“Too small to be of interest”: the losing bet Belgian SMEs make on ransomware
It is the sentence that reassures, and the sentence that condemns: “We are too small, nobody is interested in us.” It is false, and it is dangerous. Modern attacks no longer aim, they sweep: a script scans thousands of companies at once and hits the most vulnerable, without knowing or caring about their size. In Belgium, 42 % of SMEs have already been hit, and the average cost of an attack has jumped to 42,000 euros. Feeling small has become the first risk factor.
A Friday evening, in an industrial SME. The teams have gone home, the servers are running. Somewhere, an automated program tests thousands of addresses, spots a poorly protected access point, gets in. On Monday morning the files are encrypted, production is at a standstill, and a message demands a ransom in cryptocurrency. Nobody on the attackers' side has ever heard of this company. It was not chosen: it was found. That is the whole difference between yesterday's threat, targeted, and today's, industrial and blind.
The end of “it only happens to the big ones”
The Belgian figures dismantle the myth methodically. According to data cited by the specialist press on the basis of work by the Centre pour la Cybersécurité Belgique (the Belgian federal cybersecurity centre), the country suffers the equivalent of more than twenty ransomware attacks a day on average, and 42 % of Belgian SMEs have already been hit by an attack. Worse: 30 % of companies still have no cybersecurity strategy at all. The hardest-hit sectors are not only high technology: retail and industry come top, and the most common entry point remains disarmingly banal, the takeover of an account and the exploitation of an unpatched flaw. The attack almost never begins with a keyboard genius: it begins with a weak password or a forgotten update.
Phishing, the door you open yourself
The most counter-intuitive fact in all of cybersecurity comes down to one statistic: the vast majority of incidents do not start with a technical feat, but with a simple email. A message that imitates an invoice, a bank, a supplier, a colleague, and that pushes a rushed employee to click, to enter a password, to open an attachment. This is not an IT problem, it is a problem of organisation and human vigilance. Which has a decisive consequence for SMEs: most protection is not bought, it is installed in habits. Strong, unique passwords, two-factor authentication, updates applied, backups that have been tested, and teams that can recognise a booby-trapped email. None of these measures requires a large-company budget.
« An SME's cybersecurity is not first and foremost a matter of software. It is a matter of simple rules, kept by everyone, all the time. »
NIS2: the subject has just changed in nature
One new element reshuffles the cards in 2026: the European NIS2 directive, transposed into Belgian law by the act of 15 May 2025. It extends cybersecurity obligations to a far wider set of organisations, including SMEs in sectors deemed essential or important, and requires registration with the Centre pour la Cybersécurité Belgique. Two concrete effects. First, for the companies directly concerned, compliance is no longer optional. Second, and this touches almost everyone, the large clients subject to NIS2 are starting to demand security guarantees from their SME suppliers: cybersecurity is becoming a condition of market access, regardless of your own size. The subject has moved from theoretical risk to commercial requirement.
Security is no longer an option, it is a condition of survival
A cyberattack is not a technical incident you recover from in a few hours. It hits operations, finances and reputation at the same time, and for a share of the SMEs affected, it is fatal. The paradox is that basic protection costs infinitely less than the damage: a few well-kept rules stop the overwhelming majority of automated attacks, the very ones that strike at random. Believing you are too small to be targeted, in 2026, is not modesty. It is the riskiest bet a leader can make.
Sources
Centre pour la Cybersécurité Belgique (CCB), “Belgium's cyber reality in 2025” and key figures 2025 (635 notifications, +70 %, ransomware incidents) · CCB data relayed by the specialist press (ITdaily): 42 % of SMEs hit, 30 % with no strategy · SPF Économie, SME Cybersecurity Barometer 2025 (average cost of an attack from €28,000 to €42,000) · Act of 15 May 2025 transposing the NIS2 directive into Belgian law · Safeonweb and cert.be recommendations · LUCID field observations.
The first 30-minute conversation is free. That's where it gets framed, with no commitment.

