From awareness to action: SME Cyber Security

Despite their economic importance Dutch SMEs lag behind in implementing cybersecurity. To strengthen cyber resilience of SMEs in the region, THUAS, Connect2Trust, and the municipality of The Hague launched a platform in 2025 to facilitate collaboration between SMEs from various sectors. A cyber maturity survey was conducted to serve as a baseline measurement, showing three […]

ENISA Scales EU Vulnerability Services for Resilience

As the Cyber Resilience Act’s reporting obligations begin to apply and ENISA rolls out the Single Reporting Platform, this session offers a timely deep dive into vulnerability handling and reporting in Europe. It will explore how ENISA is scaling its EU Vulnerability Services, including the European Vulnerability Database (EUVD), support to Member States’ coordinated vulnerability […]

CISO survey insights: trends & priorities for 2026

This presentation draws on a 2026 survey and interview series with 27 cybersecurity leaders in the Netherlands to show how CISO priorities are evolving under pressure from regulation, AI, operational complexity, and growing reliance on cloud and third parties. The findings reveal a shift away from traditional control-focused security toward stronger auditability, resilience, monitoring maturity, […]

The upcoming Cyber Security Assessment Netherlands 2026

The Cybersecurity Assessment Netherlands (CSAN, CSBN in Dutch) is published annually. It provides insight into digital threats, national security interests, and resilience. The report is produced by the National Coordinator for Counterterrorism and Security (NCTV), in cooperation with public, private, and academic partners. This Talk about the CSAN 2026 will highlight the key findings of […]

Cybersecurity Made in Europe: Ambition without an industry?

Europe’s cybersecurity runs almost entirely on American technology. From endpoint detection and cloud security to threat intelligence and vulnerability databases, American companies dominate every layer of the cybersecurity stack. European providers remain predominantly national or regional players and often offer services rather than technology. No European company can provide the pan-European coverage that CrowdStrike, Palo […]

Police Hack and Pass-the-Cookie: No Crumbs, Full Access

In September 2024, The Netherlands police faced a data breach in which the Russian state-supported threat actor Laundy Bear gained access to the corporate address book. This presentation gives insight into how the attack occurred, how the High Tech Crime Team and the Public Prosecution Service responded and lessons learned.

Squaring the Circle: Lawful Access to Encrypted Data while preserving Cyber Security

In 2025, the EU Commission presented a roadmap for effective and lawful access to data for law enforcement. This presentation will cover the conflicting needs of law enforcement and the cyber security community, explain why old wiretapping regulations cannot easily be transferred to the Internet age, and survey the solution space. The focus will be […]

Collaborating in the Cyber Resilience Network &Cyclotron

The Netherlands is taking a major step forward in public–private cyber resilience through the development of the Cyber Resilience Network (Cyberweerbaarheidsnetwerk/CWN) and the Cyclotron collaboration. Through these initiatives, we are jointly building a new, trusted ecosystem that structurally strengthens public–private cooperation. This session presents practical examples of types of collaboration, the results thereof, and lessons […]

Difficulties of non-intrusive scanning as NCSC

The NCSC performs scanning to identify vulnerabile and compromised devices and warns their owners in order for them to take appropriate measures. The NIS2 directive and its implementation in the “Cyberbeveiligingswet” tasks the NCSC with “proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities”. There is however no legal […]

The good, the bad, and STIX/TAXII

Standards are essential; without them, the internet would not exist. In open source, organisations like the Linux Foundation drive such standards, as seen with OpenTelemetry, now widely adopted despite early scepticism. In cybersecurity, STIX/TAXII plays a similar role. Though often criticised, it remains vital, particularly for cyber threat intelligence and detection rule sharing. Its value […]