Business & Technology
Why Belgian SMEs are falling behind in software security
While the European Union accelerates toward a more regulated digital landscape with the Cyber Resilience Act and NIS2, the backbone of its economics SMEs remains perilously exposed. A comprehensive study by PXL University of Applied Sciences and Arts, utilising the OWASP SAMM framework and the relevant industry benchmarks and target postures, reveals a critical structural imbalance in software development. The research finds that while Belgian SMEs excel at reactive operational management, they are almost entirely neglecting proactive security measures like threat modelling and developer education. This article explores the findings, the economic “security debt” being accrued, and the urgent necessity of a “shift-left” strategy for cyber-resilience.
The backbone of the digital economy
Located at the “heart of Europe,” approximately 50 kilometres from Brussels, the Belgian region of Flanders serves as a critical hub for software innovation. In this landscape, small-to-medium enterprises (SMEs) are not merely participants; they are the industry’s engine, representing approximately 99% of the industrial landscape. These companies hold a software market share of between 50% and 60%, meaning the products they develop end up in the hands of millions of daily users and large-scale corporate infrastructures.
Despite their significance, the cybersecurity maturity of these organisations has remained a “blind spot” in both scientific literature and practical application. A research team from PXL University of Applied Sciences and Arts, led by Cyber Security Research Coordinator Dr Koen Gilissen and researcher Savannah Eggers, recently set out to map this maturity using a rigorous, internationally recognised framework.
Their findings suggest that the digital foundation of Europe is built on a “reactive” rather than “proactive” culture, a trend that poses significant risks as global cyber threats continue to increase exponentially.
Understanding the framework: OWASP SAMM
To measure the security posture of these SMEs, the PXL team utilised the OWASP Software Assurance Maturity Model (SAMM). OWASP (the Open Worldwide Application Security Project) is a non-profit foundation providing community-driven resources that act as the “gold standard” for application security.
SAMM assesses an organisation across five functional pillars, each essential to a secure Software Development Life Cycle (SDLC):
-
Governance: Strategy, metrics, policy, compliance, and education.
-
Design: Threat assessment, security requirements, and secure architecture.
-
Implementation: Secure build, secure deployment, and defect management.
-
Verification: Architecture assessment, requirements-driven testing, and security testing.
-
Operations: Incident, environment, and operational management.
The research findings: a “critical structural imbalance”
The analysis of Flemish software SMEs exposed a stark reality: security is often treated as a “thin sauce” poured over the end product rather than being embedded within the software itself.
The “Operations” illusion
The PXL study found that SMEs score relatively high in the Operations pillar. In fact, scores for Environment Management and Operational Management actually exceeded the “Target Posture LOW BASELINE” – the minimum requirement to avoid being considered an “easy target”. This indicates that Belgian SMEs are competent at managing systems that are already “live”.
The proactive gap
However, the “proactive” phases of the SDLC, specifically Governance and Design, showed alarming deficiencies. The most pressing observations involved two critical activities:
-
Education and Guidance: Measured at a staggering 0.02 average, compared to a target baseline of 1.0.
-
Threat Assessment: Measured at 0.25 average, against a target of 1.9.
Dr Gilissen noted, “The results were at least lower than I naively expected”. This imbalance suggests that companies are “extinguishing fires” in production rather than preventing vulnerabilities at the source.
The economic reality: Features vs. Security
Why do these gaps exist? The PXL team identified several “limitation factors” common to SMEs: a lack of manpower, expertise, skills, and, most crucially, time and resources.
Every line of code that contributes to a new feature is viewed as direct value creation or “money”. Conversely, security efforts are perceived as heavy investments that slow down the development process. This leads to what the researchers call “Security Debt”.
“What is saved today by skipping security will be paid back tomorrow, more than double, in the form of complex patches and recovery work,” the PXL problem statement warns.
This “technological debt” does more than just increase the risk of a breach; it exponentially raises future maintenance costs and threatens the long-term viability of the software.
The “shift-left” necessity and regulatory pressure
The study argues for a fundamental “shift-left” strategy. This concept involves moving security considerations to the earliest possible stages of the development cycle, such as threat modelling and developer education, rather than waiting until the implementation or verification phases.
This shift is no longer just a “best practice”, it is becoming a requirement for market access. New European regulations, such as the Cyber Resilience Act (CRA), the AI Act, and NIS2, are imposing strict demands on software security.
Under the NIS2 legislation, supply chain security is paramount. Larger clients are increasingly demanding proof of security maturity from their SME subcontractors. A low SAMM score could lead to the loss of crucial B2B contracts as larger firms seek to minimise their own third-party risks.
Hope through frameworks
Despite the “no hope” feeling some SMEs might experience when faced with mounting legislation, the PXL team remains optimistic. Frameworks like OWASP SAMM provide a manageable roadmap.
Savannah Eggers highlighted the value of structured guidance: “With SAMM, it’s very easy to pinpoint what you need to know. It tells you, okay, here’s a resource to learn more about security principles”. By breaking down maturity into levels (1, 2, and 3), the framework allows companies to prioritise their limited resources for the “biggest bang for their buck”.
Conclusion: a call to action for Flemish SMEs
The PXL study serves as both a warning and a guide. For the thousands of SMEs in Flanders and the wider Belgian and European region, the “time is now” to address the critical gaps in Education and Threat Assessment.
Increasing a company’s cybersecurity posture is not just about compliance; it is a significant business opportunity. Those who can demonstrate a secure development process will differentiate themselves from competitors, secure lucrative B2B contracts, and build products that are resilient by design rather than by chance.
As Dr Gilissen summarises for the next generation of developers, SMEs have the potential to make a massive difference in regional cyber-resilience. The journey from “firefighting” to “prevention” begins with the first step of the shift-left strategy: a good analysis of where we stand.
Business & Technology
Rosa’s Thai is giving away 4000 free Pad Thais to students
Celebrating both GCSE and A-Level Results Days, the chain will offer the popular dish to students who buy one of its bubble teas.
The free offer is available at all 42 Rosa’s Thai restaurants across England and Wales.
To avail of the free noodles, students need to register on Rosa’s Thai website for a unique code, which they should present at the restaurant together with a copy of their results.
Rosa’s Thai has a new range of bubble tea flavours, including Ube-Taro, Matcha-Coconut, Mango Sticky Rice, and Milo Chocolate Milk, as well as favourites like Home-brewed Thai Tea with Tapioca, and Lychee Mango with mango boba.
Students can sign up for their free Pad Thai at rosasthai.com/result-day-free-pad-thai and find their nearest restaurant at rosasthai.com/locations.
Business & Technology
Historic coin company enters administration after 20 years
The London Mint Office, which distributes commemorative coins and medals, appointed administrators on July 31 after 20 years in business.
The company’s website now displays a message confirming the appointment of Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP as joint administrators.
A spokesman for Alvarez and Marsal said: “On July 31 2026, Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP were appointed as Joint Administrators of The London Mint Office Limited in administration (the “Company”).
“Regrettably, the Company’s liquidity challenges have led to a number of immediate redundancies. We are supporting the affected employees through the redundancy process.
What Happens When a Company Goes Into Administration?
“The affairs, business and property of the Company are being managed by the Joint Administrators who act as agents of the Company and without personal liability.”
The announcement confirms that it is no longer possible to purchase coins or medals through the company’s website.
The London Mint Office operates a distribution centre in Tonypandy, Rhondda Cynon Taf, where it employs a significant number of people.
Administration is a formal insolvency process triggered when a business cannot meet its financial obligations.
An insolvency practitioner is appointed to manage the company’s affairs and may attempt to restructure the business or sell off assets to repay creditors.
What happens when a company goes into Liquidation?
Founded in 2006, The London Mint Office describes itself as “one of the UK’s most trusted suppliers of historic, commemorative, and collector coins.”
It is part of Samlerhuset AS, a Norwegian company based near Oslo and one of Europe’s largest distributors of commemorative coins and medals.
Samlerhuset’s website states that it offers “provide a wide range of coins from ancient to modern, originating from virtually every country in the world.”
The London Mint Office has advised anyone with an interest in the company’s assets to contact the administrators at INS_THLMOL@alvarezandmarsal.com.
Business & Technology
Warning of new rules for Aldi and Lidl after watchdog review
The Competition and Markets Authority (CMA) has provisionally decided that both discounters should be added to the Groceries Market Investigation (Controlled Land) Order 2010, which currently applies to Asda, Co-op, Marks and Spencer, Morrisons, Sainsbury’s, Tesco, and Waitrose.
This order is designed to prevent large grocery retailers from using land agreements to block competitors from opening nearby stores, often through restrictive covenants or exclusivity terms.
Juliette Enser, executive director of competition enforcement and markets at the CMA, said: “We want everyone to have the best choice of supermarket and range of prices when buying their groceries.
“To ensure this happens, we put rules in place to prevent big supermarket chains blocking rival stores from opening nearby – and now we propose applying those rules to Aldi and Lidl too.
“This is about allowing shoppers to choose where they spend their money and levelling the playing field for all major supermarkets.
“Today’s proposals are provisional and we welcome views before deciding the best way forward.”
The CMA’s review found that Aldi, Lidl GB, and Lidl NI now meet the criteria of ‘Large Grocery Retailers’ (LGRs) due to their store footprint, nationwide presence, procurement model, and the breadth of their grocery range.
Aldi and Lidl were originally excluded from the 2010 order as ‘limited assortment discounters’, offering a smaller selection of products compared to traditional supermarkets.
However, the CMA’s provisional findings indicate that this is no longer the case.
All three now operate large grocery stores, each with more than 1,000 square metres of shop floor space, and offer a full range of products, though with less category choice than some competitors.
They also purchase goods directly from suppliers through integrated wholesaling.
With the UK grocery market estimated to be worth £215 billion, Aldi and Lidl are now ranked among the top five retailers by market share.
The CMA is seeking feedback from stakeholders before reaching a final decision.
Aldi and Lidl could join the other supermarket chains later this year.
The CMA is inviting views until 5pm on Monday, September 7, 2026, and will issue its final decision in the autumn after reviewing responses.
If the discounters are included under the order, they will be prevented from using land agreements to limit competition from other supermarket chains.
The CMA aims to ensure competition across the grocery sector to give shoppers more choice and competitive pricing by removing obstacles to new store openings.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Oxford Events4 weeks agoHenley Festival 2026 highlights: Five nights of unforgettable performances and festival moments
-
Oxford united FC3 weeks agoOxford United three players who be kept after transfer ban
-
Business & Technology4 weeks agoZYMIX uses Henley event to pitch social app to Gen Z
-
Business & Technology2 weeks agoSlice golf bar swings to new heights after successful launch
-
Business & Technology3 weeks agoUK AI firms raise record GBP £4.56bn in Q2 funding
-
Oxford News3 weeks agoMan jailed for ‘sickening’ sexual assault of three girls in Cotswolds
