Cyber attacks are no longer rare incidents. Every organisation, large or small, can be affected. What exactly is a cyber attack, what does one look like and, more importantly, how can you prevent one or limit the damage caused by a cyber incident? In this article, we explain
for directors, IT board members and employees.
What's a cyber attack?
A cyber attack is an attempt by cyber criminals or malicious persons to access your digital systems, data or networks. The goal may range from stealing sensitive information to shutting down business processes or blackmailing the organisation with ransomware.
A cyber attack can be automated (e.g. via automatic bots that seek vulnerabilities), or targeted against a specific organisation. In all cases, it is about exploiting weaknesses in technology, processes or human behaviour.
Common forms of cyber attacks
1. Phishing
Attackers send emails or messages that appear to come from reliable sources. Purpose: to seduce employees to click on a link or to fill in login data.
2. Ransomware
Evil software encrypts files and systems. Only after payment (loss) promise criminals to restore access – Although that's not a guarantee.
3. DDoS attack
Servers or websites are flooded with traffic, making them unreachable. This could cause disruption for weeks.
4. Business Email Compromise (BEC)
Attackers abuse email accounts or pose as managers to commit fraud, for example by fake payment orders that often change an account number on invoices or payment certificates.
5. Malware and exploits
Harmful software exploits vulnerabilities in systems or applications to intrude or steal data.
What are the consequences of a cyber attack?
The impact of a cyber incident can be enormous. Examples:
- Financial: direct costs of recovery, claims or fines.
- Operational: Systems failure and production or service standstill.
- Reputation: customers and partners lose confidence.
- Legal: reporting obligations to supervisors (AVG, NIS2).
For many organisations, the damage in one major cyber attack is greater than for many years investment in
preventive measures.
How can you prevent a cyber attack?
No, it can't be completely prevented, but you can significantly reduce the chances with a combination of technical, organisational and human measures. A strong approach focuses on three layers: prevention, detection and response.
Preventive measures
- Use multifactor authentication (MFA) on all accounts.
- Perform an active patch and update policy.
- Limit access rights according to the least privilege principle.
- Segmentation of networks and critical systems.
- Make backups that are isolated and tested.
Detection and monitoring
- Implement central logging and monitoring.
- Use Endpoint Protection (EDR/XDR).
- Monitor active on abnormal behaviour and suspicious login attempts.
Response and recovery
- Set a incident response plan and practice this regularly.
- Set up a central hotline for employees.
- Keep contact details of suppliers and external experts ready.
- Test periodically whether backups can really be restored.
The role of governance and management
Cyber risks are no longer able to be delegated by directors and supervisors. It is their responsibility to set frameworks, make funds available and monitor them. Essential questions in the boardroom:
- Have our main risks been mapped?
- Is there any policy and are there KPIs for information security?
- When was the last time our incident response plan was tested?
- How are suppliers and chain parties included in our strategy?
Checklist: prepared for a cyber attack
- Are our backups tested and stored safely?
- Do we have MFA active for all critical accounts?
- Is there a current incident response plan?
- Will employees be taking action at phishing?
- Are suppliers included in contractual agreements on security?
Better prepared for cyber attacks
The answer to the question "what's a cyber attack?' is clear: a digital threat that can threaten your continuity and reputation. It can't be completely prevented, but investing in measures and awareness can drastically reduce the chance and impact. This will make a cyber incident Not chaos, but a manageable risk.
Take a zero-measurement cybersecurity
Plan a boardroom cyber session


