Skip to content
Beveiligingsnieuws

NCSC Community event: risico’s en incidenten beheersen

risico’s en incidenten beheersen

During the first NCSC Community event under the NCSC banner, around 500 participants gathered at the NBC in Nieuwegein to talk about the practical question that keeps cybersecurity teams busy: how do you risico’s en incidenten beheersen—in a way that works in real organizations, with real constraints?

The urgency was palpable. The current wave of cyber incidents has made it clear that cybersecurity is not limited to IT alone. Attendees discussed how legislation, certification, insurance, communication, awareness and legal responsibilities all influence how risks are managed and how organizations respond when something goes wrong.

From community “heritage” to shared action

In his opening, NCSC director Matthijs van Amelsfort described the community as valuable “input” that the Digital Trust Center brought to the partnership with NCSC. His message was consistent: the value is created by connecting people, learning together and sharing what you know—especially when the stakes are high.

That collaborative tone set the stage for a program designed around two major learning tracks. Rather than staying abstract, the event focused on approaches teams can apply and repeat over time.

Learning tracks: risk management and incident management

Two parallel themes stood out as the event’s main through-lines: risicomanagement and incidentmanagement. Participants explored questions such as what an organization needs to protect, how to build continuity, and what to do when an incident actually occurs.

Each theme was structured as a learning track with three consecutive sessions. Attendees who had signed up in advance could go deeper from different angles, guided by multiple speakers.

Plan-do-check-act for risk management

Before the afternoon program, Jorrit van der Walle introduced a risk management learning track and emphasized a key starting point: risk work is not a one-size-fits-all exercise. According to him, jumping immediately into a full risk analysis can make it harder for people inside the organization to engage.

His approach highlighted the importance of starting small and improving through iteration. In particular, he pointed to the plan-do-check-act cycle: you learn by doing, reflect after each step, and gradually build cyber maturity with every loop.

MASKeR: scenario thinking you can reuse

Next, Jaap Noordhoek from NCSC discussed MASKeR, described as a modular approach for scenario-based knowledge sharing and risk management. The format allows organizations to work on their own scenarios during a two-day workshop.

What made the method stand out was its pragmatic focus. Instead of treating scenarios as one-off documents, it aims to make them achievable, repeatable and shareable across organizations.

On the first day, teams map what they want to protect and identify the interests that matter most. From there, participants build scenarios using “building blocks,” such as:

  • the actor,
  • the attack method,
  • the target, and
  • the impact.

By combining these elements, organizations can create a set of relevant scenarios and then visualize them as a heatmap. That output supports decisions on where to invest money in prevention and response.

Preparing for incidents—then handling the aftermath

Alongside risk management, the event’s incident management track explored how organizations can prepare for an incident, what they may face during one, and how to manage the situation afterwards.

Across three building sessions, participants heard how crisis management, compliance, communication and liability interact once the incident becomes more than a threat on paper.

Legal expertise as a control mechanism

Rosalie Brand, an attorney at Kennedy van der Laan, provided a practical perspective from the legal side. Her focus was on how legal expertise can improve control during an incident, help prevent common mistakes and limit damage after a cyber incident.

In her contribution, she made the case that incident management is not only about technical triage. Legal considerations can shape what you can do, how you document decisions and how you communicate responsibly—without losing compliance.

A rough world—and blurred boundaries in cyberspace

In the plenary session, Bart van den Berg from the Clingendael Institute offered a geopolitical lens on the environment organizations are operating in. His central idea was that today’s world is “rough,” with uncertainty and competing values under pressure.

He described how the geopolitical landscape has moved from earlier patterns toward something multipolar, and he connected this to developments in the digital domain. In cyberspace, the lines between “bad actors” can blur—hacktivists, state-linked actors and criminals are not always clearly distinguishable.

To navigate that complexity, he advocated a concept he called strategic empathy: try to understand other parties, because that understanding can strengthen your position in real interactions.

More than systems: the human impact of incidents

That human focus continued in the plenary presentation by Inge van der Beijl, Manager Innovation at Northwave. She spoke from experience with major cyber incidents where she also acted as a mediator between hackers and affected organizations.

Her message challenged the tendency to frame incidents purely as technical failures. Ransomware victims—her starting point for the talk—include not only systems owners, but also employees, customers and citizens. As she put it: a cyber incident breaks more than systems.

She discussed how incidents can damage trust, including the example of a breach affecting public trust in population-related research. She also argued that crisis teams and staff carry significant emotional burdens during such events.

Inge emphasized the role of communication as a lever to reduce emotional impact. The words organizations choose when speaking publicly matter deeply, and timing matters as well—cyber criminals observe and react to what is shared.

Negotiation reality: understanding roles and incentives

One of the most striking parts of her story was an audio recording in which a hacker—seemingly upbeat—asked the target organization to create an email address for communication. Inge used this to illustrate that the interaction can be emotionally disorienting, because affected organizations often feel both anger and fear.

Her recommendation was not to ignore those emotions, but to improve your position in negotiations by understanding the cyber criminal’s business model and your own leverage. When you grasp the incentives involved, you can negotiate with more clarity.

Train for crisis: when pressure brings out “the primal human”

During the “Help! a cyber crisis” workshop, emotions were again front and center. Kelvin Rorive from the Cyber Chain Resilience Consortium (CCRC) said that under pressure, the “primal human” can surface.

Using a realistic exercise scenario, participants faced questions like: when should you be concerned if a data leak occurs both at your own organization and at a supplier? What actions do you take? Which roles must be in the crisis team?

He also noted a counterintuitive risk: experienced managers can become ineffective crisis managers if they have not practiced enough under realistic conditions.

The workshop also touched on sensitive communication and governance questions—for example, how to handle the fact that employee data may be stolen, what HR’s role is, and the difficult dilemma of whether to pay a ransom. The message was clear: it is better to explore these dilemmas during training with your organization and chain partners, so you have time to rehearse before reality forces a decision.

Tools, frameworks and practical building blocks

On the network floor, participants continued to interact with peers and try security skills through an arcade-style game. Stands from public-private partnerships and initiatives added more concrete resources to the event.

Examples included the police initiative No More Leaks, the vulnerabilities analysis tool OpenKAT, CCV with CYRA, NEN with cybersecurity standards, and NCC-NL with subsidy opportunities.

Community value created by members

Between sessions and conversations, the community manager Irene van der Zanden received flowers from chair Lucinda Sterk. Irene reflected on five years of building the community together with and for members. She highlighted that the third edition of the event showed a community that has grown to over 7,500 members—larger, more active and more vibrant than ever.

Her key takeaway was simple: even though NCSC facilitates the community, it is the members who make both the event and the online environment valuable. Knowledge and experience are shared by people who face similar realities every day.

Where to go next

The event concluded with an invitation to explore the speaker presentations, event photos and cartoons created that day. If you want to stay involved, joining the NCSC Community is positioned as a way to connect with more than 7,500 entrepreneurs and professionals focused on digital resilience.

Ultimately, the takeaway from this event is that risico’s en incidenten beheersen is a shared responsibility. It requires structured learning tracks, scenario-based planning, incident readiness that includes legal and communication angles, and—just as important—practice that turns uncertainty into prepared action.

Source: https://www.ncsc.nl/nieuws/terugblik-op-ncsc-community-event-risicos-en-incidenten-beheersen