Digital resilience

At CGK Group, cybersecurity had always been a priority, but a structured strategy was still lacking. “A cyberattack doesn’t just affect your business, but all your stakeholders too,” explains Tijl Charle, CEO of CGK Group. “We took cybersecurity seriously and identified the risks, but we lacked a proactive approach.”

CGK Group has been working with its IT partner Savaco for ten years. When the need for a cybersecurity upgrade became more pressing, Savaco proposed the VLAIO improvement programme. “Last year, CGK Group upgraded its network infrastructure, just as the NIS2 legislation came into force,” says Alex Maes, Senior GRC Consultant at Savaco. “CGK is not directly subject to NIS2, but it does work with companies that are. Thanks to our knowledge of their infrastructure and corporate culture, we were able to quickly develop a targeted strategy to improve their digital resilience.”

A cyber attack affects not only your business, but also all your stakeholders.

Tijl Charle, CEO CGK Group
Tijl Charle
CEO CGK Group

Wake-up call

Together, CGK Group and Savaco went through the entire cybersecurity process – from audit to action plan and implementation. The first step? A thorough audit to assess CGK Group’s cyber maturity. “An audit is about more than just technology. We don’t just look at the implementation of, say, Multi-Factor Authentication (MFA), but also at the processes and awareness within the organisation,” explains Alex. “Using a gap analysis, we identify areas for improvement and turn these into an action plan. This gives the company a clear roadmap without disrupting day-to-day operations.”

The audit revealed both positive aspects and areas for improvement. “It was a real eye-opener,” says Tijl. “We were doing well, but some access points weren’t properly secured, and the phishing test showed that a number of staff were still falling for fake emails. On top of that, there was a lack of documentation regarding our security measures, which poses risks if IT staff fall ill or leave. That was a real wake-up call.”

CGK is not directly subject to NIS2, but it does work with companies that are covered by it.

Alex Maes, Senior GRC Consultant bij Savaco
Alex Maes
Senior GRC Consultant Savaco

From concept to implementation

Following the audit, Savaco drew up an action plan comprising both quick wins and long-term measures. “We identified the biggest risks and looked at which improvements we could implement quickly,” explains Tijl. “Our aim was to gradually evolve our cybersecurity maturity from ‘basic’ to ‘important’, using a structured approach.” Alex adds: “We’re starting with the measures that will have the greatest impact, without losing sight of the bigger picture. That way, we’re tackling all the bottlenecks. As one of the first steps, we implemented MFA and strengthened the network with VLANs and segmentation.”


Technology alone isn’t enough. It’s just as crucial that staff are aware of their role. “Cybersecurity isn’t just a matter for the IT department, but a mindset for the whole company,” explains Tijl. “Thanks to Savaco, we’ve made significant progress in this area. Our staff are now the first line of defence and are much more alert.”

Our staff are now the first line of defence and are much more aware of their role.

Tijl Charle, CEO CGK Group
Tijl Charle
CEO CGK Group

Co-creation

The collaboration between CGK Group and Savaco was a fine example of co-creation. Savaco guided CGK step by step through the implementation of their action plan. “Cybersecurity isn’t a one-off task, but an ongoing process,” Alex emphasises. “By actively working on cyber maturity, cybersecurity is now firmly embedded throughout the organisation, ensuring they remain secure in the long term.”

Tijl from CGK Group makes a striking comparison: “We invest in fire safety without a doubt, but a cyberattack can be just as destructive. Thanks to the VLAIO programme and Savaco’s expertise, CGK Group has significantly improved its digital resilience and remains competitive in an increasingly digital world.”

Cybersecurity is now firmly embedded throughout the organisation, ensuring that it remains secure in the long term.

Alex Maes, Senior GRC Consultant bij Savaco
Alex Maes
Senior GRC Consultant Savaco

Protect your business against hackers too

As a Flemish SME, Savaco’s cybersecurity improvement programme can help you make rapid progress in enhancing your organisation’s cybersecurity. What’s more, you can count on a 50% VLAIO grant towards the cost of your improvement programme.