In the Cybercrime Threat Landscape Netherlands 2026, the police and Public Prosecution Service present a clear picture: cybercrime is becoming more professional, easier to scale and harder to classify. Artificial intelligence accelerates existing attack methods, criminals use specialised services and the boundaries between different offender types are fading. Organisations may therefore feel they should focus mainly on increasingly sophisticated hackers and new technology. My main conclusion is different. The threat is becoming more complex, while many organisations still cannot demonstrate that the fundamentals of their information security are under control. That is precisely why new developments can quickly become a serious business risk.
Cybercrime in the Netherlands: the main figures
The Safety Monitor 2025 of the CBS shows how wide online crime affects Dutch society. The figures are about Dutch people aged 15 and over and include multiple forms of online crime.
This does not mean that 2.5 million Dutch people have been hacked. The figure includes different forms of online crime.
| Number | Meaning |
|---|---|
| 16,8% | In 2025, a form of online crime was encountered |
| about 2.5 million | people aged 15 and over |
| 10,3% | was victim of online scams or fraud |
| 5,5% | was victim of hacking |
| 2,6% | experienced online threats or intimidation |
Three developments that change the cyber threat in the Netherlands
The Cybercrime Threat Landscape Netherlands 2026 describes not isolated techniques, but a cybercrime ecosystem in which infrastructure, knowledge and services can be used by different groups. Three developments are particularly relevant to organisations.
1. Different types of cybercriminals are getting more mixed up
The distinction between classic cybercriminals, organised crime, young online offenders and state actors is becoming less acute. The same criminal infrastructure, knowledge and access can be used by different groups.
Hacker Com consists of young, often Western cybercriminals for whom data diary, cryptologist, status and extortion can be mixed. Sometimes there is overlap with extremism and violence.
For organisations, the precise motivation of the attacker ultimately makes less difference. Systems, accounts and data must be resistant to different types of threat.
2. Cybercrime is becoming an ecosystem
Cybercrime is less and less the work of one technically very skilled perpetrator. Infrastructure, malware, stolen login data, access to organisations, data diary, money laundering and extortion can be purchased or used as specialized services.
An attacker doesn't have to be able to do everything himself anymore. This reduces the entry threshold.
We must therefore get rid of the idea that every cyber attack is being carried out by an exceptionally talented hacker who personally tries to invade one organisation for weeks. Sometimes one vulnerable system, misconfigured service or stolen account is enough.
3. AI makes attacks faster and more scalable
AI is mainly a catalyst for existing cybercrime. The technology can be used for phishing, programming, malware development, searching for vulnerabilities, analyzing data and automating attack steps.
The development of Agent AI can allow more steps to be carried out independently. The vulnerabilities do not necessarily change. They can only be found faster and abused more quickly.
The most important vulnerability I see in practice? Assumes.
In my daily work I still see that many directors consider cybersecurity primarily as a task of IT. Almost every organisation now depends heavily on IT. Sometimes the entire primary process runs on it. However, IT risk management is still remarkably often left entirely to the IT department or external IT service provider.
Typical statements are: It regulates the operation of the service provider and our supplier. During investigations, it is regularly found that contracts are outdated, SLAs are not sufficiently concrete, responsibilities are not clear, reports are missing, risk analyses have never been carried out and security measures are not demonstrably monitored.
Trust is important. But trust is not a management measure.
The greatest vulnerability is often not in an unknown zero-day, but in the assumption that someone else has.
Having a firewall doesn't mean he's protecting
I find in practice environments where a security function is off, malware or botnet control is not active, a license expired and no one checks it. Everyone assumed security was good.
There is also a lack of network separation, particularly in production, logistics and transport, and in organisations with a lot of local infrastructure. An attacker who reaches one system can then move unnecessarily far through the environment.
The question should not only be what security measures we have, but above all how we know they actually work. An independent Cyber Security Audit can make that exact difference between assumption and evidence visible. Good patch management and vulnerability management also reduces the time when known vulnerabilities can be abused.
Cybersecurity belongs in the boardroom
Board members need not be technical specialists. They need to know what digital risks are important, who is responsible, what measures have been chosen, why they are appropriate, what residual risks are accepted and how the operation is monitored.
This also applies to incident detection and the failure of critical suppliers. Capture roles and responsibilities in a RACI and use current risk analysis as a basis for decisions. First, understand the risk. Then determine which measure fits in with it.
The Dutch Cybersecurity Act and NIS2 make this board-level line extra topical, but good risk-driven governance is also needed outside the legal scope.
- What digital risks can affect the strategy or continuity?
- Who owns and who performs, advises or supervises?
- What measures have been chosen and what risk are they based on?
- What risks are deliberately accepted and by whom?
- How is measures actually checked?
- How are incidents detected and escalated?
- What happens when a critical supplier fails?
Subcontracting IT is not the same as outsourcing responsibility
An IT service provider can perform patching, logging, monitoring, backups, incident detection, incident response, escalation, reporting and recovery. The organisation remains responsible for the choice of the service, the associated risk and the control of the agreements made.
Make supplier management part of the company's own internal control. Not only what the supplier does, but also what evidence and periodic reporting the organisation receives.
Ask your IT supplier:
Can the supplier answer these questions in concrete terms and with proof?
- Who's monitoring our security logs?
- What time is critical patches installed?
- How do we know that backups are actually recoverable?
- Who reports an incident to us and within what time limit?
- Who's investigating a possible compromise?
- What security reports do we receive periodically?
‘The supplier is ISO 27001 certified, so it must be secure’
An ISO 27001 certificate is useful, but not a licence. Check the certification scope, the Statement of Application, relevant management measures, whether the service used falls within scope, the distribution of responsibilities, available reports and any audit rights.
When a supplier provides a crucial part of the primary process, additional assurance or an additional audit can be logical. A certification is not a substitute for supplier management.
Awareness needs to change with it
Classic awareness that warns especially about spelling errors and bad sentences becomes obsolete. With AI, attackers can create convincing and context specific messages. New awareness should therefore be about context, behaviour, control, second channel verification, different payment requests and abnormal account usage.
Employees need to learn how to ask: is this request correct, is this action logical, why suddenly changes the account number and can I check it through a second channel? A continuous security awareness program helps to make such control actions part of daily work.
Awareness must never be the only line of defence. Technical measures such as MFA, access management, safe configuration, detection, logging and monitoring remain necessary.
Many organisations probably don't notice an incident soon enough
Some organisations lack logging. There's logging in with others, but nobody's looking at it. Detection rules and a clear escalation route may be missing, while the IT provider is automatically trusted and is not clear who leads the incident response.
Some organisations are not only not sufficiently prepared for a cyber incident, but are not sufficiently equipped to detect the incident in time.
Practice before the incident occurs
A useful incident response plan connects the incident organisation with the crisis plan, current contact lists, communication, a possible notification to the Personal Data Authority, cyber insurance, an incident response partner and pre-arranged decision-making.
Also practice scenarios such as Microsoft 365's failure or the IT supplier. A document on SharePoint does not stop ransomware attack. The plan should therefore also be available and usable when the normal environment does not work.
Never washed a good incident. Let each incident lead to evaluation, root-cause analysis, evaluation of measures and structural improvement. If something has gone wrong, use the first steps out Hacked? What now?.
Discuss ransomware before you have ransomware
Police and OM emphasize the importance of not paying for ransomware. Paying does not guarantee that criminals delete data and maintains their earning model.
Please discuss in advance whether payment is excluded by definition, whether exceptional circumstances are conceivable, who may decide, what role RvT, RvC or RvA has, which external advisors are involved and what cyber insurance requires. A crisis situation is a bad time to discuss questions of principle for the first time.
What should a board member take from the Cybercrime Threat Landscape Netherlands 2026?
These seven points translate the current cybercrime image into concrete board-level control.
1. Map digital risks
- Determine which processes, data, systems and suppliers are critical.
2. Make responsibilities explicit
- Capture ownership and RACI.
3. Check that security measures work
- Ask for proof, not just confirmation.
4. Manage suppliers as part of the own risk
- Check contracts, scope, SLAs, reports and certifications.
5. Ensure detection
- Logging without monitoring is insufficient.
6. Pre-pre-decision preparation of incident
- Plan, practice and capture escalation.
7. Start with cyber hygiene
- Keep systems up-to-date and organize MFA, segmentation, patch management, access management, logging, monitoring, backups, incident response and vendor agreements.
The threat is getting more complicated. The base remains surprisingly recognizable.
The Cybercrime Threat Landscape Netherlands 2026 shows that cybercriminals are collaborating more professionally, the boundaries between offender types are fading and AI is making existing attacks faster and more scalable. That deserves attention.
But organisations should not be tempted to think that their security should automatically become more complicated. Many organisations can significantly improve their resilience by first getting what they already have arranged.
What measures are really working? What agreements are there? What risks have been deliberately accepted? Who's checking the supplier? Who's watching the logging? Who takes charge when things go south?
Because in the end, the greatest vulnerability is often not in an unknown zero-day. The greatest vulnerability is often assumed that someone else did.
Sources and deepening
Based on official frameworks and practical implementation
The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.
An independent Cyber Security Audit makes visible what measures work, where assumptions exist and which risks deserve board-level attention.
Check out the Cyber Security Audit →

