Sense of urgency needed in fighting security vulnerabilities

Cyber threats were recently in the top three concerns among the Dutch, according to research by the Clingendael Institute. Not surprisingly, because that threat is regularly accentuated, for example by recent reports that thousands of computer networks in the Netherlands show vulnerabilities that should have been fixed long ago. The perception is that accidents are waiting to happen.

There is undeniably a serious and troubling problem that affects us all. But instead of getting caught up in fear and panic, it is better to focus on structural solutions. Fortunately, these are available, but awareness of them among companies and organizations still leaves much to be desired. And so does awareness that active involvement on their part is crucial to keeping our systems safe.

Security risks and economic damage

At the heart of the problem is that vulnerable systems pose an economic risk, as well as a threat to our security. Both cybercriminals and state actors are targeting Dutch systems, making robust cyber resilience vital. Problems at non-vital companies resulting from vulnerabilities can also affect vital and critical companies (energy, telecom, etc.), so the social impact can be significant. So the least any business and organization can do is to be informed about vulnerabilities and threats and act on that information.

But that can only be done if those vulnerabilities are known. Extra annoying is that many such leaks are often unknown and thus invisible. If you are the first to know about such a leak, you can exploit it. This is why both cyber criminals and so-called ethical hackers look for them. One group to abuse them, the other, like the volunteers of the Dutch Institute for Vulnerability Disclosure (DIVD), to report them so they can be closed.

Notification and code of conduct

Much is being done in the Netherlands to find vulnerabilities and notify parties who are affected. This involves close cooperation between sectoral initiatives and the central government, particularly the Ministries of Justice & Security and Economic Affairs and Climate. Real strides have been made in this area in recent years. Many more organizations and companies are now notified by reporters of vulnerabilities than a few years ago.

Another example of an initiative to share this kind of information, but with a specific target group where the impact of security breaches and incidents is high, is the Clean Networks platform. This was created thanks to a broad collaboration of government, the Dutch Internet sector and nonprofit initiatives to combat Internet abuse in networks of ISPs and hosters. Detecting vulnerabilities, notifying affected parties and fixing those vulnerabilities is brought together in this initiative in a technical solution. This automatically sends appropriate notifications with suggested fixes and prioritization to affected parties. When incidents occur, help and support is available. For example, Clean Networks acts as CSIRT (Computer Security Incident Response Team) for Dutch ISPs and the hosting industry.

Participants also commit to a code of conduct, so that they too bear responsibility for making and keeping their systems clean. A seal of approval is being developed to show who is making active efforts to clean up nuisances, and who is less diligent about those risks. Co-funded by the European Union, the project is leading the way internationally on how to address these issues.

The National Cyber Security Center (NCSC) and the Digital Trust Center (DTC) also provide notifications for critical & critical infrastructure and for SMEs, respectively. There are also sectoral initiatives, for example for the Port of Rotterdam and for cybersecurity companies. The House of Representatives recently passed the Promoting Digital Resilience for Business Act (also known as the DTC Act), which regulates information sharing about threats, vulnerabilities and incidents with the wider business community from the DTC.

In short, organizations that want it can be informed about vulnerabilities and security breaches (as soon as) that are known. Yet we can read almost daily about successful hacks and the misuse of known security vulnerabilities. How is that possible?

Capitalizing on knowledge

What is still missing is a broader awareness within organizations that vulnerabilities can occur anywhere and that action must be taken. The era when these risks could be ignored without major consequences is long behind us, but that awareness is not yet in everyone’s mind.Therefore, it is now high time for companies and organizations to take a proactive approach to finding and combating vulnerabilities.Every company or organization has a responsibility to close vulnerabilities.

To increase resilience, Dutch companies and organizations must therefore act more decisively. Trade associations have a role to play here by informing their members and supporters (better) about their responsibilities, the risks they face and how they can reduce them.

In addition, hotlines, reporters themselves and the government have an important task to make the importance of reporting vulnerabilities and taking action even clearer.

For individual companies and organizations, it is necessary to put information security and actively plugging vulnerabilities high on the agenda, if this is not already the case.

And for all parties involved, cooperation remains key, both in terms of sharing information and raising awareness among companies and organizations that acting appropriately on information about vulnerabilities and abuse is critical.

By working together and leveraging available knowledge and resources, we can increase resilience to security vulnerabilities. Fortunately, a wealth of knowledge is available and both government and sectoral initiatives are ready to help. The time for action is now.

This column was written by NBIP general director Octavia de Weerdt and was first published with the Dutch publication AG Connect.

Wil je meer informatie of je abonneren op onze nieuwsbrief?

Platform- and supplier-independent Cloud with Haven

Thursday, 27 November – 1:50 p.m. – 2:30 p.m.

Haven is an open solution for platform- and supplier-independent Cloud services. Haven is a building block of the pGDI and the NDS. Haven offers agnostic configuration of Cloud technology and provides organisations with a feasible exit plan. Expect an inspiring story about the practice of ecosystem-driven collaboration, in which we use the power of digitisation for the benefit of society.

Highlights:

  • Haven+
  • Ecosystem-driven collaboration
  • Platform- and supplier-independent cloud services
  • Data sovereignty

About Jacco Brouwer

Jacco Brouwer works for the Association of Netherlands Municipalities as Cloud Policy Coordinator and represents municipal interests in the NDS implementation programme on Cloud. From the Innovation Knowledge Centre at VNG, Jacco is the initiator of the public Incubator GROEI, through which VNG guides municipal collaboration and innovations based on a start-up philosophy in scaling up to broad and collective use among municipalities and fellow authorities.

Jacqueline van de Werken is bijna 10 jaar actief als global general counsel bij Leaseweb, na een loopbaan in de advocatuur en actief te zijn geweest in legal & regulatory affairs bij buitenlandse telecom/ datacom aanbieders.

Sinds enige tijd is Jacqueline ook board member & secretaris van brancheorganisatie Dutch Cloud Community. Als president/chair bij Cloud Infrastructure Service Providers Europe richt ze zich ook op het behartigen van regulatory belangen van de IAAS cloud sector.

Woensdag 26 november 

Van vrijwillig naar verplicht: de nieuwe werkelijkheid van regelgeving voor providers

Interactieve sessie

11:15 – 12:00 uur

Ir. Bas Dunnebier EngD

Bas Dunnebier is Chief Science and Technology Officer (CSTO) bij de Algemene Inlichtingen- en Veiligheidsdienst (AIVD). De CSTO speelt in op de kansen en uitdagingen die technologische en wetenschappelijke innovatie met zich meebrengen, onder meer voor de offensieve en defensieve taken van de dienst.

Eerder vervulde Dunnebier verschillende andere functies binnen de AIVD, waaronder die van hoofd Unit Weerbaarheid. Hij heeft daardoor een brede expertise ontwikkeld op het gebied van (cyber)weerbaarheid, inlichtingen, en technologieën zoals AI, quantum en cryptologie. Hij studeerde Toegepaste Wiskunde aan de Universiteit Twente, en Informatie- en Communicatietechnologie aan de Technische Universiteit Eindhoven. Voordat Dunnebier bij de AIVD kwam werken, werkte hij onder meer bij Thales, TNO en Technolution.

Het huidige dreigingsbeeld volgens de AIVD: wat nu te doen?

Woensdag 26 november 
14:00 – 14:35
Parkzaal: Wet- en Weerbaarheid

During his presentation, Dr. Alberto P. Martí will provide an update on the European IPCEI Cloud Infrastructure and Services (CIS) project.

Thursday, 27 November

3:00 p.m. – 3:45 p.m.

Parkzaal: Towards digital autonomy

During NBIP NEXT, René will share more about the implementation of the eEvidence legislation that will come into force for internet service providers on 18 August 2026.

Wednesday 26 November

3:00 p.m. – 3:35 p.m.

Parkzaal: Track Law & Resilience

During NBIP NEXT, Johan will give a presentation as part of the DDoS Mitigation track on how to use a WAF to mitigate layer 7 attacks.

Wednesday, 26 November
1:15 p.m. – 1:50 p.m.
Fonteinzaal: Collaborative DDoS mitigation track (ENGLISH)

Dr. Cristina Caffarra is one of the driving forces behind EuroStack. This movement, which has the ear of politicians and policymakers in Europe, is campaigning for more investment in European technology, based on the belief that this is the only path to digital autonomy.

Caffarra is a competition expert and knows the world of big tech companies from the inside. She has made important contributions to competition investigations into mergers and antitrust cases for the European Commission. Caffarra does not mince her words and tells it like it is: we must work together to give shape to European digital autonomy as quickly as possible. At NBIP NEXT, she will share her vision during an inspiring keynote speech, followed by an opportunity for discussion.

Thursday 27 November
1:15 p.m. – 1:50 p.m.
Parkzaal: Towards digital autonomy