Specialist in digital network connections
Customization & installation available upon request
Items available from stock and on a back-to-back basis
Order today, delivered tomorrow

DINL warns of sabotage of fiber-optic cables in the North Sea  


Greater redundancy and a move away from monoculture 

In the Netherlands, there is still a monoculture when it comes to internet networks and fiber-optic cables. This means that many networks lack backup cables or systems in the event of a failure or sabotage. We still see this frequently in the digital sector in our country. This monoculture now poses significant financial and digital risks. If undersea cables are sabotaged, essential networks could simply go down because they have no backup. This problem, of course, became very clear some time ago when airports and hospitals were shut down due to an update to Microsoft’s antivirus program.  

How can you increase redundancy?

The question now, of course, is: how do we ensure greater redundancy in the Netherlands? According to political advisor Marijn van Vliet, we would do well to follow Germany’s example. There, the Center for Digital Sovereignty (ZenDiS) works to make the government less vulnerable. This initiative also promotes greater use of open-source software. Thanks to ZenDiS, the German government has an exit strategy—something we unfortunately lack in our country right now. Thanks to this initiative, public institutions can always fall back on an alternative. This makes institutions more independent and therefore better secured!

Surely that’s possible in the Netherlands too?

Yes, that should certainly be possible in the Netherlands as well. All open-source software is integrated, and then maintenance and patching are outsourced to a service provider, while hosting is handled by a cloud provider. The Ministry of the Interior and Kingdom Relations must address this in collaboration with the Ministry of Economic Affairs. But in addition to this problem, we also have the vulnerable undersea cables near the Netherlands Antilles. In this area, there are only two fiber-optic cable routes, both of which belong to the same provider. If something goes wrong here, the entire Caribbean region goes down. So, in fact, an additional cable needs to be laid here. The Ministry of Defense is currently in talks with DINL regarding the physical security of the undersea cables.


Why was the ECCO established?  

The establishment of ECCO was part of the settlement between Cispe and Microsoft in July. This settlement resolved an antitrust complaint filed with the European Commission against Microsoft. The company was accused of engaging in unfair competition. This vendor increasingly sells products such as Microsoft 365 and Windows alongside its own Azure Cloud and other services. As a result, other cloud providers with their own SaaS services are being sidelined. End customers who purchase the software ultimately suffer from this as well. In addition to co-founding the ECCO, the company paid compensation to Cispe and promised to develop an improved version of its Azure Stack HCI product for European cloud providers that is comparable to their own cloud solutions.  

This is how ECCO monitors European software suppliers!

The ECCO will monitor European software vendors for unfair practices, but initially its focus will be on ensuring that Microsoft adheres to the agreements. Members of the watchdog are currently testing Microsoft’s modifications. A meeting with the company’s technical leadership will take place in Redmond, Washington, in December, after which a progress report is expected. Further evaluations of progress regarding the agreements with the company will follow in February and March. The ECCO will also apply this approach to other software suppliers in Europe, thereby keeping the cloud market fair and open to competition! 

Independent audit by ECCO 

ECCO is therefore a completely independent organization, managed by the CISPE secretariat and operating under an independent governance model. A group of French companies and organizations under the name Cigref and a Belgian association of CIOs and digital technology leaders under the name Beltug will act as observers on behalf of consumers. This ensures that ECCO’s assessments and statements are 100% independent and based on the truth.   


1. Dora: for the financial sector 

DORA stands for the Digital Operational Resilience Act. This law primarily targets the financial sector. The European regulation is intended to strengthen the operational resilience of financial institutions. This sector is, of course, already quite strictly regulated, but new laws continue to be introduced, particularly from the EU. The law applies not only to the financial sector but also to third-party IT suppliers, especially when it comes to cloud computing that supports critical functions.  

2. NIS2: One of the most important European laws on cybersecurity!

The NIS 2 Directive is primarily focused on improving the digital and economic resilience of European member states. There are eighteen sectors that will be affected by the NIS-2 Directive, and it primarily focuses on measures related to cybersecurity risk management and the reporting of incidents in this area. Companies sometimes tend not to report cybersecurity incidents because they fear it could damage their reputation. However, reporting incidents is actually a crucial source of data for preventing such incidents in the future! 

3. EU Cloud Certification Scheme  

The EU Cloud Certification Scheme is a framework for certifying the digital security of cloud service providers. The EUCS is part of the Cybersecurity Act (CSA) of 2019. The schemes used under this directive are not mandatory, but there is a strong likelihood that they will become mandatory in the future.

4. Cyber Resilience Act: One of the European laws on product cybersecurity

This EU regulation primarily focuses on hardware and software products. It therefore does not concern the digital resilience of organizations, but rather the products that organizations use. The Cyber Resilience Act sets requirements for the cybersecurity of digital products sold in the EU, such as software and IoT devices. These requirements are mandatory, so all products must comply with them—no exceptions. All products that are directly or indirectly connected to a network are subject to this regulation! 


Kaspersky Security Network  

The figures illustrating this come from the Kaspersky Security Network list. This list has been maintained since 2013, and this year marks the first time the Netherlands has topped the list. Between July and September 2024, over 116 million cyber incidents occurred via servers in the United States. Germany follows in third place with 13 million attacks. This gives the U.S. a 25% share of all cyberattacks worldwide, while Germany accounts for just 3%. Compare that to the Netherlands, whose servers were the target of 41% of all cyberattacks worldwide in the third quarter of this year.  

Increase in cyber incidents in the Netherlands since 2022 

According to the Kaspersky Security Network report, the number of cyber incidents on Dutch servers suddenly surged in early 2022. At that time, the Netherlands ranked third on the global list of server abuse. It didn’t take long for our country to rise to second place, with only the United States ahead of it in terms of the high number of cyberattacks. The Netherlands remained in second place through the second quarter of 2024, but this changed in the last quarter. Although the number of attacks in our country did drop somewhat after mid-2022, we still ranked first in Q3, even ahead of the U.S.  

The Netherlands has become a popular target for cybercriminals  

It seems, then, that our country has suddenly become a haven for cybercriminals. When we compare the Netherlands’ share in the third quarter to that of three years ago, the difference is 36%. In 2021, it was 5%, and this year it’s 41%. The cybersecurity expert can’t explain why this increase is so massive. In 2023, the number of cyberattacks on Dutch servers dropped by more than 100 million. But unfortunately, there seems to be another rise in the number of incidents this year, keeping us in first place.  

Where does this data come from?  

Kaspersky Security Network compiles this list using data it receives in response to cyberattacks. When one of the cybersecurity provider’s customers is attacked online, they record the source of that attack. A WebAntivirus component then pinpoints the location of the threat. Their analysis focuses on malware samples, which are often found in multiple countries worldwide. One explanation for the Netherlands’ top ranking is our position within transatlantic internet traffic. A large portion of this traffic passes through the Amsterdam Internet Exchange. Our robust infrastructure is highly attractive to cybercriminals, as it allows them to easily reach many companies all over the world!


Ransomware remains one of the biggest cyber threats  

Ransomware has been a major threat for years, and it remains a significant risk today. The number of cases in which people fall victim to ransomware hasn’t necessarily increased, but cybercriminals have found new ways to scam people with it. Criminals combine ransomware with data exfiltration and then threaten to make sensitive information public. For companies that work with sensitive data, it is now therefore especially important to ensure their systems are properly secured. Hackers are also increasingly exploiting legitimate tools within systems to stay under the radar. This makes it increasingly difficult to detect them.

Social engineering is becoming more inventive 

Social engineering also remains a common threat. Phishing is one of the most common forms of social engineering. Businesses, in particular, are increasingly affected by this, as fake emails are becoming harder and harder to distinguish from genuine ones. Today, cybercriminals use AI to make these emails look as real as possible. Through these emails, they try to gain access to company data or payments. As a business, it’s therefore wise to keep your staff vigilant about filtering out fake emails. This way, you can avoid a lot of trouble! 

Malware is becoming increasingly difficult to detect 

Of course, malware isn’t exactly a new phenomenon in the world of cybercrime. However, it’s becoming increasingly difficult to detect, which naturally makes it more dangerous. Advanced cybercriminals are now even offering malware-as-a-service. This allows criminals with less technical expertise to easily launch attacks on companies. Malware is also becoming increasingly sophisticated and thus better at evading detection. To achieve this, polymorphic techniques are used, which allow the malware to change its form to bypass antivirus software.  

The manipulation of information using AI is one of the biggest new cyber threats

Unfortunately, AI has opened up a lot of opportunities for cybercriminals. It has become easier to manipulate and deceive people by manipulating information with the help of artificial intelligence. For example, it is possible to mimic someone’s voice using AI. If you think you’re on the phone with a family member or close friend asking for money, it could just as easily be a cybercriminal. In addition, a lot of misinformation is being spread to manipulate people’s views and ways of thinking using AI. Do you receive a suspicious call from someone you think you know? Be vigilant and don’t jump to conclusions too quickly! 

DDoS attacks are a nightmare for businesses  

A DDoS attack has always been something every company fears, but this risk has now become much greater than it ever was. It is the most frequently reported threat, even more so than ransomware. Here, too, it is striking that cybercriminals are increasingly offering to carry out DDoS attacks for others in exchange for payment. This significantly increases the risk of large-scale attacks. As a result, DDoS attacks are currently one of the biggest cyber threats

Data breaches and attacks on supply chains  

Finally, the threat of data breaches is increasing dramatically this year. This is because attackers are taking a much more targeted approach. Attackers also often put more pressure on companies, for example by threatening to make certain data public. As a result, companies are less likely to report a cyberattack or data breach to the police. Cybercriminals are also increasingly choosing to attack companies through their supply chains. They do this, for example, by spoofing emails from a supplier, which immediately gives them access to that supplier’s entire network.  

Conclusion: Be aware of the biggest cyber threats right now

Over the past year, therefore, we haven’t really seen the emergence of new forms of cybercrime. Instead, existing threats have grown more severe due to new techniques and the refinement of existing ones. As a result, attacks are harder to detect, and threats are also more difficult to identify. Given the rapid changes in the field of cybercrime, it is important for every company to stay informed about current threats and take appropriate measures. You can never be too careful when it comes to today’s biggest cyber threats! 


Warning from the AP 

In its “Government Sector Policy,” the Dutch Data Protection Authority (AP) highlights this risk currently faced by government agencies. This risk involves not only the danger of being overly dependent on a service provider, but also all developments taking place within the government regarding privacy. To the public, it often seems that government agencies are still struggling to comply with privacy legislation. They are occasionally reprimanded by the AP for this. One of the concerns is that when the AP discovers vulnerabilities in government agencies’ systems, it often takes too long to address them. Reasons for this include outdated IT systems, a lack of knowledge, insufficient prioritization, or even a combination of all these factors. As a result, it sometimes takes far too long for data breaches or similar issues to be resolved.  

The government lacks a great deal of knowledge  

The biggest problem, therefore, is actually a significant knowledge gap within government agencies. As a result, it takes too long for outdated systems to be replaced and for problems to be resolved. Knowledge of privacy law is also often insufficient, particularly among executives. When GDPR violations occur, they are often the result of a lack of knowledge. The Dutch Data Protection Authority (AP) recently expressed concerns about GDPR compliance at the Tax and Customs Administration. For this reason, the authority will be scrutinizing this agency closely in the coming period.  

The Impact of Generative AI on GDPR Compliance 

Unfortunately, there are still many government agencies that believe they don’t need to fully understand privacy issues. The Dutch Data Protection Authority (AP) is now deeply concerned about the impact generative AI will have on government compliance with the GDPR. Many municipalities have already indicated that they intend to experiment with this technology, but this could have significant consequences—especially since many municipalities fail to conduct proper research before proceeding with such experiments.