News item

CISODAY2026, an impression

After three years, CISODAY2026 has become a fixture on the Dutch cybersecurity calendar. A significant number of representatives from government agencies, professional associations, and nonprofits provide a solid foundation. CISOs from large, often international companies come to share their expertise. And partners gain new insights into security practices at a wide variety of organizations. But above all, visitors come for a sense of community.

4 June 2026 | 10 minutes read

Close collaboration is essential in an era where the time-to-exploit has been drastically reduced due to attackers’ use of AI

At the start of the event, Dimitri van Zantvliet, chair of the CISO Platform Nederland, was asked about the theme: Ecosystem Resilience. Close collaboration is essential in an era where the time-to-exploit has been drastically reduced due to attackers’ use of AI, he said.

Whereas three years ago, 20 days was sufficient to patch zero-day vulnerabilities, it is now increasingly a matter of hours. This requires effective triage; otherwise, you’ll be overwhelmed by the workload. The use of AI-supported tools is essential here, but people must stay in the loop. That’s the only way to avoid unnecessary stress. But to achieve that, we need to move faster, and that’s only possible within an ecosystem of CISOs and vendors who share knowledge and information.
 

Protection Level Agreement

Former CISO Bart Willemsen, cybersecurity analyst and VP at Gartner, kicked things off. He brought both good and bad news. Gartner’s latest CISO job survey shows that the budget available to CISOs is growing. The bad news is that three-quarters of respondents report a shortage of staff. Add to that the unregulated use of AI by organizations, and the CISO’s job isn’t getting any easier.

Many CISOs feel responsible for far too many things

On top of that, many CISOs feel responsible for far too many things: product security, AI governance, or the ecosystem’s overall resilience. At the same time, Willemsen is seeing more and more CISOs managing expectations within the organization through a protection level agreement (PLA). Impact assessments are essential here: where should an organization invest the most in security?

In conclusion, Willemsen warned of the consequences of quantum computing for the security domain. If you haven’t thought about post-quantum cryptography yet, you’re too late, was his message.
 

Personal responsibility at the core of digital resilience

Eefje Zents, Chief Relations Officer and Director of Digital Resilience and Public-Private Partnerships at the NCSC, spoke about sharing knowledge on vulnerabilities (CVEs) and how this makes us all stronger. She made an important distinction between security and resilience: the former is about patching, the latter about making the costs as high as possible for someone who wants to break in and holding them off for as long as possible. It’s about how long we, as an ecosystem, can hold back the flood of attackers.

In that context, she mentioned two issues affecting her organization: the scope of operations has expanded enormously, from the 300 critical organizations the NCSC previously had to protect to 2.4 million organizations and companies today. The implementation of the new Cybersecurity Act is the second. As a result, organizations will soon be required to share information about their risks, vulnerabilities, what they do to protect themselves, how they handle incidents, and how follow-up is organized.

Don't underestimate your responsibility, because what you do for others, they can do for you as well

She cited the recent hack at Ivanti as an example. In the past, the NCSC would have simply asked the affected party for information and shared it with the outside world. Today, it’s more of a partnership, Zents said. By working together, helping to protect the integrity of the affected company, and minimizing risks to national security as much as possible, everyone is better off. Under the new law, the NCSC’s role shifts to that of an operational coordinator, whereby the organization assesses in each instance whether it should strengthen its grip on a situation or, conversely, hand a problem over because someone else in the ecosystem is better positioned or more capable of resolving it.

Do not underestimate your own responsibility, because what you do for others, they can ultimately do for you as well. That is the essence of digital resilience, Zents concluded.
 

Sovereign Defense Cloud

Sharon van de Beek, CISO at the Joint IV Command (JIVC), spoke with Erik Beulen, professor of information management at the University of Manchester, about how AI can contribute to the resilience of the defense organization itself. A time is coming when attackers will start to gain more advantage from AI, but governments and companies need time to adapt their tools and working methods, she warned.

Compliance is gradually becoming less important because AI increases the speed at which vulnerabilities are found. JIVC is therefore focused on continuous testing of hardware and software, penetration testing, red teaming, purple teaming, and threat hunting. This provides valuable insights into the technology stack and all issues that need to be resolved. This information is valuable to the leadership, enabling them to make sound decisions.

Compliance is gradually becoming less important because AI increases the speed at which vulnerabilities are found

When it comes to building an ecosystem, the Ministry of Defense needs significant support from the market, but it can also contribute its own expertise. For example, JIVC is now collaborating with Thales and KPN to build a sovereign cloud. Through a strategic partnership, it can shoulder the investments for both parties. But it took courage to set this up, Van de Beek explained. Finally, she discussed the investments in post-quantum cryptography at the Ministry of Defense. NATO hardware has a long lifespan, and implementing post-quantum algorithms is a high priority.
 

Detection is a cost factor

Next, Lt. Col. Matthijs van der Wel-ter Weel, who commands the Dutch Cyber Reservists and is also a part-time CISO, spoke about fending off attacks carried out by (or on behalf of) a state actor. He explained that this is different from defending against an attacker acting out of financial motives, especially regarding detection and recovery. State-sponsored actors typically exploit existing vulnerabilities, so protection is primarily a matter of ensuring your basic security practices are in order.

Detection is a different story: while a financially motivated attacker wants to exit a system as quickly as possible – if only to recoup their investment as soon as possible – hackers working on behalf of a nation-state are particularly patient. As a result, they must take great care not to be detected. For the attacked party, this means investing more in detection, the costs of which can be two to four times higher.

Cyber reservists are extremely useful in the detection process

Recovery can also be costly. If wiperware is involved, there is a high likelihood that physical access to bare metal will be required to restore operations. This, and the preparations for it, can lead to high costs. And is the physical relocation of personnel even possible as military tensions rise? Will all personnel, including those at suppliers, remain in Europe? To make matters worse, damage caused by nation-states is excluded (from reinsurance) by Lloyd’s.

Cyber reservists, of whom there are currently 300, with 150 awaiting admission, are extremely useful in the detection process. They support not only the NCSC but also other organizations in response to requests for assistance. However, more people are needed. Those interested can find more information at the Ministry of Defence website.
 

Take responsibility

Marijn van Schoote, Managing Director at FERM, a partnership of Dutch seaports, came to explain how port companies are working together to build their resilience. He outlined a scenario in which traffic around a port grinds to a halt due to an IT problem somewhere in one of the systems, causing access gates to malfunction and the transshipment of goods and containers to come to a standstill. Before long, this becomes a problem for society as a whole. That is why cybersecurity in ports is not merely a technical or organizational issue. It is something that must be addressed within the ecosystem. But who is responsible for this ecosystem? There is often no clear agreement in public-private partnerships, and risk ownership is spread across various organizations.

CISOs must be able to switch between unifying and directive leadership

Within FERM, more than eighty organizations are working together to strengthen their collective resilience. They do this by sharing information, conducting joint exercises, and through red teaming of critical supply chains.

Van Schoote concluded with three recommendations. CISOs must take responsibility, even if there is no formal ownership. In cybersecurity, you have to make tough choices to protect what is truly critical. And CISOs must be able to switch between unifying and directive leadership.
 

Cybersecurity has gone mainstream

Dave Maasland, cybersecurity expert and CEO of ESET, was interviewed by Rob Beijleveld, co-founder of the CISO Community and organizer of CISODAY. He viewed AI as a positive development because it has brought the technology discussion to the masses. Technology and cybersecurity have gone mainstream; CISOs are much more visible, so AI has elevated the conversation to a higher level.

What is the best way to protect yourself against state-sponsored actors? Their work is becoming increasingly difficult to identify, Maasland said, because they collaborate with criminal enterprises, or because hacktivists operate under the banner of states, or due to other proxies doing so. In fact, the distinction between the different groups is no longer clear, and therefore we must adopt a risk-based approach to cybersecurity.

When asked about the CISO’s position, Maasland indicated that it is stronger than ever because executives are paying attention to cybersecurity and risks in general. If CISOs can directly link the narrative about risks to the business, things can change significantly.

We are heavily influenced by the dominant narrative from the US: that Europe is slow, weak, and not innovative

Maasland was positive about cyber legislation in general. NIS2, for example, will provide a better baseline and is risk-based. That is why it may well be that the EU is doing better than the US. When asked about the sovereignty debate, he warned against an anti-US sentiment. A pro-EU stance is better: let’s build a better economy with strong competition. In the EU, we are too heavily influenced by the dominant narrative from the US: that Europe is slow, weak, and uninnovative. The sovereignty debate can change that, and we must take advantage of it.

Indeed, the Solvinity case demonstrates a lack of strategic vision and a lack of a clear vision on technology within the cabinet, Maasland noted [this was before the news broke that the government does not approve of the takeover by Kyndryl].

Maasland concluded by suggesting we get together for a beer more often. We are in the midst of all sorts of exciting changes that may take years to unfold. When things really go south, you need to be able to call your friends.
 

Cyber maturity, security DNA, and a hard reset

Next, the three nominees for the CISO of the Year Award were invited to pitch their story.

Walter van Oostrum outlined the path to cyber maturity at his organization, het CAK, and urged CISOs to collaborate with the business, the board, partners, supply chains, and their peers. Don’t stop innovating, because the outside world isn’t either.

Kay Behnke told the audience about the groundbreaking work Genmab is doing in the field of cancer drugs. Over six years, a security organization has been built: a “distributed immune system” with security officers in key countries. Security is not technology-driven but integrated into business processes: it’s in the DNA.

Wim Sonnemans did not speak about his organization, Philips, but about the need for CISOs to move away from the traditional process-driven approach to cybersecurity, as it lags behind reality. A hard reset is needed; CISOs must start deploying hyper-automation and AI agents, based on ownership, specific training, and lifecycle management.
 

Tell a story, the right way

Carlo Schreurs, CISO at FrieslandCampina, focused on effective communication, which helps you connect with the board, employees, your team, and stakeholders in the ecosystem. And he did so through storytelling. The CISO needs an impact accelerator: we’re bombarded with so much information, and you have to keep reaching people.

Schreurs shared the story of a cyber incident in 2021. The manufacturer of the cans used for the baby food produced by FrieslandCampina fell victim to ransomware. Because the supply of cans stalled, production at FrieslandCampina also had to be halted. Once the cans were being delivered again, the problems weren’t over: the company began transporting products by plane rather than by container to make up for lost time, resulting in reputational damage nonetheless.

The crux of the story is that the board took no action based on a cybersecurity report detailing the risks to the food industry. It was spurred into action by the narrative surrounding the incident. As a result, resilience has now become an integral part of the cybersecurity strategy and is embedded in every aspect of the company's processes.

You achieve compliance through control, but you earn trust by telling stories

Ecosystem resilience does not depend on technology or policy. It’s all about the story you tell, said Schreurs, because our brains evolved in environments where stories were the primary vehicle for information. What’s important here is that your story elicits the right response. Simply scaring people triggers the release of cortisol and adrenaline, and while they might obey for a moment, they won’t be motivated to take lasting action because you haven’t convinced them of anything. Showing emotion triggers the release of dopamine and oxytocin, which helps you connect with your audience, but you do need structure in the form of a complete story. Stories don’t just come naturally, Schreurs noted, so build a story bank so you can draw on it when needed.

Vulnerability is a strength: show your scars, and people will stop being defensive. You achieve compliance through control, but you earn trust by telling stories. We are all chief information storytelling officers, Schreurs concluded.
 

Hackshield Cyber Heroes

Luisella ten Pierik, vice chair of CISO Platform Netherlands and CISO at Stedin, and Emily Jacometti, co-founder of Hackshield Cyber Heroes, announced the new partnership between the two organizations. Ten Pierik asked Jacometti about the story behind Hackshield, which was born out of the need to teach children – who, according to a recent study commissioned by the UN, spend sixty percent of their waking time online – how to use the internet safely. An effective way to do this is through a game, also called Hackshield, where children can learn to become cyber agents. This is because education is not keeping pace with the fast-moving digital reality, and children can quite easily fall prey to criminals.

An additional goal of Hackshield is to spark children’s interest in a career in cybersecurity. There are currently 850,000 participants, but Jacometti predicted that the top 100 will be in the room in ten years.

Education is not keeping pace with the fast-moving digital reality, and children can quite easily fall prey to criminals

Through its participation in the European Crime Prevention Award, Hackshield also gained recognition beyond our borders. It is now available in 8 countries, and 36 countries are on the waiting list. The platform receives government subsidies and donations from the business community, which means no commercial advertising is necessary, and it remains free for participants, who also do not have to provide any sensitive data. However, to ensure continued growth, financial support is more than welcome.
 

The most humble award winners?

The CISO of the Year Award ceremony is a celebration, but one where appropriate humility reigns: winners invariably state that they would never have gotten where they are today without their teams. This year’s winner, Kay Behnke, CISO at Genmab, was no exception. And that brings us to a defining characteristic: CISOs and other information security leaders are humble people who prioritize collaboration. Not just within their own organization, but especially outside of it. The implicit message is that you don’t compete on cybersecurity, and without a team, you’re nowhere.

That is why this year’s theme, Ecosystem Resilience, was so apt. Because the CISO is not sitting on an island, but rather on an archipelago, populated by organizations – competing or not – peers, suppliers, professional associations, and governments. It will be hard to come up with a theme for next year...
 

Drafted without AI, translated from Dutch with AI support