Greater redundancy and a move away from monoculture
In the Netherlands, there is still a monoculture when it comes to internet networks and fiber-optic cables. This means that many networks lack backup cables or systems in the event of a failure or sabotage. We still see this frequently in the digital sector in our country. This monoculture now poses significant financial and digital risks. If undersea cables are sabotaged, essential networks could simply go down because they have no backup. This problem, of course, became very clear some time ago when airports and hospitals were shut down due to an update to Microsoft’s antivirus program.
How can you increase redundancy?
The question now, of course, is: how do we ensure greater redundancy in the Netherlands? According to political advisor Marijn van Vliet, we would do well to follow Germany’s example. There, the Center for Digital Sovereignty (ZenDiS) works to make the government less vulnerable. This initiative also promotes greater use of open-source software. Thanks to ZenDiS, the German government has an exit strategy—something we unfortunately lack in our country right now. Thanks to this initiative, public institutions can always fall back on an alternative. This makes institutions more independent and therefore better secured!
Surely that’s possible in the Netherlands too?
Yes, that should certainly be possible in the Netherlands as well. All open-source software is integrated, and then maintenance and patching are outsourced to a service provider, while hosting is handled by a cloud provider. The Ministry of the Interior and Kingdom Relations must address this in collaboration with the Ministry of Economic Affairs. But in addition to this problem, we also have the vulnerable undersea cables near the Netherlands Antilles. In this area, there are only two fiber-optic cable routes, both of which belong to the same provider. If something goes wrong here, the entire Caribbean region goes down. So, in fact, an additional cable needs to be laid here. The Ministry of Defense is currently in talks with DINL regarding the physical security of the undersea cables.
What does ChatGPT Search bring to the table to compete with Google?
Of course, ChatGPT has long been used to perform searches in a similar way to how we would use Google. However, its capabilities in this regard were still limited. For example, the search function did not yet provide links to external sources, and search results were displayed only as text. ChatGPT Search not only provides answers in text but also includes links to external sources relevant to your query and, where possible, even photos, images, and visual data—such as graphs or tables. This makes the application a much stronger competitor to Google than it was before.
ChatGPT Search is an AI chatbot that cites sources
So ChatGPT actually offers real added value compared to Google, just like the AI bot Perplexity. After all, you don’t just get an answer to your question, but also a full list of sources with various links, so you can verify whether the answer is actually correct. This solves a major issue people have with using ChatGPT: you can never be sure if the answer it provides is accurate or where it gets its information from. OpenAI also recently announced that it has partnered with several companies to provide up-to-date information on topics such as the weather, sports scores, locations, and the news.
When will ChatGPT Search be available to everyone?
According to OpenAI, their search feature is now ready for the general public, but when will we all be able to use ChatGPT Search? Basically, starting right now! You can set ChatGPT as your default search engine if you want, instead of Google. In the Google Chrome browser, you can install an extension for this. The search feature is coming to the ChatGPT website and all apps. If you were on the waiting list for ChatGPT Search or have a ChatGPT Plus or Team account, you can start using the new feature right away. If you have an Enterprise or Edu account, the feature will become available to you sometime in the coming weeks. As a free user, you’ll have to wait a few more months, but eventually, everyone will be able to use ChatGPT Search instead of Google if they want!
Kaspersky Security Network
The figures illustrating this come from the Kaspersky Security Network list. This list has been maintained since 2013, and this year marks the first time the Netherlands has topped the list. Between July and September 2024, over 116 million cyber incidents occurred via servers in the United States. Germany follows in third place with 13 million attacks. This gives the U.S. a 25% share of all cyberattacks worldwide, while Germany accounts for just 3%. Compare that to the Netherlands, whose servers were the target of 41% of all cyberattacks worldwide in the third quarter of this year.
Increase in cyber incidents in the Netherlands since 2022
According to the Kaspersky Security Network report, the number of cyber incidents on Dutch servers suddenly surged in early 2022. At that time, the Netherlands ranked third on the global list of server abuse. It didn’t take long for our country to rise to second place, with only the United States ahead of it in terms of the high number of cyberattacks. The Netherlands remained in second place through the second quarter of 2024, but this changed in the last quarter. Although the number of attacks in our country did drop somewhat after mid-2022, we still ranked first in Q3, even ahead of the U.S.
The Netherlands has become a popular target for cybercriminals
It seems, then, that our country has suddenly become a haven for cybercriminals. When we compare the Netherlands’ share in the third quarter to that of three years ago, the difference is 36%. In 2021, it was 5%, and this year it’s 41%. The cybersecurity expert can’t explain why this increase is so massive. In 2023, the number of cyberattacks on Dutch servers dropped by more than 100 million. But unfortunately, there seems to be another rise in the number of incidents this year, keeping us in first place.
Where does this data come from?
Kaspersky Security Network compiles this list using data it receives in response to cyberattacks. When one of the cybersecurity provider’s customers is attacked online, they record the source of that attack. A WebAntivirus component then pinpoints the location of the threat. Their analysis focuses on malware samples, which are often found in multiple countries worldwide. One explanation for the Netherlands’ top ranking is our position within transatlantic internet traffic. A large portion of this traffic passes through the Amsterdam Internet Exchange. Our robust infrastructure is highly attractive to cybercriminals, as it allows them to easily reach many companies all over the world!
Ransomware remains one of the biggest cyber threats
Ransomware has been a major threat for years, and it remains a significant risk today. The number of cases in which people fall victim to ransomware hasn’t necessarily increased, but cybercriminals have found new ways to scam people with it. Criminals combine ransomware with data exfiltration and then threaten to make sensitive information public. For companies that work with sensitive data, it is now therefore especially important to ensure their systems are properly secured. Hackers are also increasingly exploiting legitimate tools within systems to stay under the radar. This makes it increasingly difficult to detect them.
Social engineering is becoming more inventive
Social engineering also remains a common threat. Phishing is one of the most common forms of social engineering. Businesses, in particular, are increasingly affected by this, as fake emails are becoming harder and harder to distinguish from genuine ones. Today, cybercriminals use AI to make these emails look as real as possible. Through these emails, they try to gain access to company data or payments. As a business, it’s therefore wise to keep your staff vigilant about filtering out fake emails. This way, you can avoid a lot of trouble!
Malware is becoming increasingly difficult to detect
Of course, malware isn’t exactly a new phenomenon in the world of cybercrime. However, it’s becoming increasingly difficult to detect, which naturally makes it more dangerous. Advanced cybercriminals are now even offering malware-as-a-service. This allows criminals with less technical expertise to easily launch attacks on companies. Malware is also becoming increasingly sophisticated and thus better at evading detection. To achieve this, polymorphic techniques are used, which allow the malware to change its form to bypass antivirus software.
The manipulation of information using AI is one of the biggest new cyber threats
Unfortunately, AI has opened up a lot of opportunities for cybercriminals. It has become easier to manipulate and deceive people by manipulating information with the help of artificial intelligence. For example, it is possible to mimic someone’s voice using AI. If you think you’re on the phone with a family member or close friend asking for money, it could just as easily be a cybercriminal. In addition, a lot of misinformation is being spread to manipulate people’s views and ways of thinking using AI. Do you receive a suspicious call from someone you think you know? Be vigilant and don’t jump to conclusions too quickly!
DDoS attacks are a nightmare for businesses
A DDoS attack has always been something every company fears, but this risk has now become much greater than it ever was. It is the most frequently reported threat, even more so than ransomware. Here, too, it is striking that cybercriminals are increasingly offering to carry out DDoS attacks for others in exchange for payment. This significantly increases the risk of large-scale attacks. As a result, DDoS attacks are currently one of the biggest cyber threats
Data breaches and attacks on supply chains
Finally, the threat of data breaches is increasing dramatically this year. This is because attackers are taking a much more targeted approach. Attackers also often put more pressure on companies, for example by threatening to make certain data public. As a result, companies are less likely to report a cyberattack or data breach to the police. Cybercriminals are also increasingly choosing to attack companies through their supply chains. They do this, for example, by spoofing emails from a supplier, which immediately gives them access to that supplier’s entire network.
Conclusion: Be aware of the biggest cyber threats right now
Over the past year, therefore, we haven’t really seen the emergence of new forms of cybercrime. Instead, existing threats have grown more severe due to new techniques and the refinement of existing ones. As a result, attacks are harder to detect, and threats are also more difficult to identify. Given the rapid changes in the field of cybercrime, it is important for every company to stay informed about current threats and take appropriate measures. You can never be too careful when it comes to today’s biggest cyber threats!
Warning from the AP
In its “Government Sector Policy,” the Dutch Data Protection Authority (AP) highlights this risk currently faced by government agencies. This risk involves not only the danger of being overly dependent on a service provider, but also all developments taking place within the government regarding privacy. To the public, it often seems that government agencies are still struggling to comply with privacy legislation. They are occasionally reprimanded by the AP for this. One of the concerns is that when the AP discovers vulnerabilities in government agencies’ systems, it often takes too long to address them. Reasons for this include outdated IT systems, a lack of knowledge, insufficient prioritization, or even a combination of all these factors. As a result, it sometimes takes far too long for data breaches or similar issues to be resolved.
The government lacks a great deal of knowledge
The biggest problem, therefore, is actually a significant knowledge gap within government agencies. As a result, it takes too long for outdated systems to be replaced and for problems to be resolved. Knowledge of privacy law is also often insufficient, particularly among executives. When GDPR violations occur, they are often the result of a lack of knowledge. The Dutch Data Protection Authority (AP) recently expressed concerns about GDPR compliance at the Tax and Customs Administration. For this reason, the authority will be scrutinizing this agency closely in the coming period.
The Impact of Generative AI on GDPR Compliance
Unfortunately, there are still many government agencies that believe they don’t need to fully understand privacy issues. The Dutch Data Protection Authority (AP) is now deeply concerned about the impact generative AI will have on government compliance with the GDPR. Many municipalities have already indicated that they intend to experiment with this technology, but this could have significant consequences—especially since many municipalities fail to conduct proper research before proceeding with such experiments.
Compliance with the amended Telecommunications Act
So what exactly has changed in the Telecommunications Act over the past year? We’ll explain. Last year, the Telecommunications Act was amended to include a reporting and duty-of-care obligation for internet service providers and companies offering other telecommunications services. These changes give internet service providers greater responsibility for identifying cyber threats and ensuring digital resilience. Apart from the new obligations, these stricter requirements also signal preparations for the NIS2 Directive, also known as the Cybersecurity Act.
What do the duty to report and the duty of care entail?
The reporting obligation means that internet service providers are required to report any outages or other issues to the RDI as soon as possible. Security incidents must also be reported immediately, so that the RDI can be certain that the appropriate measures are being taken to protect customer data. The duty of care stipulates that an internet service provider must “take appropriate technical and organizational measures to ensure the security and continuity of services.” The goal of the stricter legislation is to minimize security risks as much as possible and ensure that a provider’s services can be restored as quickly as possible following a disruption or other incident. Because incidents are reported quickly, security measures can be improved and greater insight into cyber threats is gained.
Preparing for the NIS2 Directive
In addition to the new obligations being imposed on internet service providers, the RDI will also examine preparations for the NIS2 Directive—which will become the Cybersecurity Act in the Netherlands—during its inspections. This is a technological directive established by the European Commission. The law has not yet entered into force, but it is expected to do so sometime next year. The directive sets stricter requirements regarding the security of network and information systems. During inspections, internet providers can therefore expect to be asked how they are already preparing for the Cybersecurity Act!
Working from home part-time is the new norm at many companies
A survey by the employers' association AWVN shows that many employers plan to continue allowing remote work. Nearly all employers offer their staff the option to work from home, and seven out of ten do not plan to require employees to return to the office more often. The survey was conducted among more than 350 employers who are members of the association. The association also reports that half of employees regularly work from home and come to the office an average of three days a week. 94% of employers indicate that working from home is practiced in their company.
Employers are positive about the work-from-home policy
Three out of four employers say they are satisfied with the current balance between working from home and working in the office. However, they do indicate that they would prefer to see the office workload spread out a bit more evenly. Currently, the office is always extremely busy on Tuesdays and Thursdays, while there are often very few people there on the other days. Otherwise, however, employers are very satisfied with how working from home is organized. According to the AWVN, employers are so positive about working from home because, in most cases in the Netherlands, there is good consultation regarding working from home. In addition, many employers see the benefits of working from home, according to the association. Consider, for example, a better work-life balance without negative effects on performance.
Employers provide internet allowance for remote work
The AWVN survey also shows that one in three employers—or 33%—contributes to their employees’ internet costs. This is usually done through a fixed allowance, either as a one-time payment or on a monthly basis. In addition, 37% are considering introducing this policy in the near future. A survey by KPN of more than 300 managers in the Netherlands confirms these figures.
Alternative to the internet allowance for working from home
KPN recently introduced an alternative to the employer’s contribution toward internet costs: Internet van de Zaak. This allows employers to easily determine how much they want to contribute toward their employees’ internet costs. The amount they contribute is automatically deducted from the employee’s monthly bill. Of course, both the employer and the employee must be KPN customers for this to work. Easily arranging financial reimbursement isn’t the only benefit of Internet van de Zaak. Through this subscription, employees also gain access to a comprehensive help desk that offers support beyond just internet connectivity. If something goes wrong with the connection at home, this help desk ensures employees are back online in no time!
The government's digital accessibility efforts are lagging behind
Under the Digital Accessibility Act, the government is required to ensure that its apps and websites are accessible, understandable, and user-friendly—including for people who struggle to keep up with the latest technological developments in society. Unfortunately, this is not yet the case in many instances; it appears to remain a problem, particularly at the municipal level. In 2023, only 6% of government apps and websites met the legally mandated accessibility requirements. While 36% of websites complied with the legal obligation, they did not include the tools that people with limited technological skills need to use them effectively.
Improvements over the past year
In the first half of this year, the government invested a great deal of time in making websites and apps more accessible. As a result, the number of accessibility statements increased by 16%. Such a statement indicates that your websites and other applications can be used by people with disabilities. If a resource meets the legal accessibility requirements, it is awarded an A rating. Figures from DigiToegankelijk show that only 6% of government websites and apps currently have an A status, following the improvements made. A B status means that improvements have been made, but that further adjustments are still needed to comply with the accessibility law. The number of declarations with a B status has increased significantly over the past year, by an average of 62% among municipalities. The government is therefore making significant improvements, but still has a long way to go in the area of digital accessibility.
What's behind these improvements?
Why has the government suddenly made such significant progress this year with its improvements in digital accessibility? One reason is that the providers of these websites and apps have made audit reports available to government agencies. This makes it easier for the agencies to justify why they deserve a compliance certificate. In addition, it naturally gives them more insight into what they can still improve on their websites and other digital applications!
What’s next for digital accessibility in the public sector?
The government’s digital accessibility has thus improved significantly over the past year, but it still has a way to go before it is fully compliant with the law. Currently, 40% of government websites and apps meet the legal requirements. That is still less than half, but it represents significant progress compared to 2023.
What are the implications of this ruling in the lawsuit against Google?
There is no doubt that the U.S. judge’s ruling will have major consequences. However, this will take some time, as Google announced after the trial that it would appeal the Washington judge’s ruling. That ruling stated that “Google is a monopolist and has acted in a manner designed to maintain this position.” In the worst-case scenario (for Google, that is), Alphabet’s company will have to cease its lucrative search engine operations. This means Google will lose its immensely high advertising revenue. This would be detrimental to the company, as the advertising market accounts for over three-quarters of Alphabet’s revenue. So far, however, the judge has only ruled that Google is violating U.S. antitrust law. It is not yet known what sanctions the court will impose on the company.
What prompted the lawsuit against Google?
Google has built a monopoly in the advertising market, but that’s not the only problem. The company is also abusing that monopoly position. In 2021 alone, Google paid $26.3 billion to ensure that its search engine is the default on smartphones and browsers. This, of course, is done with the aim of maintaining its dominant market share. Apple receives the largest annual payment to pre-install Google as its search engine. This, of course, comes at the expense of other search engines and advertisers, who lack the resources to spend that much money on such agreements. After all, Google recoups the money it spends through the high fees it charges for advertising on its search engine. Newcomers who might actually have better search engines therefore don’t stand a chance.
Google doesn't like competition
The fact that Google has a large market share is not the problem. After all, this is not illegal. The problem is that the company is doing everything it can to limit its competition, and that is not allowed. Even with its large budget and extensive legal resources, Google was unable to justify these abuses in court. For instance, the company’s lawyers tried to convince the jury that they are not a search engine, but simply answer people’s questions. The judge clearly saw it differently. The judge’s ruling in this case will significantly alter Google’s position in the advertising market, but hopefully it will also encourage authorities to take more action against Big Tech companies for illegal behavior.
What do you think—is this a step in the right direction?
Is internet too expensive in the Netherlands?
Due to the dominant position of Ziggo and KPN in the internet market, Dutch consumers have been paying too much for their internet service for years, according to the Consumers’ Association. They say there is ample evidence that there is insufficient market competition, resulting in prices that are far too high. The two providers currently control at least 75% of the market, according to the association. KPN is currently busy replacing its copper network with fiber optics. The Consumers’ Association explains that the result of this is that consumers will ultimately only be able to choose between cable internet from Ziggo or fiber optics from KPN. The providers’ prices are close to each other, but are also among the highest in Europe. Other providers are allowed to use the fiber-optic network, but here too, the Consumers’ Association sees a catch.
Use of the fiber-optic network
What the Consumers' Association finds striking is that other providers using KPN's fiber-optic network are unable to offer lower prices than KPN providers. Odido, for example, does have a lower rate than KPN—on average 6.50 to 8.50 euros cheaper—but Odido’s network is by no means available everywhere in the Netherlands. The association points to a price survey by the European Commission showing that people in the Netherlands pay an average of 10 euros more for a 100 Mbit subscription than the rest of Europe. In the Netherlands, we pay an average of 30 euros per month for such a subscription, while the average price in Sweden is 17 euros.
According to the ACM, switching discounts are evidence of market forces at work, but the Consumers’ Association notes that consumers are still reluctant to switch internet providers. Reasons for this include the hassle involved, insufficient price savings, and not wanting to lose an email address.
Conclusion of the Consumers' Association
The conclusion drawn by the Consumers' Association from its investigation is that the internet market is currently locked down due to the actions of Ziggo and KPN. This is resulting in fewer and fewer choices and ever-higher prices for consumers. The Consumers' Association is calling on the ACM to intervene and take action against KPN and Ziggo, so that internet service in the Netherlands becomes more affordable again. Ziggo and KPN have not yet responded to the situation.