Tom De Cubber

I am a cybersecurity GRC consultant based in Lokeren, Belgium, and the founder of CySLok. It is a one-person practice by design: the person you speak to in the first conversation is the person who does the work.

← Back to home

What I do

I work at governance level: ISO 27001:2022 management systems, CyberFundamentals 2025, and the obligations that follow from the Belgian NIS2 law. In practice that means scope decisions, risk assessment, the Statement of Applicability, policy people can actually follow, and the internal audit that shows whether any of it is working.

I do not sell technical implementation. Thirty years in IT means I can read your architecture and ask the uncomfortable questions about it, but my value lies a layer above that: connecting controls to business risk, and putting management in a position to defend the decisions behind them.

Why I work the way I do

Most security programmes I am asked to look at were built to survive an audit. They pass, and then nothing changes. Policies sit unread, controls are documented but never operated, and the organisation is left holding a certificate and an illusion of control.

I start from the opposite end. A control nobody can follow is a finding waiting to happen, no matter how well it is written. So I begin with what the organisation actually does, keep the system proportionate to the risk it carries, and make sure the people who have to live with it understand why it exists.

That makes me a poor fit for an organisation that wants a certificate and nothing more. It makes me a good fit for one that intends to still be using the system three years from now.

Credentials and background

How I work with clients

Engagements are bounded: a scope, an outcome and an end. I would rather run a short, focused assignment that leaves you able to carry on by yourself than a standing retainer that quietly makes you dependent on me. Where a piece of work genuinely calls for expertise I do not have, I say so and point you to someone who does.

One rule I do not bend: I will not audit a management system I implemented myself. Auditing my own work would remove the very independence that makes the audit worth paying for.

Elsewhere

I write regularly about security governance, ISO 27001, and how NIS2 and CyberFundamentals are playing out in Belgium.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call