&lt;/p&gt; 
     &lt;p&gt;Dankzij het VLAIO Cybersecurity verbetertraject kunt u als KMO tot 50% financiële steun krijgen voor professionele begeleiding. Grotere bedrijven die moeten voldoen aan de NIS2-regelgeving kunnen tot 35% financiële steun krijgen. Als door &lt;strong&gt;VLAIO erkend dienstverlener voor het 5e jaar op rij&lt;/strong&gt;, helpt Toreon u niet alleen uw cybermaturiteit te verhogen, maar nemen we ook de volledige subsidieaanvraag uit handen.&lt;/p&gt; 
     &lt;p&gt;Ontdek onze op maat gemaakte trajecten en beveilig uw organisatie zonder administratieve rompslomp.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/#form"&gt;Vraag een gratis adviesgesprek aan&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;13+ jaar expertise&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;90+ VLAIO trajecten afgewerkt&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;Meer dan 60 experten tot uw dienst&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/toreon-geselecteerd-als-vlaio-partner/"&gt;&lt;/a&gt;Vlaio helpt KMO's met 50% subsidies 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Waarom is een VLAIO Cybersecurity traject essentieel voor uw KMO?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Veel Vlaamse KMO’s erkennen het belang van een sterke digitale beveiliging, maar worstelen met beperkte tijd, budget of interne expertise. Het VLAIO Cybersecurity subsidieprogramma is speciaal ontworpen om deze drempels weg te nemen en professionele begeleiding toegankelijk te maken.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Iedere KMO moet zich beschermen.&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Niet alleen als je onderheving bent aan NIS2 of CRA is dit van belang.&amp;nbsp; Wij helpen uw algemene weerbaarheid te verhogen.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Cyberaanvallen op KMO’s stijgen het snelst&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;KMO’s zijn vaak de makkelijkste prooi.&amp;nbsp; Bereid u voor op ransomware-attacks en andere cyberrisico’s.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Maak Cybersecurity Betaalbaar met 50% VLAIO Subsidie&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Dit maakt cybersecurity plots zeer betaalbaar. Laat de administratie maar aan ons, we kunnen direct van start.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;* 50% geldt voor alle KMO's. Grotere bedrijven die aan NIS2 moeten voldoen, krijgen 35% subsidie binnen dit programma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Onze VLAIO-erkende Cybersecurity Diensten op Maat&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Iedere KMO is uniek, en daarom is een standaardaanpak voor cyberveiligheid niet effectief. Onze VLAIO verbetertrajecten zijn modulair opgebouwd. We starten met een grondige analyse en stellen vervolgens, op basis van uw specifieke noden en prioriteiten, een actieplan op maat samen. Hieronder vindt u de meest voorkomende uitdagingen waarvoor KMO’s onze hulp inschakelen&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Organisatie beter beschermen tegen cyberaanvallen&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Dit is een kritieke zorg voor veel KMO’s. Onze&amp;nbsp;&lt;strong&gt;START&lt;/strong&gt;&amp;nbsp;en&amp;nbsp;&lt;strong&gt;MEDIUM&lt;/strong&gt; pakketten focussen o.a. op:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Backupbescherming en disaster recovery planning&lt;/li&gt; 
      &lt;li&gt;Incidentresponscapaciteit opbouwen&lt;/li&gt; 
      &lt;li&gt;Endpoint protection en firewall-versterking&lt;/li&gt; 
      &lt;li&gt;Awareness training tegen phishing&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Voorbereiden op o.a. NIS2, CRA of andere regelgeving&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Als u leverancier bent van een NIS2-plichtig bedrijf of zelf onder de NIS2 of CRA reglementering valt, moet u voldoen aan strikte vereisten. Onze aanpak:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;CYFUN&lt;/b&gt;-gebaseerde assessments en roadmaps&lt;/li&gt; 
      &lt;li&gt;Compliance inbouwen in alle activiteiten&lt;/li&gt; 
      &lt;li&gt;Documentatie en beleid opzetten&lt;/li&gt; 
      &lt;li&gt;Regelmatige audits en verbetertrajecten&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Data bescherming &amp;amp; privacy verbeteren&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Databeveiliging is cruciaal in uw cloud-omgeving. Wij helpen met:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Dataclassificatie en labeling (GDPR/NIS2)&lt;/li&gt; 
      &lt;li&gt;Data Loss Prevention (DLP) implementatie&lt;/li&gt; 
      &lt;li&gt;Azure en M365 beveiligingshardening&lt;/li&gt; 
      &lt;li&gt;Zero Trust architectuurontwerp&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Incidentrespons &amp;amp; continuïteit versterken&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Bent u voorbereid op cyberincidenten? Wij zorgen ervoor dat u snel kunt reageren:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Incident response plans opstellen en testen&lt;/li&gt; 
      &lt;li&gt;Business continuity en disaster recovery planning&lt;/li&gt; 
      &lt;li&gt;Table-top exercises en crisis-simulaties&lt;/li&gt; 
      &lt;li&gt;Medewerkerstraining voor calamiteiten&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Microsoft 365 &amp;amp; cloud-omgeving veiliger maken&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;95% van onze klanten gebruiken Microsoft Cloud (M365/Azure). Speciale focus:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Microsoft 365 hardening volgens CIS benchmarks&lt;/li&gt; 
      &lt;li&gt;Azure infrastructure beveiging (Zero Trust)&lt;/li&gt; 
      &lt;li&gt;Conditional Access en MFA implementatie&lt;/li&gt; 
      &lt;li&gt;Cloud security scanning en monitoring&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toegangsbeheer &amp;amp; identiteiten verbeteren&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ongecontroleerde toegang leidt tot hacking. Wij beveiligen uw identiteitssystemen:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Multi-factor authentication (MFA) opzetten&lt;/li&gt; 
      &lt;li&gt;Role-based access control (RBAC) implementeren&lt;/li&gt; 
      &lt;li&gt;Paswoordloze verificatie introduceren&lt;/li&gt; 
      &lt;li&gt;Logging en monitoring van toegang&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wil u alvast meer te weten komen?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek zelf hoe de VLAIO trajecten u kunnen helpen. Lees er meer over in onze gratis te downloaden ebooks.&lt;/p&gt; 
     &lt;p&gt;Of u nu eigenaar bent van een KMO en uw weerbaarheid wil verhogen, of maker bent van producten en u beter wil voorbereiden op de CRA. Onze ebooks leggen u uit hoe u best te werk kan gaan.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-kmo/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-products/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Kies uw gesubsidieerd VLAIO Cybersecurity traject&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Wij bieden drie door VLAIO goedgekeurde cybersecurity verbetertrajecten aan, elk ontworpen voor een ander maturiteitsniveau. Alle pakketten starten met een verplicht assessment en bieden de flexibiliteit om de focus te leggen op wat voor uw bedrijf het belangrijkst is. De vermelde prijzen zijn na aftrek van 50% VLAIO-subsidie.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Start&lt;/h3&gt; Voor bedrijven die een eerste risicobeeld willen 
      &lt;/div&gt; 
      &lt;div&gt;
        € 5.950 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledig cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Op basis van de CyberFundamentals zoals voorgeschreven door de federale overheid. 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Technische veiligheidstests 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Security roadmap met prioriteiten 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 3 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Medium&lt;/h3&gt; Het complete pakket voor groeiende bedrijven 
      &lt;/div&gt; 
      &lt;div&gt;
        € 14.275 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledige cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Voorgeschreven opstart-fase 
         &lt;br&gt; + ruim pakket vrij besteedbare credits* 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Praktische beveilingsverbeteringen 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          NIS2-compliance voorbereiding 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 6 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt;
        Populairst 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Plus&lt;/h3&gt; Voor bedrijven met strenge beveiligingsvoorwaarden 
      &lt;/div&gt; 
      &lt;div&gt;
        € 19.950 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledig cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Voorgeschreven opstart-fase 
         &lt;br&gt; + een ruimere keuze om nog meer credits* te gebruiken 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Diepgaande beveilingsverbeteringen 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledige CYFUN-compliance 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 9 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Kies uit 30+ concrete bouwstenen &lt;br&gt; voor cybersecurity-verbeteringen&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In elk Medium- of Plus-traject krijgt u, naast een verplicht assessment, toegang tot een extra aantal dagen (uitgedrukt in credits).&amp;nbsp; Deze credits gebruikt u om exact die verbeteringen te kiezen uit ons uitgebreid menu diensten die voor uw KMO het meest waardevol zijn.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;Hier zijn enkele voorbeelden van uw bouwstenen naar een hogere cybersecurity maturiteit.&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Continue kwetsbaarheidsscans&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Implementatie van Data Loss Prevention (DLP) en dataklassificatie (GDPR/NIS2)&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Access control&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Multi-factor authentication en voorwaardelijke toegang implementeren in M365/Azure&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Cloud security&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Microsoft Cloud infrastructure beveiligen volgens CIS Benchmarks&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Data-protection&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Voortdurende externe vulnerability-scanning en 3rd-party riskmanagement&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Incident response&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Incidentplan opstellen, simulatie-oefeningen tests en table-top exercises&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Awareness &amp;amp; anti-phishing training&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grondige awareness- en anti-phishing-training voor uw medewerkers&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Backup &amp;amp; disaster recovery&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Gevalideerde backup plans en disaster recovery procedures&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Security policies &amp;amp; governance&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Beveiligingsbeleid, ISMS opzetten, rollen &amp;amp; verantwoordelijkheden definiëren&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Ethisch Hacken (Pentesting)&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Penetratietesten voor infrastructuur, netwerk en eigen-ontwikkelde applicaties&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Er zijn nog meer dan 20 andere verbeteringsopties.&lt;/p&gt; 
     &lt;p&gt;Bij Medium en Plus pakketten kan u naast upgraden naar een hoger pakket, ook kiezen voor &lt;b&gt;uitbreidingspakketten&lt;/b&gt;&amp;nbsp;waardoor u, &lt;b&gt;met VLAIO-steun&lt;/b&gt;, nog verder kunt gaan. Deze opties kunnen max. tot 6 maanden na afronding aangevraagd worden.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wat onze klanten zeggen&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek hoe wij Vlaamse bedrijven hebben geholpen&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Toreon was de logische keuze omdat zij een gerenommeerd cybersecuritybedrijf zijn met diepgaande technische kennis. Dankzij onze samenwerking met Toreon werden mijn aannames bevestigd. We kregen waardevolle inzichten en een roadmap om van start te gaan.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Jan Tanghe&lt;/h4&gt; 
          &lt;p&gt;IT Team Lead @ Dewaele&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;De professionals van Toreon waren echt bereid om ons te leren kennen en deel te worden van het verhaal van Tobania, en dat hebben we enorm gewaardeerd.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Maya Vanderhaegen&lt;/h4&gt; 
          &lt;p&gt;Quality, Risk &amp;amp; CSR Manager @ Tobania&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Het doel was om te voldoen aan de strengste beveiligingseisen van de medische sector. Die inspanningen hebben ertoe geleid dat het bedrijf ISO 27001-certificering heeft ontvangen voor zijn volledige beveiligingsbeheer.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Georges De Feu&lt;/h4&gt; 
          &lt;p&gt;CEO @ Lynxcare&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;&lt;b&gt;Samen met bijna&lt;/b&gt;&lt;b&gt;100 anderen vertrouwden deze KMO’s Toreon&lt;/b&gt; om ze te begeleiden voor hun Cybersecurity-traject.&lt;/h4&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;FAQ&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Wat is het Vlaio Cybersecurity traject?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Een VLAIO Cybersecurity verbetertraject is een subsidieprogramma van de Vlaamse overheid, ontworpen om KMO’s financieel te ondersteunen bij het verhogen van hun digitale weerbaarheid. U kunt tot 50% subsidie krijgen voor advies en begeleiding van een door VLAIO erkende dienstverlener, zoals Toreon. Het doel is om, op basis van een bewezen framework zoals CYFUN, een concreet actieplan op te stellen en uit te voeren om uw cyberveiligheid te verbeteren.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Kom ik in aanmerking voor een VLAIO cybersecurity subsidie?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Als u voldoet aan de EU-definitie van KMO (Max. 250 FTE, 50M€ omzet, 43M€ balanstotaal), komt u in aanmerking en krijgt u 50% subsidie op de pakketten zoals hier gedefinieerd.&lt;/p&gt; 
        &lt;p&gt;Grotere bedrijven die aan NIS2 moeten voldoen komen uitzonderlijk ook in aanmerking, maar krijgen slechts 35% subsidie op hun traject.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe lang duurt een VLAIO cybersecurity traject gemiddeld?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;p&gt;De doorlooptijd varieert per pakket: het Start-pakket duurt maximaal 3 maanden, Medium maximaal 6 maanden en Plus maximaal 9 maanden.&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;p&gt;Dat is een doorlooptijd die wordt vooropgesteld om het gekozen traject te doorlopen, excl. de implementaties binnen de uitbreidingspakketten.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Wat is CRA, NIS2 en CYFUN?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;CRA en NIS2 zijn EU regelgevingen waaraan bepaalde bedrijven moeten voldoen.&lt;/p&gt; 
        &lt;p&gt;CYFUN is een manier voor bedrijven om hun cybersecurity maturiteit te verhogen. &amp;nbsp;CYFUN werd ontwikkeld door de CCB (Cybersecurity Center België) i.s.m. professionele experten uit de sector en diverse vakspecialisten in hun adviesraad, waaronder ook die van Toreon.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Moet ik zelf de subsidieaanvraag indienen bij VLAIO?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Nee, Toreon neemt de volledige administratie voor de subsidieaanvraag voor zijn rekening. Zo kunt u snel starten zonder extra paperwork, waarbij zij reeds tientallen KMO’s succesvol begeleid hebben.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Kan ik mijn VLAIO cybersecurity traject later upgraden naar een uitgebreider pakket?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Uiteraard. &amp;nbsp;De meeste bedrijven starten direct met een MEDIUM (of zelfs een PLUS) pakket. &amp;nbsp;Maar indien dat niet voldoende is en u een nog hoger maturiteitsniveau wil bereiken, kan u uw pakket upgraden, of op deze pakketten één van de uitbreidingspakketten nemen. Op deze pakketten geldt eveneens de 35% of 50% subsidie-regeling. Let er wel op dat een upgrade of uitbreiding binnen 6 maanden na afloop moet opgenomen worden.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe werkt het ‘credit’-systeem van Toreon?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Elk bedrijf is uniek. &amp;nbsp;Daarom zitten in onze pakketten, naast de door VLAIO verplichte elementen die worden afgedekt door de initiële implementatiedagen, ook een pakket Toreon-credits.&lt;/p&gt; 
        &lt;p&gt;Daarnaast biedt Toreon een menu van wel 30 opties om deze te gebruiken, puur in functie van uw unieke behoeften.&lt;/p&gt; 
        &lt;p&gt;Na de initiële fase zullen we samen bekijken hoe we de resterende credits het best inzetten om het meeste rendement uit uw investering te halen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Welke concrete verbeteringen kunnen KMO’s verwachten met VLAIO subsidie trajecten?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Verbeteringen omvatten onder meer vulnerability scans, multi-factor authenticatie, cloud security, data-protection, incident response planning, awareness-training, backup &amp;amp; disaster recovery en beveiligingsbeleid op maat.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Waarom is investeren in cybersecurity met VLAIO subsidie belangrijk voor KMO’s?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Cyberaanvallen op KMO’s stijgen snel en deze bedrijven missen vaak tijd, expertise of budget. Met VLAIO subsidie tot 50% wordt cybersecurity betaalbaar en helpt het uw digitale weerbaarheid tegen ransomware en andere risico’s te verhogen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe helpt Toreon KMO’s bij de voorbereiding op NIS2 en CRA regelgeving?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Toreon voert CYFUN-gebaseerde assessments uit, bouwt compliance in activiteiten in, zet documentatie en beleid op en verzorgt regelmatige audits en verbetertrajecten om te voldoen aan NIS2 en CRA verplichtingen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Waar moet ik op letten als ik aan NIS2 moet voldoen?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grotere bedrijven die aan NIS2 moeten voldoen kunnen ook genieten van 35% subsidie, als ze nog moeten starten aan het versterken van hun cybersecuritybeleid of nog niet beschikken over een CS-roadmap. Let er wel op dat deze bedrijven enkel beroep kunnen doen op een MEDIUM of PLUS pakket.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Start vandaag met het verbeteren van uw cybersecurity&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Neem vandaag contact op voor een gratis adviesgesprek. Wij leggen uit hoe u kunt starten met VLAIO-subsidie.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Lander Reynvoet&lt;/strong&gt;&lt;br&gt; Resp. VLAIO Project-Sales&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Margot Van Overtveldt&lt;/strong&gt;&lt;br&gt; VLAIO Project Coördinator&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Plan een gratis gesprek in&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/cybersecurity-groei-met-vlaio-en-toreon" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/toreon-opgeknipt-3.png" alt="VLAIO Cybersecurity: 50% Subsidie &amp;amp; Expertbegeleiding Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Tot 50% gesubsidieerd via VLAIO&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Bent u een Vlaamse KMO en wilt u uw bedrijf beter beschermen tegen cyberdreigingen?&lt;/p&gt; 
     &lt;p&gt;Dankzij het VLAIO Cybersecurity verbetertraject kunt u als KMO tot 50% financiële steun krijgen voor professionele begeleiding. Grotere bedrijven die moeten voldoen aan de NIS2-regelgeving kunnen tot 35% financiële steun krijgen. Als door &lt;strong&gt;VLAIO erkend dienstverlener voor het 5e jaar op rij&lt;/strong&gt;, helpt Toreon u niet alleen uw cybermaturiteit te verhogen, maar nemen we ook de volledige subsidieaanvraag uit handen.&lt;/p&gt; 
     &lt;p&gt;Ontdek onze op maat gemaakte trajecten en beveilig uw organisatie zonder administratieve rompslomp.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/#form"&gt;Vraag een gratis adviesgesprek aan&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;13+ jaar expertise&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;90+ VLAIO trajecten afgewerkt&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;Meer dan 60 experten tot uw dienst&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/toreon-geselecteerd-als-vlaio-partner/"&gt;&lt;/a&gt;Vlaio helpt KMO's met 50% subsidies 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Waarom is een VLAIO Cybersecurity traject essentieel voor uw KMO?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Veel Vlaamse KMO’s erkennen het belang van een sterke digitale beveiliging, maar worstelen met beperkte tijd, budget of interne expertise. Het VLAIO Cybersecurity subsidieprogramma is speciaal ontworpen om deze drempels weg te nemen en professionele begeleiding toegankelijk te maken.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Iedere KMO moet zich beschermen.&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Niet alleen als je onderheving bent aan NIS2 of CRA is dit van belang.&amp;nbsp; Wij helpen uw algemene weerbaarheid te verhogen.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Cyberaanvallen op KMO’s stijgen het snelst&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;KMO’s zijn vaak de makkelijkste prooi.&amp;nbsp; Bereid u voor op ransomware-attacks en andere cyberrisico’s.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Maak Cybersecurity Betaalbaar met 50% VLAIO Subsidie&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Dit maakt cybersecurity plots zeer betaalbaar. Laat de administratie maar aan ons, we kunnen direct van start.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;* 50% geldt voor alle KMO's. Grotere bedrijven die aan NIS2 moeten voldoen, krijgen 35% subsidie binnen dit programma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Onze VLAIO-erkende Cybersecurity Diensten op Maat&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Iedere KMO is uniek, en daarom is een standaardaanpak voor cyberveiligheid niet effectief. Onze VLAIO verbetertrajecten zijn modulair opgebouwd. We starten met een grondige analyse en stellen vervolgens, op basis van uw specifieke noden en prioriteiten, een actieplan op maat samen. Hieronder vindt u de meest voorkomende uitdagingen waarvoor KMO’s onze hulp inschakelen&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Organisatie beter beschermen tegen cyberaanvallen&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Dit is een kritieke zorg voor veel KMO’s. Onze&amp;nbsp;&lt;strong&gt;START&lt;/strong&gt;&amp;nbsp;en&amp;nbsp;&lt;strong&gt;MEDIUM&lt;/strong&gt; pakketten focussen o.a. op:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Backupbescherming en disaster recovery planning&lt;/li&gt; 
      &lt;li&gt;Incidentresponscapaciteit opbouwen&lt;/li&gt; 
      &lt;li&gt;Endpoint protection en firewall-versterking&lt;/li&gt; 
      &lt;li&gt;Awareness training tegen phishing&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Voorbereiden op o.a. NIS2, CRA of andere regelgeving&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Als u leverancier bent van een NIS2-plichtig bedrijf of zelf onder de NIS2 of CRA reglementering valt, moet u voldoen aan strikte vereisten. Onze aanpak:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;CYFUN&lt;/b&gt;-gebaseerde assessments en roadmaps&lt;/li&gt; 
      &lt;li&gt;Compliance inbouwen in alle activiteiten&lt;/li&gt; 
      &lt;li&gt;Documentatie en beleid opzetten&lt;/li&gt; 
      &lt;li&gt;Regelmatige audits en verbetertrajecten&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Data bescherming &amp;amp; privacy verbeteren&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Databeveiliging is cruciaal in uw cloud-omgeving. Wij helpen met:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Dataclassificatie en labeling (GDPR/NIS2)&lt;/li&gt; 
      &lt;li&gt;Data Loss Prevention (DLP) implementatie&lt;/li&gt; 
      &lt;li&gt;Azure en M365 beveiligingshardening&lt;/li&gt; 
      &lt;li&gt;Zero Trust architectuurontwerp&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Incidentrespons &amp;amp; continuïteit versterken&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Bent u voorbereid op cyberincidenten? Wij zorgen ervoor dat u snel kunt reageren:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Incident response plans opstellen en testen&lt;/li&gt; 
      &lt;li&gt;Business continuity en disaster recovery planning&lt;/li&gt; 
      &lt;li&gt;Table-top exercises en crisis-simulaties&lt;/li&gt; 
      &lt;li&gt;Medewerkerstraining voor calamiteiten&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Microsoft 365 &amp;amp; cloud-omgeving veiliger maken&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;95% van onze klanten gebruiken Microsoft Cloud (M365/Azure). Speciale focus:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Microsoft 365 hardening volgens CIS benchmarks&lt;/li&gt; 
      &lt;li&gt;Azure infrastructure beveiging (Zero Trust)&lt;/li&gt; 
      &lt;li&gt;Conditional Access en MFA implementatie&lt;/li&gt; 
      &lt;li&gt;Cloud security scanning en monitoring&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toegangsbeheer &amp;amp; identiteiten verbeteren&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ongecontroleerde toegang leidt tot hacking. Wij beveiligen uw identiteitssystemen:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Multi-factor authentication (MFA) opzetten&lt;/li&gt; 
      &lt;li&gt;Role-based access control (RBAC) implementeren&lt;/li&gt; 
      &lt;li&gt;Paswoordloze verificatie introduceren&lt;/li&gt; 
      &lt;li&gt;Logging en monitoring van toegang&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wil u alvast meer te weten komen?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek zelf hoe de VLAIO trajecten u kunnen helpen. Lees er meer over in onze gratis te downloaden ebooks.&lt;/p&gt; 
     &lt;p&gt;Of u nu eigenaar bent van een KMO en uw weerbaarheid wil verhogen, of maker bent van producten en u beter wil voorbereiden op de CRA. Onze ebooks leggen u uit hoe u best te werk kan gaan.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-kmo/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-products/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Kies uw gesubsidieerd VLAIO Cybersecurity traject&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Wij bieden drie door VLAIO goedgekeurde cybersecurity verbetertrajecten aan, elk ontworpen voor een ander maturiteitsniveau. Alle pakketten starten met een verplicht assessment en bieden de flexibiliteit om de focus te leggen op wat voor uw bedrijf het belangrijkst is. De vermelde prijzen zijn na aftrek van 50% VLAIO-subsidie.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Start&lt;/h3&gt; Voor bedrijven die een eerste risicobeeld willen 
      &lt;/div&gt; 
      &lt;div&gt;
        € 5.950 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledig cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Op basis van de CyberFundamentals zoals voorgeschreven door de federale overheid. 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Technische veiligheidstests 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Security roadmap met prioriteiten 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 3 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Medium&lt;/h3&gt; Het complete pakket voor groeiende bedrijven 
      &lt;/div&gt; 
      &lt;div&gt;
        € 14.275 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledige cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Voorgeschreven opstart-fase 
         &lt;br&gt; + ruim pakket vrij besteedbare credits* 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Praktische beveilingsverbeteringen 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          NIS2-compliance voorbereiding 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 6 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt;
        Populairst 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Plus&lt;/h3&gt; Voor bedrijven met strenge beveiligingsvoorwaarden 
      &lt;/div&gt; 
      &lt;div&gt;
        € 19.950 na VLAIO-subsidie 
      &lt;/div&gt; 
      &lt;ul&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledig cybersecurity assessment 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Voorgeschreven opstart-fase 
         &lt;br&gt; + een ruimere keuze om nog meer credits* te gebruiken 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Diepgaande beveilingsverbeteringen 
        &lt;/div&gt;&lt;/li&gt; 
       &lt;li&gt; 
        &lt;div&gt;
          Volledige CYFUN-compliance 
        &lt;/div&gt;&lt;/li&gt; 
      &lt;/ul&gt; 
      &lt;div&gt; 
       &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Vraag meer informatie aan&lt;/a&gt; 
       &lt;div&gt;
         Looptijd: max. 9 maanden 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Kies uit 30+ concrete bouwstenen &lt;br&gt; voor cybersecurity-verbeteringen&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In elk Medium- of Plus-traject krijgt u, naast een verplicht assessment, toegang tot een extra aantal dagen (uitgedrukt in credits).&amp;nbsp; Deze credits gebruikt u om exact die verbeteringen te kiezen uit ons uitgebreid menu diensten die voor uw KMO het meest waardevol zijn.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;Hier zijn enkele voorbeelden van uw bouwstenen naar een hogere cybersecurity maturiteit.&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Continue kwetsbaarheidsscans&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Implementatie van Data Loss Prevention (DLP) en dataklassificatie (GDPR/NIS2)&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Access control&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Multi-factor authentication en voorwaardelijke toegang implementeren in M365/Azure&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Cloud security&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Microsoft Cloud infrastructure beveiligen volgens CIS Benchmarks&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Data-protection&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Voortdurende externe vulnerability-scanning en 3rd-party riskmanagement&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Incident response&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Incidentplan opstellen, simulatie-oefeningen tests en table-top exercises&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Awareness &amp;amp; anti-phishing training&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grondige awareness- en anti-phishing-training voor uw medewerkers&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Backup &amp;amp; disaster recovery&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Gevalideerde backup plans en disaster recovery procedures&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Security policies &amp;amp; governance&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Beveiligingsbeleid, ISMS opzetten, rollen &amp;amp; verantwoordelijkheden definiëren&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Ethisch Hacken (Pentesting)&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Penetratietesten voor infrastructuur, netwerk en eigen-ontwikkelde applicaties&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Er zijn nog meer dan 20 andere verbeteringsopties.&lt;/p&gt; 
     &lt;p&gt;Bij Medium en Plus pakketten kan u naast upgraden naar een hoger pakket, ook kiezen voor &lt;b&gt;uitbreidingspakketten&lt;/b&gt;&amp;nbsp;waardoor u, &lt;b&gt;met VLAIO-steun&lt;/b&gt;, nog verder kunt gaan. Deze opties kunnen max. tot 6 maanden na afronding aangevraagd worden.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wat onze klanten zeggen&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek hoe wij Vlaamse bedrijven hebben geholpen&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Toreon was de logische keuze omdat zij een gerenommeerd cybersecuritybedrijf zijn met diepgaande technische kennis. Dankzij onze samenwerking met Toreon werden mijn aannames bevestigd. We kregen waardevolle inzichten en een roadmap om van start te gaan.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Jan Tanghe&lt;/h4&gt; 
          &lt;p&gt;IT Team Lead @ Dewaele&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;De professionals van Toreon waren echt bereid om ons te leren kennen en deel te worden van het verhaal van Tobania, en dat hebben we enorm gewaardeerd.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Maya Vanderhaegen&lt;/h4&gt; 
          &lt;p&gt;Quality, Risk &amp;amp; CSR Manager @ Tobania&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Het doel was om te voldoen aan de strengste beveiligingseisen van de medische sector. Die inspanningen hebben ertoe geleid dat het bedrijf ISO 27001-certificering heeft ontvangen voor zijn volledige beveiligingsbeheer.&lt;/p&gt; 
        &lt;/div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
         &lt;/div&gt; 
         &lt;div&gt; 
          &lt;h4&gt;Georges De Feu&lt;/h4&gt; 
          &lt;p&gt;CEO @ Lynxcare&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;&lt;b&gt;Samen met bijna&lt;/b&gt;&lt;b&gt;100 anderen vertrouwden deze KMO’s Toreon&lt;/b&gt; om ze te begeleiden voor hun Cybersecurity-traject.&lt;/h4&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;FAQ&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Wat is het Vlaio Cybersecurity traject?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Een VLAIO Cybersecurity verbetertraject is een subsidieprogramma van de Vlaamse overheid, ontworpen om KMO’s financieel te ondersteunen bij het verhogen van hun digitale weerbaarheid. U kunt tot 50% subsidie krijgen voor advies en begeleiding van een door VLAIO erkende dienstverlener, zoals Toreon. Het doel is om, op basis van een bewezen framework zoals CYFUN, een concreet actieplan op te stellen en uit te voeren om uw cyberveiligheid te verbeteren.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Kom ik in aanmerking voor een VLAIO cybersecurity subsidie?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Als u voldoet aan de EU-definitie van KMO (Max. 250 FTE, 50M€ omzet, 43M€ balanstotaal), komt u in aanmerking en krijgt u 50% subsidie op de pakketten zoals hier gedefinieerd.&lt;/p&gt; 
        &lt;p&gt;Grotere bedrijven die aan NIS2 moeten voldoen komen uitzonderlijk ook in aanmerking, maar krijgen slechts 35% subsidie op hun traject.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe lang duurt een VLAIO cybersecurity traject gemiddeld?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;p&gt;De doorlooptijd varieert per pakket: het Start-pakket duurt maximaal 3 maanden, Medium maximaal 6 maanden en Plus maximaal 9 maanden.&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
        &lt;p&gt;Dat is een doorlooptijd die wordt vooropgesteld om het gekozen traject te doorlopen, excl. de implementaties binnen de uitbreidingspakketten.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Wat is CRA, NIS2 en CYFUN?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;CRA en NIS2 zijn EU regelgevingen waaraan bepaalde bedrijven moeten voldoen.&lt;/p&gt; 
        &lt;p&gt;CYFUN is een manier voor bedrijven om hun cybersecurity maturiteit te verhogen. &amp;nbsp;CYFUN werd ontwikkeld door de CCB (Cybersecurity Center België) i.s.m. professionele experten uit de sector en diverse vakspecialisten in hun adviesraad, waaronder ook die van Toreon.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Moet ik zelf de subsidieaanvraag indienen bij VLAIO?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Nee, Toreon neemt de volledige administratie voor de subsidieaanvraag voor zijn rekening. Zo kunt u snel starten zonder extra paperwork, waarbij zij reeds tientallen KMO’s succesvol begeleid hebben.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Kan ik mijn VLAIO cybersecurity traject later upgraden naar een uitgebreider pakket?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Uiteraard. &amp;nbsp;De meeste bedrijven starten direct met een MEDIUM (of zelfs een PLUS) pakket. &amp;nbsp;Maar indien dat niet voldoende is en u een nog hoger maturiteitsniveau wil bereiken, kan u uw pakket upgraden, of op deze pakketten één van de uitbreidingspakketten nemen. Op deze pakketten geldt eveneens de 35% of 50% subsidie-regeling. Let er wel op dat een upgrade of uitbreiding binnen 6 maanden na afloop moet opgenomen worden.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe werkt het ‘credit’-systeem van Toreon?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Elk bedrijf is uniek. &amp;nbsp;Daarom zitten in onze pakketten, naast de door VLAIO verplichte elementen die worden afgedekt door de initiële implementatiedagen, ook een pakket Toreon-credits.&lt;/p&gt; 
        &lt;p&gt;Daarnaast biedt Toreon een menu van wel 30 opties om deze te gebruiken, puur in functie van uw unieke behoeften.&lt;/p&gt; 
        &lt;p&gt;Na de initiële fase zullen we samen bekijken hoe we de resterende credits het best inzetten om het meeste rendement uit uw investering te halen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Welke concrete verbeteringen kunnen KMO’s verwachten met VLAIO subsidie trajecten?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Verbeteringen omvatten onder meer vulnerability scans, multi-factor authenticatie, cloud security, data-protection, incident response planning, awareness-training, backup &amp;amp; disaster recovery en beveiligingsbeleid op maat.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Waarom is investeren in cybersecurity met VLAIO subsidie belangrijk voor KMO’s?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Cyberaanvallen op KMO’s stijgen snel en deze bedrijven missen vaak tijd, expertise of budget. Met VLAIO subsidie tot 50% wordt cybersecurity betaalbaar en helpt het uw digitale weerbaarheid tegen ransomware en andere risico’s te verhogen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Hoe helpt Toreon KMO’s bij de voorbereiding op NIS2 en CRA regelgeving?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Toreon voert CYFUN-gebaseerde assessments uit, bouwt compliance in activiteiten in, zet documentatie en beleid op en verzorgt regelmatige audits en verbetertrajecten om te voldoen aan NIS2 en CRA verplichtingen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h3&gt;Waar moet ik op letten als ik aan NIS2 moet voldoen?&lt;/h3&gt; 
       &lt;div&gt; 
        &lt;p&gt;Grotere bedrijven die aan NIS2 moeten voldoen kunnen ook genieten van 35% subsidie, als ze nog moeten starten aan het versterken van hun cybersecuritybeleid of nog niet beschikken over een CS-roadmap. Let er wel op dat deze bedrijven enkel beroep kunnen doen op een MEDIUM of PLUS pakket.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Start vandaag met het verbeteren van uw cybersecurity&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Neem vandaag contact op voor een gratis adviesgesprek. Wij leggen uit hoe u kunt starten met VLAIO-subsidie.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Lander Reynvoet&lt;/strong&gt;&lt;br&gt; Resp. VLAIO Project-Sales&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Margot Van Overtveldt&lt;/strong&gt;&lt;br&gt; VLAIO Project Coördinator&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet/connect-with-me"&gt;Plan een gratis gesprek in&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fcybersecurity-groei-met-vlaio-en-toreon&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 22 Dec 2025 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/cybersecurity-groei-met-vlaio-en-toreon</guid>
      <dc:date>2025-12-22T23:00:00Z</dc:date>
      <dc:creator>8 minutes</dc:creator>
    </item>
    <item>
      <title>Designing Cyber Governance: Board Structures and Practices for Effective Oversight</title>
      <link>https://staging.toreon.com/en/insights/blogs/designing-cyber-governance-board-structures-and-practices-for-effective-oversight</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/designing-cyber-governance-board-structures-and-practices-for-effective-oversight" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-1.png" alt="Designing Cyber Governance: Board Structures and Practices for Effective Oversight" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Since the adoption of &lt;b&gt;NIS2&lt;/b&gt;, which introduces potential &lt;strong&gt;personal liability for individual board members&lt;/strong&gt;, we’ve observed a growing awareness among boards of the need to address cybersecurity more structurally—&lt;strong&gt;as a core governance responsibility&lt;/strong&gt;.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;At the same time, many organisations are asking the same fundamental question:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;How should we organise for cybersecurity governance at board level?&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;To help provide guidance, we’re pleased to share the article below, developed within the &lt;strong&gt;Cyber Sounding Board at Guberna&lt;/strong&gt;, which our CEO Alex Driesen has the privilege of chairing.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The article outlines key considerations and practical recommendations for boards looking to strengthen their oversight of cybersecurity—&lt;strong&gt;not just to meet regulatory expectations, but to build long-term digital resilience.&lt;/strong&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Check out the latest Toreon Cyber Insights articles&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Six Governance Models for Cybersecurity Oversight&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Model&lt;/b&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Best Fit&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;1. Fully integrated&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Cybersecurity is embedded into every board-level decision. Strategic plans, M&amp;amp;A, and risk reviews explicitly address cyber.&lt;/p&gt; 
     &lt;p&gt;Digital-native or digitally mature companies with high board literacy on cyber. Organisations for whom cyber is a strategic differentiator.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;2. Dedicated committee&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A board-level cybersecurity or technology risk committee oversees all cyber matters.&lt;/p&gt; 
     &lt;p&gt;Large, complex, or regulated firms; companies with prior breach experience.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;3. Audit/Risk committee extension&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Cyber risk is formally included in the audit or risk committee’s remit. Often supported by regular CISO briefings.&lt;/p&gt; 
     &lt;p&gt;Mid-sized companies or those starting formal cyber governance.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;4. Distributed governance&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Different aspects of cyber (e.g. compliance, HR, innovation, data ethics,…) are assigned to different committees&lt;/p&gt; 
     &lt;p&gt;Boards with strong governance culture and multiple specialist committees.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;5. Cyber champion model&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;One director is designated to lead on cybersecurity and acts as liaison with CISO and/or experts.&lt;/p&gt; 
     &lt;p&gt;Smaller boards or organisations with limited resources&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;6. Minimalist/reactive&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;No formal oversight; cyber is addressed only during crises or audits.&lt;/p&gt; 
     &lt;p&gt;Increasingly unacceptable. Transitional at best, negligent at worst.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Choosing the Right Model&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Boards often begin with model 3 or 5. (as a proactive step moving out of 6)&lt;/li&gt; 
      &lt;li&gt;Larger or regulated companies evolve toward models 1 or 2.&lt;/li&gt; 
      &lt;li&gt;Models 4 and 1 work best where cybersecurity cuts across multiple boardthemes. In 4, watch out for silos, reintegrate.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Six Plug-Ins to Strengthen Oversight&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Plug-In&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Use Case&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;a. Board cyber training&lt;/strong&gt;&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Structured learning sessions for directors on cybersecurity threats, regulation, and trends.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;All boards; especially important in early stages of maturity AND when imposed by regulation&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;b. Expert briefings (ad hoc)&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;External experts update the board on threat landscape or review major incidents.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Enhances situational awareness and challenge capability.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;c. Standing advisor or cyber council&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Ongoing access to independent experts who support board or committee work.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Ideal for boards without internal cyber expertise.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;d. CISO–board engagement&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Regular, direct reporting from the CISO to the board or designated committee.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Essential for translating operational risk into strategic insight.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;e. Board-executive taskforce&lt;br&gt; &lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Time-bound group of directors and senior leaders working on a specific cyber initiative (e.g., post-breach reform).&lt;/p&gt; 
     &lt;p&gt;Agile response to high-stakes issues.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;f. Simulations and tabletop exercises&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Structured crisis scenarios that (or rather exec team with board oversight) and decision-making.&lt;a href="https://www.notion.so/JV-Toreon-28d4eccb1c9f8017b513c767a1ff3a6d?p=2be4eccb1c9f815891e1fd6c02eec561&amp;amp;pm=s#_ftn1"&gt;[1]&lt;/a&gt;&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Useful annually or pre-emptively in high-risk sectors.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;a href="https://www.notion.so/JV-Toreon-28d4eccb1c9f8017b513c767a1ff3a6d?p=2be4eccb1c9f815891e1fd6c02eec561&amp;amp;pm=s#_ftnref1"&gt;[1]&lt;/a&gt; See also question 7 in &lt;a href="https://www.guberna.be/en/know/seven-questions-any-director-should-ask-about-cybersecurity-regularly"&gt;https://www.guberna.be/en/know/seven-questions-any-director-should-ask-about-cybersecurity-regularly&lt;/a&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;How Plug-Ins Interact with Models&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Plug-ins boost board capacity without altering structure.&lt;/li&gt; 
      &lt;li&gt;For example, model 3 (Audit/Risk) plus plug-ins a, d, and f can be highly effective.&lt;/li&gt; 
      &lt;li&gt;Model 1 (Fully integrated) typically uses plug-ins a through e.&lt;/li&gt; 
      &lt;li&gt;Boards with limited structure should start with training (a) and championing CISO access (d).&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Summary Recommendation&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Boards should:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Select a base&amp;nbsp;&lt;strong&gt;governance model&lt;/strong&gt;&amp;nbsp;aligned with company context.&lt;/li&gt; 
      &lt;li&gt;Deploy &lt;strong&gt;plug-ins&lt;/strong&gt;&amp;nbsp;to build expertise, engagement, and responsiveness.&lt;/li&gt; 
      &lt;li&gt;Review structure annually as threats, expectations, and maturity evolve.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;More on the Cyber Sounding Board at Guberna can be found here: ​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.guberna.be/en/guberna-sounding-board-committee-cybersecurity"&gt;Read more&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;INSEAD (2022).&amp;nbsp;&lt;em&gt;Designing Sustainability Governance&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;ecoDa (2020-2024).&amp;nbsp;&lt;em&gt;Cyber-Risk Oversight Handbook&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;European Union (2023).&amp;nbsp;&lt;em&gt;Directive (EU) 2022/2555 (NIS2 Directive)&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;National Institute of Standards and Technology (NIST).&amp;nbsp;&lt;em&gt;Cybersecurity Framework&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;Center for Internet Security (CIS).&amp;nbsp;&lt;em&gt;Top 18 Controls&lt;/em&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Lorem Ipsum …&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Contact us!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/designing-cyber-governance-board-structures-and-practices-for-effective-oversight" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-1.png" alt="Designing Cyber Governance: Board Structures and Practices for Effective Oversight" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Since the adoption of &lt;b&gt;NIS2&lt;/b&gt;, which introduces potential &lt;strong&gt;personal liability for individual board members&lt;/strong&gt;, we’ve observed a growing awareness among boards of the need to address cybersecurity more structurally—&lt;strong&gt;as a core governance responsibility&lt;/strong&gt;.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;At the same time, many organisations are asking the same fundamental question:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;How should we organise for cybersecurity governance at board level?&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;To help provide guidance, we’re pleased to share the article below, developed within the &lt;strong&gt;Cyber Sounding Board at Guberna&lt;/strong&gt;, which our CEO Alex Driesen has the privilege of chairing.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The article outlines key considerations and practical recommendations for boards looking to strengthen their oversight of cybersecurity—&lt;strong&gt;not just to meet regulatory expectations, but to build long-term digital resilience.&lt;/strong&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Check out the latest Toreon Cyber Insights articles&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/unlock-50-subsidies-for-cybersecurity/"&gt;Unlock 50% Subsidies for Cybersecurity&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/2026-the-year-cyber-compliance-becomes-mandatory/"&gt;2026: The Year Cyber Compliance Becomes Mandatory&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/artes-group-red-teaming-with-toreon/"&gt;Artes Group Boosts Cyber Resilience with Red Teaming&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/secure-by-design-in-the-ai-age/"&gt;Secure-by-Design in the AI Age&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://www.toreon.com/break-glass-access-done-right/"&gt;Why YubiKeys are essential for secure emergency access&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Six Governance Models for Cybersecurity Oversight&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Model&lt;/b&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Best Fit&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;1. Fully integrated&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Cybersecurity is embedded into every board-level decision. Strategic plans, M&amp;amp;A, and risk reviews explicitly address cyber.&lt;/p&gt; 
     &lt;p&gt;Digital-native or digitally mature companies with high board literacy on cyber. Organisations for whom cyber is a strategic differentiator.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;2. Dedicated committee&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;A board-level cybersecurity or technology risk committee oversees all cyber matters.&lt;/p&gt; 
     &lt;p&gt;Large, complex, or regulated firms; companies with prior breach experience.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;3. Audit/Risk committee extension&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Cyber risk is formally included in the audit or risk committee’s remit. Often supported by regular CISO briefings.&lt;/p&gt; 
     &lt;p&gt;Mid-sized companies or those starting formal cyber governance.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;4. Distributed governance&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Different aspects of cyber (e.g. compliance, HR, innovation, data ethics,…) are assigned to different committees&lt;/p&gt; 
     &lt;p&gt;Boards with strong governance culture and multiple specialist committees.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;5. Cyber champion model&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;One director is designated to lead on cybersecurity and acts as liaison with CISO and/or experts.&lt;/p&gt; 
     &lt;p&gt;Smaller boards or organisations with limited resources&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;6. Minimalist/reactive&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;No formal oversight; cyber is addressed only during crises or audits.&lt;/p&gt; 
     &lt;p&gt;Increasingly unacceptable. Transitional at best, negligent at worst.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Choosing the Right Model&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Boards often begin with model 3 or 5. (as a proactive step moving out of 6)&lt;/li&gt; 
      &lt;li&gt;Larger or regulated companies evolve toward models 1 or 2.&lt;/li&gt; 
      &lt;li&gt;Models 4 and 1 work best where cybersecurity cuts across multiple boardthemes. In 4, watch out for silos, reintegrate.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Six Plug-Ins to Strengthen Oversight&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Plug-In&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Use Case&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;a. Board cyber training&lt;/strong&gt;&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Structured learning sessions for directors on cybersecurity threats, regulation, and trends.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;All boards; especially important in early stages of maturity AND when imposed by regulation&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;b. Expert briefings (ad hoc)&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;External experts update the board on threat landscape or review major incidents.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Enhances situational awareness and challenge capability.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;c. Standing advisor or cyber council&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Ongoing access to independent experts who support board or committee work.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Ideal for boards without internal cyber expertise.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;d. CISO–board engagement&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Regular, direct reporting from the CISO to the board or designated committee.&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Essential for translating operational risk into strategic insight.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;e. Board-executive taskforce&lt;br&gt; &lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Time-bound group of directors and senior leaders working on a specific cyber initiative (e.g., post-breach reform).&lt;/p&gt; 
     &lt;p&gt;Agile response to high-stakes issues.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;f. Simulations and tabletop exercises&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Structured crisis scenarios that (or rather exec team with board oversight) and decision-making.&lt;a href="https://www.notion.so/JV-Toreon-28d4eccb1c9f8017b513c767a1ff3a6d?p=2be4eccb1c9f815891e1fd6c02eec561&amp;amp;pm=s#_ftn1"&gt;[1]&lt;/a&gt;&lt;br&gt;&lt;/p&gt; 
     &lt;p&gt;Useful annually or pre-emptively in high-risk sectors.&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;a href="https://www.notion.so/JV-Toreon-28d4eccb1c9f8017b513c767a1ff3a6d?p=2be4eccb1c9f815891e1fd6c02eec561&amp;amp;pm=s#_ftnref1"&gt;[1]&lt;/a&gt; See also question 7 in &lt;a href="https://www.guberna.be/en/know/seven-questions-any-director-should-ask-about-cybersecurity-regularly"&gt;https://www.guberna.be/en/know/seven-questions-any-director-should-ask-about-cybersecurity-regularly&lt;/a&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;How Plug-Ins Interact with Models&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Plug-ins boost board capacity without altering structure.&lt;/li&gt; 
      &lt;li&gt;For example, model 3 (Audit/Risk) plus plug-ins a, d, and f can be highly effective.&lt;/li&gt; 
      &lt;li&gt;Model 1 (Fully integrated) typically uses plug-ins a through e.&lt;/li&gt; 
      &lt;li&gt;Boards with limited structure should start with training (a) and championing CISO access (d).&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Summary Recommendation&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Boards should:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Select a base&amp;nbsp;&lt;strong&gt;governance model&lt;/strong&gt;&amp;nbsp;aligned with company context.&lt;/li&gt; 
      &lt;li&gt;Deploy &lt;strong&gt;plug-ins&lt;/strong&gt;&amp;nbsp;to build expertise, engagement, and responsiveness.&lt;/li&gt; 
      &lt;li&gt;Review structure annually as threats, expectations, and maturity evolve.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;More on the Cyber Sounding Board at Guberna can be found here: ​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.guberna.be/en/guberna-sounding-board-committee-cybersecurity"&gt;Read more&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;References&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;INSEAD (2022).&amp;nbsp;&lt;em&gt;Designing Sustainability Governance&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;ecoDa (2020-2024).&amp;nbsp;&lt;em&gt;Cyber-Risk Oversight Handbook&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;European Union (2023).&amp;nbsp;&lt;em&gt;Directive (EU) 2022/2555 (NIS2 Directive)&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;National Institute of Standards and Technology (NIST).&amp;nbsp;&lt;em&gt;Cybersecurity Framework&lt;/em&gt;&lt;/li&gt; 
      &lt;li&gt;Center for Internet Security (CIS).&amp;nbsp;&lt;em&gt;Top 18 Controls&lt;/em&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Lorem Ipsum …&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Contact us!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Connect-IT&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You can find us at Connect-IT in May. Our HR team will help you explore new career opportunities and show you what working at Toreon is like.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.connect-it26.be/"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Fdesigning-cyber-governance-board-structures-and-practices-for-effective-oversight&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Toreon News</category>
      <category>Toreon Cyber Insights</category>
      <category>Advise</category>
      <pubDate>Tue, 16 Dec 2025 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/designing-cyber-governance-board-structures-and-practices-for-effective-oversight</guid>
      <dc:date>2025-12-16T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Toreon geselecteerd als VLAIO-partner: Toegankelijke cybersecurity voor Vlaamse KMO’s</title>
      <link>https://staging.toreon.com/en/insights/blogs/toreon-geselecteerd-als-vlaio-partner</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/toreon-geselecteerd-als-vlaio-partner" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/An-Introduction-to-the-CRA-14-1.webp" alt="Toreon geselecteerd als VLAIO-partner: Toegankelijke cybersecurity voor Vlaamse KMO’s" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We zijn&amp;nbsp;verheugd te kunnen melden&amp;nbsp;dat&amp;nbsp;Toreon&amp;nbsp;is geselecteerd als&amp;nbsp;één van de weinige cybersecuritypartners binnen het prestigieuze VLAIO-subsidieprogramma. Deze erkenning stelt ons in staat om Vlaamse kleine en middelgrote ondernemingen (KMO’s) te ondersteunen bij het versterken van hun cybersecurity—met&amp;nbsp;50%&amp;nbsp;substantiële financiële steun van de Vlaamse overheid.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/"&gt;Meer info over VLAIO cybersecurity&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/toreon-geselecteerd-als-vlaio-partner/#contact"&gt;Ik wil ondersteuning&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Verder bouwen op meer dan 90 eerdere VLAIO-trajecten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Als&amp;nbsp;één&amp;nbsp;van de zeer weinige gespecialiseerde&amp;nbsp;cybersecurity&amp;nbsp;bedrijven&amp;nbsp;die zijn goedgekeurd voor dit programma, bevestigt deze selectie&amp;nbsp;Toreon’s&amp;nbsp;expertise en trackrecord&amp;nbsp;in meer dan 90 trajecten&amp;nbsp;in het begeleiden van&amp;nbsp;KMO’s&amp;nbsp;naar een hoger beveiligingsniveau. Het VLAIO-kader stelt ons in staat om onze bewezen methodologieën en praktische aanpak toegankelijker te maken voor Vlaamse bedrijven die hun digitale weerbaarheid willen versterken.&lt;/p&gt; 
     &lt;p&gt;In een tijdperk waarin cyberaanvallen steeds geavanceerder worden en regelgeving zoals de&amp;nbsp;&lt;b&gt;Cyber&amp;nbsp;Resilience&amp;nbsp;Act (CRA)&lt;/b&gt;&amp;nbsp;en&amp;nbsp;&lt;b&gt;NIS2&lt;/b&gt;&amp;nbsp;strengere eisen stellen, is deze samenwerking met VLAIO een gamechanger voor&amp;nbsp;KMO’s&amp;nbsp;die cybersecurity serieus willen nemen zonder hun budget te overschrijden.&amp;nbsp;Ook het voorbereiden op het behalen van een&amp;nbsp;&lt;b&gt;ISO27001 certificering&lt;/b&gt;&amp;nbsp;in een meer internationale omgeving kan hierdoor worden ondersteund.&lt;/p&gt; 
     &lt;p&gt;De programma’s en pakketten die door&amp;nbsp;VLAIO&amp;nbsp;worden gesubsidieerd zijn geselecteerd met een focus op het&amp;nbsp;Cyber Fundamentals&amp;nbsp;framework&amp;nbsp;dat door stakeholders zoals o.a. het Centre&amp;nbsp;for&amp;nbsp;Cybersecurity&amp;nbsp;belgium&amp;nbsp;(CCB), de KU Leuven,&amp;nbsp;Agoria,&amp;nbsp;Beltug&amp;nbsp;en Cybersecurity&amp;nbsp;Initiative&amp;nbsp;Flanders, werd uitgewerkt.&amp;nbsp;&amp;nbsp;Toreon&amp;nbsp;heeft&amp;nbsp;via&amp;nbsp;meerdere van deze stakeholders als actief lid&amp;nbsp;bijgedragen&amp;nbsp;bij de definitie van dit&amp;nbsp;framework.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Hoe uw KMO kan profiteren van het VLAIO-programma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Het &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/"&gt;VLAIO-subsidieprogramma maakt professionele cybersecuritydiensten financieel toegankelijk voor Vlaamse ondernemingen&lt;/a&gt;. Door gebruik te maken van dit programma,&amp;nbsp;kunnen&amp;nbsp;KMO’s:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Substantiële kostenbesparingen realiseren&lt;/b&gt;&amp;nbsp;door overheidssubsidies die een aanzienlijk deel van de investering dekken&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Toegang krijgen tot expertise van topniveau&lt;/b&gt;&amp;nbsp;die anders buiten bereik zou zijn&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Voldoen aan actuele compliance-eisen&lt;/b&gt;&amp;nbsp;zoals CRA,&amp;nbsp;EU AI Act,&amp;nbsp;ISO27001, NIS2 en het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Hun concurrentiepositie versterken&lt;/b&gt;&amp;nbsp;door cybersecurity om te zetten in een strategisch voordeel&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Daardoor&amp;nbsp;meer&amp;nbsp;enterprise&amp;nbsp;customers&lt;/b&gt;&amp;nbsp;sneller binnenhalen omwille van aangetoonde professionaliteit en compliance&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Risico’s beheersbaar maken&lt;/b&gt;&amp;nbsp;met een duidelijk&amp;nbsp;stappenplan&amp;nbsp;en praktische implementatie&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Internationale geloofwaardigheid opbouwen&lt;/b&gt;&amp;nbsp;met erkende certificeringen zoals ISO27001&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welke bedrijven komen in aanmerking?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Het VLAIO-programma richt zich specifiek op&amp;nbsp;Vlaamse&amp;nbsp;KMO’s&amp;nbsp;die hun cybersecuritymaturiteit willen verhogen. Ons aanbod is bijzonder relevant voor diverse bedrijfsprofielen:&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;- Software- en productontwikkelaars:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die&amp;nbsp;&lt;b&gt;software ontwikkelen&lt;/b&gt;&amp;nbsp;(embedded, SaaS, of standalone producten)&amp;nbsp;voor intern en extern gebruik&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die&amp;nbsp;&lt;b&gt;digitale producten&lt;/b&gt;&amp;nbsp;op de markt brengen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die moeten voldoen aan de&amp;nbsp;&lt;b&gt;Cyber&amp;nbsp;Resilience&amp;nbsp;Act (CRA)&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Softwareleveranciers die&lt;b&gt;oplossingen voor&amp;nbsp;connecteerbare toestellen&lt;/b&gt;&amp;nbsp;produceren&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die&amp;nbsp;&lt;b&gt;ISO27001-certificering&lt;/b&gt;&amp;nbsp;nastreven&amp;nbsp;ter ondersteuning van&amp;nbsp;internationale geloofwaardigheid&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Productie- en technologiebedrijven:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven met&amp;nbsp;&lt;b&gt;max.&amp;nbsp;250 medewerkers&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Ondernemingen&amp;nbsp;met een&amp;nbsp;&lt;b&gt;productiefaciliteit&lt;/b&gt;&amp;nbsp;(lokaal of in het buitenland)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Ondernemingen waarbij&amp;nbsp;&lt;b&gt;software een cruciaal&lt;/b&gt;onderdeel vormt&amp;nbsp;van of gekoppeld is met hun product(en)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven met&amp;nbsp;&lt;b&gt;operational&amp;nbsp;technology&amp;nbsp;(OT)&lt;/b&gt;&amp;nbsp;en industriële systemen&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Algemene KMO’s met digitale ambities:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die werken met&amp;nbsp;&lt;b&gt;Microsoft 365&lt;/b&gt;&amp;nbsp;en hun&amp;nbsp;cloud-configuratie willen optimaliseren&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die het&amp;nbsp;&lt;b&gt;CyberFundamentals&amp;nbsp;(CYFUN)&amp;nbsp;Framework&lt;/b&gt;&amp;nbsp;willen implementeren (voor alle&amp;nbsp;KMO’s, niet alleen NIS2-&amp;nbsp;of CRA-plichtig)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;KMO’s&amp;nbsp;met een&amp;nbsp;&lt;b&gt;lage tot gemiddelde cybersecuritymaturiteit&lt;/b&gt;&amp;nbsp;die een structurele aanpak zoeken, of die met een&amp;nbsp;&lt;b&gt;hoge cybersecurity maturiteit&lt;/b&gt;&amp;nbsp;die een kostenoptimalisatie willen doorvoeren.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die compliance moeten aantonen aan klanten en partners&amp;nbsp;waarbij de voor hen relevante regelgeving vraagt om ook hun business-partners daarop te screenen.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Belangrijk&lt;/strong&gt;:&amp;nbsp;Het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework is relevant voor&amp;nbsp;alle&amp;nbsp;KMO’s&amp;nbsp;die hun cybersecurity willen professionaliseren, ongeacht of ze onder NIS2-regelgeving vallen.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wil u alvast meer te weten komen?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek zelf hoe de VLAIO trajecten u kunnen helpen. Lees er meer over in onze gratis te downloaden ebooks.&lt;/p&gt; 
     &lt;p&gt;Of u nu eigenaar bent van een KMO en uw weerbaarheid wil verhogen, of maker bent van producten en u beter wil voorbereiden op de CRA. Onze ebooks leggen u uit hoe u best te werk kan gaan.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-kmo/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-products/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Waarom kiezen voor Toreon binnen het VLAIO-programma?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;1. Business-first benadering&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We spreken uw taal. Geen technisch jargon, maar focus op ROI, business impact en meetbare resultaten die relevant zijn voor uw bedrijf.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;2. Productie- en OT-expertise&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Diepgaande kennis van productieomgevingen en&amp;nbsp;operationaltechnology—cruciaal voor&amp;nbsp;KMO’s&amp;nbsp;met productiefaciliteiten en industriële systemen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;3. Product Security wereldfaam&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;4. Cloud Security specialisatie&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Ons Product Security-team heeft internationale erkenning, met name op het gebied van&amp;nbsp;ThreatModeling&amp;nbsp;en secure software development—essentieel voor CRA-compliance.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Ons&amp;nbsp;CloudSec-team kan uw&amp;nbsp;Microsoft 365-configuraties&amp;nbsp;optimaliseren en andere&amp;nbsp;cloud-platforms beveiligen, zodat u maximaal profiteert van&amp;nbsp;cloud-technologie zonder extra risico’s.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;5. Praktische implementatie&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We blijven niet bij advies. We rollen onze mouwen op en helpen u met hands-on implementatie die écht werkt in uw context.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;6. KMO-specialisatie&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Onze&amp;nbsp;VLAIO-oplossingen zijn op maat gemaakt&amp;nbsp;voor bedrijven&amp;nbsp;tot&amp;nbsp;250 medewerkers. Niet te complex, niet te simpel—precies goed.&amp;nbsp; En dit voor startups, voor allerlei bedrijven in de maakindustrie&amp;nbsp;waarbij ontwikkelde digitale componenten of software deel uitmaken van het product of de dagelijkse bedrijfsvoering&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;7. Internationale compliance-kennis&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We begeleiden u naar ISO27001-certificering, CRA-compliance, en andere internationale standaarden die uw geloofwaardigheid versterken.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;8. Framework-agnostisch&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Of u nu werkt met&amp;nbsp;CyberFundamentals, ISO27001, NIST, CIS Controls, of OWASP—we&amp;nbsp;beheersen&amp;nbsp;ze allemaal&amp;nbsp;tot in de puntjes (sommigen hebben we zelf mee uitgetekend)&amp;nbsp;en passen ze toe op uw situatie.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Klaar om te starten?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;De selectie voor het VLAIO-programma biedt een unieke kans om uw cybersecurity naar een hoger niveau te tillen met substantiële overheidssteun. Of u nu:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Software of digitale producten ontwikkelt en CRA-compliant moet worden&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Internationaal actief bent en ISO27001-certificering nastreeft&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Uw Microsoft 365-omgeving&amp;nbsp;wil&amp;nbsp;beveiligen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Een productiefaciliteit heeft met OT-uitdagingen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Gewoon uw algemene cybersecuritymaturiteit wilt verhogen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;…we hebben een pakket dat bij uw situatie past.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Onze VLAIO-pakketten: Van assessment tot volledige implementatie&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We hebben vijf gestructureerde pakketten ontwikkeld die&amp;nbsp;KMO’s&amp;nbsp;begeleiden van eerste analyse tot volledige implementatie van cybersecuritymaatregelen.&amp;nbsp;De budgetten zijn bruto en daarop wordt dus de 50% subsidie van VLAIO berekend.&lt;/p&gt; 
     &lt;p&gt;Het START Pakket ligt vast, maar&amp;nbsp;de items binnen de MEDIUM, PLUS en UITBREIDINGSPAKKETTEN zullen we in overleg samen kiezen in functie van hun relevantie in uw situatie.&amp;nbsp; We hebben een menu van meer dan 30 specifieke service-items, elk met hun eigen tegenwaarde, en zo maken we voor u een traject op maat om een maximale ROI te bereiken.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;VLAIO-pakketten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;START Pakket: ‘Security Discovery’ (€11.900, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die direct willen starten met verbeteringen&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Alle elementen van het START pakket (assessment +&amp;nbsp;roadmap)&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;&lt;b&gt;Ruim, flexibel&amp;nbsp;implementatiebudget&lt;/b&gt;&amp;nbsp;voor het uitvoeren van prioritaire maatregelen&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Hands-on begeleiding bij het implementeren&amp;nbsp;van&amp;nbsp;security&amp;nbsp;controls&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;&lt;b&gt;Microsoft 365&lt;/b&gt;&amp;nbsp;configuratie-optimalisatie&amp;nbsp;indien relevant&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Opvolging en coaching tijdens het implementatietraject&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Implementatie over mensen, processen én technologie&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;Van analyse naar actie—we helpen u&amp;nbsp;het stappenplan&amp;nbsp;daadwerkelijk uit te voeren&lt;/p&gt; 
        &lt;p&gt;Dit pakket combineert strategie met praktijk: we brengen uw security-status in kaart én helpen u de belangrijkste verbeteringen door te voeren, inclusief&amp;nbsp;cloud&amp;nbsp;security waar nodig.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;MEDIUM Pakket: ‘Security Journey’ (€28.550, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die een duidelijk startpunt zoeken&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Algemeen security assessment van uw organisatie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Technisch assessment van uw infrastructuur en systemen.&amp;nbsp; Er zijn 2 alternatieven:&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Microsoft 365 security review&lt;/b&gt;&amp;nbsp;door&amp;nbsp;ons&amp;nbsp;gespecialiseerd&amp;nbsp;CloudSec-team&amp;nbsp;(indien relevant) – Uitgebreide security&amp;nbsp;roadmap&amp;nbsp;met geprioriteerde acties&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Externe penetratietest&lt;/b&gt;&amp;nbsp;die&amp;nbsp;kwetsbaarheden zal vaststellen in de publieke en/of extern bereikbare onderdelen van het bedrijf.&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Eliminatie van blinde vlekken door gecombineerde assessments – Afstemming op het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework (CCB) – Gap-analyse voor ISO27001, CRA of andere relevante&amp;nbsp;frameworks&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;Beide alternatieven zijn onderdeel van het&amp;nbsp;altijd inbegrepen&amp;nbsp;START pakket en hebben dezelfde&amp;nbsp;waarde. De keuze hangt af van wat het meest relevant is voor de klant – een klassieke externe&amp;nbsp;pentest&amp;nbsp;of een&amp;nbsp;cloud&amp;nbsp;security assessment.&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% analyse en planning, geen implementatie&lt;/p&gt; 
        &lt;p&gt;Dit pakket geeft u een helder, beheersbaar actieplan waarbij de meest kritieke security-tekortkomingen worden geprioriteerd, zodat u weet waar u het best uw budget besteedt—of u nu compliance nastreeft of gewoon uw digitale weerbaarheid wilt versterken.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;PLUS Pakket: ‘Security Transformation’ (€39.900, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die een grondige security-transformatie willen doorvoeren&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Alle elementen van het START pakket (assessment +&amp;nbsp;roadmap)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Nog ruimer en flexibel&amp;nbsp;implementatiebudget&lt;/b&gt;&amp;nbsp;voor uitgebreide security-verbeteringen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Volledige implementatie over mensen, processen én technologie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Cloud security&amp;nbsp;optimalisatie&lt;/b&gt;&amp;nbsp;(Microsoft 365, Azure, of&amp;nbsp;andere&amp;nbsp;platforms)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Training en awareness-programma’s&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Incident response-oefeningen en&amp;nbsp;playbook-ontwikkeling&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Duurzame verankering van security in uw organisatie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Voorbereiding op ISO27001-certificering (indien gewenst)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;Volledige transformatie naar een security-bewuste organisatie&lt;/p&gt; 
        &lt;p&gt;Dit pakket biedt de meest complete aanpak: van assessment tot volledige implementatie van een robuust security-programma dat uw organisatie structureel weerbaarder maakt en klaar voor internationale compliance-eisen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Uitbreidingspakketten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;Uitbreidingspakket 1: Productveiligheid - Secure Software Development Lifecycle Coaching (€19.950, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Software- en productontwikkelaars&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Gespecialiseerde begeleiding van ons internationaal erkende Product Security-team&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Threat&amp;nbsp;Modeling&amp;nbsp;expertise&lt;/b&gt;&amp;nbsp;(wereldfaam op dit gebied)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Coaching voor het opschalen van uw ontwikkelprocessen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Cyber Resilience Act (CRA) compliance-voorbereiding&lt;/b&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Security-by-design&amp;nbsp;integratie&amp;nbsp;in&amp;nbsp;uw&amp;nbsp;SDLC&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;OWASP SAMM framework&amp;nbsp;implementatie&amp;nbsp;– Secure coding practices&amp;nbsp;en&amp;nbsp;code review-processen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% implementatie—specifiek voor productveiligheid&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Essentieel voor:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Softwarebedrijven die hun ontwikkelprocessen security-proof&amp;nbsp;willen maken&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Bedrijven die moeten voldoen aan de&amp;nbsp;&lt;b&gt;CRA&lt;/b&gt;&amp;nbsp;(verplicht voor veel digitale producten)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Organisaties die software als hoofdactiviteit hebben of SaaS-oplossingen uitbaten&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Producenten van aan het internet connecteerbare toestellen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;Dit pakket is cruciaal in het licht van de nieuwe Europese wetgeving die strikte security-eisen stelt aan softwareleveranciers en producenten van digitale producten.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;Uitbreidingspakket 2: Extra Implementatiedagen (€19.950, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die hun Security&amp;nbsp;Journey&amp;nbsp;extra&amp;nbsp;willen versnellen&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;18 extra implementatiedagen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Flexibel in te zetten voor security-verbeteringen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Kan gebruikt worden voor&amp;nbsp;cloud&amp;nbsp;security,&amp;nbsp;OT security, of andere specialisaties&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% implementatie—extra capaciteit voor ambitieuze&amp;nbsp;KMO’s.&lt;/p&gt; 
        &lt;p&gt;Dit pakket biedt extra implementatiecapaciteit voor bedrijven die verder willen gaan dan de standaardpakketten en hun security-transformatie willen versnellen.&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Neem contact met ons op&lt;/b&gt;&amp;nbsp;om&amp;nbsp;te&amp;nbsp;samen&amp;nbsp;te kijken&amp;nbsp;welk pakket het beste aansluit bij uw&amp;nbsp;noden&amp;nbsp;en hoe u optimaal&amp;nbsp;gebruik kan maken&amp;nbsp;van het VLAIO-subsidieprogramma.&lt;/p&gt; 
        &lt;p&gt;Laten we samen van cybersecurity een strategisch voordeel maken voor uw onderneming.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;om&amp;nbsp;te&amp;nbsp;samen&amp;nbsp;te kijken&amp;nbsp;welk pakket het beste aansluit bij uw&amp;nbsp;noden&amp;nbsp;en hoe u optimaal&amp;nbsp;gebruik kan maken&amp;nbsp;van het VLAIO-subsidieprogramma.&lt;/p&gt; 
     &lt;p&gt;Laten we samen van cybersecurity een strategisch voordeel maken voor uw onderneming.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;Toreon&amp;nbsp;is een gespecialiseerde cybersecurityconsultant met focus op Vlaamse&amp;nbsp;KMO’s. Als een van de weinige geselecteerde partners binnen het VLAIO-programma helpen we bedrijven hun digitale weerbaarheid te versterken met praktische, business-gedreven oplossingen—van&amp;nbsp;cloud&amp;nbsp;security tot productveiligheid, certificatie-klaar.&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/blogs/toreon-geselecteerd-als-vlaio-partner" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/An-Introduction-to-the-CRA-14-1.webp" alt="Toreon geselecteerd als VLAIO-partner: Toegankelijke cybersecurity voor Vlaamse KMO’s" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We zijn&amp;nbsp;verheugd te kunnen melden&amp;nbsp;dat&amp;nbsp;Toreon&amp;nbsp;is geselecteerd als&amp;nbsp;één van de weinige cybersecuritypartners binnen het prestigieuze VLAIO-subsidieprogramma. Deze erkenning stelt ons in staat om Vlaamse kleine en middelgrote ondernemingen (KMO’s) te ondersteunen bij het versterken van hun cybersecurity—met&amp;nbsp;50%&amp;nbsp;substantiële financiële steun van de Vlaamse overheid.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/"&gt;Meer info over VLAIO cybersecurity&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/toreon-geselecteerd-als-vlaio-partner/#contact"&gt;Ik wil ondersteuning&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Verder bouwen op meer dan 90 eerdere VLAIO-trajecten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Als&amp;nbsp;één&amp;nbsp;van de zeer weinige gespecialiseerde&amp;nbsp;cybersecurity&amp;nbsp;bedrijven&amp;nbsp;die zijn goedgekeurd voor dit programma, bevestigt deze selectie&amp;nbsp;Toreon’s&amp;nbsp;expertise en trackrecord&amp;nbsp;in meer dan 90 trajecten&amp;nbsp;in het begeleiden van&amp;nbsp;KMO’s&amp;nbsp;naar een hoger beveiligingsniveau. Het VLAIO-kader stelt ons in staat om onze bewezen methodologieën en praktische aanpak toegankelijker te maken voor Vlaamse bedrijven die hun digitale weerbaarheid willen versterken.&lt;/p&gt; 
     &lt;p&gt;In een tijdperk waarin cyberaanvallen steeds geavanceerder worden en regelgeving zoals de&amp;nbsp;&lt;b&gt;Cyber&amp;nbsp;Resilience&amp;nbsp;Act (CRA)&lt;/b&gt;&amp;nbsp;en&amp;nbsp;&lt;b&gt;NIS2&lt;/b&gt;&amp;nbsp;strengere eisen stellen, is deze samenwerking met VLAIO een gamechanger voor&amp;nbsp;KMO’s&amp;nbsp;die cybersecurity serieus willen nemen zonder hun budget te overschrijden.&amp;nbsp;Ook het voorbereiden op het behalen van een&amp;nbsp;&lt;b&gt;ISO27001 certificering&lt;/b&gt;&amp;nbsp;in een meer internationale omgeving kan hierdoor worden ondersteund.&lt;/p&gt; 
     &lt;p&gt;De programma’s en pakketten die door&amp;nbsp;VLAIO&amp;nbsp;worden gesubsidieerd zijn geselecteerd met een focus op het&amp;nbsp;Cyber Fundamentals&amp;nbsp;framework&amp;nbsp;dat door stakeholders zoals o.a. het Centre&amp;nbsp;for&amp;nbsp;Cybersecurity&amp;nbsp;belgium&amp;nbsp;(CCB), de KU Leuven,&amp;nbsp;Agoria,&amp;nbsp;Beltug&amp;nbsp;en Cybersecurity&amp;nbsp;Initiative&amp;nbsp;Flanders, werd uitgewerkt.&amp;nbsp;&amp;nbsp;Toreon&amp;nbsp;heeft&amp;nbsp;via&amp;nbsp;meerdere van deze stakeholders als actief lid&amp;nbsp;bijgedragen&amp;nbsp;bij de definitie van dit&amp;nbsp;framework.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Hoe uw KMO kan profiteren van het VLAIO-programma&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Het &lt;a href="https://www.toreon.com/cybersecurity-groei-met-vlaio-en-toreon/"&gt;VLAIO-subsidieprogramma maakt professionele cybersecuritydiensten financieel toegankelijk voor Vlaamse ondernemingen&lt;/a&gt;. Door gebruik te maken van dit programma,&amp;nbsp;kunnen&amp;nbsp;KMO’s:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Substantiële kostenbesparingen realiseren&lt;/b&gt;&amp;nbsp;door overheidssubsidies die een aanzienlijk deel van de investering dekken&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Toegang krijgen tot expertise van topniveau&lt;/b&gt;&amp;nbsp;die anders buiten bereik zou zijn&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Voldoen aan actuele compliance-eisen&lt;/b&gt;&amp;nbsp;zoals CRA,&amp;nbsp;EU AI Act,&amp;nbsp;ISO27001, NIS2 en het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Hun concurrentiepositie versterken&lt;/b&gt;&amp;nbsp;door cybersecurity om te zetten in een strategisch voordeel&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Daardoor&amp;nbsp;meer&amp;nbsp;enterprise&amp;nbsp;customers&lt;/b&gt;&amp;nbsp;sneller binnenhalen omwille van aangetoonde professionaliteit en compliance&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Risico’s beheersbaar maken&lt;/b&gt;&amp;nbsp;met een duidelijk&amp;nbsp;stappenplan&amp;nbsp;en praktische implementatie&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Internationale geloofwaardigheid opbouwen&lt;/b&gt;&amp;nbsp;met erkende certificeringen zoals ISO27001&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welke bedrijven komen in aanmerking?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Het VLAIO-programma richt zich specifiek op&amp;nbsp;Vlaamse&amp;nbsp;KMO’s&amp;nbsp;die hun cybersecuritymaturiteit willen verhogen. Ons aanbod is bijzonder relevant voor diverse bedrijfsprofielen:&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;- Software- en productontwikkelaars:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die&amp;nbsp;&lt;b&gt;software ontwikkelen&lt;/b&gt;&amp;nbsp;(embedded, SaaS, of standalone producten)&amp;nbsp;voor intern en extern gebruik&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die&amp;nbsp;&lt;b&gt;digitale producten&lt;/b&gt;&amp;nbsp;op de markt brengen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die moeten voldoen aan de&amp;nbsp;&lt;b&gt;Cyber&amp;nbsp;Resilience&amp;nbsp;Act (CRA)&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Softwareleveranciers die&lt;b&gt;oplossingen voor&amp;nbsp;connecteerbare toestellen&lt;/b&gt;&amp;nbsp;produceren&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die&amp;nbsp;&lt;b&gt;ISO27001-certificering&lt;/b&gt;&amp;nbsp;nastreven&amp;nbsp;ter ondersteuning van&amp;nbsp;internationale geloofwaardigheid&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Productie- en technologiebedrijven:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven met&amp;nbsp;&lt;b&gt;max.&amp;nbsp;250 medewerkers&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Ondernemingen&amp;nbsp;met een&amp;nbsp;&lt;b&gt;productiefaciliteit&lt;/b&gt;&amp;nbsp;(lokaal of in het buitenland)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Ondernemingen waarbij&amp;nbsp;&lt;b&gt;software een cruciaal&lt;/b&gt;onderdeel vormt&amp;nbsp;van of gekoppeld is met hun product(en)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven met&amp;nbsp;&lt;b&gt;operational&amp;nbsp;technology&amp;nbsp;(OT)&lt;/b&gt;&amp;nbsp;en industriële systemen&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Algemene KMO’s met digitale ambities:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Organisaties die werken met&amp;nbsp;&lt;b&gt;Microsoft 365&lt;/b&gt;&amp;nbsp;en hun&amp;nbsp;cloud-configuratie willen optimaliseren&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die het&amp;nbsp;&lt;b&gt;CyberFundamentals&amp;nbsp;(CYFUN)&amp;nbsp;Framework&lt;/b&gt;&amp;nbsp;willen implementeren (voor alle&amp;nbsp;KMO’s, niet alleen NIS2-&amp;nbsp;of CRA-plichtig)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;KMO’s&amp;nbsp;met een&amp;nbsp;&lt;b&gt;lage tot gemiddelde cybersecuritymaturiteit&lt;/b&gt;&amp;nbsp;die een structurele aanpak zoeken, of die met een&amp;nbsp;&lt;b&gt;hoge cybersecurity maturiteit&lt;/b&gt;&amp;nbsp;die een kostenoptimalisatie willen doorvoeren.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Bedrijven die compliance moeten aantonen aan klanten en partners&amp;nbsp;waarbij de voor hen relevante regelgeving vraagt om ook hun business-partners daarop te screenen.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Belangrijk&lt;/strong&gt;:&amp;nbsp;Het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework is relevant voor&amp;nbsp;alle&amp;nbsp;KMO’s&amp;nbsp;die hun cybersecurity willen professionaliseren, ongeacht of ze onder NIS2-regelgeving vallen.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Wil u alvast meer te weten komen?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Ontdek zelf hoe de VLAIO trajecten u kunnen helpen. Lees er meer over in onze gratis te downloaden ebooks.&lt;/p&gt; 
     &lt;p&gt;Of u nu eigenaar bent van een KMO en uw weerbaarheid wil verhogen, of maker bent van producten en u beter wil voorbereiden op de CRA. Onze ebooks leggen u uit hoe u best te werk kan gaan.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-kmo/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/vlaio-playbook-products/"&gt;Meer hierover&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Waarom kiezen voor Toreon binnen het VLAIO-programma?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;1. Business-first benadering&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We spreken uw taal. Geen technisch jargon, maar focus op ROI, business impact en meetbare resultaten die relevant zijn voor uw bedrijf.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;2. Productie- en OT-expertise&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Diepgaande kennis van productieomgevingen en&amp;nbsp;operationaltechnology—cruciaal voor&amp;nbsp;KMO’s&amp;nbsp;met productiefaciliteiten en industriële systemen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;3. Product Security wereldfaam&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;4. Cloud Security specialisatie&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Ons Product Security-team heeft internationale erkenning, met name op het gebied van&amp;nbsp;ThreatModeling&amp;nbsp;en secure software development—essentieel voor CRA-compliance.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Ons&amp;nbsp;CloudSec-team kan uw&amp;nbsp;Microsoft 365-configuraties&amp;nbsp;optimaliseren en andere&amp;nbsp;cloud-platforms beveiligen, zodat u maximaal profiteert van&amp;nbsp;cloud-technologie zonder extra risico’s.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;5. Praktische implementatie&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We blijven niet bij advies. We rollen onze mouwen op en helpen u met hands-on implementatie die écht werkt in uw context.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;6. KMO-specialisatie&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Onze&amp;nbsp;VLAIO-oplossingen zijn op maat gemaakt&amp;nbsp;voor bedrijven&amp;nbsp;tot&amp;nbsp;250 medewerkers. Niet te complex, niet te simpel—precies goed.&amp;nbsp; En dit voor startups, voor allerlei bedrijven in de maakindustrie&amp;nbsp;waarbij ontwikkelde digitale componenten of software deel uitmaken van het product of de dagelijkse bedrijfsvoering&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;7. Internationale compliance-kennis&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;We begeleiden u naar ISO27001-certificering, CRA-compliance, en andere internationale standaarden die uw geloofwaardigheid versterken.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;8. Framework-agnostisch&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Of u nu werkt met&amp;nbsp;CyberFundamentals, ISO27001, NIST, CIS Controls, of OWASP—we&amp;nbsp;beheersen&amp;nbsp;ze allemaal&amp;nbsp;tot in de puntjes (sommigen hebben we zelf mee uitgetekend)&amp;nbsp;en passen ze toe op uw situatie.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Klaar om te starten?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;De selectie voor het VLAIO-programma biedt een unieke kans om uw cybersecurity naar een hoger niveau te tillen met substantiële overheidssteun. Of u nu:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Software of digitale producten ontwikkelt en CRA-compliant moet worden&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Internationaal actief bent en ISO27001-certificering nastreeft&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Uw Microsoft 365-omgeving&amp;nbsp;wil&amp;nbsp;beveiligen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Een productiefaciliteit heeft met OT-uitdagingen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Gewoon uw algemene cybersecuritymaturiteit wilt verhogen&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;…we hebben een pakket dat bij uw situatie past.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Onze VLAIO-pakketten: Van assessment tot volledige implementatie&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We hebben vijf gestructureerde pakketten ontwikkeld die&amp;nbsp;KMO’s&amp;nbsp;begeleiden van eerste analyse tot volledige implementatie van cybersecuritymaatregelen.&amp;nbsp;De budgetten zijn bruto en daarop wordt dus de 50% subsidie van VLAIO berekend.&lt;/p&gt; 
     &lt;p&gt;Het START Pakket ligt vast, maar&amp;nbsp;de items binnen de MEDIUM, PLUS en UITBREIDINGSPAKKETTEN zullen we in overleg samen kiezen in functie van hun relevantie in uw situatie.&amp;nbsp; We hebben een menu van meer dan 30 specifieke service-items, elk met hun eigen tegenwaarde, en zo maken we voor u een traject op maat om een maximale ROI te bereiken.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;VLAIO-pakketten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;START Pakket: ‘Security Discovery’ (€11.900, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die direct willen starten met verbeteringen&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Alle elementen van het START pakket (assessment +&amp;nbsp;roadmap)&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;&lt;b&gt;Ruim, flexibel&amp;nbsp;implementatiebudget&lt;/b&gt;&amp;nbsp;voor het uitvoeren van prioritaire maatregelen&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Hands-on begeleiding bij het implementeren&amp;nbsp;van&amp;nbsp;security&amp;nbsp;controls&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;&lt;b&gt;Microsoft 365&lt;/b&gt;&amp;nbsp;configuratie-optimalisatie&amp;nbsp;indien relevant&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Opvolging en coaching tijdens het implementatietraject&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Implementatie over mensen, processen én technologie&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;Van analyse naar actie—we helpen u&amp;nbsp;het stappenplan&amp;nbsp;daadwerkelijk uit te voeren&lt;/p&gt; 
        &lt;p&gt;Dit pakket combineert strategie met praktijk: we brengen uw security-status in kaart én helpen u de belangrijkste verbeteringen door te voeren, inclusief&amp;nbsp;cloud&amp;nbsp;security waar nodig.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;MEDIUM Pakket: ‘Security Journey’ (€28.550, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die een duidelijk startpunt zoeken&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Algemeen security assessment van uw organisatie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Technisch assessment van uw infrastructuur en systemen.&amp;nbsp; Er zijn 2 alternatieven:&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Microsoft 365 security review&lt;/b&gt;&amp;nbsp;door&amp;nbsp;ons&amp;nbsp;gespecialiseerd&amp;nbsp;CloudSec-team&amp;nbsp;(indien relevant) – Uitgebreide security&amp;nbsp;roadmap&amp;nbsp;met geprioriteerde acties&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Externe penetratietest&lt;/b&gt;&amp;nbsp;die&amp;nbsp;kwetsbaarheden zal vaststellen in de publieke en/of extern bereikbare onderdelen van het bedrijf.&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Eliminatie van blinde vlekken door gecombineerde assessments – Afstemming op het&amp;nbsp;CyberFundamentals&amp;nbsp;Framework (CCB) – Gap-analyse voor ISO27001, CRA of andere relevante&amp;nbsp;frameworks&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;Beide alternatieven zijn onderdeel van het&amp;nbsp;altijd inbegrepen&amp;nbsp;START pakket en hebben dezelfde&amp;nbsp;waarde. De keuze hangt af van wat het meest relevant is voor de klant – een klassieke externe&amp;nbsp;pentest&amp;nbsp;of een&amp;nbsp;cloud&amp;nbsp;security assessment.&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% analyse en planning, geen implementatie&lt;/p&gt; 
        &lt;p&gt;Dit pakket geeft u een helder, beheersbaar actieplan waarbij de meest kritieke security-tekortkomingen worden geprioriteerd, zodat u weet waar u het best uw budget besteedt—of u nu compliance nastreeft of gewoon uw digitale weerbaarheid wilt versterken.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;PLUS Pakket: ‘Security Transformation’ (€39.900, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die een grondige security-transformatie willen doorvoeren&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Alle elementen van het START pakket (assessment +&amp;nbsp;roadmap)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Nog ruimer en flexibel&amp;nbsp;implementatiebudget&lt;/b&gt;&amp;nbsp;voor uitgebreide security-verbeteringen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Volledige implementatie over mensen, processen én technologie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Cloud security&amp;nbsp;optimalisatie&lt;/b&gt;&amp;nbsp;(Microsoft 365, Azure, of&amp;nbsp;andere&amp;nbsp;platforms)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Training en awareness-programma’s&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Incident response-oefeningen en&amp;nbsp;playbook-ontwikkeling&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Duurzame verankering van security in uw organisatie&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Voorbereiding op ISO27001-certificering (indien gewenst)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;Volledige transformatie naar een security-bewuste organisatie&lt;/p&gt; 
        &lt;p&gt;Dit pakket biedt de meest complete aanpak: van assessment tot volledige implementatie van een robuust security-programma dat uw organisatie structureel weerbaarder maakt en klaar voor internationale compliance-eisen.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Uitbreidingspakketten&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;Uitbreidingspakket 1: Productveiligheid - Secure Software Development Lifecycle Coaching (€19.950, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Software- en productontwikkelaars&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Gespecialiseerde begeleiding van ons internationaal erkende Product Security-team&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Threat&amp;nbsp;Modeling&amp;nbsp;expertise&lt;/b&gt;&amp;nbsp;(wereldfaam op dit gebied)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Coaching voor het opschalen van uw ontwikkelprocessen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;b&gt;Cyber Resilience Act (CRA) compliance-voorbereiding&lt;/b&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Security-by-design&amp;nbsp;integratie&amp;nbsp;in&amp;nbsp;uw&amp;nbsp;SDLC&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;OWASP SAMM framework&amp;nbsp;implementatie&amp;nbsp;– Secure coding practices&amp;nbsp;en&amp;nbsp;code review-processen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% implementatie—specifiek voor productveiligheid&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Essentieel voor:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Softwarebedrijven die hun ontwikkelprocessen security-proof&amp;nbsp;willen maken&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Bedrijven die moeten voldoen aan de&amp;nbsp;&lt;b&gt;CRA&lt;/b&gt;&amp;nbsp;(verplicht voor veel digitale producten)&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Organisaties die software als hoofdactiviteit hebben of SaaS-oplossingen uitbaten&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Producenten van aan het internet connecteerbare toestellen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;Dit pakket is cruciaal in het licht van de nieuwe Europese wetgeving die strikte security-eisen stelt aan softwareleveranciers en producenten van digitale producten.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
      &lt;div&gt; 
       &lt;h6&gt;Uitbreidingspakket 2: Extra Implementatiedagen (€19.950, voor 50% VLAIO-subsidie) ​&lt;/h6&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Perfect voor:&lt;/b&gt;&amp;nbsp;Bedrijven die hun Security&amp;nbsp;Journey&amp;nbsp;extra&amp;nbsp;willen versnellen&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Wat u krijgt:&lt;/b&gt;&lt;/p&gt; 
        &lt;ul&gt; 
         &lt;li&gt;18 extra implementatiedagen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Flexibel in te zetten voor security-verbeteringen&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Kan gebruikt worden voor&amp;nbsp;cloud&amp;nbsp;security,&amp;nbsp;OT security, of andere specialisaties&lt;/li&gt; 
        &lt;/ul&gt; 
        &lt;p&gt;&lt;b&gt;Focus:&lt;/b&gt;&amp;nbsp;100% implementatie—extra capaciteit voor ambitieuze&amp;nbsp;KMO’s.&lt;/p&gt; 
        &lt;p&gt;Dit pakket biedt extra implementatiecapaciteit voor bedrijven die verder willen gaan dan de standaardpakketten en hun security-transformatie willen versnellen.&lt;/p&gt; 
        &lt;p&gt;&lt;b&gt;Neem contact met ons op&lt;/b&gt;&amp;nbsp;om&amp;nbsp;te&amp;nbsp;samen&amp;nbsp;te kijken&amp;nbsp;welk pakket het beste aansluit bij uw&amp;nbsp;noden&amp;nbsp;en hoe u optimaal&amp;nbsp;gebruik kan maken&amp;nbsp;van het VLAIO-subsidieprogramma.&lt;/p&gt; 
        &lt;p&gt;Laten we samen van cybersecurity een strategisch voordeel maken voor uw onderneming.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;om&amp;nbsp;te&amp;nbsp;samen&amp;nbsp;te kijken&amp;nbsp;welk pakket het beste aansluit bij uw&amp;nbsp;noden&amp;nbsp;en hoe u optimaal&amp;nbsp;gebruik kan maken&amp;nbsp;van het VLAIO-subsidieprogramma.&lt;/p&gt; 
     &lt;p&gt;Laten we samen van cybersecurity een strategisch voordeel maken voor uw onderneming.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;Toreon&amp;nbsp;is een gespecialiseerde cybersecurityconsultant met focus op Vlaamse&amp;nbsp;KMO’s. Als een van de weinige geselecteerde partners binnen het VLAIO-programma helpen we bedrijven hun digitale weerbaarheid te versterken met praktische, business-gedreven oplossingen—van&amp;nbsp;cloud&amp;nbsp;security tot productveiligheid, certificatie-klaar.&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fblogs%2Ftoreon-geselecteerd-als-vlaio-partner&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fblogs&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Vlaio</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Thu, 11 Dec 2025 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/blogs/toreon-geselecteerd-als-vlaio-partner</guid>
      <dc:date>2025-12-11T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
  </channel>
</rss>
