Decoding the world of cybersecurity

·

Belgian study exposes dependency-driven cyber risk

More than half of Belgian organisations surveyed said a supplier had suffered or was suspected of suffering a cyber incident, pushing supply chain exposure higher in national risk priorities.

Belgian study exposes dependency-driven cyber risk
Summary
  • Belgium’s second National Cyber Study surveyed more than 300 organisations across sectors and sizes between March and May 2026.
  • Fifty-seven per cent said a supplier or service provider had suffered, or was suspected of suffering, a cyber incident.
  • The findings show resilience increasingly depends on suppliers, shared infrastructure, AI adoption, and operational readiness beyond an organisation’s own perimeter.

Supplier incidents, rising attack volumes, and growing dependence on shared digital infrastructure are reshaping the cybersecurity risk picture for Belgian organisations, according to the country’s second National Cyber Study.

The research, conducted by KPMG Advisory with the Cyber Security Coalition and supported by the Centre for Cybersecurity Belgium and technology federation Agoria, surveyed more than 300 organisations across Belgium between March and May 2026.

Fifty-three per cent of respondents said cyberattacks against their organisation had increased over the previous 12 months, while 18% reported at least one successful attack that caused disruption or damage.

The most striking result concerns the supply chain. Fifty-seven per cent said a supplier or service provider had suffered, or was suspected of having suffered, a cyber incident. The study says supply chain exposure has consequently moved sharply upwards in organisations’ risk rankings.

That finding reflects a broader change in enterprise security. Organisations may control their own endpoints, identities, networks, and development environments, but business operations increasingly rely on cloud platforms, SaaS providers, managed services, specialist software, payment infrastructure, logistics systems, and other external technology.

A supplier incident therefore does not need to compromise a customer directly to create operational consequences. Authentication failures, unavailable software, corrupted integrations, inaccessible data, or delayed third-party services can interrupt operations even when the customer’s own systems remain uncompromised.

The Belgian study also captures the ambiguity around AI. Ninety-three per cent of respondents believe artificial intelligence makes cyberattacks easier to execute, while 62% expect AI to strengthen defensive capabilities during the coming year. Those results describe AI less as a standalone threat category than as another force changing the economics and pace of both attack and defence.

Disinformation has also entered the organisational risk picture. Fifty-four per cent believe their organisation could be influenced by online disinformation campaigns, extending resilience considerations beyond conventional compromises of confidentiality, integrity, and availability.

Regulation remains an important driver. The study says many organisations have made significant progress implementing NIS2 requirements, but only a small minority consider their implementation fully complete. Belgium adopted legislation transposing NIS2 earlier than several other EU members, giving the findings relevance beyond simple awareness of the directive.

The report’s underlying theme is that compliance alone does not create resilience. Interconnected services mean the operating condition of one organisation can depend on controls and recovery arrangements elsewhere in its ecosystem. Testing, supplier governance, crisis coordination, and the ability to adapt after a disruption become as important as formal policy.

The results are based on aggregated self-reported survey responses rather than independent technical assessments of each participant. They nevertheless provide a useful view of how organisations themselves perceive changing exposure.

For Belgium, that perception is moving decisively away from cybersecurity as an isolated internal control problem. Suppliers, infrastructure, AI, regulation, and information integrity increasingly sit within the same resilience equation — and the weakest dependency may be outside the organisation that ultimately absorbs the disruption.

×