Open monitoring · analysis · guidance

From a public signal to a proportionate security decision.

The Observatory follows digital threats that may affect citizens, non-profits, schools and small organisations in Belgium. It collects lawful open sources, adds context, states uncertainty and publishes understandable measures.

IBCSC is an independent non-profit, not the national CSIRT. It conducts no covert surveillance, criminal investigation or access to a system without authorisation.
Lawful sourcesPublic information, official bulletins, vendor advisories and authorised contributions.
Belgian relevancePriority is given to risks that may affect people and small organisations in Belgium.
Dated analysisEach product states its date, sources, confidence level and validity period.
Official routesIncidents, suspicious messages and vulnerabilities are directed to the competent channels.

Intelligence begins where the raw signal ends.

An address, screenshot or technical identifier is not enough. The analysis must establish what was observed, who may be affected and which action is reasonable.

  1. 01 Data

    A domain, URL, vulnerability, message or observed behaviour.

  2. 02 Information

    The data is dated, sourced, deduplicated and linked to a technical context.

  3. 03 Assessment

    Relevance, possible impact, exposure, confidence and urgency are separated.

  4. 04 Action

    A preventive measure, check, update or referral is proposed.

Six domains monitored for their public usefulness.

The Observatory does not try to cover everything. It focuses its resources on mechanisms frequently encountered by citizens and organisations with limited means.

IDN

Identity, phishing and impersonation

Campaigns that seek credentials, divert payments or pressure a person into acting.

  • Lookalike domains
  • MFA fatigue
  • Executive fraud
VUL

Vulnerabilities and exposed services

Vendor advisories, referenced vulnerabilities and public configurations that may require an update or reduced exposure.

  • CVE and EUVD
  • Patches
  • Public exposure
MAL

Malware and ransomware

Infection chains, attachments, loaders, encryption, data theft and signs useful for prevention.

  • Initial vector
  • Persistence
  • Backups
AVL

Availability and denial of service

Events that may disrupt a website, email or essential service, without speculating about who caused them.

  • DDoS
  • Outages
  • Dependencies
SUP

Supply chain and data

Risks introduced by a provider, library, cloud dependency or poorly controlled third-party access.

  • Suppliers
  • Exposed secrets
  • Third-party access
AIX

AI, deepfakes and manipulation

Use of AI to scale phishing, imitate an identity, fabricate content or bypass instructions.

  • Voice and video
  • Prompt injection
  • Data leakage

A six-stage analysis chain.

The process follows the logic of the ENISA Cybersecurity Threat Landscape methodology, adapted to the Institute’s citizen mission and resources.

  1. 01

    Direction

    Define the question, audience, expected decision and what remains out of scope.

  2. 02

    Collection

    Gather only sources that are necessary, lawfully accessible and relevant to the question.

  3. 03

    Processing

    Date, normalise, deduplicate, classify and preserve useful references.

  4. 04

    Analysis

    Compare sources, seek contradictions and assess impact, exposure and confidence.

  5. 05

    Dissemination

    Choose the format, audience, level of detail and appropriate sharing restrictions.

  6. 06

    Feedback

    Correct, enrich, expire or withdraw information as new observations arrive.

An alert is not considered final by default. It must be possible to correct, re-date or withdraw it when the context changes.

The signal status remains visible.

Source reliability and confidence in the analysis are different. The Observatory explains why a level was selected and what is still missing.

01

Under observation

A signal exists, but its scope, cause or authenticity is not yet sufficiently corroborated.

Internal or cautious
02

Corroborated

Several independent elements converge and the risk mechanism is reasonably established.

With limitations
03

Confirmed

An official source, the relevant vendor or direct evidence confirms the essential facts.

Actionable
04

Expired or invalidated

The patch is deployed, infrastructure has disappeared or new evidence contradicts the assessment.

Updated

Different sources serve different purposes.

No source is reliable by nature. Its competence, proximity to the event, track record and whether its claims can be checked are considered.

Authorities and CSIRTs

CCB, CERT.be, Safeonweb, CERT-EU, ENISA and other competent public bodies.

Confirmation and referral

Vendors and maintainers

Security bulletins, release notes, remediation advisories and vendor CVD policies.

Product impact and patch

Vulnerability databases

EUVD, CVE and other references used to identify products, versions and records.

Normalisation and tracking

Research and technical communities

Research publications, sector CSIRTs, professional associations and documented technical analysis.

Context and corroboration

Reports and open sources

Voluntarily shared messages, public websites, articles and observations available without intrusion.

Initial detection

Five formats, depending on the decision.

The level of detail depends on the audience. A citizen needs observable signs and immediate action; an organisation also needs versions, exposure and ownership.

FLASH

Short alert

Event-driven

An urgent signal presented without unnecessary detail or speculative attribution.

Contains
Risk, affected audiences, signs and first three measures.
Audience
Citizens, families, non-profits
BRIEF

Threat brief

As needed

A structured explanation of a campaign, fraud mechanism or technique.

Contains
Timeline, sources, mechanism, confidence, prevention and limits.
Audience
Non-profits, schools, small organisations
VULN

Vulnerability bulletin

After verification

A summary that helps decide whether an update or compensating control is needed.

Contains
Products, versions, references, exposure, patch and priority.
Audience
IT owners and providers
TREND

Trend analysis

Periodic

A cross-cutting view of observed signals without turning every occurrence into a general statistic.

Contains
Period, corpus, limits, developments and practical implications.
Audience
Partners, local authorities, education
TLP

Restricted cooperation note

By agreement

Limited sharing when defensive details should not be made public.

Contains
Recipients, purpose, TLP marking and retention rules.
Audience
Authorised partners

The right report must reach the right recipient.

IBCSC can explain and guide. Official channels remain the priority when a message is suspicious, an incident is ongoing or a vulnerability must be disclosed.

Suspicious message

Safeonweb

Forward suspicious emails to suspicious@safeonweb.be. Safeonweb also explains how to recognise fake messages.

Read the instructions
Cyber incident

CERT.be / CCB

Organisations experiencing a cyber incident can use the official form or contact the national CSIRT under the stated conditions.

Report an incident
Vulnerability

CCB CVD procedure

Research and reporting must remain necessary, proportionate and compliant with Belgian coordinated disclosure conditions.

Read the CVD procedure

If a person is in immediate danger, contact the competent emergency services. Do not send a password, private key or full copy of personal data in an ordinary report.

Credible monitoring depends on verifiable limits.

The Observatory works within a preventive and analytical framework. Intrusive methods, mass collection and premature publication would increase risk instead of reducing it.

The Observatory may

  • Analyse lawfully accessible open sources
  • Passively check a public domain, URL or reference
  • Compare bulletins and document contradictions
  • Explain a risk and propose proportionate measures
  • Update or withdraw an assessment that became obsolete
  • Refer to the CCB, Safeonweb, police or an appropriate professional

The Observatory may not

  • Access a system without explicit authorisation
  • Test a vulnerability beyond what is necessary and lawful
  • Monitor a person or build a covert profile
  • Attribute an attack without solid publishable evidence
  • Publish secrets, personal data or details that enable an attack
  • Replace incident response, a judicial investigation or the national CSIRT

Cooperation improves quality, not volume.

IBCSC seeks partners able to provide a source, sector context, expertise or a clearly governed distribution channel.

Propose cooperation
Non-profits and local actors
Share mechanisms encountered in practice without exposing beneficiaries.
Education and research
Contribute to method, verification and audience understanding.
Companies and providers
Provide technical advisories, patches and verifiable evidence without imposing a conclusion.
Public authorities
Connect local observations with official channels and existing prevention messages.

Public methodology references.

These resources guide the work. Mentioning them does not imply affiliation or endorsement of IBCSC by the organisations concerned.

A useful alert also says what it does not know.

Read the published analysis or report a situation to IBCSC for initial guidance. For an incident, suspicious message or vulnerability, use the official channels above first.