Blocked cyberattacks in Belgium rose by 23.3% in the second quarter of 2026, according to figures shared by Cloudflare. Online retail is among the most targeted sectors, right behind IT. Here is what these figures mean for the security of your business website, and what to check this week.
1. What the Q2 2026 figures reveal
In Belgium, Cloudflare handled an average of 37.6 billion content requests daily in the second quarter of 2026. About 2.4% of them, or 898.6 million per day, were blocked as cyberattacks. That is 23.3% more than the previous quarter. The IT and network security sector remains the most targeted (60.43% of attacks), followed by retail (6.86%), online media (6.71%) and education (5.89%). Two defence methods dominate: DDoS mitigation (62%) and the web application firewall, or WAF (36.2%). Among the most triggered WAF rules: Directory Traversal (25.3%), SQL injection (13.7%) and Cross-Site Scripting (8.8%), three flaws that directly relate to how a site is built and hosted.
2. The real weak point for SMEs: configuration, not technology
According to the Centre for Cybersecurity Belgium (CCB), the country faces an average of 22 ransomware attacks per day. 42% of Belgian SMEs have already been hit by an attack, and 30% of companies still have no cyber strategy at all. In 2025, the CCB recorded 121 known ransomware incidents, with IT (24%), retail (20%) and industry (13%) as the hardest-hit sectors. The two main intrusion methods are account takeover (38%) and exploitation of a known vulnerability (33%). The most telling figure: during its penetration tests, security firm Cresco uncovers at least twenty vulnerabilities in 95% of cases, and in 71% of tests where the team gains full domain control, a simple misconfiguration is the cause. No new technology needed, fixing existing settings is often enough.
3. Phishing, still the number one entry point
In a well-crafted, targeted phishing campaign, 46% of recipients open the email and 60% click the link. Of those, 74% actually enter their credentials, while barely 4% report the suspicious email. Ransom demands typically start between 5 and 10% of the targeted company's turnover, an amount that can drop sharply after negotiation. The NIS2 directive, transposed into Belgian law in May 2025, now imposes reporting obligations to the CCB for many companies, with VLAIO-subsidised programmes covering up to 50% of penetration tests and compliance work.
The AI angle, humans first
Artificial intelligence is also changing the face of phishing: error-free, perfectly targeted emails, almost impossible to distinguish from a legitimate message, are now the norm. A monitoring tool can continuously scan a site's configuration, flag any drift or new vulnerability, and raise the alarm before an incident happens. But deciding on hosting architecture, patch schedules and backup strategy remains an expert call: AI executes. Expertise decides, and watches.
This week's action
Check that multi-factor authentication (MFA) is enabled on every RDP or VPN access exposed to the internet, and confirm your backups are properly isolated from the rest of your network.
At Vistalaro, Vistalaro Build designs, hosts and secures your site on European servers compliant with GDPR, with continuous monitoring of vulnerabilities and patches. The senior marketer at Vistalaro Pilot then makes sure this technical resilience fits into a coherent digital strategy, never depending on a single point of contact.
Would your site survive a penetration test?
Let's take stock together, no jargon, and prioritise what really matters for your SME's security.
Let's talk