Please beware of phishing! Emails which were not sent by our employees are currently circulating, allegedly on behalf of Vanbreda Risk & Benefits. Did you receive an email with the domain name @vanbreda-be.com? Do not click on it and report it to your usual contact person in our organisation. Our email addresses always end in @vanbreda.be.

Back to overview
November 23, 2021

Phishing: be aware and train your staff

Forget the spelling mistakes, strange layouts and outdated logos, phishers have learned their lesson and are now imitating websites so well that even specialists have to look twice. How then are non-professionals supposed to deal with this? “Awareness and training are the best ways to stop phishers in their tracks,” says Tom Van Britsom, cyber expert at Vanbreda Risk & Benefits. “And with our new ‘Phishing as a service’ offering, we can help your company achieve that goal.”

Phishing as a service

Phishing is a type of online scam in which cyber criminals try to steal login data, credit card information, pin codes or medical data. They do so by sending forged e-mails or text messages from agencies you trust: your bank, the Inland Revenue, a well-known amusement park, a large telecoms provider, … In these messages, they ask you to click through to the web site of this agency to enter your account number and pin code of your bank app, for example. Or to click on a link, which then installs a virus on your computer.

Variations of classic phishing

Meanwhile, variations of phishing are already emerging, and the inventiveness of cyber criminals knows no bounds. ‘Whaling’ is a good example, in which scammers use platforms such as WhatsApp to send messages in which they pretend to be known persons or family members. The scammer asks for money to be transferred because he has a small problem or is temporarily unable to access his account, of course with the promise of repaying this as quickly as possible. ‘CEO fraud’ is also something that is still common. The fraudster poses as the victim’s boss and asks for an urgent transfer of money to pay an unpaid invoice, for example.

Phishers are becoming ever more professional

“In the beginning, phishing messages were still quite easy to spot,” says Tom Van Britsom, cyber expert at Vanbreda Risk & Benefits. “They were often full of grammatical mistakes, had a vague title or used your e-mail address as a form of address. The websites they reproduced were also often just poor copies, immediately setting off alarm bells in the minds of many victims. However, the phishers have become ever more professional. It is becoming increasingly difficult to distinguish from legitimate emails and sites.”

In addition to the fact that the hackers are getting better and better in their fraudulent attempts, the number of phishing messages is also enormously on the increase, causing more and more victims. According to the bank federation, Febelfin, in 2020 about 67,000 fraudulent bank transactions took place due to phishing. In so doing, 34 million euros were stolen. By way of comparison: a year earlier, the damage amounted to ‘only’ 8 million euros.

Insurers are responding

Vanbreda Risk & Benefits also notes that there are more reported claims and the amounts involved are higher. “We find that insurers usually respond to this in three possible ways,” says Tom Van Britsom. “They increase policy premiums for both new and existing customers. Or they adjust their terms and conditions and, for example, provide for lower cap rates, higher excesses and amended clauses. Finally, insurers are also tightening up their acceptance policy. Companies have to demonstrate that their security policy is in order otherwise certain sectors are simply excluded.”

The human factor

Of course, a sound technical safety policy is an important factor in deterring phishers, says Van Britsom. But it is equally important to invest in the ‘human factor’. “The vast majority of claims have a human link, which you as a company can never completely eliminate, but on which you must continuously provide training. Vanbreda Risk & Benefits does this in two ways. Firstly, through the cyber workshops that we organise and that we base on our own experiences in cyber damage. We will teach you best practices: how to deal with phishing as soon as you are affected. So, the do’s and the don’ts, what can you do to prepare your company and how can you respond appropriately after an attack?”

The second part is an online ‘phishing training course’ offered by Vanbreda. Van Britsom: “Using our platform, we can set up highly realistic phishing simulations, which are tailored to your company. You do not have to make any adjustments to your own IT infrastructure. We send out the so-called phishing emails and then keep a very accurate record of how your employees respond to them. Afterwards, we will of course provide you with comprehensive reports and analyses of how the test went.”

Every employee is an expert

For example, the reports explain how many emails were sent, how many emails were opened, who entered what data or answered the emails, how many people clicked on suspicious attachments, how many employees informed the IT department, and so on. “In this way we are able to provide both the company and the employees with greater insight into the digital risks and teach them how to deal with them correctly. This also clearly demonstrates to your company how its internal cybersecurity policy can be optimised,” says Van Britsom. “The training course turns every employee into a real phishing expert. For example, your employees are prepared for cyber attacks, which means that the data, assets and reputation of your organisation are better protected.”

Related posts

ADSF45704

Cyber attacks: a growing risk for the food industry

Cyber & fraud
18.03.2025

In 2024, Vanbreda Risk & Benefits, Belgium’s largest insurance broker, recorded one new cyber incident at Belgian businesses every week. This represents an increase on the previous year of no less than 64%. Although most of these incidents cost no more than 20,000 euros, 4% of businesses lost more than 1 million euros due to downtime. These figures show that cyber attacks are a growing risk for businesses, and the food industry is no exception.

Read more
Read more about Cyber attacks: a growing risk for the food industry
Cyber resized

One new cyber incident at Belgian businesses every week

Press
13.03.2025

Cyber attacks are hitting Belgian businesses harder than ever: Vanbreda Risk & Benefits, the country’s largest insurance broker, recorded one new cyber incident every week last year. That represents an increase of 64% on 2023. Although three-quarters of these incidents cost no more than 20,000 euros, 4% of businesses lost more than 1 million euros. Despite this, many businesses in Belgium continue to underestimate the risks. The new European legislation* designed to boost businesses’ resilience to cyber attacks should change this situation in 2025.

Read more
Read more about One new cyber incident at Belgian businesses every week
Aflevering 15 Vanbreda S2 Foto website

Videopodcast — Legislative changes

Videopodcast
18.02.2025

In the latest episode of our video podcast Succes Verzekerd, find out how you can successfully include new risks in your company’s risk management approach. A panel of four in-house experts explains the recent legislative changes affecting your insurance portfolio, focusing on four topical areas: auxiliary party liability, mobility, solar panels and cyber.

Read more
Read more about Videopodcast - Legislative changes
U7353792727 A wide angle photo of a team meeting between collea a51adf9f 9b75 4329 a058 bb181446da87

NIS2: new legislation forces businesses to tighten up cyber security

Cyber & fraud
10.02.2025

What do auxiliary party liability, mobility, solar panels and cyber have in common? They are four factors that affect your company’s risk profile. In the latest episode of our video podcast Succes Verzekerd, a panel of in-house experts discusses how you can successfully include new risks in your company’s risk management approach. Tom Van Britsom explains the legal requirements that companies must meet in the fight against cyber crime.

Read more
Read more about NIS2: new legislation forces businesses to tighten up cyber security
CTA Image

More information?

Vous souhaitez obtenir de plus amples informations sur les formations que nous proposons en matière de phishing ? Contactez-nous à l’adresse