Insights & ideas
The through-line
Bart Asnot's argument is that defence is structurally, almost by design, one step behind, and that this gap is organisational rather than technical. Attackers face no procurement cycle, no audit, no compliance calendar: "De andere kant, de cyberactoren, they don't care, die zien gewoon iets nieuw, iets cool en die gaan dat proberen binnen te geraken" [2], which is why "soms hebben die een kleine voorsprong" [3]. Everything else follows from that asymmetry, whether the subject is cloud migration, generative AI, or the sheer arithmetic of unfilled SOC vacancies. His counterweight is not a product but a posture: "Wat ik altijd aanraad aan mensen is: denk als een hacker. Denk als een cyberactor. Als je de digitale wereld wil gaan beveiligen, denk hoe de andere kant werkt" [2][3].
Underneath the pessimism about the gap sits a firm humanism about who is in charge. "Wij leiden. Technologie volgt. Vanaf het moment dat technologie onafhankelijk begint te leiden, ja, dan gaan we een shift krijgen. Ik zie dat niet echt gebeuren. Ik hoop ook dat dat niet echt gebeurt" [2]. That expectation is being tested by his own later framing of adversaries as AI-powered systems that "collaborate, adapt, escape intended boundaries, and pursue complex objectives with remarkable persistence" [1], but the underlying rule he applies to every innovation stays constant: "Hoe meer een innovatie kan gemaakt worden voor het goede, hoe meer dat ook kan worden misbruikt voor het slechte" [2][3].
On the war that starts before the war
Hybrid conflict, in his account, begins digitally long before anything kinetic. Russia's invasion of Ukraine was preceded by a full year of mis- and disinformation campaigns in the eastern regions, aimed at shifting the population's mindset before a single border was crossed [2][3]. The implication is that the observable attack is the late stage of a campaign whose opening moves were informational, and that a country reading only technical indicators is watching the wrong phase.
That framing extends to how targeting moves around the map. Attack waves follow geopolitical and economic shifts toward whichever sector is currently most exposed. During COVID, criminals and espionage-focused states deliberately went after hospitals, precisely because their security maturity was low and they could not afford to stop operating [2][3]. Vulnerability plus operational necessity is the combination adversaries look for.
On Belgium as a target and as a defender
Belgium's exposure is diplomatic rather than industrial. With roughly 48,000 registered members of the international diplomatic community on its territory, government and diplomacy have become the critical target sector, and the timing is explicit: pro-Russian groups such as NoName057 launch DDoS attacks the day after Belgian announcements of support for Ukraine [2][3]. Retaliation is fast, visible and political.
He is nonetheless unusually positive about the country's posture, pointing to European and foreign reporting in which "eigenlijk België altijd in de top drie, soms top één staat van best beveiligde land in Europa" [2][3]. Much of what sustains that position is deliberately invisible, which he defends as strategy rather than secrecy for its own sake.
On attribution, silence and why not everything gets named
Attribution is asymmetric in a way that shapes every possible response. Opportunistic ransomware groups tend to self-identify, because naming themselves builds street cred; targeted state-linked operations are hidden by default behind routers and infrastructure spread across many countries, which makes legal recourse close to impossible and makes something like a NATO Article 5 trigger nearly unreachable [2][3].
He also argues against the instinct to publicise every malicious attempt. Announcing everything would breed paranoia, and paranoia is itself the adversary's objective, since the goal of destabilisation campaigns is a country's economic and social stability rather than any single system [2][3]. Deliberate quiet is therefore part of the defence, not a failure of transparency.
On threat intelligence as gold or mud
"Cyber threat intelligence is het goud of de modder van cyber" [3]. The scale involved is enormous: Microsoft ingests roughly 78 trillion security-related signals per day, anonymises and scrubs them, and has human analysts correlate the patterns [2][3]. The output that matters is narrow and confidential, the so-called nation state notifications sent to organisations when there is near-certain evidence of state-linked activity against them, sometimes before the attack lands [2][3]. The volume is only useful because people turn it into a specific warning to a specific customer.
On AI arming both sides
Generative AI has, in his reading, massively scaled up the script kiddie. Attacks that once required genuine coding skill can now be generated on demand, and AI combined with crawling engines lets low-skill actors find vulnerabilities and reach actions on objective far faster than before, raising both the volume and the impact of low-end cybercrime [2][3]. This is the clearest case of his general rule about innovation cutting both ways [2][3].
The picture has since sharpened into something less about amateurs and more about machines. Today's adversaries are "no longer limited by human speed", with AI-driven systems observed performing sophisticated attack chains, collaborating, adapting and escaping intended boundaries in pursuit of complex objectives [1]. That is the second of the two fronts he describes cybersecurity teams as fighting simultaneously [1].
On the talent gap
The first front is people, and the numbers are the argument. In Belgium alone the EURES employment platform listed 2,723 new SOC-related vacancies in a single month, with more than 24,000 cybersecurity-related openings posted across the broader EURES database over the same period [1]. His conclusion is blunt: "there are not enough skilled defenders to keep pace with demand" [1]. Finding SOC analysts has become increasingly difficult, and the shortage is worsening rather than easing [1]. He positions Project Perception as an attempt to address the talent shortage and AI-powered adversaries together, treating them as one problem with one answer rather than two separate procurement lines [1].
On why 100% security does not exist
"100% bescherming bestaat nooit in de digitale wereld. In die fysieke wereld eigenlijk ook niet" [2][3]. The reason is not budget but motion: the risk landscape changes constantly, so a fully funded security programme is already outdated days later once employees adopt a new device or a new technology, and the threat model changes overnight [2][3]. Security leadership is therefore a continuous exercise in re-assessing risk and deciding what is acceptable and what is not, rather than a project with a completion date [2][3].
The same lag shows up structurally in cloud adoption. Organisations migrate but keep applying legacy on-prem thinking to a shared-responsibility model, and that mismatch hands attackers a head start, because they immediately probe anything new while the defending organisation is still working through regulations and audits [2][3].
On killing the hoodie
His strongest cultural point is that the technical framing of cybersecurity actively blocks awareness. Security should work like driving a car: users do not need to understand the engine, only the rules, in the same way a driver simply observes a 30 km/h limit [2][3]. Translated into practice that means a small set of instructions, a password manager, two-factor authentication, and not clicking unknown links [2]. The image of the hacker in a hoodie, and the complexity it signals, has to go if awareness is ever going to reach ordinary people [2][3].
Takeaways
- Assume attackers move first on anything new, because they operate without regulation, audit or procurement delay: "die zien gewoon iets nieuw, iets cool en die gaan dat proberen binnen te geraken" [2][3].
- Treat security as a rolling risk decision, not a finished programme: a fully funded posture is outdated days later once staff adopt new devices or technologies [2][3].
- Watch information operations as the opening phase of conflict; a year of mis- and disinformation preceded the physical invasion of Ukraine [2][3].
- Expect targeting to follow vulnerability plus operational necessity, as with hospitals during COVID and, in Belgium, the roughly 48,000-strong diplomatic community and DDoS retaliation from groups like NoName057 [2][3].
- Plan for the talent gap as a hard constraint: 2,723 new SOC-related vacancies in Belgium in one month and over 24,000 cybersecurity openings across EURES [1].
- Do not port on-prem security assumptions into cloud's shared-responsibility model; the mismatch is a structural head start for attackers [2][3].
- Build awareness on rules, not mechanics, and drop the hoodie imagery: password manager, 2FA, no unknown links [2][3].
In the news
- If you are passionate about technology and supporting people and organizations to use the power of GenAI through Microsoft Copilot, give my friend Radek, the awesome architect manager in Microsoft Poland a ping. Great company and team to work for!
- Ik kijk ernaar uit om 24 September te kunnen spreken over NIS2, impact van AI, de fysieke/hybride laag in het threat landscape en hoe dit alles geconnecteerd is. Dank je CommScope Bart Deboeck Johan Torfs om aan mij te denken voor dit event! #NIS2 #Cybersecurity #AI #HybrideSecurity #Microsoft #CCB #VUB
- Project Perception: Solving Two Cybersecurity Challenges at Once Cybersecurity teams are fighting a war on two fronts. Challenge #1: The talent gap is getting worse. Finding SOC analysts has become increasingly difficult. In Belgium alone, the EURES employment platform listed 2,723 new SOC-related vacancies in the last month. Across the broader EURES database, more than 24,000 cybersecurity-related openings were posted during the same period. The reality is simple: there are not enough skilled defenders to keep pace with demand.
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.

