Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Cingulum: Cingulum is a cybersecurity consultancy firm that helps organisations structure and maintain their cybersecurity approach, whether you’re subject to NIS2 regulation or working towards ISO 27001 & CyFun as a best-practice framework. ## Sitemaps [XML Sitemap](https://cingulum.eu/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [NIS2 beyond the hype](https://cingulum.eu/nis2-beyond-the-hype/): For many SMEs, NIS 2 feels like yet another compliance exercise. In reality, the directive is about something far simpler: can you demonstrate that you know, manage, and monitor the cyber risks within your organisation? - [Knowing where you stand: How Xpo Group Mapped and Addressed Its Security Risks](https://cingulum.eu/xpo-group/): Technical security sorted? Check. But who is responsible for what? Which risks are flying under the radar? What happens when an external supplier makes a mistake? These were the questions Xpo Group wanted clear, formally documented answers to. Cingulum helped them find those answers and laid the groundwork for an approach that goes well beyond tools and systems. - [CRA Compliance: What the Cyber Resilience Act means for your software and hardware](https://cingulum.eu/cra-compliance-what-the-cyber-resilience-act-means-for-your-software-and-hardware/): By means of the Cyber Resilience Act (CRA), the European Union defines a clear minimum level of cybersecurity that products with digital elements must meet within the European Union. While NIS2 is concerned with protecting organisations, the CRA is aimed at the products themselves. - [What should you do if your SME experiences a cyber incident?](https://cingulum.eu/what-should-you-do-if-your-sme-experiences-a-cyber-incident/): A cyber incident is not purely an IT problem. It strikes at the core of your business: your processes, your customer data and your reputation. That is why senior management or the business owner must be involved from the outset. It is important to foster a culture where this is possible. Fear of involving management only increases risk. - [3 clear signs your organisation is not NIS2-compliant](https://cingulum.eu/3-clear-signs-your-organisation-is-not-nis2-compliant/): In practice, we see that many organisations are confident about their cybersecurity posture. They often feel they are “doing reasonably well”: there is a firewall in place, backups are running, and an IT service provider is responsible for day-to-day operations. - [How do you prepare for an ISO 27001 or CyFun audit?](https://cingulum.eu/how-do-you-prepare-for-an-iso-27001-or-cyfun-audit/): An ISO 27001 or CyFun audit is often seen as an exciting moment of inspection. Yet an audit is not about flawless paperwork, but about one central question: does your organisation have its information security under control, and can it demonstrate that? - [Happy Holidays from the Cingulum team!](https://cingulum.eu/happy-holidays-from-the-cingulum-team/): https://vimeo.com/1141422634 - [What is a CISO?](https://cingulum.eu/what-is-a-ciso/): It's been a long time that cybersecurity was just a technical IT issue. Nowadays, it's plain and simple; it's a business risk. In many cases, it's also a legal obligation. That’s where a Chief Information Security Officer (CISO) fits in. - [What is IT Security?](https://cingulum.eu/what-is-it-security/): Data is one of an organisation’s most valuable assets. But with this digital growth comes a rising tide of threats, from hackers and malware to insider risks and data breaches. That’s where IT security comes in. - [Choosing ISO27001 or CyberFundamentals for NIS2?](https://cingulum.eu/iso27001-vs-cyberfundamentals/): CyberFundamentals (CyFun) is a security framework developed by the Centre for Cybersecurity Belgium (CCB) as a pragmatic response to the growing need for cybersecurity maturity under NIS2. It’s designed for Belgian organisations and aligns directly with the directive’s expectations. ## Pages - [Framework Contracts](https://cingulum.eu/framework-contracts/): Skip the procurement process and start your security journey faster. - [Get ready for the Cyber Resilience Act (CRA)](https://cingulum.eu/cyber-resilience-act/): From December 2027, products with digital elements sold in the EU must meet mandatory cybersecurity requirements. If you develop, manufacture, import, or distribute connected products or software, the CRA applies to you. - [Doing business securely without an IT department](https://cingulum.eu/doing-business-securely-without-an-it-department/): Cybersecurity is no longer just a concern for large corporations. Flemish SMEs are just as vulnerable to phishing, ransomware, and supply chain attacks, but often lack the internal IT capacity to tackle them effectively. - [Job Days](https://cingulum.eu/job-days/): That’s why we created the Cingulum Job Days. - [Thank you for requesting your spot.](https://cingulum.eu/thank-you-for-requesting-your-spot/): We have successfully received your request.  - [(Closed) Cybersecurity Lunch: Third-Party Risk Management](https://cingulum.eu/cybersecurity-lunch-third-party-risk-management/): That’s why we’re hosting a Cybersecurity Lunch; a deliberately small, off-the-record gathering focused on how leading organisations actually manage third-party risk. - [Download Free Phishing Awareness Posters](https://cingulum.eu/download-free-phishing-awareness-posters/): Get your free Phishing Awareness Posters here. Don't get CatphishedPhishers use familiar names and friendly language to trick you. If the request feels off—pause, check, report. Download Something smells phishy...Phishing emails thrive on urgency and pressure. Trust your gut. Don’t click. Don’t reply. Report it. Download He’s just bossyPhishers impersonate executives to make you act fast. Slow down. Question authority. Verify before acting. Download - [Events](https://cingulum.eu/events/): Events Upcoming events Past Events - [From Excel to Evidence: ISMS tooling as an engine of NIS2 Compliance](https://cingulum.eu/webinar-from-excel-to-evidence-isms-tooling-as-an-engine-of-nis2-compliance/): NIS2 is no longer about preparing yourself, it’s about proving . That means you need more than awareness. You need structure, evidence, and a clear way to show your compliance to auditors, partners, and regulators. - [VLAIO Cybersecurity Verbetertraject](https://cingulum.eu/vlaio-cybersecurity-verbetertraject/): Get up to 50% of your cybersecurity project subsidised. - [newsletter](https://cingulum.eu/newsletter/): Want insights on cybersecurity, updates on NIS2, invites to exclusive events, or practical content that helps you protect your organisation? Join the Cingulum community and get the information you need, when it matters. - [Cybersecurity Maintenance](https://cingulum.eu/cybersecurity-maintenance/): Cingulum’s Cybersecurity Maintenance gives your organisation the ongoing support it needs to stay compliant and confident. Modular, expert-led, and designed around your reality, not ours. - [Third Party Risk Management](https://cingulum.eu/third-party-risk-management/): Cingulum’s Third Party Risk Management (TPRM) gives you clear visibility, continuous monitoring, and actionable insights across your entire supply chain from onboarding to offboarding. - [NIS2 Awareness Training for Boards & Executives](https://cingulum.eu/nis2-awareness-training/): Understand your role and limit your exposure. - [Cybersecurity consultancy](https://cingulum.eu/cybersecurity-consultancy/): At Cingulum, we don’t just advise, we implement. Whether you need a cybersecurity consultant for a specific compliance challenge or long-term resilience, we provide tailored, board-ready solutions that work across your organisation. - [Terms and Conditions](https://cingulum.eu/terms-and-conditions/): In these Terms and Conditions, the following words and expressions shall have the following meaning: - [Cookie Policy](https://cingulum.eu/cookie-policy/): This Cookie Policy was last updated on April 29, 2026 and applies to citizens and legal permanent residents of the European Economic Area and Switzerland. - [NIS2: A strategic guide for business leaders](https://cingulum.eu/download-nis2-ebook/): Download the eBook now and put clarity at the heart of your NIS2 strategy. - [Download Supply Chain Attacks eBook](https://cingulum.eu/download-supply-chain-attacks-ebook/): If you’re a business leader, IT manager, security officer or compliance lead, Supply Chain Attacks aren’t just another threat on the list. It’s the one that blurs the line between your security and someone else’s mistake. And with growing pressure from NIS2, ISO27001 and increasingly demanding client standards, you don’t need more noise. You need clarity.  - [Supply Chain Attacks: When their problem, becomes yours](https://cingulum.eu/download-supply-chain-attacks-webinar/): Supply chain attacks are no longer rare — they’re the new normal. And with NIS2 pushing organisations to take third-party risks seriously, it’s time to tighten up your defenses. - [ISO27001 vs CyFun: Which is the best option for your organisation?](https://cingulum.eu/download-iso27001-vs-cyfun-ebook/): In recent years, cybersecurity started moving from the server room to the boardroom and with the introduction of the NIS2 directive the pace of this move only increased. Yet, NIS2 leaves many organisations struggle with the same question: Should we go for the CyberFundamentals framework promoted by the CCB, or implement ISO/IEC 27001 instead? - [Cybermaturity Assessment](https://cingulum.eu/cybermaturity-assessment/): Unsure? That’s exactly why we created the Cingulum Cybermaturity Assessment: a deep, structured scan to uncover your blind spots, and help you close them. - [ISO as a Service](https://cingulum.eu/iso-as-a-service/): Security strategy needs execution, which takes time, structure and expertise. With Cingulum’s ISO as a Service (ISOaaS), you get an external security professional, adapted to your preferred level and maturity, who supports your day-to-day security governance.   - [cybersecurity implementation](https://cingulum.eu/cybersecurity-implementation/): The ISMS implementation is where your security framework takes shape, grounded in your unique risks, driven by clear objectives, and designed for long-term impact. - [Internal Security Audit](https://cingulum.eu/internal-security-audit/): An internal security audit is not a box to tick. It is the moment where you find out whether your security policies and initiatives would hold up in an external audit by an independent certification body. - [External audit & certification](https://cingulum.eu/external-audit-certification/): Our External Audit & Certification Support covers everything from internal readiness checks to hands-on guidance during the audit itself. - [NIS2](https://cingulum.eu/nis2/): NIS2 compliance is now a legal obligation for many EU organisations. We help you assess, implement and validate the right security measures, so you meet the standard, avoid penalties, and stay in control. Choose full support or just the steps you need. - [Why work for Cingulum](https://cingulum.eu/why-work-for-cingulum/): Cingulum is where sharp minds meet real opportunity. We’re a growing information security consultancy with big ambitions, backed by the trusted CRANIUM group. And we’re building something special. - [Team](https://cingulum.eu/team/): Curious who you'll be working with?  - [ISO 27001](https://cingulum.eu/iso-27001/): Become demonstrably ISO 27001-ready within 3 - 6 months, without overloading your team.Cingulum supports organisations end-to-end towards ISO/IEC 27001 certification. From gap analysis to audit guidance, we keep it practical, structured and focused on real business value. - [Supply Chain Attacks & NIS2 Compliance](https://cingulum.eu/supply-chain-attacks-nis2-compliance/): Supply Chain Attacks (SCAs) are no longer rare, they’re a growing threat that directly targets your business through the weak links you don’t control: your vendors, service providers, and software suppliers. - [Content hub](https://cingulum.eu/content-hub/): Whether you’re starting from scratch or fine-tuning what’s already in place, we’ll help you take the next right step. - [Standard-Based Risk Assessment](https://cingulum.eu/standard-based-risk-assessment/): Security gaps matter, but how much? The standard-based risk assessment give you clarity and direction. Our consultants help you move from reacting to threats to building a mature, evidence-driven security posture. - [Partners](https://cingulum.eu/partners/): We’re always on the lookout to build strong partnerships with like-minded organisations who understand the value of robust governance, risk management, compliance, and security processes. Whether you're a managed service provider, an IT consultancy, a legal advisor, or a technology vendor, if you share our commitment to excellence in security, we want to talk.  - [CISO as a Service](https://cingulum.eu/ciso-as-a-service/): CISO as a service can also offer a short-term solution when your own internal CISO is currently unavailable or on temporary leave. - [Security Solutions](https://cingulum.eu/security-solutions/): That’s why Cingulum offers a range of solutions within one large journey.  Every solution designed to meet you where you are, and move you forward. Whether you're defining your strategy, implementing controls, or scaling governance, our experts help you make confident, risk-informed decisions. - [Job openings](https://cingulum.eu/job-openings/): We’re looking for consultants who combine technical know-how with a healthy dose of common sense. - [How we hire](https://cingulum.eu/how-we-hire/): We get it. In information security, time and clarity matter. That’s why our recruitment process is streamlined, transparent, and respectful of your time. - [Does NIS2 Apply to Your Organisation?](https://cingulum.eu/nis2-test/): Take our free NIS2 Applicability Assessment and find out if your organisation falls within the scope of the directive.Quick, clear, and built to give you an immediate answer, no guesswork. - [Discover your organisation’s cybersecurity risks](https://cingulum.eu/riskrecon-cybersecurity-test/): Your security rating shows you how attackers can target and potentially breach your organisation’s critical assets, potentially leading to data loss. Being aware of this rating is the start of improving your overall cybersecurity risk. - [Security Staffing](https://cingulum.eu/security-staffing/): Cingulum’s Security Staffing model provides consultants who become part of your team technically, operationally, and culturally. - [Contact us](https://cingulum.eu/contact/): You can reach us via the contact form on this page, send an email to info@cingulum.eu, or call us on 02 310 39 63.We are based in Zaventem, Belgium. - [About Cingulum](https://cingulum.eu/about/): This is where Cingulum steps in as your independent advisor and operational partner. Born from CRANIUM, a recognised leader in data governance and compliance, Cingulum was created to help organisations turn security risks into structured systems that protect business continuity, meet legal demands, and earn trust. - [Careers](https://cingulum.eu/careers/): We’re looking for people who know to combine technical know-how with a healthy dose of common sense. If you’re passionate about cybersecurity, compliance, and having real impact, you might just be our kind of person. - [404](https://cingulum.eu/404-2/): 404 Our firewall blocked this one too hard. 🔥 This page didn’t make it past the perimeter. We’re good at keeping the wrong things out. Sometimes even our own content. Take me back home → Reach out to us - [Cingulum](https://cingulum.eu/): Cingulum is a cybersecurity consultancy firm that helps organisations structure and maintain their cybersecurity approach, whether you're subject to NIS2 regulation or working towards ISO 27001 & CyFun as a best-practice framework.  - [Privacy Statement](https://cingulum.eu/privacy-statement/): This Privacy Statement is applicable to the following data subjects: ## Theme Builder - [Cingulum services](https://cingulum.eu/?uicore-tb=cingulum-services): Get a clear view of where you currently stand. - [Footer](https://cingulum.eu/?uicore-tb=nis2): Pioneering a cyber-resilient society. - [Expertise](https://cingulum.eu/?uicore-tb=extertise): Discover the differences between ISO 27001 and CyFun - [Careers](https://cingulum.eu/?uicore-tb=careers): Our Talent Recruiter is your go-to guide through the application process. No fuss, no ghosting, just honest conversations and clear next steps. Reach out, and let’s see if we’re a match. - [Resources](https://cingulum.eu/?uicore-tb=resources): Doing Business Securely Without an IT Department - [Solutions](https://cingulum.eu/?uicore-tb=solutions-megamenu): Assess Cybermaturity Assessment Standard-based Risk Assessment Implement Cybersecurity Implementation NIS2 Management Awareness Training Validate Internal Audit & Management Review External Audit Support Maintain Cybersecurity Maintenance Third Party Risk Management CISO-as-a-Service ISO-as-a-Service Security Staffing Practical cybersecurity for SMEs? Thanks to VLAIO, Cingulum can offer up to 50% funding on improvement programmes. More information ## Custom Dashboard - [Custom TO Dashboard Footer](https://cingulum.eu/uicore-cd/ui-cd-to/) - [Custom WP Dashboard Footer](https://cingulum.eu/uicore-cd/ui-cd-wp/)