NIS2: You Have 24 Hours, and the Clock Starts Without You Sunday, 10:40 p.m. An alert hits the system administrator's phone: files are being encrypted on a file server. He isolates the server within twenty minutes. Good reflex. Then the real questions arrive... Sep 18, 2026
Your Supplier Got Hacked. It Just Became Your Incident. Monday, 6:50 a.m. Your IT provider — three people, very good, who have run your backups for eight years — calls before opening hours. They were encrypted over the weekend. Their remote administration ... Sep 16, 2026
CyFun: The Framework Belgium Chose for NIS2 A Tuesday in November, 8:40 a.m. Your largest client sends over an eleven-page supplier questionnaire. Question 4: "What is your CyFun level?" Nobody in the company knows what to answer. The IT manage... Sep 15, 2026
Louis Collard Why We Built Our GRC on Odoo The Problem With Standalone GRC Tools We've seen it enough times to recognise the pattern. A company invests in a dedicated GRC platform : feature-rich, well-marketed, genuinely capable in isolation. ... May 4, 2026
Louis Collard ISO 27001 Certification for SMEs: Introduction A large enterprise client has just sent you a tender document. Somewhere in the requirements, one line stops you cold: "Suppliers must hold ISO 27001 certification or be able to present a... Apr 27, 2026
Louis Collard Still Running Your Risk Register on Excel? Monday, 9:02 AM. Your CFO reopens RiskRegister_v12_FINAL_corrected.xlsx. Three tabs are hidden. A formula returns #REF!. Nobody knows who edited the "Residual Impact" column last week. The external au... Apr 20, 2026
Louis Collard 48 Hours of Production Downtime, One Lost Client, a Damaged Reputation. Tuesday morning, 6:43 AM The packaging line operator notices first. The supervision screens are black. He restarts the workstation but nothing. He calls the colleague next to him and same thing. Withi... Apr 20, 2026
Louis Collard ISO 27001 and NIS2: Stop Treating Them Separately Two Projects, One Problem Have you received a NIS2 compliance notice while already running an ISO 27001 project? Or the other way around? In either case, there's a good chance your teams — or your con... Apr 5, 2026
Louis Collard Cybersecurity Used to Be IT's Problem. NIS2 Just Made It Yours. NIS2 and Director Liability: What the Law Actually Says Since October 2024, a European directive has applied to tens of thousands of companies across Europe. Its name: NIS2 . Its most significant chan... Mar 29, 2026
Louis Collard Cybersecurity Compliance in Europe: A Guide for SMEs European cybersecurity compliance is no longer a concern reserved for large enterprises In 2025, Belgium's Centre for Cybersecurity (CCB) recorded an average of 275 cyberattacks per day. Across Europe... Mar 22, 2026
Louis Collard GRC: why your current tool might be your biggest risk GRC: why your current tool might be your biggest risk You manage risks in a spreadsheet. Your policies live on SharePoint. Your incidents sit in a ticketing tool. And your NIS2 compliance is somewhere... Mar 15, 2026
Louis Collard ISO 27001: Build it in-house or bring in a consultant? A practical guide The question we hear most "Can't we just do it internally?" Yes. Sometimes. But before deciding, it's worth facing reality. ISO 27001 means 93 controls to assess, an ISMS to build, evidence to documen... Mar 7, 2026