Public interest · rights · accountability

Trust requires visible rules.

This code turns IBCSC values into decisions that can be checked. It governs cybersecurity research, publications, training, the use of artificial intelligence, partnerships and every activity carried out in the association’s name.

Version 1.0 26 July 2026
Dignity before performanceSecurity does not justify disproportionate harm to people.
Documented independenceA funder or partner does not control the Institute’s conclusions.
Limits remain visibleCompetence, uncertainty and conflicts of interest are stated.
A right to questionA good-faith concern can be raised without internal retaliation.

An operational code, not a decorative statement.

The code is used to prepare an activity, resolve doubt, document a refusal and examine a departure from the rules. Compliance with law is the minimum. When an action remains technically possible but creates human risk, the Institute chooses the option that best protects people and the public interest.

Who it covers
Directors, members, employees, volunteers, trainers, experts, trainees, service providers and partners when they act on behalf of IBCSC.
Decision rule
When serious doubt remains, the activity is paused until the applicable law, authorisation, impact and accountable person are clear.

Eight non-negotiable commitments.

Each commitment must leave a concrete trace in the work. Good intent does not compensate for an intrusive method, a weak source or undefined accountability.

01

Legality and fundamental rights

Every activity respects applicable law, dignity, privacy, data protection, freedom of expression, equality and the rights of the child.

Basis, authorisation and purpose identified
02

Necessity and proportionality

Collection, testing and distribution are limited to what is genuinely needed. The least intrusive effective option is preferred.

Scope and stopping rule recorded
03

Independence and neutrality

IBCSC remains independent of commercial, partisan and personal interests. It does not present itself as a public authority or use its work to support a political party.

Role and funding made visible
04

Rigour and intellectual honesty

Facts, interpretations and hypotheses are separated. Important conclusions carry sources, dates, limits and an appropriate confidence level.

Traceable sources and a correction path
05

Confidentiality and data minimisation

Personal data, secrets, reports and technical access are protected and only collected, shared or retained for a defined need.

Restricted access and justified retention
06

Competence and care

No one accepts work beyond their ability without supervision. Criminal, medical, social and legal matters are referred to the competent services.

Qualified owner and stated limits
07

Inclusion and accessibility

Activities oppose discrimination, adapt language and materials and work to include people with disabilities or limited digital access.

Audience, needs and adjustments recorded
08

Accountability and remedy

An important decision has an identifiable owner, can be explained and can be challenged. An acknowledged error leads to a visible and proportionate correction.

Decision, author and follow-up retained

Five gates before a sensitive action.

This check is used before a test, collection, publication, partnership or deployment of AI that may affect a person.

  1. 01

    Is it lawful and authorised?

    The legal basis, mandate and owner of the system or data are known.

  2. 02

    Is it necessary?

    The public-interest objective cannot reasonably be achieved with less data or access.

  3. 03

    Is this the least intrusive means?

    Scope, duration, rate and distribution are reduced to the actual need.

  4. 04

    Can we explain it?

    An affected person can understand the logic, limits and consequences of the decision.

  5. 05

    Who is accountable?

    An owner can stop the action, handle a challenge and organise a correction.

Cybersecurity remains defensive, authorised and proportionate.

IBCSC observes, prevents, teaches and helps reduce risk. It does not conduct clandestine operations, punitive attribution or offensive access to third-party systems.

Read the CVD policy
  • No active testing without written authorisation or an applicable public policy
  • No exploitation beyond the minimum evidence needed
  • No deliberate access to third-party communications, accounts or data
  • No retention of secrets, tokens or data unnecessary for the report
  • OSINT uses lawfully accessible sources for a defined purpose
  • Indicators of compromise are shared according to need, risk and sensitivity
  • No public attribution of an attack without strong evidence, context and critical review
  • A vulnerability is reported through the CVD channel and published only after coordination

AI assists the work, it does not dilute responsibility.

A local model can reduce some data transfers, but it does not guarantee confidentiality, accuracy or freedom from bias. Risk depends on the data, model, hosting, access controls and actual use.

HUM

Human control

A competent person remains responsible for decisions, publications and advice and can reject, correct or stop the system.

TRC

Traceability

The tool, version, purpose and important checks are documented when AI influences a significant result.

DAT

Controlled data

Personal, confidential or protected data is not sent to an external service without necessity, a valid basis and appropriate safeguards.

VER

Verification

Citations, technical facts, translations, images and recommendations produced with model assistance are checked before release.

FAI

Fairness and accessibility

Effects on different groups are considered. A discriminatory or inaccessible result is not accepted as a mere technical limitation.

SEC

Robustness and safety

Risks of leakage, prompt injection, malicious content, dependency, unavailability and misuse are assessed.

LIT

AI literacy

People using a system understand its purpose, limits, likely errors and required verification procedures.

IBCSC does not use a fully automated decision to publicly accuse a person, reject a candidate, determine access to training or settle a matter affecting rights without appropriate human review.

Teach young people without normalising intrusion.

Courses for school pupils and students develop technical curiosity in a lawful, supervised and respectful setting. Being able to do something never amounts to permission to do it.

  1. 01

    Authorised environments

    Exercises use laboratories, machines, accounts and datasets created or expressly authorised for training.

  2. 02

    Age-appropriate protection

    Content, communication, schedules and supervision take account of age, maturity and rules protecting minors.

  3. 03

    Minimum data

    Registration requests only necessary information. Personal accounts and learner work do not become promotional material by default.

  4. 04

    Trainer conduct

    Trainers maintain professional boundaries, reject harassment and humiliation and report concerning situations through the defined channel.

  5. 05

    Fair access

    Lack of equipment, income, language proficiency or a disability is treated as a barrier to reduce, not a lack of merit.

  6. 06

    Responsible progress

    Success includes documentation, teamwork, safety, respect for scope and the ability to ask for help.

A partnership funds an action, not a conclusion.

Agreements define the objective, responsibilities, data, visibility, payments or contributions and stopping conditions. Public interest and beneficiary safety remain the priority.

Editorial independence

A partner does not choose the outcome of an analysis, alert or recommendation.

Identifiable visibility

Sponsorship, equipment contributions and supported content are presented without hidden advertising.

Declared conflicts

A relevant personal, financial or professional relationship is declared before the decision.

Limited access

A partnership does not automatically grant access to data, systems, beneficiaries or restricted reports.

Gifts and benefits

A personal benefit capable of influencing a decision is refused or declared and handled by someone who is not affected.

Right to refuse

IBCSC may refuse or end cooperation that conflicts with law, safety, independence or this code.

See the partnership framework

Publish with precision, context and a correction path.

Publications should help readers decide without amplifying fear, exposing a victim or turning a hypothesis into an established fact.

Sources and dates
Important claims point to an identifiable source and state the observation period.
Fact and interpretation
Confirmed elements, analysis and hypotheses are distinguished with an appropriate confidence level.
Protection of people
Names, images, identifiers and technical details are minimised when they could expose a victim or facilitate abuse.
AI and contributions
Substantial assistance from AI, a partner or an external author is stated when it clarifies the method or its limits.
Corrections
A significant error is corrected promptly. The nature and date of the correction remain understandable to the reader.

A conflict of interest is managed before the decision.

A conflict may be actual, potential or merely perceived. Declaring one is not misconduct. Concealing it can weaken the decision and public trust.

  1. 01

    Declare

    The person describes the relevant link, benefit or relationship as soon as they become aware of it.

  2. 02

    Assess

    An unaffected person considers influence, the appearance of bias and available safeguards.

  3. 03

    Step back when needed

    Access to the file, discussion, voting or external representation may be restricted.

  4. 04

    Document

    The decision, chosen safeguard and its duration are retained proportionately.

An ethical concern must be capable of review.

Anyone may report in good faith conduct, a decision, a conflict or a risk that may breach this code. The message should describe known facts, affected people or activities and any urgent protection need.

Ethics channel info@ibcsc.be

Do not send a technical secret or vulnerability evidence through this channel. Use the CVD policy for a security flaw. Confidentiality is pursued, but cannot be promised absolutely when a legal duty or urgent protection requires referral.

  1. 01

    Restricted receipt

    Access to the message is limited to people needed for the review and immediate protection.

  2. 02

    Conflict checked

    If the concern involves the usual recipient, it is transferred to an unaffected director or reviewer.

  3. 03

    Fair review

    Facts, documents, rules and relevant responses are examined without presuming fault or exposing the reporter unnecessarily.

  4. 04

    Decision and follow-up

    Measures, reasons, limits and follow-up routes are recorded and communicated to an appropriate extent.

Human acknowledgement
5 working days
Initial assessment
15 working days
Update while the matter remains open
Every 30 days

A rule without consequences protects no one.

A response considers severity, intent, impact, repetition, cooperation and the possibility of repair. It respects the statutes, agreements and rights that apply.

  • Advice, clarification of the rule or additional training
  • Correction, withdrawal or updating of content, access or a decision
  • Increased supervision, restriction of a task or removal from a matter
  • Suspension or ending of cooperation under the applicable framework
  • Referral to a competent service or authority when a duty or danger justifies it

The code is reviewed at least annually and after a significant incident, a material legal change or the launch of an activity presenting a new risk.

Questions about applying the code.

The code cannot anticipate every situation. These answers explain how common cases are handled.

Does the code replace employment rules, statutes or law?

No. It complements applicable rules and does not reduce a legal right or duty. Where there is a conflict, applicable law and mandatory texts prevail.

Can I report something without complete evidence?

Yes, when the report is made in good faith and separates what was observed from what remains suspected. Do not conduct your own intrusion, surveillance or excessive collection to obtain evidence.

Must every use of AI be disclosed publicly?

Not every minor wording correction. Disclosure is expected when AI substantially influences content, a recommendation, image, assessment or decision and that information helps people evaluate the result.

May a partner review content it funds?

It may check facts about itself or an agreed mention, but it cannot impose a conclusion, remove justified criticism or turn educational content into hidden advertising.

What if the matter is a vulnerability?

Use the coordinated vulnerability disclosure page. It sets out the authorised scope, channel, testing rules and publication conditions.

A credible organisation allows its methods to be questioned.

Use the ethics channel for conduct, a decision or a conflict. For a technical vulnerability, follow the CVD policy to protect users and evidence.