In an earlier article I explained what CyberFundamentals (CyFun) is: the Belgian framework from the CCB that makes cybersecurity manageable for companies without a dedicated security team. Great. But then you open the framework, see dozens of measures spread across functions and categories, and think: where on earth do I start?

This article is that answer. Not a full retelling of the framework (for that I’ll gladly point you to the official CyFun documentation from the CCB), but the order that works in practice for an SME of five to fifty people.

Step 1: know what you have

Everything starts with the inventory. Which servers are running? Which laptops are in circulation? Which software, which cloud services, which domain names, which certificates? Sounds trivial, but in nine out of ten companies I visit, reality differs sharply from what people think they have. Forgotten test servers, a NAS belonging to an ex-employee, certificates quietly expiring next month.

You cannot secure what you don’t know. Start with a list. A spreadsheet beats nothing, an automated inventory beats a spreadsheet, because it doesn’t go stale.

Step 2: limit who can access what

Access management is the cheapest security there is. Multi-factor authentication on everything reachable from outside: email, VPN, cloud applications. Individual accounts per person, no shared passwords, and admin rights only for those who genuinely need them. Someone leaves? Their access is cut the same day, not “at some point”.

This mostly costs discipline, not money. And it’s the measure that stops the most real-world intrusions.

Step 3: make sure you can recover

Backups, but real ones. Not “there’s a copy somewhere”, but: automatic, daily, with at least one copy disconnected from your network, because ransomware will happily encrypt your backup drive too if it’s just sitting there attached. And at least once a year: actually test that you can restore that backup. A backup that has never been tested is a hope.

Step 4: notice when things go wrong

This is where detection and logging come together, and where most SMEs fall through the ice. Ask yourself honestly: if a server goes down tonight, or if someone tries to log in a thousand times at three in the morning: do you know? Or do you hear about it tomorrow from a client?

CyFun Basic expects you to detect outages and anomalies and to keep event records. In practice that means: monitoring on your systems, alerting when something deviates, and logs retained long enough to reconstruct afterwards what happened. This is the part that’s hardest to set up yourself and easiest to outsource.

Step 5: know what to do when it happens anyway

An incident plan doesn’t have to be a book. One A4 page is enough to start: who do I call first, who is allowed to decide to shut systems down, where are the contact details of the supplier and the insurer, and who informs the clients. Print it. A digital incident plan on a server that’s down is an irony you want to spare yourself.

Do it yourself, or outsource?

Steps 2, 3 and 5 you can largely handle yourself, possibly with your existing IT partner. Steps 1 and 4, inventory and detection, are exactly where professional monitoring makes the difference: they happen automatically, continuously, and produce as a by-product the reports you’ll use to answer the questionnaires from your NIS2 clients.

Want to know where your company stands today against these five steps? Book a free call: a first assessment costs you half an hour and not a single euro.