What's up
Security & safety for systems with no right to fail
Resilience used to be an engineering concern but is now a public policy with a number attached. When allied countries committed to five percent of GDP on defense by 2035, one and a half of those went to critical infrastructure and resilience rather than to weapons. That line did not exist a few years ago.
Sovereignty followed the same path. Where is industrial data computed, who can update a machine remotely, whether a plant keeps running when a supplier or a network fails. These have become industrial questions.
Safety keeps people safe from the machine whereas security keeps the machine safe from people. For a long time, those were two different jobs held by two different teams, and that worked. That is no longer the case today, because a machine that can be reached from the outside can be made to hurt someone.
In Charleroi that shift is not an abstract debate. Since April 2024, the Belgian Cyber Force has had a foothold inside A6K. It was the first time the national Cyber Command established itself in a civilian environment.
Cyber capability in our community
Cybersecurity is no longer a specialist subject, it is becoming a condition of doing business. Most companies discover it through a customer questionnaire rather than through a legal text, and from September manufacturers have to report an exploited vulnerability within a day. The direction is set and it will not reverse.
What matters is having somewhere to go. CETIC, an applied research centre working on software engineering, cybersecurity and cyber physical systems, and part of our community, tests industrial systems the way an attacker would, and has run evaluations at the level of scrutiny normally reserved for classified environments. That capability sits a few doors away from the companies that need it.
Safety was never a software problem, until now
In an industrial hub, safety is the older discipline. Alstom employs more than 1400 people here and designed ETCS, the system that keeps European trains from meeting each other. That work assumes a machine can fail on its own, and engineers it so that failure stays harmless.
Those same machines are now connected. From 2027, European law puts both disciplines in the same file, and there is no CE marking left for a machine without a cybersecurity case. Here, Alstom and CETIC have been having that conversation for a while already.
Defense asks for both at once
Defense is where the two disciplines merged first, because it is the only customer that demands both on the same object. A drone must not fall on anyone and must not be taken over. A firmware update on a vehicle fleet has to be secured without invalidating the safety case.
We approach defense as a field of concrete collaboration rather than as a market to comment on. Through the Cyber Defense Factory we host the first official implantation of the Belgian Cyber Force within a civilian environment, where military expertise and civilian engineering work on the same problem, from an identified operational need to a deployable technology. The STRIKE-IT call, run with the Royal Higher Institute for Defence, selected twelve projects, half of them working from Charleroi.
That is also why the fifth component of Belgian Defence, covering more than forty professions and aiming for a workforce that is two thirds civilian, chose to sit among engineers rather than behind a fence.
The demand behind it is not a one off. Belgium has committed 34 billion euros of equipment investment by 2035, with more than three and a half billion for AI and cyber, and Wallonia already counts more than 140 companies working for these markets. Two kilometers from here, thirty hectares of former steelworks on the Porte Ouest site are becoming Quartier du Futur, opening in 2032 for around 1500 military and civilian personnel, cyber and AI capabilities included.
The challenge is no longer only to invent but is to structure, test, industrialize and deploy faster, while keeping strategic autonomy.
Proof travels through companies
Calyos, twenty people in the Jumet industrial zone, builds fully passive two phase cooling, no pump, no water, no maintenance. The company we supported for eighteen months was selected in 2026 for the NATO DIANA cohort, 150 companies out of 3680 applications.
Its CEO, Antoine de Ryckel, puts the whole subject in one sentence. "Our system does not break down. Even in the event of a cyberattack."
That principle travels further than cooling. A sensor that carries no firmware and exposes no network port has nothing to attack, and still reports what a structure is doing. A new demonstrator built on exactly that idea has just been installed in our building, and we will come back to it shortly.
Sovereignty needs machines, not speeches
Sovereignty survives well in a speech and badly in practice. It becomes real when you can point at the machine.
Moonshot, a Proximus initiative we partner on and host here, is about building a distributed edge cloud in Belgium so that industrial data can be processed close to where it is produced rather than somewhere else entirely. Lyra and Hyperion, the ULB clusters inaugurated here in January, were designed for full data sovereignty. Lucia, the Walloon supercomputer operated by Cenaero on this site, reserves part of its compute time for companies. The 5G lab, the first in Wallonia, was built so that industrial players could test private networks they actually control. And Aerospacelab is building in Charleroi what will be Europe's largest satellite factory, because a continent that wants its own eyes in orbit has to be able to build them.
None of these is a security product. Together they change what a company still holds in its own hands when something goes wrong.
Building a system that cannot afford to fail? Connect with the expertise and technologies to make it happen.