K

Cybersecurity

Cybersecurity is the practice of protecting software, devices, networks and the people using them against deliberate attack, organised around where in the chain the defence is placed.

Overview

Cybersecurity is the practice of keeping software, devices, networks and the people who use them out of an attacker's reach, and the field divides mainly by the point in the chain where the defence is placed. The work happens before code ships, by scanning source and cloud configuration for known weaknesses; after it ships, by hardening a released application so it survives on a device the vendor does not control; at the endpoint and the network edge; and inside the humans, who stay the cheapest way in. The second axis cuts across all of those and concerns who finds the flaw, your own automation on a subscription or outsiders paid per valid finding, which trades predictable cost against unpredictable coverage. Belgian companies occupy most of these positions: Aikido Security in Ghent scans code and cloud infrastructure for development teams, Guardsquare in Leuven hardens iOS and Android applications against reverse engineering and tampering, XFA in Antwerp secures unmanaged and personal devices on a Zero Trust model, Stack Canaries in Hasselt works on cloud security posture, OutKept in Ghent runs phishing simulation through a community of ethical phishers, and Intigriti in Antwerp runs the outsider side by connecting organisations to ethical hackers through managed bug bounty programs. The consultancy layer sits alongside the products, with Kurt Ceuppens at NVISO in Brussels and Sebastien Deleersnyder at Toreon in Antwerp, while Thales Belgium and Proximus Ada carry the defence and telecom end of the same work. The tooling for the attacker's own craft is Belgian too, since Hex-Rays in Liege builds IDA Pro, the disassembler used widely in malware analysis and vulnerability research, which is the same instrument both sides reach for.

Stated facts & numbers

  • Entities tied to this concept on the wiki: 46, of which 15 companies and 15 people
  • Code and cloud scanning: Aikido Security, Ghent, founded 2022, EUR 78M raised, led by Willem Delbare
  • Mobile app hardening: Guardsquare, Leuven, founded 2014, iOS and Android code hardening
  • Bug bounty and ethical hacking: Intigriti, Antwerp, founded 2016, Stijn Jans founder and CEO, Inti De Ceukelaire Chief Hacker Officer
  • Device and endpoint security: XFA, Antwerp, founded 2021, Zero Trust alternative to MDM, Lars Veelaert co-founder and CEO
  • Cloud security posture: Stack Canaries, Hasselt, founded by Martijn Claes
  • Phishing simulation: OutKept, Ghent, founded 2020, Simon Bauwens co-founder and CEO
  • Reverse engineering tooling: Hex-Rays, Liege, founded 2005, maker of IDA Pro
  • Consultancy layer: NVISO in Brussels under Kurt Ceuppens, Toreon in Antwerp under Sebastien Deleersnyder
  • Corporate and defence end: Thales Belgium in Tubize, Herstal, Hasselt and Brussels; Proximus Ada in Brussels
  • Regulatory driver: NIS2 directive, 18 critical sectors, national transposition due 17 October 2024
  • Cross-sector body: Cyber Security Coalition, joining academia, private sector and public authorities
  • Endpoint share of incidents: Over 70% start at endpoints, over 90% through a clicked link, per Pelle Aardewerk

Something wrong or missing? Send an update. Fixed within 24 hours.