| ]

or Dunning-Kruger doesn't self-correct anymore.

> TL;DR. The Dunning-Kruger effect, that is, the difference between what people think they can do
and what they can actually do, used to close and self corrects with experience. My hypothesis that I introduce in this post is that AI keeps it open: it increases confidence and splits real capability into "with the tool" and "without the tool." For companies, that turns intrinsic capability from a productivity question into a governance one, and it is the capability that quietly erodes.

  1. The ending that used to be guaranteed (more or less)
  2. About the Dunning Kruger curve
  3. What AI changes
  4. The Gap that no longer closes
  5. Does it really matter?
  6. What it means for companies

1. The ending that used to be guaranteed (more or less)

Everyone knowns "Mount Stupid". Whether it’s the co-worker who’s researched a single online thread and wants to completely upend the operations of the team, or the new hire who’s watched a tutorial video and is convinced that everyone was doing everything incorrectly, we’ve all been there at one point or another.

The great thing about Dunning-Kruger is that there really is an ending to it. In the battle of experience vs. confidence, experience always wins. The difference between what you think you can do and what you can do is going to close on its own. There’s a simple, and really quite boring iteration that explains what happens: you do it, you break things, you mess up, but you figure it out. Until the day that your perception aligns with reality, the reality of the situation is going to keep the lights on.

Figure 1. The classic picture. Perceived capability runs ahead, crashes, then converges on actual capability. The gap closes.[Thierry ZOLLER]

Figure 1. The classic picture. Perceived capability runs ahead, crashes, then converges on actual capability. The gap closes.[Thierry ZOLLER]

2. About the Dunning-Kruger curve

Here's the thing: the chart that everyone think they know is actually not what it seems. The famous Dunning-Kruger curve, with its peak of confidence and valley of despair, didn't actually come from Dunning and Kruger. You won't find it in their 1999 paper, or in any of Dunning's later work. So, where did it come from? It started spreading like wildfire through management training and the internet in the mid-2000s. But the real study is actually pretty different. It compared how people thought they'd do with how they actually scored, and it was divided into four groups. The interesting thing is, the line on the chart just keeps going up - it doesn't peak and then drop like everyone thinks.

There's a lot of debate about this effect, and experts can't seem to agree on what it really means. Some researchers think it's just a statistical illusion, a combination of people naturally rating themselves higher than average and the phenomenon of regression to the mean. They point to studies that suggest this pattern is just a mirage, not really telling us anything significant. In my opinion, the key takeaway is that the pattern itself is real - that's what matters most to my hypothesis. What it actually signifies, however, is still up for debate.

I'm using this well-known chart on purpose, because it's familiar to everyone, not because it's the 1999 data. I guess, the point I'm making doesn't rely on the curve being entirely accurate. It only needs one thing that nobody disagrees with: people are not good at judging their own abilities, and the difference between what they can actually do and what they think they can do is significant. This gap is made even wider by a tool that affects how we perceive ourselves.

Belgium published first, France went deeper. Belgium's CCB released CyFun well before the October 2024 NIS 2 transposition deadline, built on NIST CSF and officially mapped to ISO 27001/27002. France's ANSSI published ReCyF, but as of March 2026 the underlying legislation still has not passed - making it a technically superior but legally unenforceable framework.Bottom line: ISO 27001-certified organisations in Belgium are largely compliant with a manageable gap list. The same organisations in France still have significant work ahead - and no hard deadline yet to do it by.

Table of Contents

  1. Introduction
  2. Belgium - The Head Start (4 Level Architecture, Control Counts, ISO27002 clusters, What are key measure and why do they matter, self-assessment)
  3. France - The Thorough Approach (The objective and means architecture, still waiting for the law, ISO Alignement ANSSIs own assessment
  4. ISO27002 Mapping as a common Anchor
  5. The Divergences
  6. Practical Impliaction

Part I: Introduction - One Directive, Two Answers

When the EU adopted NIS 2 (Directive 2022/2555) in December 2022, it set a clear expectation: member states had until October 17, 2024 to transpose its requirements into national law. What followed, at least across the Franco-Belgian border, is a study in contrasting regulatory cultures, institutional histories, and practical philosophies.

NIS 2 expanded covered sectors from 7 to 18, lowered size thresholds, made supply chain security and multi-factor authentication explicit obligations, and - most significantly - introduced Article 21's detailed list of required risk management measures. What the directive deliberately does not do is specify how each measure should be implemented. That granularity was left to member states, producing genuine policy diversity: two technically credible frameworks that are compatible at the technical level but structurally different in regulatory philosophy, timing, and practical demands.

The timeline below tells the story at a glance. Belgium formalised an existing, mature framework and published its official cross-framework mapping nine months before the deadline. France is still working through its legislative process 18 months after that same deadline.

Figure 1 : NIS2 Transposition timeline. Belgium met the Octobre 2024 deadline, France Transposing law remains a bill of March 2026.


Introduction

For years, we’ve all heard it: “Cyber threats are on the rise.” But how much is hype, and how much is reality ?

According to the IRIS 2025 report by Cyentia, it’s not hype. Since 2008, the number of publicly reported cyber incidents has increased by over 650%, climbing from 450 to nearly 3,000 per quarter.

But here’s the nuance that matters: this rise isn’t just about more attacks. It’s also about how attackers evolve, how we detect threats, and how regulation drives transparency. From the stealthy era of APTs to the ransomware boom and the pandemic’s IT transformation, every major spike has a cause.

As risk managers and CISOs, this isn’t just trivia-it’s critical context. Understanding these shifts helps us future-proof our strategies, rather than plan for a past that no longer exists.