CBS and the Dutch National Cyber Security Centre (NCSC) report that cyber incidents affecting Dutch businesses have declined, but microbusinesses, self-employed workers, and other SMEs remain materially less protected than large enterprises. In the 2025 monitor, 86% of large companies had implemented at least 10 of 12 assessed security measures, compared with 13% of microbusinesses; companies reporting at least one external cyber incident fell to 4% in 2024. Phishing and spoofing remained the most commonly reported incident types, affecting 23% of businesses.
The disparity extends to foundational controls: only 29% of surveyed SMEs conduct risk assessments, 9% mandate security training, 37% encrypt data, 61% use multifactor authentication, and 66% keep backups at a separate physical location. The trend follows prior monitors showing increased adoption of 2FA—from 26% of businesses in 2017 to 61% in 2024—and fewer ransomware and other ICT-security incidents, while large organizations continue to report more incidents due partly to more complex environments and stronger detection. NCSC urged SMEs to adopt its five digital-security basics and CyberVeilig Check, noting that participation in security collaboration networks correlates with stronger safeguards.

See the reporting duties and controls this puts on the clock.
10 events from the most recent confirmed update back to the earliest known activity.
In 2025, 86% of Dutch companies with at least 250 employees had implemented at least 10 of 12 surveyed cybersecurity measures, compared with 13% of microbusinesses. MFA adoption reached 97% among large companies, while only 33% of microbusinesses used data encryption.
In 2024, 16% of large Dutch companies reported at least one externally caused cyber incident, unchanged from 2023. Across all companies, the proportion reporting at least one external incident was 4%, while 23% reported phishing or spoofing.
In 2023, 1% of Dutch companies with at least two employees reported ransomware; 2% of affected firms paid ransom. Twenty percent of firms reporting either internal or external cybersecurity incidents incurred costs, down from the 2016 levels.
The share of the largest Dutch companies reporting an externally caused ICT security incident fell to 18% in 2022. Ransomware-affected companies with at least two employees engaged a cybersecurity firm in 37% of cases and reported the incident to police in 18% of cases.
Dutch businesses reported 6,300 ransomware attacks in 2021, including 4,000 involving self-employed workers. Eleven percent of affected companies with at least two employees paid ransom.
The total number of internally and externally caused ICT security incidents began a downward trend across all Dutch company sizes in 2020.
Dutch companies' use of secure login methods rose from 26% in 2017; among companies with 10 to 50 employees, MFA use was 29%.
Nearly 40% of Dutch companies with 250 or more employees reported an externally caused cybersecurity incident in 2016.
NCSC presented CBS findings that only 29% of surveyed Dutch SMEs performed a risk analysis, 9% required ICT-security training, and 37% used data encryption. The findings also showed 61% used MFA and 66% retained backups at a separate physical location.
The Digital Trust Center became part of the Dutch National Cyber Security Centre on 1 January 2026.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcecbs.nl
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.