// BRIEFING

Would we even notice? Four ways an attack stays invisible. Zouden we het überhaupt merken? Vier manieren waarop een aanval onzichtbaar blijft.

Every other briefing assumes someone is watching. This one is about the watching itself: the logs, the alerts, the people on duty — in plain language: where it goes dark, what that costs, and the single control that switches the light back on. Elke andere briefing gaat ervan uit dat iemand meekijkt. Deze gaat over het meekijken zelf: de logs, de meldingen, de mensen die dienst hebben — in gewone taal: waar het donker wordt, wat dat kost, en welke maatregel het licht weer aandoet.

// STEP 01STAP 01

The evidence was deleted before anyone looked. Het bewijs was al weg voordat iemand keek.

logging / retention / nothing to investigate logging / bewaartermijn / niets om te onderzoeken
RETENTION: 14 DAYSBEWAARTERMIJN: 14 DAGEN
🖥️
Our systemsOnze systemen
🔎
Investigator · month 4Onderzoeker · maand 4
NOTHING TO READNIETS OM TE LEZEN
🗑
AUTO-DELETE · DAY 15AUTOMATISCH GEWIST · DAG 15
LOG
LOG
LOG

Most breaches are discovered months after they started, often by someone else: a bank, a customer, the police. The first question is always the same: what did they touch, and since when? The answer lives in logs. If those were never collected, or were overwritten after two weeks to save disk space, the answer is “we do not know”. Every server, cloud account and application writes logs; the question is only whether anyone kept them.

Business impact: without evidence you must assume the worst. Every customer record becomes “possibly affected”, every notification becomes maximal, and the regulator hears that we cannot say what happened. Storage for a year of the important logs costs less than one hour of the lawyers who will otherwise be guessing.

De meeste inbreuken worden maanden na het begin ontdekt, vaak door iemand anders: een bank, een klant, de politie. De eerste vraag is altijd dezelfde: wat hebben ze aangeraakt, en sinds wanneer? Het antwoord zit in logs. Als die nooit zijn verzameld, of na twee weken zijn overschreven om schijfruimte te sparen, is het antwoord “we weten het niet”. Elke server, elk cloudaccount en elke applicatie schrijft logs; de vraag is alleen of iemand ze heeft bewaard.

Bedrijfsimpact: zonder bewijs moet u van het slechtste uitgaan. Elk klantrecord wordt “mogelijk getroffen”, elke melding wordt maximaal, en de toezichthouder hoort dat we niet kunnen zeggen wat er is gebeurd. Een jaar opslag van de belangrijke logs kost minder dan één uur van de advocaten die anders moeten gokken.

NO EVIDENCE · MAXIMAL NOTIFICATION · “WE DON'T KNOW”GEEN BEWIJS · MAXIMALE MELDING · “WE WETEN HET NIET” FIX: CENTRAL LOG STORE + 12 MONTHS RETENTIONOPLOSSING: CENTRALE LOGOPSLAG + 12 MAANDEN BEWAREN
// STEP 02STAP 02

The alarm went off. Nobody was listening. Het alarm ging af. Niemand luisterde.

alert fatigue / no one on duty / the real one buried meldingsmoeheid / niemand van dienst / de echte begraven
SATURDAY 02:40ZATERDAG 02:40
LOGIN OK
DISK 81%
CERT 30D
LOGIN OK
SCAN DONE
NEW ADMIN 02:40NIEUWE ADMIN 02:40
DISK 82%
VPN OK
PATCH OK
LOGIN OK
BACKUP OK
DISK 83%
LOGIN OK
CERT 29D
VPN OK
LOGIN OK
🌙
Security team · off dutySecurityteam · geen dienst

Buying a monitoring tool produces alerts. It does not produce attention. A typical set-up generates thousands of notifications a day, most of them noise: a disk filling up, a certificate expiring, a user mistyping a password. The one that mattered — a new administrator account created at 02:40 on a Saturday — sits in the same list, in the same colour, and is read on Monday, if at all. Attackers know office hours. They work weekends and holidays on purpose.

Business impact: a tool without people is a receipt, not a defence. It proves afterwards that the warning was there. The real cost is the gap between “detected” and “seen”: for most organisations that gap is the weekend, and a weekend is enough to encrypt everything.

Een monitoringtool kopen levert meldingen op. Het levert geen aandacht op. Een gemiddelde opstelling produceert duizenden meldingen per dag, meestal ruis: een schijf die vol raakt, een certificaat dat verloopt, een gebruiker die zijn wachtwoord verkeerd typt. De melding die telde — een nieuw beheerdersaccount aangemaakt om 02:40 op een zaterdag — staat in dezelfde lijst, in dezelfde kleur, en wordt maandag gelezen, als het meezit. Aanvallers kennen kantooruren. Ze werken met opzet in het weekend en op feestdagen.

Bedrijfsimpact: een tool zonder mensen is een kassabon, geen verdediging. Het bewijst achteraf dat de waarschuwing er was. De echte kosten zitten in het gat tussen “gedetecteerd” en “gezien”: voor de meeste organisaties is dat gat het weekend, en een weekend is genoeg om alles te versleutelen.

NOISE · NO NIGHT SHIFT · READ ON MONDAYRUIS · GEEN NACHTDIENST · MAANDAG GELEZEN FIX: TEN DETECTIONS THAT MATTER + 24/7 EYES ON THEMOPLOSSING: TIEN DETECTIES DIE TELLEN + 24/7 IEMAND DIE KIJKT
// STEP 03STAP 03

We watch where it is easy. They attack where it is not. Wij kijken waar het makkelijk is. Zij vallen aan waar het niet is.

blind spots / coverage / cloud, SaaS, legacy, factory floor blinde vlekken / dekking / cloud, SaaS, legacy, fabrieksvloer
WHAT IS MONITOREDWAT WORDT BEWAAKT
🏢
Office networkKantoornetwerk
💻
LaptopsLaptops
☁️
Cloud accountsCloudaccounts
🧩
SaaS toolsSaaS-tools
🏭
Legacy · factoryLegacy · fabriek
🕵️SETTLES WHERE NO ONE LOOKSNESTELT ZICH WAAR NIEMAND KIJKT

Monitoring grew up around the office network and the laptops, because that is where the tools worked first. Meanwhile the business moved: to cloud accounts, to a hundred SaaS tools, to the production line whose controllers run software from 2009 and cannot send a log anywhere. Ask for the coverage map and the honest answer is often “we see about half”. Attackers find the other half quickly, because it is also the half nobody patches.

Business impact: the board hears “we have monitoring” and assumes it means everything. A breach in the unmonitored half lasts months rather than hours, and is found by an outsider. The first step is not more tooling; it is a one-page map that says, per system, watched or not watched, and who signed off on the “not”.

Monitoring is opgegroeid rond het kantoornetwerk en de laptops, omdat de tools daar het eerst werkten. Ondertussen verhuisde het bedrijf: naar cloudaccounts, naar honderd SaaS-tools, naar de productielijn waarvan de besturingen software uit 2009 draaien en nergens een log naartoe kunnen sturen. Vraag om de dekkingskaart en het eerlijke antwoord is vaak “we zien ongeveer de helft”. Aanvallers vinden de andere helft snel, want dat is ook de helft die niemand patcht.

Bedrijfsimpact: de directie hoort “we hebben monitoring” en neemt aan dat het alles dekt. Een inbreuk in de onbewaakte helft duurt maanden in plaats van uren, en wordt door een buitenstaander gevonden. De eerste stap is niet meer tooling; het is een kaart van één pagina die per systeem zegt: bewaakt of niet bewaakt, en wie het “niet” heeft afgetekend.

HALF THE ESTATE UNSEEN · FOUND BY OUTSIDERSHELFT ONZICHTBAAR · GEVONDEN DOOR BUITENSTAANDERS FIX: A SIGNED COVERAGE MAP + CLOUD AND SAAS LOGS IN THE SAME PLACEOPLOSSING: EEN AFGETEKENDE DEKKINGSKAART + CLOUD- EN SAAS-LOGS OP DEZELFDE PLEK
// STEP 04STAP 04

Detected on Friday. Handled on Monday. Vrijdag gedetecteerd. Maandag opgepakt.

detection without response / the ticket queue / dwell time detectie zonder respons / de ticketwachtrij / verblijftijd
FRIDAY 17:30VRIJDAG 17:30
FRISATSUNMONMA
🔔
Alert firesAlarm gaat af
🕵️
Attacker · insideAanvaller · binnen
TICKET QUEUE · P3TICKETWACHTRIJ · P3
TICKET

Detection is only half a control. The alert fires, becomes a ticket, lands in a queue with a priority someone set years ago, and waits. The person who could isolate the machine is not the person who saw the alert, and neither of them is sure they are allowed to pull a server off the network on a Friday evening. So it waits until Monday. The attacker did not wait.

Business impact: the difference between a contained incident and a company-wide one is usually measured in hours, and it is decided by two things: whether someone is on duty, and whether they have written permission to act without asking. Both are decisions for this room, not for the tool.

Detectie is maar een halve maatregel. Het alarm gaat af, wordt een ticket, landt in een wachtrij met een prioriteit die iemand jaren geleden heeft ingesteld, en wacht. De persoon die de machine kan isoleren is niet degene die het alarm zag, en geen van beiden weet zeker of hij op vrijdagavond een server van het netwerk mag halen. Dus wacht het tot maandag. De aanvaller wachtte niet.

Bedrijfsimpact: het verschil tussen een beheerst incident en een bedrijfsbreed incident wordt meestal in uren gemeten, en wordt door twee dingen bepaald: of er iemand dienst heeft, en of die schriftelijk toestemming heeft om te handelen zonder te vragen. Beide zijn beslissingen voor deze vergaderzaal, niet voor de tool.

SEEN BUT NOT STOPPED · THE ATTACKER HAD THE WEEKENDGEZIEN MAAR NIET GESTOPT · DE AANVALLER HAD HET WEEKEND FIX: PLAYBOOKS + STANDING AUTHORITY TO ISOLATEOPLOSSING: DRAAIBOEKEN + VASTE BEVOEGDHEID OM TE ISOLEREN
// CONTROLSMAATREGELEN

What makes us see. Wat ons laat zien.

one place for logs, ten detections, people on duty, permission to act één plek voor logs, tien detecties, mensen van dienst, bevoegdheid om te handelen
DEFENCE STACKVERDEDIGINGSLAGEN
CENTRAL LOGSCENTRALE LOGS EDR 24/7 MONITORING24/7 BEWAKING COVERAGE MAPDEKKINGSKAART PLAYBOOKSDRAAIBOEKEN
ControlFixesIn one line
Central log storeLogs (01)Every key system sends its logs to one place that an attacker cannot edit, kept for at least a year.
Ten detectionsAlerts (02)A short, written list of the events that matter to us: new administrator, backup deleted, login from a new country, gigabytes leaving. Everything else is a report, not an alarm.
24/7 monitoringAlerts (02), Response (04)Someone awake and watching at 02:40, in-house or a managed provider. The contract says who acts within how many minutes, not just who emails.
EDR everywhereAlerts (02), Blind spots (03)Software on every endpoint and server that spots attacker behaviour and reports to the same place as the logs.
Coverage mapBlind spots (03)One page: every system, watched or not watched, and a signature under every “not”. Reviewed quarterly.
Playbooks and authorityResponse (04)For each of the ten detections, the steps to take and standing permission to isolate a machine or account without asking first.
Detection testingAll fourSimulate the attack a few times a year and time how long until someone acts. If nobody notices, that is the finding.
Two numbers to the boardAll fourMean time to detect and mean time to respond, every quarter, in hours. The trend matters more than the number.
MaatregelLost opIn één zin
Centrale logopslagLogs (01)Elk belangrijk systeem stuurt zijn logs naar één plek die een aanvaller niet kan aanpassen, minstens een jaar bewaard.
Tien detectiesMeldingen (02)Een korte, opgeschreven lijst van gebeurtenissen die voor ons tellen: nieuwe beheerder, back-up gewist, inlog vanuit een nieuw land, gigabytes die vertrekken. Alles daarbuiten is een rapport, geen alarm.
24/7 bewakingMeldingen (02), Respons (04)Iemand die wakker is en kijkt om 02:40, intern of bij een dienstverlener. Het contract zegt wie binnen hoeveel minuten handelt, niet alleen wie mailt.
EDR overalMeldingen (02), Blinde vlekken (03)Software op elk apparaat en elke server die aanvallersgedrag herkent en rapporteert naar dezelfde plek als de logs.
DekkingskaartBlinde vlekken (03)Eén pagina: elk systeem, bewaakt of niet bewaakt, en een handtekening onder elk “niet”. Elk kwartaal herzien.
Draaiboeken en bevoegdheidRespons (04)Voor elk van de tien detecties de te nemen stappen en een vaste bevoegdheid om een machine of account te isoleren zonder eerst te vragen.
DetectietestenAlle vierSimuleer de aanval een paar keer per jaar en klok hoe lang het duurt voordat iemand handelt. Merkt niemand het, dan is dát de bevinding.
Twee getallen naar de directieAlle vierGemiddelde tijd tot detectie en gemiddelde tijd tot respons, elk kwartaal, in uren. De trend telt zwaarder dan het getal.
The board-level point: prevention fails eventually; every other briefing on this site assumes it. The only real question is whether we find out in hours, from our own screens, or in months, from a journalist. Ask one thing at the next meeting: what was our mean time to detect last quarter? If nobody can answer, that is the answer. De kern voor de directie: preventie faalt uiteindelijk; elke andere briefing op deze site gaat daarvan uit. De enige echte vraag is of we het binnen uren ontdekken, op onze eigen schermen, of na maanden, van een journalist. Stel bij de volgende vergadering één vraag: wat was onze gemiddelde tijd tot detectie vorig kwartaal? Kan niemand antwoorden, dan is dát het antwoord.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Something will get past prevention. Without detection, every other risk on this site runs for months instead of hours.Er komt iets door de preventie. Zonder detectie loopt elk ander risico op deze site maanden in plaats van uren.

ImpactImpactHighHoog

Long dwell time multiplies every incident: more systems, more data, no evidence, maximal notifications, and discovery by an outsider.Een lange verblijftijd vermenigvuldigt elk incident: meer systemen, meer data, geen bewijs, maximale meldingen, en ontdekking door een buitenstaander.

Residual after controlsRestrisico na maatregelenLow to mediumLaag tot middel

With central logs, ten tuned detections and someone on duty with authority to act, most intrusions are caught and contained within hours.Met centrale logs, tien afgestelde detecties en iemand van dienst met bevoegdheid om te handelen, worden de meeste inbraken binnen uren ontdekt en ingedamd.

Risk ownerRisico-eigenaarCIO / CISOCIO / CISO

Owns the coverage map and the two numbers. The board owns the decision to fund people on duty, not only tools.Eigenaar van de dekkingskaart en de twee getallen. De directie is eigenaar van de beslissing om mensen van dienst te betalen, niet alleen tools.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

mean time to detect last quarter, in hours · % of critical systems sending logs to the central store · log retention in months · % of high alerts acted on within one hour, including nights and weekends.gemiddelde tijd tot detectie vorig kwartaal, in uren · % kritieke systemen dat logs naar de centrale opslag stuurt · bewaartermijn van logs in maanden · % hoge meldingen binnen een uur opgepakt, inclusief nachten en weekenden.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Insufficient logging, monitoring coverage and out-of-hours response allow an intrusion to persist undetected for months, multiplying its damage and leaving no evidence for investigation or notification.”“Onvoldoende logging, monitoringdekking en respons buiten kantooruren laten een inbraak maandenlang onopgemerkt voortduren, vermenigvuldigen de schade en laten geen bewijs achter voor onderzoek of melding.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Incident handling and logging are named risk management measures. You cannot report within 24 hours what you cannot detect, so detection capability is implicitly mandatory. Confirm scope with legal.There is no NIS2 certificate. Ask what they monitor around the clock, how fast they must tell you about an incident touching your data, and write that number into the contract.The reporting clocks start when you become aware: early warning within about 24 hours, notification within 72, final report within a month. Late awareness does not stop the clock; the regulator will ask why detection took months.
DORAFor financial entities: mechanisms to detect anomalous activity promptly, logging, and classification of incidents within hours. Detection is an explicit chapter of the ICT risk framework. Confirm scope with legal.Check whether monitoring of the service you outsource is in their scope, what their notification deadline to you is, and whether their logs are available to your investigation.Classification and the initial notification run in hours after awareness, intermediate within about 72 hours, final within a month. Your logs are the evidence those reports are built on; without them the reports are guesses.
SOC 2If you issue one: the monitoring criteria test logging, anomaly detection, alert handling and incident response over the period. Unhandled alerts become printed exceptions.Read whether monitoring and incident response are in scope, how fast they commit to detect and notify, and the exceptions in that area. A clean opinion with monitoring out of scope proves nothing here.An intrusion discovered late is a control failure for the whole period it went unseen. Expect a deviation, a bridge letter request, and customers asking for your detection timeline.
ISAE 3402Relevant where processing affects financial reporting: logging of who changed what, and monitoring of processing integrity. Security monitoring is only covered if it is a control objective.Check the control objectives for logging and monitoring. If they are absent, the report says nothing about whether the supplier would notice an intrusion in your data.An undetected intrusion in a service organisation is a risk of misstatement for every client. It must be disclosed to the user auditors, and the missing evidence is itself a finding.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Incidentafhandeling en logging zijn benoemde risicobeheersmaatregelen. U kunt niet binnen 24 uur melden wat u niet detecteert, dus detectievermogen is impliciet verplicht. Bevestig de reikwijdte met legal.Er bestaat geen NIS2-certificaat. Vraag wat zij dag en nacht bewaken, hoe snel zij u moeten informeren over een incident dat uw data raakt, en zet dat getal in het contract.De meldklokken starten zodra u het weet: vroegtijdige waarschuwing binnen ongeveer 24 uur, melding binnen 72 uur, eindrapport binnen een maand. Laat ontdekken stopt de klok niet; de toezichthouder vraagt waarom detectie maanden duurde.
DORAVoor financiële instellingen: mechanismen om afwijkend gedrag snel te detecteren, logging, en classificatie van incidenten binnen uren. Detectie is een expliciet hoofdstuk van het ICT-risicokader. Bevestig de reikwijdte met legal.Controleer of bewaking van de uitbestede dienst binnen hun scope valt, welke meldtermijn zij naar u hebben, en of hun logs beschikbaar zijn voor uw onderzoek.Classificatie en de eerste melding lopen in uren na ontdekking, tussenrapport binnen ongeveer 72 uur, eindrapport binnen een maand. Uw logs zijn het bewijs waarop die rapporten rusten; zonder logs zijn het gissingen.
SOC 2Als u er zelf een afgeeft: de monitoringcriteria toetsen logging, detectie van afwijkingen, afhandeling van meldingen en incidentrespons over de periode. Onbehandelde meldingen worden gedrukte afwijkingen.Lees of monitoring en incidentrespons binnen scope vallen, hoe snel zij beloven te detecteren en te melden, en welke afwijkingen daar staan. Een schoon oordeel met monitoring buiten scope bewijst hier niets.Een laat ontdekte inbraak is een tekortkoming voor de hele periode dat die onopgemerkt bleef. Verwacht een afwijking, een verzoek om een bridge letter, en klanten die uw detectietijdlijn opvragen.
ISAE 3402Relevant waar verwerking de financiële verslaggeving raakt: logging van wie wat heeft gewijzigd, en bewaking van de integriteit van de verwerking. Securitymonitoring valt er alleen onder als het een beheersdoelstelling is.Controleer de beheersdoelstellingen op logging en monitoring. Ontbreken die, dan zegt het rapport niets over of de leverancier een inbraak in uw data zou opmerken.Een onopgemerkte inbraak bij een serviceorganisatie is een risico op onjuistheden voor elke klant. Het moet aan de auditors van de klanten worden gemeld, en het ontbrekende bewijs is zelf een bevinding.