The latest Cybersecuritymonitor 2025 from the CBS (Statistics Netherlands) paints a mixed picture for Dutch businesses. On the one hand, the share of companies that experienced a cyberattack has dropped to the lowest level seen in the past nine years. On the other hand, the gap in cyber resilience between large and small organisations remains stubbornly wide.
Below, we summarize the key findings that matter most for managers, IT leaders, and owners who want to understand where progress is being made—and where more preparation is still needed.
Cybersecuritymonitor 2025: fewer companies faced outside attacks
One of the clearest trends in the Cybersecuritymonitor 2025 is the decline in cyber incidents caused by attacks from the outside. In 2024, only 4% of companies reported at least one such incident. That is a substantial decrease compared with 11% in 2016.
This downward trend appears across company sizes. The main exception is the largest companies (250 employees or more), where the percentage remained stable at 16% in 2023 and did not show the same drop.
Phishing and spoofing still dominate the threat landscape
Even as incident numbers decline, the types of attacks companies report are fairly consistent. According to the monitor, phishing and spoofing are by far the most frequently occurring incident types. In 2024, 23% of companies indicated they had experienced phishing and/or spoofing.
Other incident categories appear much less often. DDoS attacks, data leaks, and BEC (Business Email Compromise) fraud were each reported by roughly 1% of all companies.
Notably, larger organisations are affected more often by certain high-impact incident types. In the monitor, 14% of large companies reported a data leak or data manipulation, and 11% reported BEC fraud. Ransomware, meanwhile, is reported by just 1% of companies in this study.
Cyber resilience depends heavily on how many security measures companies adopt
A central message of the Cybersecuritymonitor 2025 is that cyber resilience rises as companies implement more security measures. Large businesses take far more steps than smaller ones—especially when it comes to the wider set of measures covered in the study.
Large companies adopt far more measures than microbusinesses
In 2025, 86% of large companies implemented 10 or more of the 12 security measures that were assessed. By comparison, microbusinesses (with 2 to 10 employees) scored much lower: only 13% implemented 10 or more measures. Even more striking, 40% of microbusinesses reported adopting three or fewer measures.
Freelancers (zzp’ers) are reported to have the lowest scores of all groups.
Some basics are widespread, but advanced measures show bigger gaps
For well-known measures, the difference between company sizes is smaller. For example, antivirus software is used by 85% of companies overall.
However, the monitor shows much larger disparities for more complex protections. For instance, data encryption is used by 33% of microbusinesses, while it is used by 91% of large companies. This illustrates how the resilience gap is not only about “having something,” but about adopting protections that can significantly reduce damage when incidents occur.
MFA adoption keeps rising—and is now nearly universal at large firms
One of the most positive developments in the Cybersecuritymonitor 2025 is the continued growth of multi-factor authentication (MFA). MFA improves the security of logins by requiring more than one proof of identity.
At large companies (250 employees or more), MFA increased from 71% in 2017 to 97% in 2025. For smaller companies (10 to 50 employees), adoption rose from 29% in 2017 to 79% in 2025.
In practice, MFA is now among the broadest adopted security measures across Dutch businesses.
Which sectors lead—and which lag behind
The monitor also highlights differences between business sectors. Industries that work intensively with ICT systems or handle sensitive personal data tend to implement more security measures over time.
According to the Cybersecuritymonitor 2025, the ICT sector, financial services, and healthcare generally lead. Meanwhile, hospitality remains one of the sectors that lags.
As an example, more than half of financial services companies implement 10 or more security measures. In contrast, only 7% of hospitality businesses do so.
What to do next: prepare, practice, and institutionalize
The findings in the Cybersecuritymonitor 2025 are not only about percentages. They also point to practical next steps for organisations that want to strengthen their security without relying on luck.
Because larger organisations more often implement the harder-to-reach measures, smaller businesses are encouraged to focus on preparation and organisational embedding of controls. The monitor suggests building capabilities such as incident preparedness, regular testing, and clear procedures.
Practice incident response, not just policies
One concrete recommendation is to practice handling cyber incidents. That can include running exercises so staff know what to do when phishing or spoofing attempts succeed and suspicious activity needs to be contained.
Create a contact list and an incident response plan
Another suggested step is to set up a contact list and an incident response plan. These items help teams coordinate quickly across roles—especially when time pressure and uncertainty are high.
Organize access management
Finally, access management is singled out as a key organisational activity. Strong access controls reduce the risk that attackers can move laterally inside an organisation after compromising credentials.
Why the Cybersecuritymonitor matters
The Cybersecuritymonitor 2025 has been published by CBS for the ninth year in a row, commissioned at the request of the Ministry of Economic Affairs and Climate Policy. Its goal is to provide an up-to-date view of cyber resilience among Dutch businesses and individuals.
The monitor relies mainly on CBS data about security measures and cyber incidents. It also explores related topics such as whether companies have a cyber insurance policy, what documentation exists about controls or procedures, and how businesses score on applying safe internet standards.
For decision-makers, these details help move the conversation from “we have security” to “we can prove we are resilient in practice.”
Conclusion: progress is real, but the resilience gap is not closing
The Cybersecuritymonitor 2025 shows encouraging progress: fewer companies reported cyber incidents caused by outside attacks, and MFA adoption continues to rise. Yet the overall message is clear—security maturity is not evenly distributed.
Large companies implement a broader range of measures and more advanced protections like encryption. Smaller firms, including microbusinesses and freelancers, lag behind and therefore face a persistent resilience gap. The most effective next step for those organisations is to prepare and institutionalize controls: test incident response, establish clear procedures, and strengthen access management.
In a landscape where phishing and spoofing remain the most common threats, readiness—not just awareness—will determine how quickly organisations can respond and limit damage when incidents occur.
Source: https://www.ncsc.nl/nieuws/cybersecuritymonitor-2025-minder-cyberaanvallen-weerbaarheidskloof-blijft
