At the Heart of Europe: Belgium’s CISOs to Watch

Related

Share

Belgium was among the first countries to put the EU’s NIS2 directive into national law, and the five leaders below spend much of their time working through what it demands. They protect an insurance group, a chemicals company, a biopharma company, a retail group, and one of Europe’s oldest universities. Four of the five have taught at universities or business schools alongside their security careers. Their earlier work spans ICT auditing, Java application platforms, industrial security consulting, managed security services, and running a DJ business.

Iwona Muchin – CISO & DPO, Ageas Group

Iwona Muchin started as a security consultant at Hewlett Packard in Brussels, then spent more than eight years at BNP Paribas Fortis. She worked as an ICT auditor, information security and risk advisor, and head of IT operational risk and permanent control. At BNP Paribas she became group business continuity supervisor, working from Paris, and co-chaired the bank’s Managers in Connection network. Muchin joined Ageas Group in February 2017 as CISO and Data Protection Officer, a combined role she has held for more than nine years. Outside Ageas, she serves as an independent expert on the audit committees of both the Flemish Administration and the Flemish Parliament, bringing private-sector security and continuity expertise to public-sector internal audit. She is a member of European Women on Board. In the long winter months she crafts seasonal decorations and clothing, which she says frees her mind for new ideas.

Xavier Paulus – Group CISO, Solvay

For two years, Xavier Paulus taught the Black-Scholes options pricing model to bachelor’s students at ICHEC Brussels Management School. His day job at the time was cybersecurity consulting. He had started as a WebSphere developer at ING, spending nearly eight years designing the bank’s Java web application platform before becoming an IT architect there. After security engineering work at BNP Paribas Fortis and more than three years at EY advising financial market infrastructure firms on identity and access management, he consulted for SWIFT on insider threat and extreme risk assessment. Paulus joined Solvay in 2020 as a cybersecurity advisor, built its 24/7 group security operations center as head of cyber security operations, and became Group CISO in July 2023. He built an independent cybersecurity function covering IT and OT during a large corporate carve-out, and he now leads cyber risk governance at executive committee level, including NIS2 readiness. He also taught cybersecurity specialization courses at HE2B for five years.

Olivier Verack – CISO, UCB

Olivier Verack spent his first decade in hands-on infrastructure. He ran IT at LabCorp Clinical Trials in Mechelen for nearly six years and later managed networks across five countries for Egemin. After identity and access management consulting, he moved into risk advisory at Ascure and then spent nearly five years as a senior manager at PwC in Brussels. He briefly served as managing partner at Toreon before founding his own firm, ZEF Consulting. As a freelancer he led the Cyber and Information Security Office for the Belgian railways through Ypto, then worked as an enterprise security architect for the Federal Public Service Justice. He also founded Securiacs, an industrial security advisory firm. Verack joined UCB in 2023 as an industrial cybersecurity architect, became head of enterprise security architecture in June 2025, and was named CISO in July 2026.

Dirk Beynaerts – CISO, Colruyt Group

Dirk Beynaerts has worked in IT since 1988, starting as a system engineer at SBB Accountants & Advisors. He ran IT infrastructure and operations at Acerta for seven years, supporting 1,100 users across 23 locations on a budget above €14 million. Most of the next 15 years were spent building security services businesses. At Verizon he rose to managing director for EMEA security and IT consulting, at one point leading 200 security professionals across more than ten countries. At IBM he ran the security services business for the Benelux region and later led delivery for IBM Security Services across Europe, the Middle East, and Africa. Beynaerts moved to the customer side in June 2023 as CISO of Colruyt Group, where he heads the CISO office and the governance, risk, and compliance function. He sits on Evanta’s Benelux CISO Governing Body and the advisory board of Pointury.

Koen De Maere – CISO, KU Leuven

Koen De Maere ran a small entertainment company, bemydj.be, while starting his IT career in service and project management consulting. He joined BASF in 2009 and stayed nearly 17 years. There he managed IT services, then information security, implementing an ISO 27001-certified management system in Antwerp, and later served as data protection officer leading the GDPR program for BASF’s Belgian entities. He then ran BASF’s global data protection management framework from Ludwigshafen and finished as divisional data office and AI lead for legal, compliance, and insurance. Alongside BASF, De Maere spent 11 years researching IT governance and digital strategy at the University of Antwerp and taught an MBA course on AI governance and ethics in Switzerland. He served on the board of ISACA’s Belgium chapter and its EU Advocacy Task Force. He became CISO of KU Leuven in March 2026.

Security Leaders Who Also Teach

What sets this group apart is how many of them split their time between running security and explaining it. Paulus taught options pricing and secure coding, De Maere researched IT governance for over a decade and taught AI ethics to MBA students, and Muchin brings her expertise to the audit committees of the Flemish government. Beynaerts spent years building security services teams across EMEA, and Verack moved between consulting, freelance CISO work, and founding his own firms before joining UCB. Belgium sits at the center of European regulation, and its security leaders appear to treat knowledge-sharing as part of the job rather than a side project.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.