Latest resources

Stay up to date with all our publications!

At Approach Cyber, we are committed to making Governance, Risk & Compliance (GRC) more effective, more accessible, and better aligned with real business needs. Today, we are proud to announce our partnership with Formalize, a sovereign GRC platform that perfectly complements our expertise and vision.
We receive a lot of questions from clients about the NIS 2 directive. What is it like and what is its purpose? How is it different from NIS 1? Does NIS 2 apply to my organization? What steps do I need to take to be in compliance? Isn’t there an overlap with the GDPR?
Anonymisation isn’t just a compliance tactic — it’s a strategic enabler that reduces risk, builds trust, and unlocks data for innovation. In this practical guide, our Data protection expert Ana-Maria Luca explains why anonymisation matters, how it strengthens smarter data governance, and how organisations can get started through a phased approach.
The EU AI Act is changing how organisations can deploy AI — depending on the risk level and their role in the value chain. Our GRC expert Kevin Lavrijssen provides a clear overview of what’s coming, when it applies, and how to take the first steps toward compliance and stronger AI governance. 
Managing an IT security incident isn’t so different from fighting a fire. Both demand rapid assessment, tight coordination, decisive action, and constant feedback. Drawing on backgrounds in cyber security, incident response, forensics, and volunteer firefighting, we use this analogy to show how crisis management principles apply across both worlds.
A Qilin ransomware attack froze an industrial company within minutes. Encrypted systems, stolen data, operations halted. Approach Cyber’s technical and legal teams moved fast, contained the threat, met GDPR duties, and restored control in under 48 hours. This case study shows how coordinated response drives rapid recovery.
Cybercriminals exploited human trust, not systems, to trick an employee into leaking sensitive client data. This case shows how DFIR, GDPR expertise, and coordinated crisis communication contained the breach across France and Switzerland.
What begins as a cyber security nightmare ends as a transformation story. This real-life case shows how one retail organisation, with Approach Cyber’s help, turned a ransomware attack into the catalyst for lasting resilience.
A ransomware attack on Brussels Airport’s key IT supplier brought flights to a halt and stranded thousands. This is the new face of supply chain risk—where one compromised vendor can paralyse critical infrastructure across Europe.
The European Union’s Cyber Resilience Act (CRA) entered into force on December 10, 2024, and will fundamentally reshape how businesses approach cyber security for products with digital elements. Unlike NIS2, which focuses on organizational security measures, the CRA targets the products themselves.
In 2025, the secure development landscape is at a turning point. Critical regulations like the EU’s Cyber Resilience Act are forcing organisations to shift from optional best practices to mandatory secure-by-design strategies. But are organisations truly ready?
Cyber security isn’t just IT’s problem — it’s a business advantage. Explore stories that expose the myths and show how smart security drives growth.
Threat modeling isn’t just a technical step, it’s a mindset. It empowers development teams to think like attackers, ask the right questions early, and embed security from the start. By making security collaborative, practical, and developer-friendly, it lays the foundation for resilient, trusted software delivery.
“Everything we needed to take control was already online.” That’s not fiction, it’s a real case from a recent penetration test. Cybercriminals often don’t need to hack in, they log in using credentials and data already exposed on the Dark Web.
As the threat landscape grows more complex, organisations face rising pressure from AI-driven attacks, ransomware-as-a-service, and stricter regulations like NIS2 and DORA. In this article, we examine how businesses can shift from reactive defence to proactive strategy.
Dorian Pacquet shares how FinTechs can move beyond compliance to build true cyber confidence through proactive risk management and resilience.
Discover why regular, tested backups are crucial to protect your data from cyber-attacks, hardware failures, and human error—this World Backup Day.
In an interview for Dynam!sme, the digital magazine for Union Wallonne des Entreprises (UWE), David Vanderoost, CEO at Approach Cyber, discusses the Walloon cyber security landscape. 
Find out more about the NIS2 Directive in our guide. Approach Cyber can help you comply! 
Stay on top of cyber security trends with our Annual Pentest Report. Get unmatched insights and practical advice to defend your digital assets.
Cyber security’s vital role in defence is highlighted as Approach Cyber supports in enhancing EU’s cyber defence strategies amid global tensions.
Explore the dynamic world of cyber security! Experts highlight public-private collaboration, multi-factor authentication, and the business opportunities it presents.
Discover the latest trends and vulnerabilities in application security with our third edition of the annual penetration testing statistic report. This report focuses on the detection of unique business logic flaws, which can cause significant damage if left undetected.
Download our updated whitepaper on Hackable Intelligence. Discover potential attacks against machine learning based solutions and how to assess your security level.
Hear from our customers about their ISO 27001 certification journeys and learn from their experience. 
SSO (Single Sign-On) allows an organisation’s users to easily and securely access web applications without having to remember multiple login credentials. Discover the benefits.
ISO 27001 is a great business enabler, and cloud-based companies may benefit from a smooth and easy ISMS implementation, while reducing significantly cyber security risks in today’s digital world.
Discover how two of the most commonly used deception techniques can improve your security at low cost.
Identify a volunteer within your developers team willing to support the integration of security earlier in the development lifecycle and avoid delays due to vulnerabilities.
How to use psychology to improve your security? Watch the replay and get the answers from our expert.
The best cyber-security strategy is a layered one. The most important aspect is to be prepared for any eventuality and be ready to react immediately when a cyber-attack happens.
What is a SOC and what is its purpose? In this FAQ, we are demystifying the SOC and answering some important questions about it including who needs one.
When an organisation adopts the shift-left principle, they reduce their costs and their time to market while improving security of their application and customer experience.
When a company is compromised by a cyber-attack, recovery time is front of mind. How safe are your critical assets? Learn more
How secure are your web applications? Performing pentests allows vulnerabilities to be detected quickly and efficiently in order to fix them.
How to avoid an incident with your website hosting provider from causing critical data loss and business disruptions?
Our ethical hacking team is sharing statistics based on the pentests they performed in 2020 on web applications. Get your copy.
Get tips on how to initiate a sustainable privacy compliance program within your organisation.
An inspiring interview for any organisations looking to get certified.
Do you know what the TOP 3 GDPR infractions in Europe are? Our privacy consultants have highlighted the trends and share some recommendations.
Comment obtenir des subventions pour vos projets de cybersécurité auprès du gouvernement wallon? Retrouvez toutes les informations dans notre FAQ.
Reduce the exposure, facilitate the detection, and train our users: these are the steps we take to decrease the risk of successful phishing attacks. Is it enough? Read more.
Get concrete applications from our pentesters to limit your attack surface by using functionalities of Search Engines. Read more. 
Throughout our story, we will share advices and show how human can be the strongest link to face phishing attacks.  Discover more!
Humans have limited resources and energy when it comes to threat detection. Check out our fourth chapter to discover more.
Find out why humans can be considered the strongest security link in our third chapter!
Chapter two of our cyber security story!  How will our experts reduce the impact of the phishing attack?
Two security experts face a phishing attack but the story ends as a dark day for one of them … Discover the first chapter of our cyber security story!
Hoe uw subsidies voor uw cyber security projecten aan de Vlaamse Overheid aanvragen?  Vind alle informatie terug in onze FAQ.
Why security shouldn’t be overlooked when implementing Artificial Intelligence solutions.  Learn more in our white paper – request your copy! 
Let’s have a closer look at the typical ways for a product owner, a developer team and a CISO to interact during a software development project and see how frustrating it can be…
National press coverage: Approach has discovered a critical flaw in major online shops relating to IBAN
Learn everything about the technical and legal aspects of Electronic Signature on our FAQ.
Approach has been invited by ISACA Belgium to write a technical briefing about the WAF technology. Download the Tech Brief!
Fourth chapter of our ISO 27001 story written by our experts. What are the common pitfalls during an ISO 27001 implementation?
Third chapter of our ISO 27001 story. Look at the typical roadblocks encountered during an ISO 27001 certification project.
Second chapter of our ISO 27001 story presented by our experts. Learn why obtaining the ISO 27001 certificate can be a fantastic business-enabler.
First chapter of ISO 27001 by our experts. Let’s have a look to the meaning of the certification and discover what the next chapters will talk about !
Nothing should be left behind when speaking in terms of security…  A story by David Bloom, Cyber-Security Consultant at Approach.
Several cases of targeted phishing by email have been reported by some of our clients. Download our white paper to learn more about the mechanism of such an attack.
With the emergence of digital and online services, using a trusted digital identity for your users, collaborators, partners has become even more important and challenging.
Approach est l’une des discrètes chevilles ouvrières derrière la solution d’identification sécurisée Itsme, dévoilée récemment. Interview de Régional-IT.

Clients who trust us

As AI adoption accelerates, organisations must innovate responsibly while preparing for regulations like the EU AI Act. The joint approach of Approach Cyber and Yields helps them do exactly that. Our first project with itsme® shows how AI governance can be implemented quickly, effectively, and without slowing innovation.
Cybersecurity is more than technology — it’s about people, expertise, and trust. See how Approach Cyber empowers organisations to stay resilient and focused, no matter the threat.
Approach Cyber and AXS Guard join forces to create one of Belgium’s leading cyber security providers, delivering end-to-end protection and resilience for organisations.
Compliance alone isn’t enough—your people are the real first line of defence. Turn awareness into action and build a security culture that lasts.
In today’s volatile digital landscape, cybersecurity is no longer just a technical matter, it’s a question of trust. At Approach Cyber, digital trust is more than a goal; it’s our foundation. This article shares how we embed trust across our culture, systems, and practices—and why it matters more than ever.
As cyber threats continue to evolve and regulatory expectations tighten, understanding where organisations stand has never been more critical. Our 2025 Pentest Report offers an unfiltered look into the vulnerabilities shaping today’s security landscape, and what can be done about them.
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.