Digital resilience
AI and cybersecurity: what the statement from Dutch intelligence and security services asks of your business
In September 2026 the Dutch intelligence services AIVD and MIVD, the NCSC, the NCTV, the Public Prosecution Service, CIO Rijk and the police published a joint statement on AI and cybersecurity. It is addressed to directors. Here is what it says and what it means for a business without its own security department.
What the statement says
Attackers use AI to find and exploit vulnerabilities in software faster. That does not take advanced models, because it also works with models anyone can access. As a result a larger group can carry out attacks, phishing emails get better, and the time between a vulnerability becoming known and its abuse gets shorter. On updates, the services write that weeks become days, and days become hours.
What stays the same
The measures the statement names are not new. Good updates, few systems reachable from the internet, logging, and knowing which systems you have. According to the services, organisations that have this in order are considerably stronger. What differs from before is the speed at which it now has to happen.
The three actions from the statement
- Get the basics in order. Reduce the number of systems exposed to the internet and replace systems that no longer receive security updates. Invest in staff awareness and report incidents to the police.
- Check whether your security still fits. Make sure updates reach your systems faster, and prepare for the moment it goes wrong anyway. Make a plan and practise it.
- Take signals seriously. Follow developments and get advice from technical specialists.
What this means for an SME
In a smaller business the director is usually the owner. They do not need to be a specialist. Someone does need to know which systems exist, who updates them and how fast. Many businesses have their website, email or software managed by a supplier. Ask that supplier how fast security updates are installed and who you call in an incident, and put it in writing.
Your own use of AI too
The statement also asks you to include the risks of AI inside your own organisation in your security. Think of an AI assistant with access to your email or CRM, or customer data pasted into a chat service. Record for each use where the data goes and what the AI may do.
Where to start
The Dutch NCSC has five fundamentals for businesses: identify your risks, encourage safe behaviour, protect systems and devices, manage access to data and services, and prepare for incidents. Our playbook turns them into five steps you can take this month.
Frequently asked questions
Does the Dutch Cyberbeveiligingswet apply to my business?
That depends on your sector and size. The law, the Dutch implementation of NIS2, has applied since 15 August 2026 to more than 8,000 organisations in 18 sectors. If it does not apply to you, a customer it does apply to may ask how your security is arranged.
Should we deploy AI ourselves to defend?
That is not the first step. The statement puts the emphasis on the basics: updates, a small attack surface, logging and good backups.
Sources
- AIVD, MIVD, NCSC, NCTV, OM, CIO Rijk en Politie: AI versnelt de dreiging, nu handelen is noodzakelijk · Gezamenlijke verklaring aan bestuurders, september 2026
- NCSC: de 5 basisprincipes van digitale weerbaarheid · Voor zzp en mkb
- Rijksoverheid: Cyberbeveiligingswet vanaf 15 augustus 2026 van kracht · Ruim 8000 organisaties in 18 sectoren, 7 juli 2026
Our approach
From advice to management, with one partner
The same rhythm for every project.
Advice
We start with a conversation, not with code. First clarity on what you need and what you do not.
Build
We build and integrate to measure, with technology that fits you. You own your data and your code.
Manage
We stay involved: monitoring, adjusting and growing with your business.
Do you know which of your systems are reachable from the internet?
Call us and we will go through your list together.
Call 085 083 5775A 30-minute intake