{"id":10025,"date":"2026-06-18T11:25:52","date_gmt":"2026-06-18T09:25:52","guid":{"rendered":"https:\/\/gvision.be\/?p=10025"},"modified":"2026-07-10T06:02:42","modified_gmt":"2026-07-10T04:02:42","slug":"nis2-belgium","status":"publish","type":"post","link":"https:\/\/gvision.be\/en\/nis2-pme-belgique\/","title":{"rendered":"NIS2 for SMEs in Belgium: are you affected, and what concrete steps do you need to take?"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"10025\" class=\"elementor elementor-10025\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"has_eae_slider elementor-element elementor-element-9a5f61c e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"73344\" data-id=\"9a5f61c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0b9a50b elementor-widget elementor-widget-image\" data-id=\"0b9a50b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1000\" height=\"616\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" data-src=\"https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1.jpg\" class=\"attachment-full size-full wp-image-10031 lazyload\" alt=\"NIS2 SME Belgium\" data-srcset=\"https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1.jpg 1000w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-300x185.jpg 300w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-768x473.jpg 768w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-18x12.jpg 18w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><noscript><img decoding=\"async\" width=\"1000\" height=\"616\" src=\"https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1.jpg\" class=\"attachment-full size-full wp-image-10031 lazyload\" alt=\"NIS2 SME Belgium\" srcset=\"https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1.jpg 1000w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-300x185.jpg 300w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-768x473.jpg 768w, https:\/\/gvision.be\/wp-content\/uploads\/2026\/06\/nis2-directive-compliance-steps-1000x616-1-18x12.jpg 18w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/noscript>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-6655f3e e-con-full e-flex e-con e-child\" data-eae-slider=\"15808\" data-id=\"6655f3e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fe9f753 elementor-widget elementor-widget-text-editor\" data-id=\"fe9f753\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The NIS2 directive has become a must-discuss topic for Belgian businesses. Many SME managers are now asking themselves the same questions: am I concerned? What do I need to implement? Is it solely an administrative obligation or a genuine issue of <a href=\"https:\/\/gvision.be\/en\/cybersecurity\/\" data-type=\"page\" data-id=\"4230\">cyber security<\/a> ?<\/p>\n<p>For SMEs in Brussels and Belgium, NIS2 should not be seen as a theoretical constraint reserved for large companies. Even when an SME is not directly subject to the law, it can be indirectly impacted by its clients, suppliers, or partners.<\/p>\n<p>This article explains what NIS2 means in practice for a Belgian SME, who is concerned, and what actions to take to remain in the best possible conditions.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-0716144 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"73531\" data-id=\"0716144\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-114025d aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"114025d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>NIS2: what are we talking about?<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-99b6acc elementor-widget elementor-widget-text-editor\" data-id=\"99b6acc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The NIS2 Directive is a European regulation intended to strengthen the cybersecurity level of organisations that play an important role in the economy and society. It replaces the first NIS Directive (see the <a href=\"https:\/\/ccb.belgium.be\/fr\/cybersecurite\/reglementation\/nis2\" target=\"_blank\" rel=\"noopener noreferrer\">Centre for Cybersecurity Belgium<\/a>and significantly expands the number of organisations concerned.<\/p>\n<p>In Belgium, this directive has been transposed via the NIS2 Act. The objective is clear: to improve the security of networks and information systems, to strengthen incident management, and to establish national supervision. It sets out minimum obligations regarding cybersecurity, risk management, incident notification, and supply chain security.<\/p>\n<p>The sectors concerned are numerous: energy, transport, health, water, digital infrastructure, digital services, public administrations, managed service providers, critical manufacturing industry, and many others.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-0e38997 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"91651\" data-id=\"0e38997\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1336b0c aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"1336b0c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>What NIS2 requires in practice<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1768121 elementor-widget elementor-widget-text-editor\" data-id=\"1768121\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Specifically, NIS2 requires the organisations concerned to better manage their IT risks. This is not simply a matter of having antivirus software installed on computers. It must be possible to demonstrate that the company has identified its risks, implemented appropriate protective measures, documented its procedures, and planned a response in the event of an incident.<\/p><p>For a Belgian SME, this can concern several very concrete aspects:<\/p><ul><li style=\"list-style-type: none;\"><ul><li><a href=\"https:\/\/gvision.be\/en\/modern-workplace\/microsoft-entra\/\" target=\"_blank\" rel=\"noopener\">User account and access rights management; ;<\/a><\/li><li><a href=\"https:\/\/gvision.be\/en\/modern-workplace\/multi-factor-authentication-mfa\/\" target=\"_blank\" rel=\"noopener\">multi-factor authentication;<\/a><\/li><li><a href=\"https:\/\/gvision.be\/en\/endpoint-protection-xdr-mdr\/\" target=\"_blank\" rel=\"noopener\">protection of workstations and servers; ;<\/a><\/li><li><a href=\"https:\/\/gvision.be\/en\/cybersecurity\/back-up-cloud-local\/\" target=\"_blank\" rel=\"noopener\">backups and their restore testing ;<\/a><\/li><li>security incident management ;<\/li><li><a href=\"https:\/\/gvision.be\/en\/modern-workplace\/microsoft-365\/\" target=\"_blank\" rel=\"noopener\">Microsoft 365 and cloud tools configuration; ;<\/a><\/li><li><a href=\"https:\/\/gvision.be\/en\/cybersecurity\/firewall-vpn-ztna\/\" target=\"_blank\" rel=\"noopener\">remote access security ;<\/a><\/li><li>the IT infrastructure documentation ;<\/li><li>IT vendor and supplier management.<\/li><\/ul><\/li><\/ul><p>For a small or medium-sized enterprise (SME) that does not yet have a formalised security policy, this can seem daunting. However, in practice, many of these measures are accessible and proportionate to the size of the company.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-cb9a5bf e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"94763\" data-id=\"cb9a5bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3f074a2 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"3f074a2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Veuillez traduire le texte suivant en anglais (UK), en ne retournant que le texte traduit et sans ajouter de commentaires ou de guillemets suppl\u00e9mentaires.\n\nLes entit\u00e9s qui sont soumises \u00e0 la directive NIS2 en Belgique comprennent :\n\n1.  **Les entit\u00e9s essentielles** : Ces entit\u00e9s sont actives dans les secteurs jug\u00e9s critiques pour le fonctionnement de la soci\u00e9t\u00e9 et de l'\u00e9conomie. Il s'agit notamment des secteurs suivants :\n    *   \u00c9nergie (\u00e9lectricit\u00e9, p\u00e9trole, gaz)\n    *   Transport (a\u00e9rien, ferroviaire, maritime, routier)\n    *   Banque\n    *   March\u00e9s financiers\n    *   Sant\u00e9\n    *   Eau potable\n    *   Eaux us\u00e9es\n    *   Infrastructure num\u00e9rique\n    *   Gestion d'infrastructures critiques TIC\n    *   Espace\n    *   Services postaux et d'exp\u00e9dition\n    *   Gestion des d\u00e9chets\n    *   Production, fabrication et distribution de produits chimiques\n\n2.  **Les entit\u00e9s importantes** : Ces entit\u00e9s sont actives dans une gamme plus large de secteurs, mais sont toujours consid\u00e9r\u00e9es comme ayant un impact significatif sur la s\u00e9curit\u00e9 et la r\u00e9silience. Ces secteurs comprennent :\n    *   Services num\u00e9riques (fournisseurs de services d'h\u00e9bergement, services en ligne, plateformes de n\u00e9gociation en ligne)\n    *   Fabrication de biens critiques (produits du g\u00e9nie, machines, produits m\u00e9talliques, produits du bois, textiles, papier, plastiques)\n    *   Traitement des denr\u00e9es alimentaires\n    *   Production de denr\u00e9es alimentaires\n    *   Certains services professionnels (services juridiques, comptables, fiscaux, de conseil, de publicit\u00e9)\n    *   Recherche\n    *   Fabrication de dispositifs m\u00e9dicaux\n    *   Fabrication de produits informatiques, \u00e9lectroniques et optiques\n    *   Fabrication de mat\u00e9riel \u00e9lectrique\n    *   Services de cybers\u00e9curit\u00e9\n    *   Services informatiques et TIC\n\nIl est important de noter que la classification exacte peut d\u00e9pendre de la taille de l'entit\u00e9, mesur\u00e9e par le nombre d'employ\u00e9s ou le chiffre d'affaires annuel. Les petites entreprises peuvent \u00e9galement \u00eatre couvertes si elles sont consid\u00e9r\u00e9es comme particuli\u00e8rement importantes dans leur secteur ou si elles font partie d'une cha\u00eene d'approvisionnement critique.\n\nLa transposition de la directive NIS2 en droit belge est en cours, et les d\u00e9tails pr\u00e9cis concernant la port\u00e9e et les obligations sp\u00e9cifiques sont susceptibles d'\u00eatre pr\u00e9cis\u00e9s dans les textes l\u00e9gislatifs nationaux.<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ade3957 elementor-widget elementor-widget-text-editor\" data-id=\"ade3957\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Not all Belgian SMEs are automatically subject to NIS2. To determine if your company is affected, several criteria must be analysed.<\/p>\n<h6>The businesses directly involved<\/h6>\n<p>NIS2 directly applies to companies that operate in sectors defined as essential or important, AND that reach certain size thresholds (generally: at least 50 employees or more than \u20ac10 million in turnover).<\/p>\n<p>Key sectors include, but are not limited to: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration.<\/p>\n<p>Key sectors include: postal services, waste management, chemicals, food, manufacturing, digital providers.<\/p>\n<h6>Businesses indirectly affected<\/h6>\n<p>Even if your SME does not meet the thresholds or operate in a regulated sector, it may still be affected if it is a supplier, subcontractor, or service provider to an organisation subject to NIS2.<\/p>\n<p>In practice, this means that a Brussels-based SME providing IT, logistics, legal, accounting, or communication services to a larger organisation may be subject to contractual security requirements.<\/p>\n<p>This is why, even for SMEs that are not directly targeted by NIS2, an IT security approach remains important.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-94eb485 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"46158\" data-id=\"94eb485\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ac7ab93 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"ac7ab93\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>NIS2 and SMEs indirectly affected<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-291a8f8 elementor-widget elementor-widget-text-editor\" data-id=\"291a8f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Many SMEs in Belgium will not be directly subject to NIS2. However, they will still need to adapt. Why? Because NIS2 also strengthens requirements within the supply chain.<\/p>\n<p>Let's take a simple example. A Brussels-based SME provides IT, logistics, or consulting services to a player in the health or energy sector. This player, subject to NIS2, must ensure that its suppliers also comply with minimum security standards. It can therefore ask the SME for guarantees, documentation, or even certification.<\/p>\n<p>In this context, an SME that has not prepared itself risks losing contracts or being unable to respond to tenders.<\/p>\n<p>The areas where the pressure is greatest are: outsourced IT services, cloud, Microsoft 365 tools, and remote access. Small and medium-sized enterprises (SMEs) that manage sensitive data or access to their clients' critical systems must be particularly vigilant.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-f7df9b3 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"32481\" data-id=\"f7df9b3\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-84f1b28 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"84f1b28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Concrete measures to implement<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0194598 elementor-widget elementor-widget-text-editor\" data-id=\"0194598\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NIS2 obligations should not be understood as a simple list of documents to produce. They imply real IT risk management. The company must know where its weaknesses lie, what measures already exist, and what actions should be prioritised.<\/p>\n<p>For an SME, concrete measures can be grouped into several categories.<\/p>\n<h6>Securing access and identities<\/h6>\n<p>The first priority concerns user accounts. Today, many attacks begin with a compromised Microsoft 365 account, a reused password, or poorly secured administrator access.<\/p>\n<p>The recommended actions are:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>enable multi-factor authentication ;<\/li>\n<li>Protect administrator accounts ;<\/li>\n<li>Delete old user accounts; ;<\/li>\n<li>restrict access rights; ;<\/li>\n<li>implement conditional access policies ;<\/li>\n<li>use a professional password manager ;<\/li>\n<li>Monitor suspicious connections.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>In a Microsoft 365 environment, tools such as Entra ID, Conditional Access, Defender and Intune can significantly enhance security, provided they are correctly configured.<\/p>\n<p>GVISION supports SMEs in setting up and securing Microsoft 365: user accounts, MFA, access rights, Exchange., <a href=\"https:\/\/gvision.be\/en\/support-sharepoint-bruxelles\/\" data-type=\"post\" data-id=\"9985\">SharePoint<\/a>, OneDrive, Teams, Intune and device protection.<\/p>\n<h6>Protecting workstations, servers and applications<\/h6>\n<p>The second priority concerns the devices used by the company: PCs, laptops, servers, virtual machines, business applications, company smartphones.<\/p>\n<p>A small and medium-sized enterprise must at a minimum plan for:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>A professional antivirus or EDR solution ;<\/li>\n<li>centralised update management ;<\/li>\n<li>an inventory of appliances; ;<\/li>\n<li>monitoring of critical alerts; ;<\/li>\n<li>a clear policy for personal devices ;<\/li>\n<li>ransomware protection;<\/li>\n<li>a hardening of roles and servers.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The objective isn't just to install a tool. It's necessary to be able to monitor the actual state of the IT park and react quickly when a problem appears.<\/p>\n<p>This is precisely the role of a <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/managed-it-services\/\" data-type=\"page\" data-id=\"4312\">structured outsourcing<\/a> To monitor, maintain, secure, and document the company's IT environment.<\/p>\n<h6>Make backups reliable<\/h6>\n<p>Backups are a cornerstone of cybersecurity. In the event of a ransomware attack, accidental deletion, or server failure, the question isn't \u201cdo you have a backup?\u201d, but rather \u201ccan you restore your data quickly?\u201d.<\/p>\n<p>A small to medium-sized enterprise (SME) should check:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>What data is saved? ;<\/li>\n<li>where the backups are stored ;<\/li>\n<li>if a copy is isolated or outsourced; ;<\/li>\n<li>if Microsoft 365 is also backed up; ;<\/li>\n<li>how often are restorations tested; ;<\/li>\n<li>How long can the company operate without servers, emails or business applications?.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>An untested backup gives a false sense of security. In a NIS2 approach, it must be possible to prove that the restoration works.<\/p>\n<p>GVISION can help SMEs implement a suitable backup strategy: servers, critical workstations, Microsoft 365, OneDrive., <a href=\"https:\/\/gvision.be\/en\/support-sharepoint-bruxelles\/\" data-type=\"post\" data-id=\"9985\">SharePoint<\/a>, Exchange, local data and cloud backups.<\/p>\n<h6>Prepare incident management<\/h6>\n<p>NIS2 strongly emphasises incident management. An SME must know what to do in the event of a cyberattack, data leak, account compromise, or significant unavailability.<\/p>\n<p>A simple procedure should answer these questions:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Who should be contacted first?<\/li>\n<li>Who makes the decision to isolate a workstation or a server?<\/li>\n<li>How to communicate internally?<\/li>\n<li>What elements should be kept as evidence?<\/li>\n<li>Who is contacting the IT provider?<\/li>\n<li>How to restart the activity?<\/li>\n<li>Which authorities or stakeholders need to be informed if necessary?<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Even a short procedure is better than total improvisation on the day of the incident.<\/p>\n<h6>Documenting the IT environment<\/h6>\n<p>Documentation is often the weak point for SMEs. However, without documentation, it is difficult to prove that the environment is under control.<\/p>\n<p>Basic documentation should include:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>the inventory of workstations and servers; ;<\/li>\n<li>The list of critical software ;<\/li>\n<li>network documentation ;<\/li>\n<li>administrator access; ;<\/li>\n<li>backup procedures; ;<\/li>\n<li>IT contracts ;<\/li>\n<li>onboarding and offboarding procedures ;<\/li>\n<li>the security measures in place ;<\/li>\n<li>supervision reports.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>This documentation facilitates compliance, but also daily support.<\/p>\n<p>At GVISION, we always recommend transforming IT documentation into an operational tool. It should help to resolve incidents more quickly, facilitate hardware replacements, secure access, and prevent all IT knowledge resting with a single person.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-d9fc0aa e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"65768\" data-id=\"d9fc0aa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7e388fe aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"7e388fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Concrete risks for an SME that does not prepare<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-44d14eb elementor-widget elementor-widget-text-editor\" data-id=\"44d14eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Failing to prepare for NIS2 can create several risks for an SME.<\/p>\n<p>The first risk is operational. A cyber-attack can block emails, files, business applications, the RDP server, the ERP, VoIP telephony, or access to customer data. For an SME, a few hours of downtime can have a significant impact on activity.<\/p>\n<p>The second risk is commercial. Large companies and public organisations are increasingly incorporating IT security criteria into their tender documents and supplier contracts. SMEs that cannot demonstrate a minimum level of cybersecurity maturity risk losing business opportunities.<\/p>\n<p>The third risk is legal and regulatory. If an organisation directly subject to NIS2 suffers an incident partly related to an insecure supplier, questions of liability may arise. Furthermore, if an SME is directly subject to NIS2 and does not comply with its obligations, it exposes itself to sanctions.<\/p>\n<p>Finally, reputational risk is a real threat. A leak of customer data, a ransomware attack, or an email compromise can have a lasting impact on the trust of customers and partners.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-f22c166 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"35652\" data-id=\"f22c166\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-60870e6 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"60870e6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>NIS2 Brussels:<\/span><\/span><span class=\"dblh__title dblh__title-2\"><span>Local specificities and challenges<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7fa2464 elementor-widget elementor-widget-text-editor\" data-id=\"7fa2464\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>SMEs located in Brussels operate within a particular environment. The region concentrates numerous non-profit organisations, consultancies, service companies, public bodies, international institutions, B2B companies, and suppliers to large accounts.<\/p>\n<p>This proximity to more regulated organisations increases the requirements. A Brussels-based SME can quickly be faced with stricter security demands, even if it is not directly targeted by NIS2.<\/p>\n<p>For local businesses, the priorities are often as follows:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Securing Microsoft 365 ;<\/li>\n<li>Protect remote access; ;<\/li>\n<li>Set up structured IT outsourcing; ;<\/li>\n<li>document the network and servers; ;<\/li>\n<li>make backups more reliable ;<\/li>\n<li>protect user posts ;<\/li>\n<li>train teams on phishing risks ;<\/li>\n<li>have a <a href=\"https:\/\/gvision.be\/en\/it-support-brussels\/\" data-type=\"post\" data-id=\"9739\">Responsive IT provider in Brussels<\/a> or in Belgium.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Local IT support remains important. In the event of a critical failure, network incident or server problem, a rapid intervention can make all the difference. An IT provider who knows the SME\u2019s environment can also better prioritise actions and avoid solutions that are too complex or poorly suited.<\/p>\n<p>GVISION supports SMEs in Brussels and Belgium with a practical approach: <a href=\"https:\/\/gvision.be\/en\/it-support-brussels\/\" data-type=\"post\" data-id=\"9739\">IT support<\/a>, <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/managed-it-services\/\" data-type=\"page\" data-id=\"4312\">Managed IT services<\/a>, <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/microsoft-365-brussels-2\/\" data-type=\"page\" data-id=\"9267\">Microsoft 365<\/a>, <a href=\"https:\/\/gvision.be\/en\/cybersecurity\/\" data-type=\"page\" data-id=\"4230\">cyber security<\/a>, backups, network infrastructure, servers, cloud and VoIP telephony. The goal is to have a reliable, secure and well-maintained environment over time.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-69daf8d e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"96437\" data-id=\"69daf8d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6e01a1 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"a6e01a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Where to start? A step-by-step approach<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-628f0a1 elementor-widget elementor-widget-text-editor\" data-id=\"628f0a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>To move forward effectively, a small or medium-sized enterprise (SME) must not start by buying several tools at random. The right approach is progressive.<\/p>\n<h6>1. Check if your SME is affected<\/h6>\n<p>The first step is to analyse your situation: company size, business sector, services provided, clients and suppliers. This analysis will determine if you are directly targeted, indirectly impacted, or simply being cautious.<\/p>\n<h6>2. Conduct an IT and security audit<\/h6>\n<p>An audit assesses the current state of your infrastructure: workstations, servers, access, Microsoft 365, backups, user rights, network, telephony, and business applications. It identifies existing weaknesses and allows for the creation of a prioritised action plan.<\/p>\n<h6>3. Implement priority measures<\/h6>\n<p>Based on the audit, the actions to be taken first are selected: MFA, backups, updates, endpoint protection, access rights, user training. These basic measures often have the greatest impact for the lowest cost.<\/p>\n<h6>4. Document and structure<\/h6>\n<p>NIS2 compliance also relies on the ability to prove what has been implemented. It is therefore necessary to document the environment, security measures, procedures, and responsibilities. This documentation is also useful on a daily basis for support and maintenance.<\/p>\n<h6>5. Maintain and supervise over time<\/h6>\n<p>Cybersecurity is not a one-off project. Systems need to be kept up to date, alerts monitored, access regularly reviewed and measures adapted according to the evolution of the business and threats.<\/p>\n<p>This is the approach GVISION recommends: progressive, tailored to each SME, focused on concrete results and sustained over time.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-ff7fa1c e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"22183\" data-id=\"ff7fa1c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f7ad8e4 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"f7ad8e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>GVISION and NIS2 preparedness:<\/span><\/span><span class=\"dblh__title dblh__title-2\"><span>A pragmatic approach for Belgian SMEs<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-82255e7 elementor-widget elementor-widget-text-editor\" data-id=\"82255e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>For many SMEs, managing the full scope of NIS2 requirements alone is difficult. Leaders don't always have the time, in-house skills, or necessary tools to properly monitor IT security.<\/p>\n<p>GVISION supports Belgian SMEs with a pragmatic approach: securing what is critical, documenting what needs to be, implementing suitable tools and maintaining the environment over time.<\/p>\n<p>Our support can include:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>IT audit and cybersecurity ;<\/li>\n<li>Microsoft 365 security ;<\/li>\n<li>set up MFA and access management ;<\/li>\n<li>Workstation and server protection ;<\/li>\n<li>Local, cloud and Microsoft 365 backup ;<\/li>\n<li>supervision and maintenance ;<\/li>\n<li>IT documentation ;<\/li>\n<li>User support ;<\/li>\n<li>incident management;<\/li>\n<li><a href=\"https:\/\/gvision.be\/en\/modern-workplace\/managed-it-services\/\" data-type=\"page\" data-id=\"4312\">Managed IT services<\/a> with regular follow-up; ;<\/li>\n<li>Conseils pour am\u00e9liorer la maturit\u00e9 de la cybers\u00e9curit\u00e9.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The goal isn't to sell a one-size-fits-all solution to all businesses. A small to medium-sized enterprise with 10 users, a non-profit organisation, an accounting firm, a construction company, or a business with multiple sites don't have the same priorities.<\/p>\n<p>The right approach is to start with what already exists, identify the most significant risks, and build a realistic action plan.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-dbac304 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"73855\" data-id=\"dbac304\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-79c9897 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"79c9897\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Microsoft 365 et NIS2 :<\/span><\/span><span class=\"dblh__title dblh__title-2\"><span>An environment to secure as a priority<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8ba9171 elementor-widget elementor-widget-text-editor\" data-id=\"8ba9171\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Microsoft 365 has become central to many Belgian SMEs. Emails, files, calendars, Teams, <a href=\"https:\/\/gvision.be\/en\/support-sharepoint-bruxelles\/\" data-type=\"post\" data-id=\"9985\">SharePoint<\/a> et OneDrive sont souvent au c\u0153ur du fonctionnement quotidien.<\/p>\n<p>But <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/microsoft-365-brussels-2\/\" data-type=\"page\" data-id=\"9267\">Microsoft 365<\/a> Poorly configured can also become an entry point for cyberattacks. In a NIS2 SME Belgium approach, it is therefore essential to correctly secure the environment.<\/p>\n<p>The key points are:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>activate MFA for all users ;<\/li>\n<li>configure conditional access policies ;<\/li>\n<li>Activate Defender for Business ;<\/li>\n<li>configure email inboxes against phishing and spam; ;<\/li>\n<li>manage SharePoint and OneDrive permissions; ;<\/li>\n<li>Back up Microsoft 365 With a Third-Party Tool ;<\/li>\n<li>monitor connections and alerts via Entra ID and Defender; ;<\/li>\n<li>manage devices with Intune; ;<\/li>\n<li>train users in best practices.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>GVISION offers complete Microsoft 365 security: accounts, MFA, Entra ID, Conditional Access, Exchange, SharePoint, OneDrive, Teams, Intune, Defender, and backups.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-ffee7a7 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"40329\" data-id=\"ffee7a7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f2790aa aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"f2790aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>How should you choose your IT service provider for NIS2?<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-67004c7 elementor-widget elementor-widget-text-editor\" data-id=\"67004c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The choice of IT provider is an important step. NIS2 compliance does not solely rely on tools, but on a method, documentation, and monitoring.<\/p>\n<p>A good provider must be able to understand the reality of an SME: limited budget, need for simplicity, reliance on business tools, need to move quickly, and the importance of business continuity.<\/p>\n<p>Before choosing a partner, ask the following questions:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Can he carry out a clear IT audit?<\/li>\n<li>Does he know <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/microsoft-365-brussels-2\/\" data-type=\"page\" data-id=\"9267\">Microsoft 365<\/a>, Entra ID, Intune, Defender et <a href=\"https:\/\/gvision.be\/en\/support-sharepoint-bruxelles\/\" data-type=\"post\" data-id=\"9985\">SharePoint<\/a> ?<\/li>\n<li>does it offer a <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/managed-it-services\/\" data-type=\"page\" data-id=\"4312\">Managed IT services<\/a> with monitoring and reporting?<\/li>\n<li>Can it handle backups and restore tests?<\/li>\n<li>Does it document the IT environment?<\/li>\n<li>Does it propose an incident management procedure?<\/li>\n<li>Can he intervene quickly in Brussels or Belgium?<\/li>\n<li>Does he understand the challenges faced by B2B SMEs?<\/li>\n<li>Can it support the company in the long term, and not just when an incident occurs?<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Deliverables are also important. Serious support must produce concrete elements:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>audit report ;<\/li>\n<li>prioritised action plan;<\/li>\n<li>Network documentation ;<\/li>\n<li>Inventory of equipment ;<\/li>\n<li>security report ;<\/li>\n<li>backup status; ;<\/li>\n<li>interlocutory proceedings; ;<\/li>\n<li>Budgeted recommendations.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>For an SME, the objective is not to obtain a theoretical report of 100 pages. The objective is to have real, understandable, and maintainable security.<\/p>\n<p>This is GVISION's philosophy: to offer clear support, tailored to Belgian SMEs and focused on tangible results.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-aa14508 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"33609\" data-id=\"aa14508\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8d8b1bb aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"8d8b1bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Conclusion :<\/span><\/span><span class=\"dblh__title dblh__title-2\"><span>NIS2 is an opportunity to strengthen your IT security.<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-261cee4 elementor-widget elementor-widget-text-editor\" data-id=\"261cee4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NIS2 isn't just another regulatory obligation. It's also an opportunity to seriously review your company's IT security.<\/p>\n<p>For a small and medium-sized enterprise in Belgium, the priority is to answer three questions:<\/p>\n<ol>\n<li><strong>Are we directly or indirectly affected by NIS2?<\/strong><\/li>\n<li><strong>Is our IT infrastructure sufficiently secure?<\/strong><\/li>\n<li><strong>Do we have the necessary evidence, procedures, and safeguards in case of an incident?<\/strong><\/li>\n<\/ol>\n<p>The best way to move forward is to start with an IT audit. This allows you to identify risks, prioritise actions, and build a roadmap tailored to your SME.<\/p>\n<p>Whether you are based in Brussels, Wallonia or Flanders, cybersecurity is becoming a criterion of trust. Companies that anticipate will be better prepared, more credible with their clients and more resilient in the face of incidents.<\/p>\n<p>GVISION supports Belgian SMEs in their NIS2 preparation, their <a href=\"https:\/\/gvision.be\/en\/modern-workplace\/managed-it-services\/\" data-type=\"page\" data-id=\"4312\">Managed IT services<\/a>, their <a href=\"https:\/\/gvision.be\/en\/cybersecurity\/\" data-type=\"page\" data-id=\"4230\">cyber security<\/a> and their Microsoft 365 environment.<\/p>\n<p>Do you want to know if your SME is affected by NIS2 or get a concrete action plan? <a href=\"https:\/\/gvision.be\/en\/contact\/\" data-type=\"page\">Contact GVISION<\/a> to carry out an IT and cybersecurity audit of your company.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-f912d09 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"32342\" data-id=\"f912d09\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-623a3af aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"623a3af\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>FAQ \u2014 NIS2 SMEs Belgium<\/span><\/span><\/h3><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-421b5b1 elementor-widget elementor-widget-text-editor\" data-id=\"421b5b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em><strong>Is a small Belgian SME automatically covered by NIS2?<\/strong><\/em><\/p>\n<p>No, not all small SMEs are automatically affected. The application particularly depends on the size, sector of activity, and service provided. However, a small SME could be indirectly impacted if it is a supplier or subcontractor to an organisation subject to NIS2.<\/p>\n<p><em><strong>What are the penalties for non-compliance with NIS2?<\/strong><\/em><\/p>\n<p>For essential entities directly subject to NIS2, the penalties can be significant. For others, the risks are more commercial and contractual: loss of markets, client demands, difficulties accessing certain tenders.<\/p>\n<p><em><strong>What is the difference between NIS and NIS2?<\/strong><\/em><\/p>\n<p>NIS2 significantly expands the scope of application compared to NIS. More sectors are affected, requirements are reinforced, and management responsibility is clarified. NIS2 also places greater emphasis on supply chain security.<\/p>\n<p><em><strong>Concr\u00e8tement, qu'est-ce qu'une PME doit faire face \u00e0 NIS2 ?<\/strong><\/em><\/p>\n<p>The first step is to assess whether the SME is directly or indirectly affected. This is then followed by an IT audit to identify existing vulnerabilities. The priority measures are generally: MFA, backups, endpoint protection, access rights, and documentation.<\/p>\n<p><em><strong>Does GVISION support SMEs with NIS2?<\/strong><\/em><\/p>\n<p>Yes. GVISION offers practical support: audits, action plans, Microsoft 365 security, IT outsourcing, backups, and documentation. The aim is to implement real security, tailored to the size and needs of the SME.<\/p>\n<p><em><strong>Does NIS2 apply to Belgian non-profit organisations and public bodies?<\/strong><\/em><\/p>\n<p>Yes, in many cases. Public administrations are concerned and certain non-profit organisations operating in essential sectors may also be targeted. It is important to assess each situation individually.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"has_eae_slider elementor-element elementor-element-a7fd958 e-flex e-con-boxed e-con e-parent\" data-eae-slider=\"67160\" data-id=\"a7fd958\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-875efa8 aleft elementor-widget elementor-widget-wgl-double-heading\" data-id=\"875efa8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wgl-double-heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wgl-double-heading\"><a class=\"dblh__link\" href=\"https:\/\/forms.cloud.microsoft\/e\/R2MMm7ZB9F\" target=\"_blank\" rel=\"noopener\"><h3 class=\"dblh__title-wrapper\"><span class=\"dblh__title dblh__title-1\"><span>Answer 20 questions in under 3 minutes and receive your score immediately.<\/span><\/span><\/h3><\/a><div class=\"dblh__content\"><p><a href=\"https:\/\/forms.cloud.microsoft\/e\/R2MMm7ZB9F\" target=\"_blank\" rel=\"noopener\">Free NIS2 check-up for Belgian SMEs \u2013 Fill out form<\/a><\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a292fff elementor-widget elementor-widget-html\" data-id=\"a292fff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<iframe class=\"lazyload\" width=\"640px\" height=\"480px\" data-src=\"https:\/\/forms.cloud.microsoft\/e\/R2MMm7ZB9F?embed=true\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" style=\"border: none; max-width:100%; max-height:100vh\" allowfullscreen webkitallowfullscreen mozallowfullscreen msallowfullscreen> <\/iframe>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Need SharePoint support in Brussels? GVISION helps SMEs structure, secure, and optimise their Microsoft 365 documents.<\/p>","protected":false},"author":4,"featured_media":10028,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_price":"","_stock":"","_tribe_ticket_header":"","_tribe_default_ticket_provider":"","_tribe_ticket_capacity":"0","_ticket_start_date":"","_ticket_end_date":"","_tribe_ticket_show_description":"","_tribe_ticket_show_not_going":false,"_tribe_ticket_use_global_stock":"","_tribe_ticket_global_stock_level":"","_global_stock_mode":"","_global_stock_cap":"","_tribe_rsvp_for_event":"","_tribe_ticket_going_count":"","_tribe_ticket_not_going_count":"","_tribe_tickets_list":"[]","_tribe_ticket_has_attendee_info_fields":false,"footnotes":""},"categories":[18,96],"tags":[],"class_list":["post-10025","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-fr"],"_links":{"self":[{"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/posts\/10025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/comments?post=10025"}],"version-history":[{"count":33,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/posts\/10025\/revisions"}],"predecessor-version":[{"id":10191,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/posts\/10025\/revisions\/10191"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/media\/10028"}],"wp:attachment":[{"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/media?parent=10025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/categories?post=10025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gvision.be\/en\/wp-json\/wp\/v2\/tags?post=10025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}