The alarm has gone off. What happens next is decided not by technology but by who picks up the phone, what gets switched off, and who says what to whom — in plain language: how the first three days derail, and what has to be ready in advance. Het alarm is afgegaan. Wat daarna gebeurt wordt niet bepaald door techniek, maar door wie de telefoon opneemt, wat er wordt uitgezet en wie wat tegen wie zegt — in gewone taal: hoe de eerste drie dagen ontsporen, en wat vooraf klaar moet liggen.
The on-call engineer sees the encryption spreading at 03:00 on a Sunday. Switching off the network would stop it — and also stop the factory, the webshop, the hospital ward. Is that the engineer's call? Their manager's? The CIO's, who is on holiday? The CEO's, whose number they do not have? Every minute spent finding out, the incident grows. Most companies discover on the night itself that nobody has ever written down who may pull the plug.
Business impact: the hours lost here are the most expensive of the whole incident, because the damage is still small and every decision still matters. Indecision is itself a decision: it means the attacker keeps going. And the person who finally acts without a mandate carries the blame for whatever it costs.
De dienstdoende engineer ziet om 03:00 op zondag de versleuteling zich verspreiden. Het netwerk uitzetten zou het stoppen — en ook de fabriek, de webshop, de ziekenhuisafdeling. Mag de engineer dat beslissen? Zijn leidinggevende? De CIO, die op vakantie is? De CEO, van wie hij het nummer niet heeft? Elke minuut die aan uitzoeken opgaat, groeit het incident. De meeste bedrijven ontdekken die nacht zelf dat nooit is opgeschreven wie de stekker eruit mag trekken.
Bedrijfsimpact: de uren die hier verloren gaan zijn de duurste van het hele incident, omdat de schade nog klein is en elke beslissing nog telt. Niet beslissen is ook een beslissing: de aanvaller gaat door. En degene die uiteindelijk zonder mandaat ingrijpt, draagt de schuld voor wat het kost.
The instinct of every capable engineer is to fix things. Reboot the server, wipe the laptop, restore the image, rotate the passwords, get people working again. Each of those actions destroys something: the memory that held the attacker's tools, the logs that showed which files were opened, the timestamps that prove when it started. By the time a forensics team arrives, the crime scene has been cleaned.
Business impact: without evidence, we cannot answer the only questions that matter afterwards. Was customer data taken? Which customers? Since when? The regulator, the insurer and our own lawyers will all ask. “We do not know” means notifying everyone, assuming the worst, and paying for it — and the insurer may refuse the claim because we cannot show what happened.
Het instinct van elke goede engineer is dingen repareren. De server herstarten, de laptop wissen, het image terugzetten, de wachtwoorden vervangen, mensen weer aan het werk krijgen. Elk van die handelingen vernietigt iets: het geheugen waarin het gereedschap van de aanvaller stond, de logs die lieten zien welke bestanden zijn geopend, de tijdstempels die bewijzen wanneer het begon. Tegen de tijd dat een forensisch team aankomt, is de plaats delict schoongemaakt.
Bedrijfsimpact: zonder bewijs kunnen we de enige vragen die achteraf tellen niet beantwoorden. Zijn er klantgegevens meegenomen? Van welke klanten? Sinds wanneer? De toezichthouder, de verzekeraar en onze eigen advocaten zullen het allemaal vragen. “We weten het niet” betekent iedereen informeren, van het slechtste uitgaan en daarvoor betalen — en de verzekeraar kan de claim weigeren omdat we niet kunnen aantonen wat er is gebeurd.
On day one, five groups want answers at once: staff, customers, press, the regulator and the insurer. Without a plan, five different people answer them. Someone reassures customers that “no data was affected” before anyone knows. Someone tells the press “no comment”, which reads as guilt. Nobody calls the regulator, though the legal clocks — 72 hours for a personal-data breach under GDPR, and shorter early-warning duties for organisations under NIS2 — started the moment we became aware. Which of those apply to us is a question for legal, but the answer has to be known before the incident, not looked up during it.
Business impact: every contradictory statement is on record and will be quoted back to us by journalists, customers and lawyers. A missed statutory deadline is a separate offence on top of the breach. And the insurer's policy almost certainly requires notification within a fixed window; miss it and the cover we paid for may not respond.
Op dag één willen vijf groepen tegelijk antwoord: personeel, klanten, pers, de toezichthouder en de verzekeraar. Zonder plan geven vijf verschillende mensen dat antwoord. Iemand stelt klanten gerust dat “er geen gegevens zijn geraakt” voordat iemand dat weet. Iemand zegt tegen de pers “geen commentaar”, wat als schuldbekentenis wordt gelezen. Niemand belt de toezichthouder, terwijl de wettelijke klokken — 72 uur voor een datalek onder de AVG, en kortere vroegtijdige-waarschuwingsplichten voor organisaties onder NIS2 — begonnen te lopen op het moment dat we het ontdekten. Welke daarvan op ons van toepassing zijn is een vraag voor juridisch, maar het antwoord moet vóór het incident bekend zijn, niet tijdens het incident worden opgezocht.
Bedrijfsimpact: elke tegenstrijdige uitspraak ligt vast en wordt ons door journalisten, klanten en advocaten voorgehouden. Een gemiste wettelijke termijn is een aparte overtreding bovenop het lek. En de polis van de verzekeraar eist vrijwel zeker een melding binnen een vaste termijn; mis die, en de dekking waarvoor we betaalden komt misschien niet uit.
Serious incidents need people we do not employ: forensic investigators, a negotiator who has talked to this ransomware group before, lawyers who know the notification rules, a crisis-communication team. Without a retainer, day one becomes a procurement exercise. Firms are fully booked, because attacks come in waves and everyone is calling at once. Contracts need signatures, signatures need approvals, approvals need people who are asleep. Meanwhile the attacker is still inside.
Business impact: each hour without expert help is an hour of decisions made by people who have never done this before. A retainer costs a fixed, modest fee per year and buys one phone number that answers within the hour, with a team that already knows our systems and our contacts. It is the cheapest line in the entire security budget — and the one most often missing.
Ernstige incidenten vragen om mensen die niet bij ons op de loonlijst staan: forensisch onderzoekers, een onderhandelaar die deze ransomwaregroep al eens aan de lijn had, advocaten die de meldregels kennen, een crisiscommunicatieteam. Zonder retainer wordt dag één een inkooptraject. Bureaus zitten vol, omdat aanvallen in golven komen en iedereen tegelijk belt. Contracten vragen handtekeningen, handtekeningen vragen goedkeuring, goedkeuring vraagt mensen die slapen. Ondertussen zit de aanvaller nog binnen.
Bedrijfsimpact: elk uur zonder deskundige hulp is een uur aan beslissingen door mensen die dit nog nooit hebben gedaan. Een retainer kost een vast, bescheiden bedrag per jaar en levert één telefoonnummer op dat binnen het uur opneemt, met een team dat onze systemen en onze contactpersonen al kent. Het is de goedkoopste regel in het hele beveiligingsbudget — en degene die het vaakst ontbreekt.
| Control | Fixes | In one line |
|---|---|---|
| Response plan | Who decides (01) | A short written plan with named roles and named deputies for each. Not a binder: a few pages everyone has read. |
| Decision rights | Who decides (01) | Written in advance: who may take systems offline, who may talk to the attacker, who may spend money, and up to what amount. |
| Phone list | Who decides (01) | Personal mobile numbers of every role and deputy, printed and at home. The digital copy will be encrypted along with everything else. |
| Isolate, don't wipe | Evidence (02) | One rule every engineer knows: disconnect a suspicious machine, never reboot or reimage it until forensics says so. |
| Communication templates | Comms (03) | Holding statements for staff, customers, press and regulator, approved by legal in advance, with one named spokesperson. |
| Deadline list | Comms (03) | Which notification duties apply to us, to whom, within how many hours — GDPR, NIS2, contracts, the insurer — confirmed by legal, on one page. |
| Out-of-band channel | All four | A way for the crisis team to talk when email and chat are compromised or down: a separate messaging group, a bridge number. |
| Retainer | Help (04) | A signed agreement with a forensics and response firm that answers within the hour, and knows our environment before the call. |
| Tabletop exercise | All four | Once a year, the board and executives walk through a realistic scenario for two hours. Every gap found there is one less gap at 03:00. |
| Maatregel | Lost op | In één zin |
|---|---|---|
| Responsplan | Wie beslist (01) | Een kort geschreven plan met benoemde rollen en voor elke rol een plaatsvervanger. Geen ordner: een paar pagina's die iedereen heeft gelezen. |
| Beslisrechten | Wie beslist (01) | Vooraf vastgelegd: wie systemen mag uitzetten, wie met de aanvaller mag praten, wie geld mag uitgeven, en tot welk bedrag. |
| Bellijst | Wie beslist (01) | Privémobielnummers van elke rol en plaatsvervanger, geprint en thuis. De digitale kopie wordt samen met de rest versleuteld. |
| Isoleren, niet wissen | Bewijs (02) | Eén regel die elke engineer kent: een verdachte machine loskoppelen, nooit herstarten of opnieuw installeren tot forensisch onderzoek het zegt. |
| Communicatieteksten | Communicatie (03) | Voorlopige verklaringen voor personeel, klanten, pers en toezichthouder, vooraf goedgekeurd door juridisch, met één benoemde woordvoerder. |
| Termijnenlijst | Communicatie (03) | Welke meldplichten voor ons gelden, aan wie, binnen hoeveel uur — AVG, NIS2, contracten, de verzekeraar — bevestigd door juridisch, op één pagina. |
| Noodkanaal | Alle vier | Een manier voor het crisisteam om te overleggen als e-mail en chat gecompromitteerd of uitgevallen zijn: een aparte berichtengroep, een vergadernummer. |
| Retainer | Hulp (04) | Een getekende overeenkomst met een forensisch en responsbureau dat binnen het uur opneemt en onze omgeving al kent vóór het telefoontje. |
| Tabletop-oefening | Alle vier | Eén keer per jaar lopen bestuur en directie twee uur lang een realistisch scenario door. Elk gat dat daar wordt gevonden, is één gat minder om 03:00. |
A serious incident is a matter of when. A badly handled one is the default outcome for any organisation that has never rehearsed.Een ernstig incident is een kwestie van wanneer. Een slecht afgehandeld incident is de standaarduitkomst voor elke organisatie die nooit heeft geoefend.
Poor handling multiplies the damage of the incident itself: longer downtime, missed statutory deadlines, refused insurance claims and personal liability for management.Slechte afhandeling vermenigvuldigt de schade van het incident zelf: langere stilstand, gemiste wettelijke termijnen, geweigerde verzekeringsclaims en persoonlijke aansprakelijkheid van het bestuur.
The incident still happens. A rehearsed plan, a retainer and pre-approved communication turn chaos into a controlled, documented response.Het incident gebeurt nog steeds. Een geoefend plan, een retainer en vooraf goedgekeurde communicatie maken van chaos een beheerste, gedocumenteerde respons.
Not delegable to IT: the plan assigns decisions to executives. Legal owns the deadline list, the CISO owns the technical playbook.Niet te delegeren aan IT: het plan legt beslissingen bij de directie. Legal is eigenaar van de termijnenlijst, de CISO van het technische draaiboek.
months since the last board tabletop exercise · roles in the plan without a named deputy · hours until the retainer party answers, per contract · notification deadlines on the list not yet confirmed by legal.maanden sinds de laatste tabletop-oefening met het bestuur · rollen in het plan zonder benoemde plaatsvervanger · uren tot de retainerpartij opneemt, volgens contract · meldtermijnen op de lijst die legal nog niet heeft bevestigd.
“An unrehearsed response to a security incident causes prolonged downtime, destroyed evidence, missed statutory notifications and loss of insurance cover.”“Een niet-geoefende respons op een beveiligingsincident veroorzaakt langdurige stilstand, vernietigd bewijs, gemiste wettelijke meldingen en verlies van verzekeringsdekking.”
| Framework | What it requires of you | When a supplier hands you their report | When this incident happens |
|---|---|---|---|
| NIS2 | An incident-handling process as part of the risk management measures, with management accountable. Reporting to the national authority is the organisation's duty, not IT's, and cannot be outsourced. | There is no NIS2 certificate. Ask how quickly the supplier will warn you of an incident that affects you, in which channel and with what detail, and write those hours into the contract, because your own clock starts when you become aware. | Three clocks: early warning within 24 hours, full notification within 72 hours, final report within one month. Affected customers must also be informed. Who files, and where, must be on the deadline list. Confirm with legal whether NIS2 applies to you. |
| DORA | For financial entities: an ICT incident management process with classification criteria, a communication plan for clients and the public, and management that is trained to decide during a crisis. | Critical ICT providers must contractually support your incident reporting: notification duties, cooperation with your supervisor, participation in your exercises. Their report tells you whether they have rehearsed it, not whether they will do it for you. | Once the incident is classified as major: initial notification to the supervisor within hours, intermediate report within 72 hours, final report within one month. Classification itself is a decision someone must be mandated to make. Confirm with legal. |
| SOC 2 | If you issue one: incident response controls — detection, escalation, communication, post-incident review — are tested over the period (Type II). A plan nobody follows is an exception in the report. | Read the incident response controls and their test results, and check the complementary user entity controls: usually they say you must report incidents to the supplier and act on their notifications. Both need a named owner on your side. | The incident and how it was handled are disclosed in the next report. Customers ask for a bridge letter covering the gap and for the post-incident review. A well-documented response is itself evidence the control works. |
| ISAE 3402 | Assurance over outsourced processes relevant to financial reporting. Incident response is only in scope if the service organisation chose to include it, so the report can be silent on it. | Check whether incident handling and client notification are among the control objectives. If not, ask for them in the contract; the report alone gives you no assurance that you will hear about an incident in time. | The service organisation must disclose the incident to its user auditors. If you are the service organisation, the response, the notifications and their timing will be examined and may qualify the opinion. Confirm with your auditor. |
| Kader | Wat het van u vraagt | Als een leverancier u zijn rapport geeft | Als dit incident u treft |
|---|---|---|---|
| NIS2 | Een proces voor incidentafhandeling als onderdeel van de risicobeheersmaatregelen, met een aansprakelijk bestuur. Melden aan de toezichthouder is een plicht van de organisatie, niet van IT, en kan niet worden uitbesteed. | Er bestaat geen NIS2-certificaat. Vraag hoe snel de leverancier u waarschuwt bij een incident dat u raakt, via welk kanaal en met welke details, en zet die uren in het contract, want uw eigen klok begint te lopen zodra u het weet. | Drie klokken: vroegtijdige waarschuwing binnen 24 uur, volledige melding binnen 72 uur, eindrapport binnen een maand. Getroffen klanten moeten ook worden geïnformeerd. Wie meldt, en waar, hoort op de termijnenlijst. Bevestig met legal of NIS2 op u van toepassing is. |
| DORA | Voor financiële instellingen: een proces voor ICT-incidentbeheer met classificatiecriteria, een communicatieplan voor klanten en publiek, en een bestuur dat getraind is om tijdens een crisis te beslissen. | Kritieke ICT-leveranciers moeten uw incidentmelding contractueel ondersteunen: meldplichten, medewerking aan uw toezichthouder, deelname aan uw oefeningen. Hun rapport zegt of zij het geoefend hebben, niet of zij het voor u doen. | Zodra het incident als ernstig is geclassificeerd: eerste melding aan de toezichthouder binnen enkele uren, tussenrapport binnen 72 uur, eindrapport binnen een maand. De classificatie zelf is een beslissing waarvoor iemand gemandateerd moet zijn. Bevestig met legal. |
| SOC 2 | Als u er zelf een afgeeft: maatregelen voor incidentrespons — detectie, escalatie, communicatie, evaluatie achteraf — worden over de periode getest (Type II). Een plan dat niemand volgt, staat als afwijking in het rapport. | Lees de incidentresponsmaatregelen en hun testresultaten, en controleer de complementary user entity controls: meestal staat daar dat u incidenten aan de leverancier moet melden en op zijn meldingen moet handelen. Beide hebben aan uw kant een benoemde eigenaar nodig. | Het incident en de afhandeling ervan worden in het volgende rapport vermeld. Klanten vragen om een bridge letter voor de tussenliggende periode en om de evaluatie achteraf. Een goed gedocumenteerde respons is zelf het bewijs dat de maatregel werkt. |
| ISAE 3402 | Zekerheid over uitbestede processen die relevant zijn voor de financiële verslaggeving. Incidentrespons valt alleen binnen scope als de serviceorganisatie dat zelf heeft gekozen, dus het rapport kan erover zwijgen. | Controleer of incidentafhandeling en het informeren van klanten tot de beheersdoelstellingen behoren. Zo niet, vraag ze in het contract; het rapport alleen geeft u geen zekerheid dat u tijdig van een incident hoort. | De serviceorganisatie moet het incident melden aan de auditors van haar klanten. Bent u zelf de serviceorganisatie, dan worden de respons, de meldingen en hun tijdigheid onderzocht en kunnen zij het oordeel beïnvloeden. Bevestig met uw auditor. |