🤖 AI Summary
This study addresses the acute vulnerability of Belgian small and medium-sized enterprises (SMEs) to escalating AI-driven cyber threats, exacerbated by widespread shortages of security resources and expert support. Since 2019, the “Keep It Secure” initiative has established and evaluated a certified network of cybersecurity professionals in Wallonia, delivering an integrated support framework encompassing awareness raising, protection, auditing, and incident response. The research presents the first systematic six-year longitudinal analysis of a regional cybersecurity expert ecosystem, aligning practitioner certification labels with Belgium’s national Cyber Fundamentals framework. Through structured qualitative methods—including in-depth interviews and thematic analysis—the project collected longitudinal data from over 90 enterprises and 120 professionals. Findings demonstrate that this approach significantly enhances organizational security postures, validating the effectiveness and scalability of integrating standardized certification with practical, regionally embedded cybersecurity capacity building.
📝 Abstract
The importance of cybersecurity for Small and Medium Enterprises (SMEs) has never been greater, especially given the rise of AI-driven threats. Supporting SMEs requires a sustained effort to ensure they have access to resources and expertise covering awareness, protection, auditing, and incident response. Since 2019, our work with the Keep It Secure initiative has focused on helping Belgian (Walloon) SMEs strengthen their cybersecurity posture through access to a network of labelled cybersecurity experts. In this process, we interviewed over 120 professionals from around 90 companies and gathered rich insights about the nature, strengths and weaknesses of our regional ecosystem. While our initiative primarily targets the labelling of cybersecurity experts, we demonstrate increasing alignment with the broader Cyber Fundamentals framework deployed at the federal level in Belgium, which supports official certification. This paper reports on the progress and lessons learned from this long-term effort, highlighting how expert validation, based on a structured evaluation approach, can help improve SME cybersecurity.