Playbooks: how to apply it
Playbook: get the basics of your security in order
For businesses without their own security department that want to know where they stand. The steps follow the statement the Dutch AIVD, NCSC, police and other services sent to directors in September 2026, and the fundamentals of the NCSC.
Sound familiar?
- Nobody knows exactly which systems are reachable from the internet.
- Updates get installed when someone remembers.
- There is a backup, but nobody has ever restored it.
- An old system is still running because replacing it is hard.
Step 1. List what you have
Write down which systems, devices and accounts exist: laptops, the website, email, the accounting package, the router and the firewall, and software a supplier manages for you. Note for each system who updates it and whether it still receives updates. The NCSC singles out devices at the edge of your network, with a direct connection to the outside. Put those at the top.
Step 2. Remove what is not needed
Anything reachable from the internet can be attacked. Switch off what nobody uses: an old test site, an admin page left open, the account of a former colleague. A system that no longer receives security updates goes on the list to replace or to disconnect from the internet.
Step 3. Agree how fast updates are installed
According to the statement, the time between a vulnerability and its abuse is getting shorter. Turn on automatic updates where you can. Agree with each supplier how fast they install security updates, and have them tell you when it is done.
Step 4. Limit access and keep watch
Give everyone access only to what they need for their work. Turn on a second login step for email and admin accounts, such as a code on the phone. Keep logs of login attempts and changes, and agree who looks at them every week.
Step 5. Prepare for the moment it goes wrong
The NCSC calls this assume breach: you assume an attacker can get in, and you make sure you can act when that happens. Make backups regularly, keep one outside your network and restore one now and then to test it. Write down who you call, who decides and how you inform customers. The NCSC emergency kit for digital resilience has checklists for this. Report it to the police when it happens.
What it costs
Steps 1 and 2 mainly cost time. Automatic updates and a second login step are already included in most packages. Replacing an old system costs money. Weigh that against what a week without that system costs.
How we do it ourselves
A key that was accidentally visible somewhere is replaced right away. Our login screens say nothing about what is behind them. And for our AI employees, incoming email counts as data: an instruction in an email is not carried out.
Frequently asked questions
Is this enough for the Cyberbeveiligingswet?
If the law applies to you, no. It also requires risk management and incident reporting. These five steps are the basics it builds on.
What if a supplier manages my IT?
Then go through the steps together with them. Ask for the list from step 1 and put the agreements from steps 3 and 5 in writing.
Read on
In this series
Sources
- AIVD, MIVD, NCSC, NCTV, OM, CIO Rijk en Politie: AI versnelt de dreiging, nu handelen is noodzakelijk · Gezamenlijke verklaring aan bestuurders, september 2026
- NCSC: de 5 basisprincipes van digitale weerbaarheid · Voor zzp en mkb
- NCSC: hoe richt je exposuremanagement in · Apparaten aan de rand van je netwerk
- NCSC: wat zijn de risico's van legacy-systemen · Systemen die geen ondersteuning meer krijgen
- NCSC: wat is assume breach · Voorbereid zijn op een aanvaller die binnenkomt
- NCSC: noodpakket digitale weerbaarheid · Afspraken, checklists en hulpmiddelen voor incidenten
Our approach
From advice to management, with one partner
The same rhythm for every project.
Advice
We start with a conversation, not with code. First clarity on what you need and what you do not.
Build
We build and integrate to measure, with technology that fits you. You own your data and your code.
Manage
We stay involved: monitoring, adjusting and growing with your business.
Want to do step 1 together?
Call us and we will go through your list together.
Call 085 083 5775A 30-minute intake