Please beware of phishing! Emails which were not sent by our employees are currently circulating, allegedly on behalf of Vanbreda Risk & Benefits. Did you receive an email with the domain name @vanbreda-be.com? Do not click on it and report it to your usual contact person in our organisation. Our email addresses always end in @vanbreda.be.

Back to overview
February 10, 2025

NIS2: new legislation forces businesses to tighten up cyber security

What do auxiliary party liability, mobility, solar panels and cyber have in common? They are four factors that affect your company’s risk profile. In the latest episode of our video podcast Succes Verzekerd, a panel of in-house experts discusses how you can successfully include new risks in your company’s risk management approach. Tom Van Britsom explains the legal requirements that companies must meet in the fight against cyber crime.

Every company and every working environment is becoming increasingly digital. This trend has many advantages, including increased efficiency and speed, and has been confirmed by the adoption of working from home at many organisations. The downside of digitisation is that cyber risks are growing. With legislators tightening the requirements in the area of cyber security, businesses are obliged to step up their efforts

Digital risks affect cyber security

The way many businesses work has changed significantly in recent years. Production lines that are now controlled almost entirely by digital means or administrative processes that are taken care of using a digital accounting package are examples of this.

As a result of this wave of digitisation, most businesses have to some extent become IT businesses. This makes them more attractive to criminals, who have not stood idly by, but are eagerly making use on a huge scale of phishing emails that lead to ransomware attacks all over the world.

If a haulage business is hacked, it may not be possible to deliver a product to the supermarket for days as a result.

NIS2: new legislation since 2024

In 2024, the NIS2 Law was introduced in Europe. This stricter and more extensive version of the initial NIS legislation from 2016 aims to beef up businesses’ efforts in the area of cyber security, specifying the approach they must take to their security policy. The scope of businesses and sectors covered by the legislation has been extended: the focus was previously on crucial sectors such as hospitals, banks, energy and the water supply, but NIS2 now also relates to sectors such as food, production and transport.

CCB Infographic1 NIS2 E crop
*source: Centre for Cybersecurity Belgium (CCB)

Penalties for non-compliance

The NIS2 legislation is managed in Belgium by the Centre for Cybersecurity (CCB). Companies in breach of the legislation may face a range of measures, from advice, instructions, bans, inspections and fines all the way through to the removal of directors from their position.

Looking to the future

Both businesses and private individuals will increasingly face digital risks. Alongside current legislation such as GDPR (focusing on data protection and privacy) and NIS and NIS2 (focusing on cyber security), new legislation is being developed all the time to increase resilience to digital risks.

The next piece of legislation to come out is the Cyber Resilience Act, focusing on the products that businesses make. It will seek to ensure that the software in smartphones, for example, is safe.

Our advice

We advise companies to manage cyber risks optimally, with the help of their broker, by focusing on three aspects:

  1. Arranging an insurance solution that provides support in the event of incidents and offers a financial safety net.
  2. Providing training so that employees can spot phishing emails and respond appropriately.
  3. Holding workshops to prepare for a cyber incident on the basis of a realistic case study and to develop an action plan.

Related posts

ADSF45704

Cyber attacks: a growing risk for the food industry

Cyber & fraud
18.03.2025

In 2024, Vanbreda Risk & Benefits, Belgium’s largest insurance broker, recorded one new cyber incident at Belgian businesses every week. This represents an increase on the previous year of no less than 64%. Although most of these incidents cost no more than 20,000 euros, 4% of businesses lost more than 1 million euros due to downtime. These figures show that cyber attacks are a growing risk for businesses, and the food industry is no exception.

Read more
Read more about Cyber attacks: a growing risk for the food industry
Cyber resized

One new cyber incident at Belgian businesses every week

Press
13.03.2025

Cyber attacks are hitting Belgian businesses harder than ever: Vanbreda Risk & Benefits, the country’s largest insurance broker, recorded one new cyber incident every week last year. That represents an increase of 64% on 2023. Although three-quarters of these incidents cost no more than 20,000 euros, 4% of businesses lost more than 1 million euros. Despite this, many businesses in Belgium continue to underestimate the risks. The new European legislation* designed to boost businesses’ resilience to cyber attacks should change this situation in 2025.

Read more
Read more about One new cyber incident at Belgian businesses every week
Aflevering 15 Vanbreda S2 Foto website

Videopodcast — Legislative changes

Videopodcast
18.02.2025

In the latest episode of our video podcast Succes Verzekerd, find out how you can successfully include new risks in your company’s risk management approach. A panel of four in-house experts explains the recent legislative changes affecting your insurance portfolio, focusing on four topical areas: auxiliary party liability, mobility, solar panels and cyber.

Read more
Read more about Videopodcast - Legislative changes
Cyber laptop

Vanbreda Cyber Security Study: 21% of all cyber security incidents in 2022 resulted in damage in excess of 100,000 euro

Cyber & fraud
13.02.2023

Now, more than ever Belgian companies are aware of potential digital risks and recognise the need to protect themselves via cyber security insurance. Damage statistics in our cyber portfolio also show that cyber security incidents are becoming more and more costly for Belgian companies. In 2022 the total cost of 1 in 5 incidents exceeded 100,000 euro. Regular security updates, employee training and choosing the right IT partner should all be part of an effective prevention strategy. They are also important criteria when it comes to arranging cyber security insurance in the Belgian market today.

Read more
Read more about Vanbreda Cyber Security Study: 21% of all cyber security incidents in 2022 resulted in damage in excess of 100,000 euro