Many organizations view the European NIS2 Directive as an administrative burden. The City of Bruges sees it as a strategic accelerator. Together with Inetum, the city is transforming NIS2 compliance into a smart investment in resilience. But how do you translate complex legislation into a practical action plan when resources are limited and political priorities are high?
Customer Success Stories
City of Bruges turns NIS2 into a catalyst for stronger cyber resilience
Published: 8/10/2026
The introduction of NIS2
With the introduction of NIS2, organizations operating in critical sectors, including local governments, are legally required to strengthen their cybersecurity posture. Furthermore, senior leaders can now be held personally accountable in cases of serious negligence. For the IT department of the City of Bruges, which manages a complex IT landscape following its integration with the Public Center for Social Welfare (OCMW), NIS2 became an additional driver to fundamentally reassess its security strategy.
Infrastructure IT Director Ollivier Francq acknowledges that NIS2 is an absolute necessity. The legislation mandates a broad range of security measures. At the same time, however, he sees it as an opportunity.
"You obviously want to avoid a situation where a major incident has to occur before funding becomes available to improve cybersecurity. Thanks to the legal requirements introduced by NIS2, we were able to secure budget for critical projects, such as our CrowdStrike implementation."
A pragmatic path forward
For public-sector organizations, the challenge lies in achieving compliance without getting lost in costly and overly complex consulting programs. The City of Bruges chose a pragmatic approach, supported by Maarten Loose, GRC Expert at Inetum. "My first piece of advice is always: stay calm," he says with a smile. "At first glance, NIS2 can seem overwhelming. In practice, however, many of its requirements come down to common sense and proper documentation."
Inetum began by conducting a comprehensive maturity assessment based on the CyFun framework developed by the Belgian Centre for Cybersecurity (CCB). This framework translates regulatory requirements into tangible controls and actions. "Our approach is not about trying to do everything at once. First, we establish a clear picture of the current situation. Then we develop a roadmap with realistic milestones," explains Maarten Loose.
As a local government, the City of Bruges proactively registered as an Essential Entity. "On paper, there can sometimes be debate as to whether a city should be classified as an Important Entity or an Essential Entity under NIS2," explains Ollivier Francq. Depending on the classification, different security requirements apply.
"We choose the safest scenario. We manage critical data and deliver essential services to our citizens. That is not the time to push the limits of compliance. We'd rather do a little too much than too little."
Turning compliance into action
A key element of Inetum's approach is converting theoretical control requirements into concrete actions. The maturity assessment identified where improvements were needed within the City of Bruges.
"We translated NIS2's theoretical requirements into very practical tasks in a language the IT department understands," says Maarten Loose. "Instead of vaguely stating that an organization must comply with a specific article, we define concrete actions, such as segmenting the network to prevent external partners from gaining unrestricted access to internal servers."
In short, Inetum provided a practical to-do list that enabled the City's IT team to take immediate action.
"That suddenly makes NIS2 very tangible," says Loose. "These are practical challenges for the IT department to solve, but they also deliver visible improvements in security."
The impact of NIS2, however, extends far beyond technology alone. One of the biggest challenges often lies in documenting implemented measures and managing the human side of change.
"Changes in the way people think and work, which are often necessary in the context of cybersecurity, do not happen overnight," says Ollivier Francq. "They require awareness-building and training. We are also less experienced when it comes to documenting processes and policies. That is where Inetum's experts brought significant added value. They handled much of the paperwork, allowing us to focus on the actual implementation."
The supply chain: a new frontier
A specific focus area within NIS2 is supply chain security. Public organizations work closely with numerous external partners, and NIS2 requires those partners to provide the same level of security assurance as the organization itself.
"For the City of Bruges, we developed a decision tree and a technical questionnaire for procurement processes," explains Maarten Loose. "Different requirements apply depending on the type of data a supplier can access. This allows us to embed security considerations directly into the purchasing process, without turning every procurement into a complex legal exercise. It ensures risk management at the source."
Finally, there is the responsibility of management. NIS2 requires senior leadership to develop sufficient knowledge and maturity regarding cybersecurity. In the case of the City of Bruges, this involves both the Board of Aldermen and the Executive Committee. Through dedicated board-level training, Inetum helps elected officials and senior leaders gain a better understanding of cybersecurity risks.
"When something goes wrong, there must be a business continuity plan in place," explains Maarten Loose. "That is a core responsibility of city leadership. Thanks to the transparent reporting and roadmap we developed, the IT department can now confidently report risks and mitigation measures to the Board of Aldermen."
The City of Bruges demonstrates that, with a pragmatic approach, NIS2 can become much more than a compliance exercise. It can serve as a powerful catalyst for improving the cybersecurity of a public organization.
The city continues to move forward through a structured roadmap, and the journey does not end once compliance has been achieved. "NIS2 compliance is something that requires ongoing maintenance if you want to retain your status. But thanks to the approach we developed together with Inetum, we are fully on track," concludes Ollivier Francq.
Related success stories
- Title
- Description
- Date
- 1
- 2
- 3
- 4
- 5
- 6
- 7