The Netherlands integrated the Digital Trust Center (DTC) into the National Cyber Security Centre (NCSC) on 1 January 2026, consolidating the DTC, NCSC and CSIRT-DSP into a national capability for public- and private-sector cyber-threat, victim and target notifications. The organizations had already established a single NCSC intake point for threat and incident data and a common assessment framework, aiming to provide organizations with a scalable warning service from one sender. The Wet bevordering digitale weerbaarheid bedrijven provides the legal basis to process and share vulnerability, threat and incident information—including necessary IP-address and business-contact data—with non-critical businesses.
The DTC’s notification service expanded from targeted alerts launched in 2021 to more than 140,000 company-specific warnings in 2023 and over 238,000 vulnerability warnings during 2024. Notifications covered exposed internet services, configuration errors, vulnerable software and leaked corporate credentials, including alerts connected to Operation Endgame. At Saxion University of Applied Sciences, a DTC alert about stolen email credentials enabled rapid password resets, log reviews and user notification; MFA prevented account misuse and the institution found no resulting damage. The integrated NCSC service will continue delivering actionable alerts and supporting Dutch organizations with NIS2 preparedness guidance, community intelligence sharing and cyber-resilience tools.

See the reporting duties and controls this puts on the clock.
22 events from the most recent confirmed update back to the earliest known activity.
The DTC notified Saxion University of Applied Sciences that stolen Saxion email credentials had been identified in Operation Endgame victim data. Saxion reset affected active accounts, reviewed logs, and found no evidence of misuse or damage; it said MFA prevented credential-based logins.
Hundreds of DTC Community members attended the first in-person Digital Trust Community Event to exchange knowledge on AI, quantum technology, behavioral change, and ransomware.
The Europe-wide Operation Endgame law-enforcement action against botnets used in ransomware attacks resulted in 33 servers being taken offline in Dutch data centers. The operation also exposed Dutch victim data held by criminals.
During 2024, the DTC warned Dutch businesses about more than 238,000 vulnerabilities, a 70% increase in Notification Service warnings over 2023.
The DTC and the Ministry of Economic Affairs and Climate held the webinar “De impact van NIS2 op jouw organisatie” to explain the NIS2 Directive and preparations for forthcoming legislation.
The DTC, NCSC, and CSIRT-DSP began intensive cooperation on target and victim notifications, expanding and automating the delivery of company-specific threat warnings.
The DTC published its Benchmarkonderzoek, examining cybersecurity-control adoption among Dutch self-employed workers and SMEs, including organizations with and without IT service providers.
The DTC notification service sent more than 140,000 company-specific cyber-threat warnings to Dutch businesses during 2023, aided by expanded intelligence sources, automation, and cooperation with NCSC and CSIRT-DSP.
The DTC launched the CyberVeilig Check in 2023, offering self-employed workers and small and medium-sized businesses a practical checklist of baseline cybersecurity measures.
By 15 June 2022, the DTC had proactively notified more than 1,700 Dutch companies of serious company-specific threats or vulnerabilities, including exposed systems, configuration errors, and stolen credentials.
During 2022, the DTC sent more than 6,500 warnings to companies that were victims of, or vulnerable to, cyberattacks. Many warnings involved vulnerabilities in internet-accessible systems.
A DTC pilot matched participant technical data against threat intelligence to issue automated targeted warnings. Its first pilot notification was issued in October 2021.
After receiving OKTT status, the DTC began proactively notifying individual non-critical-sector companies about serious vulnerabilities and other acute cyber threats using intelligence shared by the NCSC.
During 2021, the DTC launched its Community information-sharing environment and introduced active warnings for individual companies facing serious cyber threats.
The Digital Trust Center (DTC) was established within the Dutch Ministry of Economic Affairs and Climate Policy to improve the cyber resilience of non-vital Dutch businesses.
The Digital Trust Center became part of the National Cyber Security Centre following the integration of the DTC, NCSC, and CSIRT-DSP functions.
The Tweede Kamer adopted the proposed Wet bevordering digitale weerbaarheid bedrijven by a large majority, providing a legal basis for warning non-vital businesses about vulnerabilities and security incidents.
The three organizations intensified work on a joint national cyber-threat warning service, using a central NCSC intake point and a uniform assessment framework for company-specific notifications.
The Wet bevordering digitale weerbaarheid bedrijven entered into force, authorizing the Dutch economic minister to process and distribute vulnerability, threat, and incident information to non-vital businesses, including for direct risk notifications.
The DTC's notification-service pilot involved 57 companies; 46 received one or more alerts, totaling more than 2,000 notifications based on approximately one million submitted technical data points.
Following a DTC notification, B.F. Systemen immediately corrected an incorrectly configured LDAP service that was publicly accessible and could have exposed confidential information.
The DTC promoted its closed Community for Dutch businesses and cybersecurity personnel, providing urgent threat intelligence, a knowledge-sharing forum, and access to cybersecurity experts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
19 references tracked. Mallory keeps watching after this page renders.
digitaltrustcenter.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.