Universities of applied sciences test their preparedness for a cyber crisis

by
Davina Luyten

Communications Officer @ Belnet

What if your organisation is hit by a cyberattack and your IT systems suddenly stop working? How do you ensure business continuity, and how do you make sure your stakeholders are informed quickly and accurately? Over the past few months, around ten universities of applied sciences have put their cyber crisis preparedness to the test. Kristof Van Doorsselaere, Network & Security Project Manager at HOGENT, looks back on the programme.

Between November 2025 and June 2026, Belnet and the Centre for Cybersecurity Belgium (CCB) organised, for the third time, a training programme for Belnet customers, guiding participants step by step through the process of designing and facilitating their own cyber crisis exercise. This year, the programme was tailored specifically to universities of applied sciences.

Interactive workshops 

The training programme consisted of three interactive workshops, combining theory and practice. 

The first session focused on the fundamentals of crisis management and crisis communication. Experts from the CCB also provided an overview of the NIS2 Directive and illustrated the role of CERT.be through a practical case study. Participants then took part in a realistic, multi-round crisis simulation in small groups, allowing them to apply crisis management best practices in a hands-on setting. 

The second and third sessions focused on developing a (cyber) crisis exercise. Participants were guided through the entire process, from defining the scope of the exercise to developing injects for the crisis team and evaluating the exercise afterwards. Particular attention was also given to the roles of the exercise facilitator and observer. 

The universities of applied sciences then got to work on their own exercises. Those who wished could receive additional advice and guidance on their chosen scenario and approach. 

“The workshops were extremely valuable and well structured,” says Kristof Van Doorsselaere from HOGENT. “Preparing for our first exercise was quite demanding – it involved several preparatory meetings – but it helped us think everything through thoroughly.” 

An innovative approach 

Before running the actual exercise, HOGENT organised a dry run with colleagues from the IT team. “Because these were mainly technical IT profiles, the dynamic was very different from the one we later experienced with the crisis management team. However, the dry run proved extremely valuable: it helped us refine the scenario and identify potential issues before the actual exercise.” 

For the exercise itself, HOGENT deliberately opted for an innovative approach. “Instead of using a traditional PowerPoint presentation, we created an HTML slideshow that provided a gamified environment. It felt a bit like an escape room, and we received a lot of positive feedback from the crisis team. This interactive approach made the exercise more engaging and realistic.” 

Raising awareness 

During a joint debriefing session, participants shared their experiences and lessons learned. For most universities of applied sciences, raising awareness was one of the main objectives of the exercise. 

“Our first major objective was achieved: it was a real eye-opener for the crisis team. Everyone became fully aware of the importance of being prepared for a cyber crisis. At the same time, the exercise highlighted several areas for improvement, which is exactly what we wanted to achieve with this first exercise.” 

Kristof Van Doorsselaere, Network & Security Project Manager at HOGENT

One lesson that came up repeatedly was the need to establish clear criteria for declaring a crisis. “During the first round of our exercise, we deliberately provided the crisis team with limited information in order to create a situation where it was not immediately clear whether a crisis should be declared. This demonstrated – and it became apparent during the exercise itself – that we need clear criteria defining when an incident escalates into a crisis.” 

Alternative communication channels 

Many participating universities of applied sciences immediately started working on a number of quick wins after the exercise, including HOGENT. 

“Our Director of Communications immediately set to work addressing a number of blind spots. We now have a comprehensive document describing our crisis communication approach from A to Z in the event of a cyber crisis.” 

The exchange of knowledge with other universities of applied sciences also proved valuable. “Following a recommendation from our colleagues at Howest, we signed a contract with Proximus to enable rapid SMS communication during a crisis. We have also agreed on which alternative tools we will use if our regular communication channels become unavailable or can no longer be trusted.” 

Exercising is worthwhile 

Participants unanimously agree on the key conclusion of the programme: practising is both important and worthwhile. Working through a realistic crisis scenario provides valuable insight into the strengths and weaknesses of your organisation’s crisis management processes. 

“We realise there is still a lot of work ahead of us. We still need to develop several playbooks and ensure that all critical information is available through alternative tools. However, thanks to the programme organised by Belnet, we now have a solid foundation and a clear roadmap for the future.”

Kristof Van Doorsselaere, Network & Security Project Manager at HOGENT

Did you find this news interesting?
Copyright © 2026 Belnet.