More than just a technical shield, cybersecurity must be integrated at the heart of corporate strategy. Between the evolution of digital threats and increasing regulatory pressure, Governance, Risk and Compliance (GRC) form the pillars of a comprehensive and structured approach to security — but not only that, explains Cédric Mauny, Strategic Advisor in Cybersecurity at Proximus NXT. When properly managed, it also provides an operational framework that helps prioritize and secure day-to-day activities, while strengthening the company’s resilience and performance.

Between the evolution of cyberthreats, the tightening of regulatory requirements and the need to guarantee the resilience of activities increasingly dependent on technology, organizations have their work cut out for them. “In this environment, cybersecurity is no longer limited to technical responses designed merely to stay protected from attacks or to react effectively in case of an incident. Today, it must be approached from a broader perspective, with the ambition to transform constraints into levers for creating value for the company,” explains Cédric Mauny.

From this perspective, the Governance, Risk and Compliance (GRC) approach provides a clear direction across the organization and ensures effective management of its security posture.

In the end, what we are really talking about is trust and risk control,
Cédric Mauny

Cédric MaunyStrategic Advisor in CybersecurityProximus NXT

Building a Robust Approach

Every organization must navigate an increasingly complex and fast-evolving environment. Security and risk management leave no room for improvisation. “In the end, what we are really talking about is trust and risk control,” continues the cybersecurity expert. “GRC provides a backbone that ensures consistent management of all issues and greater agility in the face of changing constraints. A robust approach in this area also represents a real competitive advantage.”

When regulatory requirements evolve, it is essential to understand them quickly and integrate them effectively. And when an incident occurs, teams must be ready to react without delay to protect operations and limit impacts. More broadly, this approach aims to strengthen trust and position the company as a reliable and credible partner — both to clients and investors.

Beyond Compliance

To support companies facing these many challenges, Proximus NXT has continuously developed its expertise in GRC and established a solid approach. Drawing on hands-on experience within its Luxembourg-based group of nearly 900 employees, this expertise provides valuable feedback ready to be shared with clients and applied in daily operations. “While GRC is often seen as a pure compliance exercise, the true objective is not simply to check boxes. On the contrary, it is about embedding enterprise risk management and regulatory compliance at the very heart of the company’s strategy,” explains Cédric Mauny. “When discussing risk, we must assess potential negative impacts — whether a sanction from the regulator or a cybersecurity incident — but also the related opportunities. These may include strengthening trust with clients or partners, or anticipating new regulations to turn them into opportunities for development and process optimization.”

we start from the company’s strategy, its objectives, strengths and weaknesses, and its positioning
Cédric Mauny

Cédric MaunyStrategic Advisor in CybersecurityProximus NXT

Supporting Development

As its name suggests, this approach revolves around implementing clear governance, a sound understanding of business-related risks, and mastering the regulatory framework in which the company operates. “This reflection therefore goes well beyond security issues alone. In our support, we start from the company’s strategy, its objectives, strengths and weaknesses, and its positioning,” continues Cédric Mauny. “Security and compliance can then be seen as key components of business development, rather than as obligations, constraints or barriers.”

Ensuring Operational Continuity

Risks are not limited to cyberthreats, potential data leaks or IT vulnerabilities. The approach also encompasses risks related to business, production, operations or clients. Identifying the critical elements of a service’s operation allows for more effective protection.

“For most companies, security is not their core business — their purpose is to sell services or products, relying on technology and data accessible from their IT systems. Security is a means that must primarily aim to ensure the continuity of operations and the availability of critical systems and data,” adds Cédric Mauny. “The goal is not to implement security solely to meet regulatory requirements, but to secure the business itself, strengthen resilience, and at the same time meet compliance expectations. It thus becomes a genuine lever for creating value for the company.”

Governance and Accountability

Identifying critical elements and activities is essential, but good governance also involves setting up key indicators that enable designated managers to make informed decisions. “Governance helps support strategic directions and ensures alignment of responsibilities around a shared vision,” adds the Proximus NXT expert. “It acts as the steering wheel that allows everyone to move forward together, with agility, toward a common goal.”

A Catalyst for Resilience and Competitiveness

Proximus NXT makes GRC a central pillar of its cybersecurity and risk management offering. By combining technical expertise, business understanding and mastery of the regulatory landscape, its teams help organizations strengthen their security posture, prioritize projects and manage risks, all while maximizing performance.

For Proximus NXT, cybersecurity should not be seen as a constraint — it should become a catalyst for trust, resilience and competitiveness.