Information Security in Belgian Healthcare

Since the NIS2 Act came into force in October 2024, healthcare organisations in Belgium have been required to significantly strengthen their information security. Organisations can choose to implement only the measures required under NIS2. 

However, for those looking to demonstrate a commitment that goes beyond their legal obligations, ISO/IEC 27001 provides a robust framework for continuous improvement and risk management. Implementing the standard not only enables you to meet the requirements of the NIS2 Directive, but also helps you establish an information security management system that extends beyond the NIS2 requirements.

Whether you are taking your first steps or are already well into the process, Kerteza can guide you at every stage towards an effective information security system.

 

Initiation and exploration

Just getting started with information security? Kerteza can help you build a solid foundation. The first step is to understand the standards and legislation that apply to your organisation, including NIS2 and ISO 27001. To help strengthen your employees’ knowledge, we offer training including the Training Norminterpretatie ISO 27001 en NIS2.

 

Planning and design

A sound information security strategy starts with a clear understanding of your current position. Together, we assess where your organisation stands and identify the steps required to meet the requirements of NIS2 and/or ISO 27001.

Our system assessment evaluates how efficiently and effectively your information management system has been implemented and identifies potential areas for improvement. Based on the findings in the resulting report, we can then help you develop an action plan.

 

Implementation

Whether you are working from the findings of our system assessment or your own analysis, we can support you in implementing the processes needed to meet the requirements of NIS2 and/or ISO 27001. Drawing on our extensive experience, we tailor our approach to your organisation and aim to integrate new processes into your existing ways of working wherever possible.

 

Maintaining your system through the PDCA cycle

Once an information security system is in place, it requires continuous attention and maintenance in line with the PDCA cycle. Without this ongoing focus, its effectiveness will diminish over time. Kerteza can support you throughout every stage of the PDCA cycle.

 

Plan:

Employees need to understand the requirements and structure of standards such as ISO 27001. For those who want to develop their knowledge of the standard, we offer the Training Norminterpretatie ISO 27001, helping everyone within your organisation understand what is expected of them.

 

Do:

If you need to introduce new processes or expand existing ones within your information security system, we can support you with process implementation. Our consultants tailor their involvement to your needs, ranging from remote advice to active participation in the project.

Whatever level of support you choose, the goal remains the same: to create an efficient system that fits seamlessly into the way you work, so that the system works for you – not the other way around.

 

Check:

Regular checks are essential to maintaining effective information security. Our Training interne auditvaardigheden prepares your employees to carry out audits, while the Training omgaan met Non-conformiteiten en corrigerende maatregelen helps ensure that nonconformities are addressed effectively.

If you do not have sufficient in-house capacity or expertise to conduct internal audits, Kerteza can carry out the audit of your information security management system on your behalf.

 

Act:

If internal checks or an audit by the certification body reveal that your information security system is not performing as it should, we can support you in addressing any nonconformities. Our consultants can be particularly valuable when time is limited or the issues involved are complex.

Looking to go beyond simply resolving the immediate issue? Our process optimisation support helps you improve the way your processes are designed and strengthen your information security for the long term.

 

Discover what Kerteza can do for you.

Download our brochure or get in touch using the contact form.