Brussels-based · EU-focused · EMEA Delivery · DORA · NIS2 · EU AI Act · ISO 42001
Strategic Intelligence Briefing
Forward-looking analysis: 2-year cyber risk outlook, emerging technology assessments, testable predictions, and board governance gap analysis.
Strategic Intelligence
Cyber Governance Intelligence Briefing
Forward-looking analysis, emerging technology risk assessments, testable predictions, and board-level governance gaps — updated daily via automated research.
Cyber Risk Outlook 2026–2028
Strategic Forecast
Regulatory Convergence Acceleration
DORA, NIS2, EU AI Act, and CRA enforcement creates a “tipping point” where a single supply-chain glitch triggers simultaneous reporting across three regimes. CRA vulnerability reporting obligations begin 11 Sep 2026; full enforcement Dec 2027 (Hogan Lovells, Apr 2026). EU AI Act high-risk registration opens Q2 2026; Digital Omnibus proposes delay to Dec 2027. EU AI Act Digital Omnibus political trilogue scheduled 28 Apr 2026 — agreement expected before European Parliament recess. EC NIS2 targeted amendments proposed Jan 2026 for cross-border clarity. 13 of 27 EU member states still have not transposed NIS2. UK CS&R Bill (introduced Parliament 12 Nov 2025) expanding NIS Regulations to digital supply chains, expected to pass 2026 with phased commencement. UK Data (Use and Access) Act 2025 (Royal Assent Jun 2025) provisions phasing in Jun 2025–Jun 2026. Organisations without integrated GRC face exponential compliance cost growth.
AI-Native Threats Outpace Defences
CrowdStrike 2026: 89% YoY increase in AI-enabled attacks; eCrime breakout time 29 minutes (fastest: 27 seconds). By 2027, >40% of initial breach vectors will involve AI-orchestrated attack chains. Current SOC architectures designed for human-speed adversaries require fundamental redesign.
Board Personal Liability Expansion
NIS2 Art.20, SEC rules, CMMC 2.0, and DORA establish personal liability for directors. CISOs now face fines, career bans, and criminal charges — Uber and SolarWinds SEC actions set precedent. 77% of boards now discuss material/financial implications of cyber incidents (up 25 points since 2022); 72% of directors undertook cyber risk education in past year. Only 29% describe cybersecurity updates as “very effective”; forward-thinking orgs bifurcating CISO role into strategic CISO (board/risk) and VP Security Engineering (IANS/IDC/VantEdge, Apr 2026).
Identity as the Security Perimeter
Zero trust maturity will shift budget allocation — IAM and identity governance will command 25–30% of security spend by 2028, up from 12% in 2024. Non-human identities will outnumber human identities 100:1.
Quantum Transition Deadline Pressure
Three papers in three months rewriting quantum resource estimates — what once required 20M qubits now potentially <100K (Quantum Insider, Mar 2026). 2026 designated “Year of Quantum Security” by FBI/NIST/CISA. NSA CNSA 2.0 mandates quantum-safe national security systems by Jan 2027. Google 2029, Pentagon 2030, UK NCSC 2028/2031/2035, EU CNI by 2030. >50% of web traffic through Cloudflare now uses PQ key agreement. Gartner 2026: fewer than 5% of enterprises have formal quantum-transition plans. Canada mandates federal PQC migration plans submitted Apr 2026, critical systems by 2031, full migration 2035. Organisations without cryptographic inventory by 2027 face 5+ year migration timelines. World Quantum Day (14 Apr 2026): “Harvest Now, Decrypt Later” confirmed at scale by IBM/Google/NIST — state actors actively stockpiling encrypted comms for future decryption. Meta published PQC Migration Framework (16 Apr 2026) sharing production lessons across inventory, risk tiers, and deployment guardrails — Meta cryptographers co-authored NIST’s HQC backup algorithm. US Senate panel advanced Quantum Initiative Reauthorization (15 Apr 2026) focusing on applications and security — signals accelerating federal quantum security policy (Gartner/NCSC/NIST/Canada CCCS/World Quantum Day/Meta/US Senate, Apr 2026).
Practitioner Note — 30 Apr 2026 PRIORITY
EU estates Thursday open: EDPB Guidelines 2/2026 on smart-building biometric access — 6-week consultation closes 11 June 2026; asset managers with smart-access systems should submit before end May. CRA vulnerability reporting obligations confirmed 11 Sep 2026 — 134 days for HVAC/BMS vendors to assess in-scope product status. EU AI Act Digital Omnibus: legal scrubbing complete; publication June 2026; Annex III high-risk AI deadline 2 Dec 2027 — building-management AI compliance audits should begin now. EDPB-EDPS Joint Opinion 4/2026: single-entry point for personal data breach notifications proposed — affects fund-admin and property-data operations. eIDAS2 wallets go-live December 2026 — LP/fund-admin identity verification workflows need advance assessment. CISA ED-26-05 (Apache Tomcat CVE-2026-34141, CVSS 9.8) 29 Apr: EU property-sector IT teams using Tomcat in tenant portals or asset-mgmt platforms advised to patch immediately (EDPB/EC/ENISA/CISA, 30 Apr 2026).
EU estates Wednesday 29 Apr: EDPB Guidelines 2/2026 (smart-building biometric access control) — 47 initial stakeholder submissions filed through day 8; IAPP-EU working group coordinating industry response; property owners and FM operators advised to contribute or align with sector position by 22 May deadline. ENISA NIS2 supply-chain mapping: BMS, HVAC, smart-metering, and access-control vendors must self-assess ICT dependency maps by 30 Jun — supervisory letters to facility operators and essential-service entities expected Q3 2026; recommended action: commission vendor assessment now. CRA 11 Sep 2026: smart-property device manufacturers in-scope for vulnerability-reporting obligations — legal review of firmware-update SLAs and ENISA-CERT notification procedures recommended immediately. CJEU C-446/25 (landlord data retention) advocate-general opinion listed 17 Jul 2026 — outcome affects EU residential and commercial lease data archives across all 27 member states; data-mapping exercise and retention-policy review advisable H1 2026. Lloyd’s syndicate renewals: NIS2-compliance attestation clause standard for EU commercial property cyber portfolios from 1 Jul 2026 — risk committee review of attestation process recommended this quarter. Apache Tomcat CVE-2026-34141 (CVSS 9.8): BMS vendors using Tomcat web interfaces advised to validate patch status; ENISA advisory issued (EDPB/ENISA/EC/CJEU/Lloyd’s/CRA/CERT-FR, 29 Apr 2026).
Emerging Technology Risk Assessments
Technology Radar
Agentic AI Systems RISK: CRITICAL
Autonomous AI agents with tool-use capabilities introduce uncontrolled decision chains. 48% of cybersecurity professionals identify agentic AI as the #1 2026 attack vector (Dark Reading). Attack breach window collapsed to 22 seconds under agentic AI coordination (Jazz CyberShield, Apr 2026). Emerging risks: prompt injection, tool misuse, privilege escalation, memory poisoning, cascading failures, and supply chain attacks on AI agent frameworks. Current governance frameworks lack kill-switch mandates, audit trail requirements, and liability allocation for autonomous actions. CrowdStrike 2026 GTR: 340% increase in AI-assisted intrusion attempts vs 2024; adversarial AI now responsible for ~38% of all credential-harvesting globally. ClawJacked attack class (Apr 2026): localhost WebSocket exploitation enables silent AI agent hijack from browser. CVE-2026-32211 (CVSS 9.1, Apr 3 2026): missing authentication in Microsoft Azure DevOps MCP — first critical AI infrastructure CVE in enterprise MCP tooling; AI agent frameworks confirmed as primary attack surface in their own right. IBM Autonomous Security (15 Apr 2026): industry’s first multi-agent defence service for coordinated response at machine speed — signals enterprise AI security entering an arms-race phase requiring board-level investment decisions (NIST NVD/IBM, Apr 2026).
Quantum Computing RISK: HIGH
Q-Day probability at historic high: 28–49% within 10 years. Three research papers in Q1 2026 sharply reduced quantum resource estimates — RSA potentially breakable with <100K qubits under newer architectures. 2026 declared “Year of Quantum Security” (FBI/NIST/CISA). NSA CNSA 2.0 mandates quantum-safe systems by Jan 2027. >50% of web traffic now using PQ key agreement. Gartner 2026: fewer than 5% of enterprises have formal PQC plans. Canada mandates federal PQC submissions Apr 2026, full migration by 2035. Google March 2026: new research accelerates ECC break timeline meaningfully. NIST FIPS 203/204/205 final; HQC code-based KEM backup selected Mar 2025, finalization 2026–2027. Meta PQC Migration Framework (16 Apr 2026): production-tested framework covering inventory, risk tiering, and deployment guardrails — co-authored HQC algorithm, open-sourcing lessons to industry. US Senate Quantum Initiative Reauthorization advanced (15 Apr 2026). Organisations without PQC migration roadmaps face retroactive data exposure across entire encrypted estate (Gartner/NIST/Google/Canada CCCS/Meta/US Senate, Apr 2026).
Synthetic Media & Deepfakes RISK: CRITICAL
US deepfake fraud losses tripled to $1.1B in 2025; projected $40B by 2027 (Deloitte). 72% of business leaders cite AI fraud as top operational challenge (Experian 2026). Experian warns of AI-powered emotionally intelligent bots sustaining dozens of simultaneous scam relationships. Financial industry groups published AI identity attack roadmap (HelpNetSecurity, Apr 2026). WEF March 2026: global AI fraud roadmap priority. FBI: AI voice cloning scams cost elderly Americans $2.3B in 2026 alone; success rate rose from 12% (2024) to 34% (2026); voice can be cloned from 60 seconds of audio (FBI/Keepnet, Apr 2026).
Edge AI & Federated Learning RISK: EMERGING
AI inference at the edge creates distributed attack surfaces beyond traditional perimeter controls. Model poisoning, adversarial inputs, and data leakage via federated training require new governance paradigms.
Digital Identity Wallets (eIDAS2) RISK: HIGH
EU Digital Identity Wallets scheduled to go live December 2026, creating immediate new attack surface for credential theft, wallet compromise, and identity federation attacks. Financial groups published plan to fight AI identity attacks (HelpNetSecurity, Apr 2026). Organisations processing EU user identity must assess eIDAS2 integration risk before go-live — wallet-based authentication will intersect with NIS2 and DORA identity requirements.
Bold Testable Predictions
Falsifiable Claims · Confidence-Scored
Prediction 1 90% CONFIDENCE
By December 2027, at least one EU member state will levy a >€10M fine under NIS2 Article 34 against a board member personally for cyber governance failure.
Prediction 2 85% CONFIDENCE
Before 2028, a Fortune 500 company will suffer a >$500M loss directly attributable to an AI-generated deepfake attack (single incident, not aggregate).
Prediction 3 75% CONFIDENCE
By 2028, >50% of FTSE 100 boards will have a dedicated Cyber/Technology committee (vs. ~15% today), driven by NIS2 and UK regulatory pressure.
Prediction 4 70% CONFIDENCE
The first successful quantum-assisted decryption of a commercially-relevant encrypted dataset will be publicly confirmed before December 2030.
Prediction 5 85% CONFIDENCE
By 2027, cyber insurance premiums for organisations without AI governance frameworks will be 3–5× higher than those with documented AI risk management, creating a de facto market mandate.
What Boards Are Getting Wrong
Governance Gap Analysis
Treating Cyber as an IT Problem
77% of boards now discuss material/financial implications of cyber incidents (up 25pts since 2022); 72% of directors undertook cyber risk education in past year. Yet only 29% describe cybersecurity updates as “very effective”; 53% say “somewhat effective” (IANS 2026). Forward-thinking orgs bifurcating CISO role: strategic CISO (CEO/board reporting) and VP Security Engineering. NIS2 and SEC rules mandate board-level governance — delegation without oversight is a compliance violation and personal liability risk (IANS/VantEdge, Apr 2026).
Compliance-Driven Rather Than Risk-Driven
Boards chase regulatory checkboxes rather than threat-informed risk management. Result: compliant but vulnerable. DORA explicitly requires proportionate risk-based measures, not prescriptive compliance.
Ignoring Non-Human Identities
SpyCloud 2026 Identity Exposure Report: 65.7B total identity records recaptured (+23% YoY) — new industry record; 8.6B stolen session cookies; 18.1M exposed API keys and tokens. CyberArk 2026: machine identities outnumber human users 92:1; <5% of organisations include NHI in their identity governance programme. Delinea Mar 2026: 90% of organisations report pressure from leadership to loosen identity controls for AI systems — creating new entitlement exposure. Agentic AI systems are creating new classes of NHI with privileged access and minimal oversight. SANS Apr 2026: machine identities surging — 76% of organisations report growth; agentic AI deployments exposing new NHI governance gaps with no single safeguard adopted by more than 40% of organisations surveyed. Starkiller phishing suite (Mar 2026) now proxies real login pages to capture session tokens in real time. Token theft has become the dominant identity attack vector in 2026 — kits from $200 (CyberArk/Delinea/SANS, Apr 2026).
Underestimating Recovery Time
Average actual recovery: 23 days. Board-assumed: 48 hours. 7,500+ organisations on leak sites in 2025 (+58% YoY); ransomware in 44% of all breaches, 88% of SMB breaches (Verizon 2026). Median ransom $1.32M; mean recovery cost $1.53M. Groups increasingly skip encryption for pure data extortion. Over two-thirds of attacks target businesses with fewer than 500 employees — avg incident cost now exceeds $5M. This gap between board assumption and operational reality is itself a governance failure.
No AI Governance Framework
<10% of organisations have a board-approved AI governance policy. EU AI Act compliance deadlines are imminent — boards without AI risk frameworks face enforcement action and competitive disadvantage.
STRATEGIC INTELLIGENCE LAST REFRESHED: 19 Jun 2026 · 21:30 CEST · AUTO-UPDATED DAILY
Intelligence without pre-delegated authority to act is surveillance, not governance.
The breach that satisfies a board is always the one that was neutralised before it required board notification.
Board Mandate Engagement
This intelligence informs active mandates. Yours could be next.
Kieran Upadrasta (“we”, “us”) operates rlkestates.eu. This policy explains how we collect, use, and protect personal data.
Data Collected: When you submit the contact form, we collect your name, email address, organisation, and message content. We do not collect data through cookies or tracking technologies beyond essential site functionality.
Purpose: Personal data is used solely to respond to your enquiry and, where applicable, to discuss potential engagements. We do not sell, share, or transfer your data to third parties.
Legal Basis: Processing is based on your consent (form submission) and our legitimate interest in responding to business enquiries, in accordance with the General Data Protection Regulation (GDPR).
Data Retention: Contact form submissions are retained for a maximum of 24 months, after which they are securely deleted.
Your Rights: Under GDPR, you have the right to access, rectify, erase, or restrict processing of your personal data. Contact [email protected] to exercise these rights.
Security: We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, or destruction.
By accessing rlkestates.eu, you agree to these terms. This website is provided for informational and professional engagement purposes only.
Intellectual Property: All content, frameworks, trademarks (including Board-Survivable Cyber Architecture™, The Evidence Chain Model™, Decision Rights Architecture™, Recoverability Mandate™, Contract Control Matrix™, and AI Accountability Stack™), and materials on this site are the intellectual property of Kieran Upadrasta. Reproduction without written permission is prohibited.
Professional Disclaimer: Content on this website does not constitute legal, regulatory, or financial advice. Engagement terms are governed by separate contractual agreements.
Limitation of Liability: Information is provided on an “as is” basis. We make no warranties regarding accuracy, completeness, or suitability for any particular purpose.
Governing Law: These terms are governed by the laws of Belgium.
Effective Date: 1 March 2026 · revised 25 April 2026
rlkestates.eu uses minimal cookies to ensure essential site functionality. No advertising cookies, tracking pixels, or third-party analytics are deployed.
Categories of cookies used:
Strictly necessary. Required for basic operation (session, CSRF security, consent state). These cannot be disabled.
Preferences (where applicable). Store language or display preferences locally.
Third-party cookies: none. This site does not load Google Analytics, Facebook Pixel, advertising networks, or any third-party tracking. System fonts are used; no data is transferred to Google Fonts, Adobe, or equivalent.
Retention: session cookies expire when the browser closes. Preference cookies (where set) expire after 12 months.
Your choices: you can block or delete cookies via your browser settings. Disabling essential cookies may impair functionality. To learn more about cookies generally, see aboutcookies.org.
Effective Date: 8 March 2026 · revised 25 April 2026
Commitment. Kieran Upadrasta is committed to ensuring digital accessibility for all users, in line with EU Web Accessibility Directive (2016/2102/EU) as transposed in Belgium, and the European Accessibility Act (Directive 2019/882/EU), and the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA published by the W3C.
Conformance status. rlkestates.eu is designed to be partially conformant with WCAG 2.2 Level AA. “Partially conformant” means that some content does not yet fully meet the standard.
Measures applied. Semantic HTML structure, keyboard-navigable interface, skip-to-content link, ARIA landmarks, sufficient colour contrast ratios (≥ 4.5:1 for body text), focus-visible indicators, accessible form controls with error messaging, alternative text for meaningful images, scalable text up to 200% without loss of content, and respect for user preferences (prefers-reduced-motion, prefers-color-scheme).
Known limitations. Some interactive elements (carousels, modals, sticky CTAs, decorative SVGs) may not yet fully meet WCAG 2.2 Level AA under all assistive-technology combinations. Long doctrine PDFs are tagged but may contain complex tables that screen readers traverse non-linearly. We actively test and remediate.
Testing approach. Automated evaluation via axe-core and Lighthouse. Manual evaluation via keyboard-only navigation, screen readers (NVDA, JAWS, VoiceOver), and 200% browser zoom. The site is reviewed against WCAG 2.2 quarterly.
Alternative formats. If you encounter an accessibility barrier, contact [email protected] for the information in an accessible alternative format (accessible PDF, plain text, telephone discussion).
Feedback & enforcement. Accessibility feedback is welcomed and triaged within 5 business days. If you are not satisfied with our response, you may refer the matter to the relevant equality body in Belgium.
Effective Date: 1 March 2026 · revised 25 April 2026
Commitment. Kieran Upadrasta (“the practice”) supports the United Nations Guiding Principles on Business and Human Rights, the International Labour Organization (ILO) Declaration on Fundamental Principles and Rights at Work, and the OECD Guidelines for Multinational Enterprises. The practice acknowledges the Belgian Penal Code provisions on human trafficking (Articles 433quinquies through 433decies) and the EU Anti-Trafficking Directive (2011/36/EU).
Modern slavery. The practice commits to ensuring that no slavery, servitude, forced or compulsory labour, or human trafficking takes place within its engagements, supply chain, or counterparty arrangements. This includes child labour, debt bondage, deceptive recruitment, and any restriction on freedom of movement.
Due diligence. Given the individual professional nature of this practice, the supply chain is limited (cloud hosting, software tooling, editorial vendors). Each supplier is risk-assessed at engagement and at annual renewal. Suppliers materially failing the assessment must remediate or be replaced.
Diversity & non-discrimination. Engagements are accepted without regard to gender, race, ethnicity, sexual orientation, disability, religion, or age. Counterparty conduct that is materially incompatible with these principles is grounds for engagement termination.
Training & awareness. The practitioner maintains current awareness of human-rights and anti-trafficking standards via continuing professional development under ISACA, (ISC)², and IRM.
Reporting concerns. Concerns relating to modern slavery, human trafficking, or any human-rights matter may be reported confidentially to [email protected]. The practice will investigate, escalate where required, and cooperate with relevant authorities.
Review. This statement is reviewed annually and republished at the same URL.
Professional Code of Conduct
Effective Date: 1 March 2026
Kieran Upadrasta maintains a professional standard aligned with the codes of conduct of ISACA, (ISC)², IRM, and CIPP/E. Engagements are governed by:
Integrity. Advice is never shaped by financial, political, or personal interest. Conflicts of interest are disclosed in writing before engagement and at any point a conflict arises during delivery.
Confidentiality. All client data is handled at regulator-grade standard. No disclosure, identification, or cross-engagement reuse without written authorisation. Sensitive matters are subject to NDA and segregated storage.
Competence. Advice is provided only in areas where the practice has demonstrable expertise. Out-of-scope topics are escalated or declined — never bluffed.
Diligence. Contractual, regulatory, and confidentiality obligations are honoured in full. Engagements are delivered to procurement-grade artefact standard, on time, with documented evidence chains.
Independence. No referral fees, kickbacks, or undisclosed commissions are accepted from any third-party vendor or platform.
Help
This page collects everything you need to navigate rlkestates.eu, contact the practice, or report a problem.
Site Requirements
rlkestates.eu is optimised for the latest two major versions of Chrome, Edge, Firefox, and Safari. JavaScript and CSS must be enabled. The site adapts down to 320 px viewport width. No proprietary plug-ins or extensions are required.
Search Tips
To search content on the site, use your preferred search engine with a site: operator — for example: site:rlkestates.eu DORA, site:rlkestates.eu “evidence chain”, or site:rlkestates.eu ISO 42001. Search engines are not case-sensitive; common words like “and”, “or”, “the” are typically ignored. Quotation marks force an exact phrase match. No tracking or analytics cookies are set.
Browser & Mobile
The site is fully responsive and works on mobile phones, tablets, laptops, and desktops. All modals, forms, and downloadable artefacts (PDFs) function on touch devices.
Print & Save
Press Ctrl + P (Windows / Linux) or Cmd + P (macOS) to print or save any page as PDF. A print-friendly stylesheet is applied automatically.
Accessibility
The site is designed to conform with WCAG 2.2 Level AA. Semantic HTML, keyboard navigation, ARIA landmarks, and high-contrast colour ratios are applied throughout. See the Accessibility statement for known limitations and remediation plans.
Business enquiries, media requests, or site feedback: [email protected]. Concerns relating to privacy, accessibility, or professional conduct can also be raised at this address. Response within one business day for engagement enquiries.
Effective Date: 1 March 2026 · revised 25 April 2026
Information accuracy. The content published on rlkestates.eu is provided for general information only and reflects Kieran Upadrasta's analysis at the date of publication. The regulatory landscape evolves continually; some information may become outdated and no commitment is made to keep it perpetually current.
No professional advice. Nothing on this site constitutes individualised legal, tax, financial, regulatory, or insurance advice. Strategic decisions should be the subject of a separate written engagement.
Reliance. Visitors are responsible for assessing the relevance and accuracy of the content for their own circumstances. Kieran Upadrasta accepts no responsibility for actions taken or not taken in reliance on this site without engagement under contract.
Limitation of liability. To the fullest extent permitted by law, Kieran Upadrasta excludes all liability (in contract, tort, negligence, or otherwise) for any direct, indirect, incidental, consequential, or punitive loss arising from use of, or inability to use, this site, or reliance placed on its content.
Third-party links. rlkestates.eu may contain links to external websites. Kieran Upadrasta does not control, endorse, or accept liability for third-party content.
Intellectual property. All content, doctrine, trademarks (including Board-Survivable Cyber Architecture™, The Evidence Chain Model™, Decision Rights Architecture™, Recoverability Mandate™, Contract Control Matrix™, and AI Accountability Stack™), and methodologies are the intellectual property of Kieran Upadrasta. Reproduction, distribution, or adaptation without prior written permission is prohibited.
Governing law. Refer to the Terms of Use modal for the governing law and exclusive jurisdiction applicable to your use of this site.
Updates. This disclaimer may be amended without notice; check back periodically.
The following information is published in accordance with the EU Services Directive 2006/123/EC, as transposed into Belgian law, applicable in Belgium.
Service provider: Kieran Upadrasta, an individual professional practice.
Contact address:[email protected] · written correspondence may also be sent to the practice address provided on engagement.
Areas of practice: institutional cyber governance; operational resilience architecture; regulatory delivery (DORA, NIS2, EU AI Act, GDPR, ISO 27001, ISO 42001); board-level advisory and interim CISO mandates.
Professional affiliations: ISACA (Platinum Member), (ISC)² (Gold Member), Institute of Risk Management (IRM), PRMIA (Cyber Security Programme Lead), Information Security Forum (ISF Lead Auditor).
Certifications: CISSP, CISM, CRISC, CCSP.
Academic appointments: Honorary Professor (Cybersecurity, AI & Quantum Computing), Honorary Senior Lecturer at Imperials, UCL Researcher.
Professional indemnity insurance: in force; policy details disclosed under engagement contract on request.
VAT / tax registration: registration details provided in engagement-level documentation as required by Belgium tax authorities.
Complaints procedure: complaints should be addressed in writing to [email protected]. Initial acknowledgement within 5 business days; substantive response within 30 days. Complaints are tracked in writing and reviewed under the Code of Conduct.
Out-of-court dispute resolution: if internal complaints handling is exhausted, mediation or arbitration may be invoked under the rules of the competent body in Belgium. Consumer-related complaints may also be referred to the relevant national consumer-protection authority.
Code of Conduct: the practice is bound by the codes of conduct of ISACA and (ISC)² (see Code of Conduct modal).