CyberNovaLabs.io

Resources

One practical guide a month, with figures and sources, on B2B prospecting, websites, AI and automation.

October 7, 2026 · 7 min read

Data breach at FWB: three weeks before it was confirmed (05/10)

Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.

Read the article →
October 7, 2026 · 7 min read

NIS2 France: are hotels and tourism in scope?

Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.

Read the article →
October 6, 2026 · 7 min read

DGFiP breach: stolen logins, no MFA, no detection (29/09/2026)

On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.

Read the article →
October 6, 2026 · 8 min read

B2B appointment setting: phone, LinkedIn or email?

Channel choice is not a matter of taste. It is set first by what the law of each country allows for the contact you target, then by the buyer's role. Here are the four national regimes, the channel table by buyer profile, and the formula that tells you how many contacts you need to work.

Read the article →
October 6, 2026 · 9 min read

NIS2 Luxembourg: is your online shop in scope?

Luxembourg brought NIS2 into national law with the Law of 5 May 2026. An online shop selling its own products is, in most cases, not an entity in scope. But three situations put it in scope, and a fourth catches it through the supply chain. Here are the tests, in order.

Read the article →
October 5, 2026 · 7 min read

FortiMail: critical flaw exploited on your mail gateway (01/10/2026)

On 1 October 2026 Fortinet issued an emergency advisory for a critical FortiMail flaw that is already being exploited. The appliance in question filters and relays every message you send. For an SME, email gateway security is not one more technical topic: it is the channel your quotes and invoices travel on.

Read the article →
October 5, 2026 · 9 min read

NIS2 Belgium: are estate agents and syndics in scope?

Short answer: no. Real estate appears in no annex of the Belgian NIS2 law. But your in-scope client will send you its security questionnaire, your professional rules already demand discretion, and your client-funds account is a target. This guide separates what does not apply from what does.

Read the article →
October 4, 2026 · 8 min read

NIS2 Netherlands: are law firms in scope of the Cbw?

The Cyberbeveiligingswet took effect on 15 August 2026. Legal services appear in none of its sector annexes, so a Dutch law firm is not a regulated entity. It still receives its clients' NIS2 questionnaires, and the Advocatenwet and Voda already require measures.

Read the article →
October 3, 2026 · 8 min read

B2B appointment setting for transport and logistics

Road hauliers are licensed, which means every country keeps an official register of licence holders - the cleanest prospect list you will ever build. Then it is a matter of calling at the right hour and leading with cost per kilometre. The method for the Netherlands, Belgium, France and Luxembourg.

Read the article →
October 2, 2026 · 7 min read

NetScaler: two flaws exploited before the patch (27/09/2026)

Eight vulnerabilities, two exploited before the patch existed, and four national authorities raising the alarm within three days. Here is the part that matters to an SME that does not run its own remote-access appliances.

Read the article →
October 2, 2026 · 7 min read

B2B appointment setting: define a qualified appointment

A qualified appointment is not an appointment you feel good about. It is an appointment that matches a grid written and signed before the first call. Here is the one we use, with the proof expected for every line and a closed list of rejection reasons.

Read the article →
October 2, 2026 · 7 min read

NIS2 France: are accounting firms and fiduciaries in scope?

An accounting practice is not an entity listed by NIS2, and France has not even finished transposing it. This guide sets out what does affect you, with the official texts and figures.

Read the article →
October 1, 2026 · 7 min read

Jims data breach: 150,000 members, IBANs exposed (29/09/2026)

On 29 September 2026 Colruyt Group admitted it had underestimated the data breach at its Jims gym chain. The headline number is not the lesson. The ten-week gap between the first statement and the second one is — and so is what the GDPR expects of you during that time.

Read the article →
October 1, 2026 · 7 min read

NIS2 Luxembourg: manufacturing, who is actually in scope?

Luxembourg's NIS 2 Act has applied since 10 May 2026, and self-registration with the ILR was due by 10 July 2026. For a manufacturer, everything hinges on one line of Annex II: five NACE divisions, and nothing else. This guide settles the scope, the reporting clock, the fines and the public funding available.

Read the article →
September 30, 2026 · 7 min read

Cyber Resilience Act: ANSSI briefs manufacturers (23/09/2026)

One official event, two deadlines and a reporting platform that is already live. Here is what the Cyber Resilience Act changes for an SME that sells software, resells hardware under its own brand, or simply buys both.

Read the article →
September 30, 2026 · 8 min read

NIS2 Belgium: healthcare, hospitals and labs, who is in scope?

Belgium puts healthcare among the highly critical NIS2 sectors. Here is who is genuinely in scope, what the CCB expects, and why two deadlines have already gone by.

Read the article →
September 29, 2026 · 7 min read

GDPR fines: the EDPB sets a five-step method (17/09/2026)

Before writing an amount, a data protection authority will now have to work through five questions in order. The text is open for public feedback until 13 November 2026. Here is what an SME in the four countries should take from it, and what it can prepare this week.

Read the article →
September 29, 2026 · 7 min read

B2B appointment setting: pay per appointment or retainer?

Two vendors, two invoices: one charges per appointment booked, the other a flat monthly fee. The cheaper quote on paper is rarely the cheaper option by year end. Here is the arithmetic, the only public figures available, and the clauses to write before you sign.

Read the article →
September 29, 2026 · 9 min read

NIS2 Netherlands: transport and logistics, who is in scope?

The Dutch NIS2 implementing act entered into force on 15 August 2026. Against expectations, most road hauliers are not directly in scope. Here are the exact criteria, the competent authority, the reporting deadlines, the fines, and the supply chain route that catches you anyway.

Read the article →
September 25, 2026 · 7 min read

B2B prospecting and GDPR: France, Belgium, the Netherlands

The GDPR does not tell you whether you may cold-email a company. National laws implementing Directive 2002/58/EC decide that — and they do not use the same test. Named or impersonal address, link to the recipient's professional activity, an address published to receive offers: what makes a send lawful in Brussels can make it unlawful in Amsterdam.

Read the article →
September 24, 2026 · 7 min read

How much does a qualified B2B appointment cost? 2026 prices and how to calculate yours

From €80 to €1,200 excl. VAT: the spread is huge, and it has reasons. Here are the prices actually charged in 2026, what drives them, and the one formula that decides.

Read the article →
Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked