“Organisations should take an ecosystem approach to cyber resilience”
Every organisation is part of a wider ecosystem. Yet when it comes to cybersecurity, collaboration across that ecosystem is still the exception rather than the rule. Marijn van Schoote, Director of Ferm Zeehavens, believes that needs to change. “CISOs shouldn’t be sitting opposite one another. They should be sitting side by side.”
Ferm Zeehavens is a collaboration between five major Dutch seaports of national importance. Together, they work to strengthen cyber resilience across the port ecosystem. According to Marijn, it is a successful example of cluster collaboration that deserves to be replicated across many more sectors. During CISODAY2026, he shared his vision on ecosystem resilience in his keynote.
“What often happens in practice is that organisations are part of the same supply chain or ecosystem, yet everyone remains inward-looking.”
The result is that organisations strengthen their own cybersecurity while the wider ecosystem remains vulnerable. “The question we should be asking is: what does it take to make the entire ecosystem as resilient as possible, rather than just our own organisation?”
Ferm Zeehavens: creating impact far beyond five organisations
Although Ferm Zeehavens is formally a partnership between five organisations, its impact extends far beyond those participants, Marijn explains. “The five partners contribute people and resources to the collaboration, but hundreds of organisations across the Netherlands benefit from it.”
One characteristic of collaborations such as Ferm Zeehavens is that no single organisation is in charge. While that can make the initial phase more challenging, because ultimate responsibility is shared, Marijn believes the model has enormous potential.
“There are similar initiatives in healthcare, education and local government, but within the private sector they are still relatively rare.”
That, he argues, is both a missed opportunity and a risk. “Looking at resilience across the entire supply chain will always take you further than focusing solely on your own organisation.”
Taking the initiative
To establish successful ecosystem partnerships, leading organisations need to come together and take the initiative, says Marijn.
“I like to say: take responsibility, even when you're not formally responsible. It takes a group of frontrunners willing to step forward and say, ‘We believe this matters, and we're going to make it happen for the benefit of the entire sector.’”
Too often, however, organisations wait for someone else to make the first move. “That’s exactly where CISOs have a crucial role to play. They are uniquely positioned to operate across organisational boundaries.”
As a CISO, your job isn't to keep everyone happy or defend every decision your organisation makes, Marijn explains. “Your role is to identify vulnerabilities, ask difficult questions and highlight uncomfortable truths.”
For that reason, Marijn believes CISOs are ideally placed to build relationships with peers across their sector and drive new collaborative initiatives.
“As a CISO, simply take the lead. Reach out to your fellow CISOs across the sector, identify the shared challenges together, and then work within your own organisation to strengthen the resilience of the wider ecosystem.”
Prioritising together
Ferm Zeehavens has already demonstrated the value of this approach in practice. One example is conducting red team exercises across the entire ecosystem rather than within individual organisations.
“That immediately revealed vulnerabilities we hadn't previously identified. Once you have that insight, you can implement improvements that benefit the entire sector. That's something no organisation can achieve on its own.”
Looking at resilience from an ecosystem perspective also exposes the complexity of securing an entire sector. “It forces difficult choices. What do you protect first, and what can wait? You can't do everything, so you have to prioritise.”
Throughout that process, Marijn believes it is essential that CISOs continue working together instead of retreating into their own organisations.
“CISOs shouldn't be sitting opposite one another within an ecosystem partnership. They should be sitting side by side.”
CISOs must be able to adapt their leadership style
Marijn argues that strengthening resilience across an ecosystem also requires strong leadership within each participating organisation.
“Boards aren't always eager to invest in initiatives that primarily benefit the wider ecosystem rather than their own organisation.”
That is where situational leadership becomes essential. “CISOs need to recognise that different situations require different leadership styles.”
Marijn understands that this can be particularly challenging for less experienced CISOs. “But don't fall into the trap of thinking, ‘They don't understand me’ or ‘Nobody is listening.’ That mindset isn't productive. Take responsibility and be prepared to challenge the status quo.”
“If your organisation is a prominent player within its ecosystem, then contributing to the resilience of that ecosystem isn't just good practice. It's a moral responsibility.”


