Weekly #cybersecurity digest to your inbox

Subscribe for our weekly digest and get each Friday the most important cyber security news, list of upcoming free webinars and a summary of Cyberday development to your inbox.
Thanks! See you in your inbox on Fridays. :)
Unfortunately something went wrong. You can contact us at team@cyberdayai.

What is the NIS2 Law in Belgium? 🇧🇪 Introduction to requirements

Learn what the Belgian NIS2 Law is, Belgium’s national implementation of the EU NIS2 Directive. Understand key requirements, compliance timelines, sector coverage, and how Cyberday helps you meet them.

article

29.4.2025

What is CyberFundamentals? 🇧🇪 Belgium's cybersecurity framework

Learn what is CyberFundamentals, Belgium's cybersecurity framework for SMEs. Get an overview of requirements, benefits, and steps for compliance.

article

29.4.2025

10 things I wish I knew: Starting your ISO 27001 project on the right track

This post shares 10 key lessons learned from going through an ISO 27001 certification project - from the importance of setting clear goals and managing documentation to the realities of risk management and the value of using the right tools.

article

23.4.2025

Understanding NIS2: supervision and penalties of non-compliance

Let's now look into the NIS2 directive, it's supervision in EU member states and what is supervised. We'll also check out NIS2 penalties for noncompliance and how you can stay compliant (to avoid penalties).

article

15.4.2025

Comparing EU cybersecurity frameworks: NIS2, GDPR, DORA and more

A comparison of key cybersecurity frameworks in the EU, including NIS2, GDPR, DORA, CRA, and ISO 27001. Learn who they apply to and what they require.

article

10.4.2025

ISO 27001 compliance vs. certification: differences, benefits & which path to choose

Understanding when to pursue ISO 27001 compliance rather than going for certification—or vice versa—hinges on your organizational priorities, resources, and long-term security strategies. Check the differences and learn which path to choose.

article

1.4.2025

Framework recap, US security & and role management: Cyberday product and news summary 3/2025 🛡️

The March product and news update presents updates to role management and the new Trust Center, a review of the key frameworks for 2025 and US security.

article

28.3.2025

Understanding DORA compliance: Key steps to prepare your organization

Understand DORA compliance and get a clear DORA requirements summary with key compliance areas, practical steps, and essential guidelines to strengthen your organization's digital resilience.

article

18.3.2025

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

⚠️ New AiTM #phishing kit (sold for 300$/mo) is growing fast in cybercrime world. AiTM phishing involves intercepting password and session cookies by deploying a proxy server between the user and the website - and can thus go around MFA.

Go to article at
17.3.2023

Exfiltration malware takes center stage in cybersecurity concerns

📈 Spike in #malware designed to exfiltrate data directly from devices and browsers. Infostealers let cybercriminals to work at scale - stealing credentials, cookies, and auto-fill data to use in targeted attacks or sell on the darknet.

Go to article at
17.3.2023

LockBit Claims it Stole SpaceX Schematics From Parts Supplier, Threatens to Leak Them

⚠️ #Ransomware gang boasts breaking into Maximum Industries, SpaceX supplier, and stealing 3,000 "certified rocket part drawings". LockBit's other recent alleged victims include e.g. ION and Royal Mail.

Go to article at
17.3.2023

Fortinet warns of new critical unauthenticated RCE vulnerability

"Critical" buffer underflow #vulnerability (CVSS 9.3) impacting FortiOS and FortiProxy disclosed. Allows unauthenticated attacker to execute arbitrary code or perform DoS on vulnerable devices. Updates and workarounds in article >>

Go to article at
10.3.2023

Ransomware review: March 2023

Recent #ransomware numbers: ☢️ LockBit alone leaked data of 126 victim organizations on its leak site during February 2023 🏭 Services, logistics and tech top industries 🦹 Medusa a new active gang

Go to article at
10.3.2023

Fifth of Government Workers Don't Care if Employer is Hacked

Survey 800 public sector workers found "not my job” -attitude exposing governments to risk 👤 34% of workers recognize their actions impact organization’s security ⚠️ 21% said they don’t care if organization is hacked #cybersecurity

Go to article at
10.3.2023

GitHub begins 2FA rollout for code contributors

Developer accounts are popular targets for #phishing and account takeover. Protecting them is a critical step toward securing the software supply chain. 🔑 GitHub developers and admings now have 45 days to configure 2FA on their accounts.

Go to article at
10.3.2023

The Pain of Double Extortion Ransomware

⚠️ Double extortion #ransomware means stealing & encrypting victim's data, enabling demanding two (or more) separate ransom payments. 71% say double extortion tactics have increased 65% agree these make tougher to refuse ransom demands

Go to article at
10.3.2023

Record Number of Mobile Phishing Attacks in 2022

🎣 50% of mobile phone owners worldwide exposed to a #phishing attack every quarter 📈 Mobile phishing encounters have increased every quarter since Q2 2020 ⚖️ Insurance, legal, healthcare among most heavily targeted

Go to article at
3.3.2023