Published: 30/09/2026
Customer Success Stories
City of Bruges strengthens cyber resilience with CrowdStrike MDR
How can a public sector organization strengthen its cyber resilience against ransomware and targeted attacks without expanding its existing IT team? The City of Bruges found the answer in CrowdStrike’s Managed Detection & Response (MDR) solution. Ollivier Francq, IT Director Infrastructure, explains how, together with Inetum, he transformed a fragmented security landscape into a clear and effective security strategy, resulting in a higher level of protection, greater peace of mind, and predictable costs.
The Challenge: Integrating Cybersecurity
The City of Bruges and the Bruges Public Social Welfare Centre (OCMW Brugge) have been working toward a close operational integration during the current administrative term. The goal is to bring services together and streamline operations for greater efficiency. This created a complex cybersecurity challenge, as the integration involved not only merging teams but also consolidating the underlying infrastructures.
“Across the city and OCMW environments, we were using three different endpoint protection solutions on our clients and servers,” says Ollivier Francq, IT Director Infrastructure at the City of Bruges. “From a management perspective, that was far from ideal.”
This fragmented approach also created a growing sense of insecurity, as protection was not applied consistently across the environment. At a time when cyberattacks against government organizations have become the rule rather than the exception, the lack of a Security Operations Center (SOC) outside office hours became a significant concern.
“We felt vulnerable. What if something happened at three o’clock in the morning? We needed a single overarching platform and a trusted partner to monitor our environment around the clock.”
The Best Choice Within Budget, with a Strong Focus on Identity
The City of Bruges approached the search for a new solution pragmatically and with clear objectives. “We consulted the Gartner Magic Quadrant and created a shortlist of the three market leaders.”
Following an initial screening and an in-depth proof of concept, CrowdStrike emerged as the preferred solution. Not because it was the simplest tool, but because of the depth of capabilities it offered.
“CrowdStrike aligned much better with our requirements,” explains Ollivier Francq. “Our technical teams quickly became comfortable with the platform. We were also able to perform the deployment almost entirely on our own. The solution was up and running within a single day.”
Ultimately, CrowdStrike’s focus on identity protection proved to be the decisive factor. In today’s cybersecurity landscape, blocking malware is often only part of the story. The greatest damage occurs when attackers steal credentials and move laterally through the network.
“We are convinced that this is where the greatest risk lies,” says Ollivier Francq. “CrowdStrike immediately exposed those vulnerabilities. During the proof of concept, a healthy competition even emerged between our network and server administrators to reduce risk scores as quickly as possible. Thanks to that level of transparency, we significantly strengthened our security posture before the project was even completed.”
Reducing Complexity Through a Framework Agreement
For public sector organizations, selecting a technical solution is often only the first hurdle. It is typically followed by a lengthy and complex public procurement process.
That was not the case here. The City of Bruges was able to leverage the City of Bruges Framework Agreement, which enables public organizations to directly subscribe to specific services such as MDR without launching a new tender process.
“The framework agreement is a tremendous advantage for public organizations,” says Ollivier Francq. “It enables a fast start and predictable costs. The budget we received for CrowdStrike was a direct investment in meeting our obligations under NIS2. Thanks to Inetum’s MDR service model, we do not need to hire additional cybersecurity specialists ourselves.”
24/7 Monitoring
It did not take long for the value of continuous monitoring to become evident. The IT Director Infrastructure recalls two incidents in which the solution immediately demonstrated its worth.
“It was a classic phishing attack,” he explains. “An employee clicked on a malicious PDF attachment in an email, triggering malware. CrowdStrike instantly stopped the script and isolated the laptop from the network. I received a call from CrowdStrike’s SOC warning us that an incident was in progress. That provides an enormous sense of security.”
The same happened when an employee’s account was compromised. “We blocked the user before the attackers could steal data or cause damage. Without 24/7 monitoring, we might have discovered the breach much later, and the outcome could have been very different.”
Peace of Mind
According to Ollivier Francq, the value of an MDR service should be assessed correctly. “It does not mean your own team has less work to do,” he says. “Quite the opposite. You gain much better visibility into your network. You see more and identify issues sooner, which leads to more preventive actions.”
But the peace of mind it delivers is invaluable. “We no longer lose sleep over the possibility of something happening in the middle of the night while nobody is watching.”
A cyber insurance policy can never provide the same level of reassurance, he adds. “I would much rather have a technical solution that actively protects us. Insurance may compensate the financial damage after an incident, but you are still left dealing with operational disruption and reputational damage. We choose prevention.”
The Smartest Investment
Thanks to the combination of CrowdStrike’s technology, Inetum’s expertise, and easy access through the City of Bruges Framework Agreement, the City of Bruges has significantly strengthened its cyber resilience.
“It is the smartest investment we could have made: maximum protection with minimal administrative burden.”
Related success stories
- Title
- Description
- Date
- 1
- 2
- 3
- 4
- 5
- 6
- 7