Skip to main content
BilgeQor
Back to industries

CISO, CTO

Telecommunications & Connectivity

Verified incident-notification context · Belgium / Centre for Cybersecurity Belgium (CCB)

Incident notifications recorded by CCB — Belgium 2025

Market context — not industry-specific evidence

The Centre for Cybersecurity Belgium's March 2026 news release reports 635 total incident notifications and 556 cyber-related incident notifications recorded by CCB in calendar year 2025. Source-defined categories within the 556 cyber-related notifications include 144 account compromise cases and 105 ransomware incidents. Separately, approximately 10 million suspicious phishing emails were processed via the Safeonweb public reporting platform in 2025. These figures are Belgium CCB incident-notification and Safeonweb reporting context only; they are not total Belgian business incident prevalence and not industry-specific evidence.

Belgium · CCB incident-notification and Safeonweb reporting contextCalendar year 2025

Total incident notifications recorded by CCB — 2025

Total incident notifications
635
Unit
incident notifications
Period
Calendar year 2025 incident-notification and Safeonweb reporting context
Scope
Belgium CCB incident notifications and Safeonweb reporting context

CCB recorded 635 total incident notifications in calendar year 2025.

Belgium CCB incident-notification reporting context only. This figure is not total Belgian business incident prevalence, hidden incident prevalence or industry-specific evidence.

Cyber-related incident notifications recorded by CCB — 2025

Cyber-related incident notifications
556
Unit
cyber-related incident notifications
Period
Calendar year 2025 incident-notification and Safeonweb reporting context
Scope
Belgium CCB incident notifications and Safeonweb reporting context

CCB recorded 556 cyber-related incident notifications in calendar year 2025.

Belgium CCB incident-notification reporting context only. This figure is not total Belgian business incident prevalence, hidden incident prevalence or industry-specific evidence.

Selected incident categories within CCB cyber-related notifications

Account compromise cases — 144
144
Unit
cases
Period
Calendar year 2025 incident-notification and Safeonweb reporting context
Scope
Belgium CCB incident notifications and Safeonweb reporting context
Ransomware incidents — 105
105
Unit
incidents
Period
Calendar year 2025 incident-notification and Safeonweb reporting context
Scope
Belgium CCB incident notifications and Safeonweb reporting context

Source-defined categories within the 556 cyber-related incident notifications recorded by CCB in 2025. These are counts, not percentages of Belgian businesses, and not industry-specific evidence.

Suspicious phishing emails processed via Safeonweb — 2025 (approximate)

Approximate suspicious phishing emails (Safeonweb)
10,000,000
Unit
suspicious phishing emails (approximate)
Period
Calendar year 2025 incident-notification and Safeonweb reporting context
Scope
Belgium CCB incident notifications and Safeonweb reporting context

Approximately 10 million suspicious phishing emails were processed via the Safeonweb public reporting platform in calendar year 2025.

Source-described approximation only; the source uses the term 'approximately'. This is Safeonweb public-reporting platform context and not a measure of total Belgian phishing volume or industry-specific evidence.

Source: CCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026

Scope: Official CCB news release context. The 635 total and 556 cyber-related figures describe incident notifications received by CCB in calendar year 2025. The 144 account compromise and 105 ransomware values are source-defined categories within the 556 cyber-related notifications. The approximately 10 million figure describes suspicious phishing emails processed via the Safeonweb public reporting platform in 2025; the source uses the term 'approximately'. These figures do not measure total Belgian business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official CCB news release context. The 635 total and 556 cyber-related figures describe incident notifications received by CCB in calendar year 2025; 144 account compromise and 105 ransomware are source-defined categories within the 556 cyber-related notifications. The approximately 10 million figure describes suspicious phishing emails processed via the Safeonweb public reporting platform in 2025; the source uses the term 'approximately' and this value is a source-described approximation, not a precisely counted total. These figures are Belgium CCB incident-notification and Safeonweb reporting context only; they do not measure total Belgian business incident prevalence, hidden incident prevalence, industry-specific evidence, compliance achievement, certification, or proof of security.

Accessible data table
Verified Belgium CCB incident-notification and Safeonweb reporting context data from CCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026, reporting period Calendar year 2025 incident-notification and Safeonweb reporting context.
MetricValueSourceScopeReporting period
Total incident notifications635 incident notificationsCCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026Belgium CCB incident notifications and Safeonweb reporting contextCalendar year 2025 incident-notification and Safeonweb reporting context
Cyber-related incident notifications556 cyber-related incident notificationsCCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026Belgium CCB incident notifications and Safeonweb reporting contextCalendar year 2025 incident-notification and Safeonweb reporting context
Account compromise cases — 144144 casesCCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026Belgium CCB incident notifications and Safeonweb reporting contextCalendar year 2025 incident-notification and Safeonweb reporting context
Ransomware incidents — 105105 incidentsCCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026Belgium CCB incident notifications and Safeonweb reporting contextCalendar year 2025 incident-notification and Safeonweb reporting context
Approximate suspicious phishing emails (Safeonweb)10,000,000 suspicious phishing emails (approximate)CCB, More attacks, more reporting: Belgium's cyber reality in 2025, 26 March 2026Belgium CCB incident notifications and Safeonweb reporting contextCalendar year 2025 incident-notification and Safeonweb reporting context

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Service Disruption
  • API Abuse
  • Unauthorized Access

Digital surfaces in scope

Customer PortalsIoT DashboardsManagement APIs

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.