BCM: most organizations are not as ready as they think
Business continuity management is not a document, it is a tested capability. Many organizations think they are prepared, but real resilience depends on critical function mapping, recovery priorities, supplier awareness, and regular exercises.
PCI DSS applies to every business with a card terminal and most businesses still underestimate that fact
If your business accepts card payments, PCI DSS applies to you. Size and transaction volume do not remove the requirement, and many businesses underestimate how much responsibility still sits with the merchant.
Supply-chain resilience is now an economic-security issue
Supply-chain resilience is no longer just a logistics concern. Geopolitical tension, trade fragmentation, and de-risking policies are turning supply chains into an economic-security issue that every organization needs to understand.
You Can Buy IT, Not Responsibility
Having IT is not the same as being secure. SMEs still own their cybersecurity, continuity, and accountability, even when those tasks are partially outsourced to an IT provider. “But we have IT.” is a warning sign, not a comfort.
The uncomfortable truth: Most SME’s are less ready than they think
SMEs are being told to build resilience, but the reality is less glamorous: resilience is cashflow discipline, supplier visibility, recovery planning, and fast decision-making. In 2026, the businesses that survive disruption are the ones that prepare before they are forced to.
How Geopolitical Risk Management Will Reshape Defense Procurement
The EU is tightening ICT supply-chain expectations, and defense suppliers are feeling the pressure first. Trusted sourcing, tier-3 visibility, and PQC readiness are becoming operational requirements, not future ambitions.
Is NIS2 indirectly shaping UK Cyber strategy?
The UK is not adopting NIS2, but it is moving its cyber regime in a similar direction. For UK and EU suppliers alike, the real pressure is now supply-chain assurance, incident readiness, and the ability to prove resilience on demand.
Why Identity, Not Malware, is Breaking European Healthcare
From the administrative exposure of 15.8 million records in France to fleet-wide wiper attacks on medical devices, the healthcare sector is facing an identity crisis. Discover the Forculus Verdict on why Inherently Resilient healthcare requires auditing the Administrative Path, not just the Compliance Checklist.
The DORA Debt: Why Compliance Faces Real Stress Tests
The FICOBA breach and the AI-driven surge in credential theft have proven that DORA compliance is not enough. The financial sector is facing a "Visibility Surcharge" where traditional defenses fail against skill-less AI actors. Discover the Forculus Verdict on why identity is the new perimeter and how to build true Inherently Resilient financial systems in 2026.
The Great Exposure: Why 2026 is the Year of the "Skill-less" Breach
The data from April 2026 is brutally honest: Your multi-layered defenses are no longer a deterrent. The AI upsurge has collapsed the barrier to entry for cybercrime. A teenage hacker with a basic LLM can now execute perfect spear-phishing and chain vulnerabilities that bypass your MFA. Discover the Forculus Verdict on the recent wave of Dutch breaches and why Inherently Resilient defense requires auditing the Path, not the Portal.
The Sovereign Provider Myth: Is "European" enough?
Is Open Source the answer, or can we trust Sovereign Providers? Stop asking if you can trust a tool or a partner. You can’t. True Digital Sovereignty is not about where your data is stored; it’s about where your control resides. In 2026, resilience isn't about finding the lowest price, it's about ensuring your Total Cost of Exit is lower than your Total Cost of Staying.
Mythos & The Glasswing Trap: Why Your “Minor” Bugs are Now Major Liabilities
The Era of "Minor" Bugs is Dead. In April 2026, the cybersecurity landscape has been split in two. On one side, Anthropic is claiming a "nuclear" breakthrough with its superpowered Claude Mythos. On the other, skeptics are calling it high-stakes theater to pad their IPO valuation.
The brutal reality lies in the data: Mythos isn't a "magic hacking button," but it has turned a months-long human exploitation process into a days-long autonomous one.
The "Double Agent" Crisis: The 2026 Resilience Pivot
The honeymoon is over. In 2026, we aren't just worried about what AI says, we’re terrified of what it does. As "Agentic AI" takes over corporate tasks, a new breed of "Double Agent" risk has emerged. If your AI agents have the keys to your kingdom, they might just be waiting for an external attacker to tell them to unlock the door.
The Strategic Autonomy Paradox
Sovereignty and resilience are the twin pillars of 2026 security, yet they often pull in different directions. Understanding how to build independent, indestructible infrastructure, without relying on global hyperscalers, is now the ultimate strategic advantage for the modern organization.
The 24-Hour Rule: Navigating the AVG and NIS2 Overlap
The biggest myth in Dutch cybersecurity is that you have three days to catch your breath after a breach. While the AVG (GDPR) gives you a 72-hour window, the new Cyberbeveiligingswet (CbW) has effectively deleted that luxury for thousands of Dutch companies.
The AI Hangover
In 2026, the AI honeymoon is officially over. As we shift from simple chatbots to autonomous "Agentic AI," the attack surface has fundamentally changed. From indirect prompt injection to the looming deadlines of the EU AI Act, organizations must now treat AI models as untrusted third-party software. It’s time to move past the hype and confront the "black box" liabilities currently sitting in your core infrastructure.
The NATO iPhone
The tech world is buzzing: Apple’s iOS 26 has officially entered the NATO Information Assurance Product Catalogue. But before you swap your ruggedized laptop for a standard iPad, understand the "Indigo" reality. Accreditation doesn't mean "secure by default", it means secure by lockdown. From mandatory biometric liveness checks to strict physical custody protocols, the iPhone is only as safe as the perimeter you build around it.
The New Standard: Navigating the ABRO 2026 Landscape
The era of "voluntary" security for Dutch government vendors has ended. With the full rollout of the ABRO 2026, every supplier from IT services to infrastructure is now a vital link in national security. This isn't just about passing a tender; it’s about a continuous lifecycle of trust verified by the NBIV. If you aren't ABRO-ready, you aren't just missing a contract; you're missing the new baseline for public sector partnership.
BIO2: the New Dutch Government Security Standard
As of January 1, 2026, the "baseline" has moved. The transition from BIO 1.04 to BIO2 (Baseline Informatiebeveiliging Overheid 2) is no longer just a technical upgrade, it is a legal evolution. For provinces, water boards, and the central government, BIO2 is now a mandatory framework for self-regulation, while for municipalities, it serves as the essential blueprint for meeting the Cyberbeveiligingswet (CbW).
ISO 27001 Certification
In the Dutch business landscape of 2026, ISO 27001 is no longer just a "nice-to-have" certificate for your lobby. With the Cyberbeveiligingswet (CbW) now in force, ISO 27001 has become the primary defensive shield for directors. It is the most robust way to prove you have met your legal "duty of care."
