Skip to content

Belgium tests cyber crisis response during Cyber Europe 2026

Ccb.Belgium.Be June 12, 2026

This week the Centre for Cybersecurity Belgium (CCB) took part in Cyber Europe 2026, the large-scale European cyber crisis exercise coordinated by ENISA and organised together with the participating Member States.

The 2026 edition focused on the rail and maritime transport sectors. Cyber incidents in the transport sector can quickly move beyond IT systems. When maritime or rail operations are disrupted, the effects can be felt in logistics chains, ports, passengers and essential services.

We contributed to the development of the scenario for Belgium, helping to ensure that the exercise reflected realistic challenges and could test both national and European cyber crisis procedures in a coherent way.

A relevant exercise for Belgium

Cyber Europe 2026 did not test a theoretical risk. The CCB’s 2025 cyber threat landscape shows that Belgian organisations remain under sustained pressure from account compromise, ransomware, DDoS attacks, phishing, vulnerability exploitation and supply-chain incidents. In 2025, the CCB received 635 notifications from Belgian organisations, almost 70% more than in 2024, of which 556 were cyber-related. Among NIS2-defined organisations, transportation was one of the most impacted sectors in Belgium, alongside public administration, energy and healthcare.

This makes this year’s focus particularly relevant for Belgium. Ports, rail networks and logistics chains are deeply interconnected, which means that a cyber incident in one organisation can quickly create pressure elsewhere. In essential services, digital disruption can rapidly become operational disruption.

Testing Belgium’s new crisis approach

For us, the exercise came at an important moment. Belgium recently adopted a new National Cyber Emergency Plan, which clarifies how the country organises national cyber crisis response, coordination and support.

During Cyber Europe 2026, we tested our internal crisis procedures as realistically as possible. Incident reports linked to the scenario were handled through existing CCB channels and operational processes, from notification and triage to follow-up by the relevant teams. Other elements of the national crisis architecture were simulated where needed.

The exercise was not only plans and procedures. CCB colleagues involved in the exercise worked together in person at our offices. In a crisis, effective response depends not only on formal structures, but also on how quickly teams build a shared understanding, exchange information and coordinate decisions under pressure.

Strengthening the European response

Cyber crises do not stop at borders, and transport is by nature a cross-border sector. Cyber Europe 2026 was therefore an important opportunity to test how Belgium interacts with the European cyber crisis layer, including the CSIRTs Network and EU-CyCLONe.

The exercise also assessed how the Belgian approach connects with the new EU Blueprint for Cyber Crisis Management, which aims to strengthen coordination between Member States and EU-level actors during major cyber incidents.

Through Cyber Europe 2026 Belgium rehearsed how an incident reported through national channels can develop into a broader European cyber crisis, how information should flow between technical and crisis-management levels, and how essential services can be protected when disruption crosses borders.

By taking part, the CCB strengthened Belgium’s preparedness and contributed to a more resilient Europe. In transportation, resilience is connected and so must be the response.