Belfort Advisory5 October 20265 min read

Gesloten Bedrijvendag: New Threats, Familiar Weaknesses

AI speeds up external attacks, but the weaknesses that decide the damage are old ones: access, visibility, workarounds, silence and legal readiness.

Hand holding a 24/7 "Gesloten voor cybercriminelen" sign on a glass door (CCB campaign)

Yesterday, Belgian organizations opened their physical doors to the public for Open Bedrijvendag. Today, the Gesloten Bedrijvendag initiative urges them to close those doors digitally. The campaign highlights how artificial intelligence allows threat actors to discover and exploit network vulnerabilities faster and at greater scale, reducing the time organizations have to defend their perimeters.

While securing the perimeter against automated threats is a fundamental necessity, allowing emerging technology to dominate the boardroom conversation creates a strategic blind spot. Cybersecurity discussions tend to follow the newest headline, pivoting from ransomware to supply-chain attacks and now to generative AI. Meanwhile, many organizations continue to struggle with the same recurring structural failures. These include former employees retaining access to critical financial systems, sensitive corporate data moving outside approved boundaries, rigid operational rules that encourage employees to cut corners, and a corporate culture where errors or suspected internal fraud are hidden rather than reported.

These problems are not new, nor are they secondary to external threats. They often determine how far an incident can spread, how long it remains unnoticed, and how difficult it becomes to contain.

The Threat Changes. The Basics Do Not.

Recent global breach data understandably grabs attention by highlighting that exploiting external vulnerabilities has overtaken stolen credentials as the primary method attackers use to enter a network.

Read beyond the headline, however, and the operational picture becomes deeply familiar. Compromised credentials remain central to attacks, and human involvement remains a factor in over sixty percent of all breaches. Administrative errors still cause significant data exposure, and access privileges persist far longer than they should. Furthermore, the risk is not exclusively external. Ponemon’s 2026 benchmark paints a similar picture from an insider-risk perspective. Incidents involving negligence, malicious insiders, or compromised legitimate credentials took an average of 67 days to contain, with only 13% contained within 30 days.

The technological methods of attack are evolving rapidly, but the underlying governance and control failures they exploit are remarkably persistent.

The Five Pillars of Internal Resilience

Instead of merely focusing on the external threat landscape, leadership teams must prioritize internal resilience. This requires establishing a framework of controls that limits the financial and operational impact of a compromised identity, an internal fraud attempt, or an honest mistake once the perimeter has been crossed.

Before chasing the next security trend, organizations must ensure they have established the following five foundational elements of internal control, answering the critical questions associated with each.

Diagram of the five pillars of internal resilience: access, visibility, guardrails, culture and legal, sitting beneath the perimeter and identity layers
The Five Pillars of Internal Resilience

1. Access Governance and Privilege Management

Accumulated permissions, dormant contractor accounts, and delayed offboarding bypass the segregation of duties and create direct pathways for both external attackers and internal fraud. Access must be systematically managed throughout the entire employee lifecycle.

Question to ask: Who currently holds access to our critical systems, and are those privileges justified by their active employment status and current role?

2. Data Visibility and Anomaly Detection

Visibility is not about micromanaging daily employee tasks; it is about establishing a baseline of normal business operations so that deviations stand out immediately. That visibility must itself be designed proportionately and within the applicable employment and privacy framework. Monitoring ensures that unauthorized movements of intellectual property or financial data are flagged before months go by.

Question to ask: If an account suddenly exports large volumes of confidential client data or accesses financial systems at unusual hours, would our monitoring catch the anomaly before significant damage occurs?

3. Pragmatic Operational Guardrails

Complex, overly restrictive policies often fail in practice because they create excessive friction. When security or compliance rules prevent employees from completing their tasks efficiently, workarounds become more likely, such as moving sensitive files to personal devices or utilizing unsanctioned cloud tools.

Question to ask: Do our employees have clear, usable guidelines that enable them to work securely, or are our internal controls inadvertently driving them to bypass security measures?

4. A Transparent Reporting Culture

The greatest risk in incident management is the delay between a security event occurring and the response team discovering it. In a punitive corporate culture, an employee who clicks a suspicious link or suspects a colleague of fraudulent activity will likely remain silent out of fear. A mistake reported in five minutes is a manageable technical task, whereas the same mistake concealed for three weeks becomes an organizational crisis.

Question to ask: If a mistake is made or an anomaly is spotted, is our culture supportive enough that an employee will report it immediately rather than concealing it?

5. Legal and Procedural Readiness

Discovering an incident often triggers panic, leading to hasty internal actions that can jeopardize subsequent legal proceedings. In Belgium, internal monitoring and investigations sit within a specific employment, privacy, and evidence framework. CAO 81, for example, places conditions on monitoring electronic communications, while other forms of monitoring and investigation have their own requirements. Digging into communications or confronting staff without a legally sound procedure can quickly turn a security incident into a severe employment law liability.

Question to ask: If an internal breach or fraud incident occurs tomorrow, does our leadership team know how to conduct a legally compliant investigation?

Close the Outside Door. Then Check Who Holds a Key.

Securing the digital perimeter is a necessary starting point in an era of accelerated cyber threats. However, leadership teams must not let the latest technological headline distract them from the foundational controls that govern what happens once someone bypasses that perimeter. Artificial intelligence might explain how an attacker found a vulnerability so quickly, but it does not explain why a former contractor still has access to the payroll system six months later, or why an incident response team compromises its own investigation through procedural errors.

Those challenges are much older. And while no organization can control the global threat landscape, it has far greater control over these weaknesses.

Want to discuss how this applies to your organisation?