// BRIEFING

Phishing. Four ways a person gets played. Phishing. Vier manieren waarop een mens wordt bespeeld.

No malware, no exploit — just a convincing message and a moment of trust. In plain language: how each trick works, what it costs us, and the single control that takes the sting out of the click. Geen malware, geen exploit — alleen een overtuigend bericht en een moment van vertrouwen. In gewone taal: hoe elke truc werkt, wat het ons kost, en welke maatregel de klik onschadelijk maakt.

// STEP 01STAP 01

A login page that isn't ours. Een inlogpagina die niet van ons is.

credential phishing / the fake sign-in credential phishing / de nagemaakte inlogpagina
TUESDAY 08:12DINSDAG 08:12
👤
EmployeeMedewerker
🕵️
AttackerAanvaller
🔑

The message says a document is waiting, a password is expiring, or a parcel could not be delivered. The link opens a page that looks exactly like ours — same logo, same colours, a web address one letter off. The employee types their password. The page quietly forwards them to the real site, so nothing looks wrong. The attacker now has a working login, and the employee has no idea anything happened.

Business impact: a stolen password is the starting point for almost every serious incident, from mailbox takeover to the ransomware chain. The employee cannot spot a good fake — nobody can, reliably. A control that works must not depend on the person noticing.

Het bericht meldt dat er een document klaarstaat, een wachtwoord verloopt of een pakket niet bezorgd kon worden. De link opent een pagina die er precies uitziet als de onze — hetzelfde logo, dezelfde kleuren, een webadres met één letter verschil. De medewerker typt zijn wachtwoord. De pagina stuurt hem stilletjes door naar de echte site, dus niets lijkt mis. De aanvaller heeft nu een werkende inlog, en de medewerker heeft niets gemerkt.

Bedrijfsimpact: een gestolen wachtwoord is het startpunt van bijna elk ernstig incident, van een overgenomen mailbox tot de ransomwareketen. De medewerker kan een goede vervalsing niet herkennen — niemand kan dat betrouwbaar. Een maatregel die werkt, mag niet afhangen van iemand die het opmerkt.

LOOKS REAL · NOTHING BREAKS · NOBODY NOTICESZIET ER ECHT UIT · NIETS GAAT STUK · NIEMAND MERKT HET FIX: PASSKEYS OR HARDWARE KEYS — THEY REFUSE THE WRONG SITEOPLOSSING: PASSKEYS OF HARDWARESLEUTELS — DIE WEIGEREN DE VERKEERDE SITE
// STEP 02STAP 02

The second factor gets talked out of the door. De tweede factor wordt naar buiten gepraat.

MFA fatigue / real-time relay of the code MFA-vermoeidheid / live doorspelen van de code
22:40 — THE PHONE22:40 — DE TELEFOON
📱
Employee's phoneTelefoon medewerker
🕵️
AttackerAanvaller
22:40Approve sign-in from Amsterdam?Inloggen vanuit Amsterdam goedkeuren?
DENYWEIGERAPPROVEKEUR GOED
22:41Approve sign-in from Amsterdam?Inloggen vanuit Amsterdam goedkeuren?
DENYWEIGERAPPROVEKEUR GOED
22:43Approve sign-in from Amsterdam?Inloggen vanuit Amsterdam goedkeuren?
DENYWEIGERAPPROVEKEUR GOED

“We have MFA” is where most boards stop worrying. Attackers did not. With the stolen password they trigger a login, and the employee's phone buzzes: approve? They decline. It buzzes again. And again, late in the evening, until one tap makes it stop. The other route is faster still: the fake page from step 01 simply asks for the six-digit code too, and relays it to the real site within the thirty seconds it stays valid.

Business impact: a code that a person can read out or type in is a code a person can be tricked into handing over. Codes by text message and app prompts stop the casual attacker, not the one who has already chosen us. Passkeys and hardware keys cannot be relayed — they only answer to the genuine site — which is why they are the fix for steps 01 and 02 at once.

“Wij hebben MFA” is waar de meeste directies stoppen met zorgen maken. Aanvallers niet. Met het gestolen wachtwoord starten ze een inlog, en de telefoon van de medewerker trilt: goedkeuren? Hij weigert. Hij trilt opnieuw. En opnieuw, laat op de avond, tot één tik het laat ophouden. De andere route is nog sneller: de nagemaakte pagina uit stap 01 vraagt gewoon ook om de zescijferige code, en speelt die binnen de dertig seconden dat hij geldig is door naar de echte site.

Bedrijfsimpact: een code die een mens kan voorlezen of intypen, is een code die een mens kan worden afgetroggeld. Sms-codes en app-meldingen stoppen de toevallige aanvaller, niet degene die ons al heeft uitgekozen. Passkeys en hardwaresleutels zijn niet door te spelen — ze antwoorden alleen de echte site — en daarom zijn ze de oplossing voor stap 01 en 02 tegelijk.

“WE HAVE MFA” IS NOT ENOUGH · ONE TAP AT 22:43“WIJ HEBBEN MFA” IS NIET GENOEG · ÉÉN TIK OM 22:43 FIX: PHISHING-RESISTANT MFA + NUMBER MATCHING + LIMIT PROMPTSOPLOSSING: PHISHINGBESTENDIGE MFA + CIJFERCONTROLE + MELDINGEN BEGRENZEN
// STEP 03STAP 03

A request from the CEO that moves the money. Een verzoek van de CEO dat het geld verplaatst.

CEO fraud / payment redirection / business email compromise CEO-fraude / factuuromleiding / zakelijke e-mailfraude
FRIDAY 16:50VRIJDAG 16:50
🎭
“The CEO”“De CEO”
💳
FinanceFinance
“Confidential deal. Pay € 240.000 today. Can't talk — in a meeting.”“Vertrouwelijke deal. Vandaag € 240.000 betalen. Kan niet bellen — zit in overleg.”
💶

Nothing technical happens here at all. A message arrives from the CEO — or from a supplier the company has paid for years — asking for an urgent transfer, or announcing “new bank details”. It is well written, it knows the names, it arrives late on a Friday, and it discourages a phone call. Sometimes it comes from a mailbox taken over in step 01, which makes it genuinely from the right address. Finance does what Finance is asked to do.

Business impact: direct, uninsured, unrecoverable loss — the money is moved on within hours. No filter catches it, because there is nothing malicious to catch. The only defence is procedural: every payment instruction, and every change of bank details, is confirmed through a second channel using a number we already had. Not the number in the email. And “the CEO said urgent” never overrides that step.

Hier gebeurt technisch helemaal niets. Er komt een bericht van de CEO — of van een leverancier die het bedrijf al jaren betaalt — met een dringend betaalverzoek, of met “nieuwe bankgegevens”. Het is goed geschreven, het kent de namen, het komt laat op vrijdag, en het ontmoedigt een telefoontje. Soms komt het uit een mailbox die in stap 01 is overgenomen, waardoor het écht van het juiste adres komt. Finance doet wat Finance gevraagd wordt.

Bedrijfsimpact: direct, onverzekerd, onherstelbaar verlies — het geld is binnen uren doorgesluisd. Geen filter vangt dit, want er valt niets kwaadaardigs te vangen. De enige verdediging is procedureel: elke betaalinstructie, en elke wijziging van bankgegevens, wordt bevestigd via een tweede kanaal met een nummer dat we al hadden. Niet het nummer uit de e-mail. En “de CEO zei dat het dringend was” zet die stap nooit opzij.

DIRECT LOSS · NOTHING FOR A FILTER TO CATCHDIRECT VERLIES · NIETS VOOR EEN FILTER OM TE VANGEN FIX: CALL-BACK ON A KNOWN NUMBER + FOUR EYES ON EVERY BANK CHANGEOPLOSSING: TERUGBELLEN OP EEN BEKEND NUMMER + VIER OGEN OP ELKE BANKWIJZIGING
// STEP 04STAP 04

Not just email any more. Al lang niet meer alleen e-mail.

smishing / vishing / quishing / messaging apps smishing / vishing / quishing / chat-apps
ANY CHANNELELK KANAAL
📱
Text messageSms
📞
Phone callTelefoontje
QR codeQR-code
💬
Chat appChat-app
👤
🎣
🎣
🎣
🎣

Everything we built to inspect email is bypassed by simply not using email. A text about a missed delivery. A phone call from “the IT helpdesk” asking the employee to read out the code that just arrived. A QR code on a poster, or inside a PDF, that the mail filter cannot follow. A message on a chat app from a colleague's cloned account. The device is often the employee's own phone — outside our network, outside our filters, and outside our visibility.

Business impact: the attack surface is every channel a person can be reached on, not the ones we monitor. The controls that still work here are the ones that do not depend on the channel at all: a login that refuses the wrong site, a payment procedure that insists on a call-back, and staff who know that a report is always welcome and never punished — even when they already clicked.

Alles wat we bouwden om e-mail te controleren, wordt omzeild door simpelweg geen e-mail te gebruiken. Een sms over een gemiste bezorging. Een telefoontje van “de IT-helpdesk” met het verzoek de zojuist ontvangen code voor te lezen. Een QR-code op een poster, of in een pdf, die het mailfilter niet kan volgen. Een bericht in een chat-app vanaf het gekloonde account van een collega. Het apparaat is vaak de eigen telefoon van de medewerker — buiten ons netwerk, buiten onze filters, buiten ons zicht.

Bedrijfsimpact: het aanvalsoppervlak is elk kanaal waarop een mens bereikbaar is, niet alleen de kanalen die wij bewaken. De maatregelen die hier nog werken, zijn die welke niet van het kanaal afhangen: een inlog die de verkeerde site weigert, een betaalprocedure die om terugbellen vraagt, en medewerkers die weten dat melden altijd welkom is en nooit bestraft wordt — ook als ze al geklikt hebben.

OUTSIDE OUR FILTERS · OFTEN ON A PRIVATE PHONEBUITEN ONZE FILTERS · VAAK OP EEN PRIVÉTELEFOON FIX: CHANNEL-INDEPENDENT CONTROLS + A REPORT BUTTON THAT IS USEDOPLOSSING: KANAALONAFHANKELIJKE MAATREGELEN + EEN MELDKNOP DIE GEBRUIKT WORDT
// CONTROLSMAATREGELEN

What takes the sting out of the click. Wat de angel uit de klik haalt.

assume the click happens — design so it cannot hurt ga ervan uit dat er geklikt wordt — richt het zo in dat het geen pijn doet
DEFENCE STACKVERDEDIGINGSLAGEN
PASSKEYS REPORT BUTTONMELDKNOP CALL-BACK CHECKTERUGBELCONTROLE MAIL FILTERINGMAILFILTERING SIMULATIONSOEFENINGEN
ControlTakes the sting out ofIn one line
Passkeys / hardware keysThe page (01), the code (02)A login bound to the real website. A fake page gets nothing, a relayed code does not exist. Start with administrators and Finance.
Number matchingThe code (02)Until passkeys are everywhere: the app shows a number the employee must type, so a random late-night tap approves nothing. Cap the number of prompts.
Call-back procedureThe request (03)Every payment instruction and every bank-detail change is confirmed by phone, on a number we already had on file. No exceptions for urgency or seniority.
Four eyes on paymentsThe request (03)Above a threshold, two people release a transfer. One of them is allowed to say no to the CEO.
Mail filtering + bannersThe page (01)Block known-bad links and attachments; mark external senders and look-alike names visibly. Lowers the volume, never to zero.
Browser protectionThe page (01), the channels (04)The browser and phone warn on or block known phishing sites, whatever channel delivered the link.
Report buttonAll fourOne click to report, a thank-you back within the hour, and never a reprimand — including for people who already clicked. Fast reports are how we catch the campaign.
SimulationsAll fourRun to measure how fast people report, not to shame the ones who click. Publish the report rate, not the names.
Fast resetThe page (01)A reported click leads to a password reset and session sign-out within minutes, not a ticket that waits until Monday.
MaatregelHaalt de angel uitIn één zin
Passkeys / hardwaresleutelsDe pagina (01), de code (02)Een inlog die vastzit aan de echte website. Een nagemaakte pagina krijgt niets, een door te spelen code bestaat niet. Begin bij beheerders en Finance.
CijfercontroleDe code (02)Tot passkeys overal zijn: de app toont een getal dat de medewerker moet intypen, zodat een willekeurige tik 's avonds laat niets goedkeurt. Begrens het aantal meldingen.
TerugbelprocedureHet verzoek (03)Elke betaalinstructie en elke wijziging van bankgegevens wordt telefonisch bevestigd, op een nummer dat we al hadden. Geen uitzondering voor haast of rang.
Vier ogen op betalingenHet verzoek (03)Boven een grens geven twee mensen een overboeking vrij. Een van hen mag nee zeggen tegen de CEO.
Mailfiltering + markeringDe pagina (01)Blokkeer bekende kwaadaardige links en bijlagen; markeer externe afzenders en lookalike-namen zichtbaar. Verlaagt het volume, nooit tot nul.
BrowserbeschermingDe pagina (01), de kanalen (04)Browser en telefoon waarschuwen bij of blokkeren bekende phishingsites, via welk kanaal de link ook binnenkwam.
MeldknopAlle vierEén klik om te melden, binnen het uur een bedankje terug, en nooit een reprimande — ook niet voor wie al geklikt heeft. Snelle meldingen zijn hoe we de campagne vangen.
OefeningenAlle vierOm te meten hoe snel mensen melden, niet om klikkers aan de schandpaal te nagelen. Publiceer het meldpercentage, niet de namen.
Snelle resetDe pagina (01)Een gemelde klik leidt binnen minuten tot een wachtwoordreset en uitloggen van alle sessies, niet tot een ticket dat wacht tot maandag.
The board-level point: someone in this company will click. This year, probably this month. That is not a training failure; it is arithmetic. The question to ask is not “how do we stop people clicking” but “can one click move our money or open our network?” If the answer is yes, the fix is a passkey and a call-back procedure — not another awareness poster. De kern voor de directie: iemand in dit bedrijf gaat klikken. Dit jaar, waarschijnlijk deze maand. Dat is geen falen van training; dat is rekenen. De vraag is niet “hoe zorgen we dat mensen niet klikken”, maar “kan één klik ons geld verplaatsen of ons netwerk openen?” Is het antwoord ja, dan is de oplossing een passkey en een terugbelprocedure — niet nog een bewustwordingsposter.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansCertainZeker

Every employee with an inbox or a phone is a target, every week. Someone will click; the only question is what happens next.Elke medewerker met een mailbox of telefoon is doelwit, elke week. Iemand gaat klikken; de enige vraag is wat er dan gebeurt.

ImpactImpactHighHoog

Direct, unrecoverable payment loss; a taken-over mailbox used against customers and staff; the first step of a larger intrusion.Direct, onherstelbaar betaalverlies; een overgenomen mailbox die tegen klanten en medewerkers wordt ingezet; de eerste stap van een grotere inbraak.

Residual after controlsRestrisico na maatregelenLowLaag

Clicks continue. With passkeys a stolen password is worthless and with a call-back procedure a fake request moves no money.Er wordt nog steeds geklikt. Met passkeys is een gestolen wachtwoord waardeloos en met een terugbelprocedure verplaatst een vals verzoek geen geld.

Risk ownerRisico-eigenaarCFO + CIOCFO + CIO

The CFO owns the payment procedure, the CIO the login. HR owns the no-blame reporting culture. Nobody owns “people should know better”.De CFO is eigenaar van de betaalprocedure, de CIO van de inlog. HR van de meldcultuur zonder schuld. Niemand is eigenaar van “mensen moeten beter weten”.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

Report rate within one hour of a simulation · click rate, as a trend not a verdict · % of staff and administrators on phishing-resistant MFA · % of payments and bank-detail changes verified out-of-band.Meldpercentage binnen een uur na een oefening · klikpercentage, als trend en niet als oordeel · % medewerkers en beheerders met phishingbestendige MFA · % betalingen en bankwijzigingen die via een tweede kanaal zijn geverifieerd.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“A phishing message on any channel leads to a stolen login, an approved MFA prompt or a fraudulent payment, causing direct financial loss, account takeover and a route into the network.”“Een phishingbericht via welk kanaal ook leidt tot een gestolen inlog, een goedgekeurde MFA-melding of een frauduleuze betaling, met direct financieel verlies, accountovername en een toegangsweg tot het netwerk als gevolg.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Basic cyber hygiene and security awareness training are named among the required measures, as is multi-factor authentication. Management must follow training itself and approve the measures. Confirm scope with legal.There is no NIS2 certificate. Ask how the supplier trains its staff, whether its logins are phishing-resistant, and how it verifies instructions that appear to come from you.A large-scale account compromise or fraud can be a significant incident: early warning within 24 hours, full notification within 72 hours, final report within a month. Confirm thresholds with legal.
DORAFor financial entities: an ICT security awareness programme and digital resilience training for all staff, including management, plus strong authentication for access to ICT systems.Ask what their report says about staff phishing results and about how they authenticate a payment or change instruction from you before acting on it.Payment fraud through compromised accounts can qualify as a major ICT incident: initial notification within hours of classification, intermediate report within 72 hours, final report within a month.
SOC 2If you issue one: security awareness training, logical access and MFA are tested over a period (Type II). A failed simulation trend or an admin without MFA becomes an exception in print.Read the exceptions on awareness and access first. CEO fraud at a supplier can redirect your payments too: check how they verify changed payment details.A takeover or fraud appears in the next report as a deviation, the auditors test the response, and customers ask for a bridge letter and root-cause analysis.
ISAE 3402Assurance over outsourced processes relevant to financial reporting, with a focus on authorisation of instructions. Awareness controls are only present if the service organisation put them in scope.Ask one question: how do they verify a changed bank account or an urgent payment instruction that arrives by email? If the answer is not in the report, ask for it in writing.A payment made on a forged instruction is a control failure that the service organisation must disclose to the user auditors, and that appears in its opinion.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Basale cyberhygiëne en bewustwordingstraining staan expliciet tussen de vereiste maatregelen, net als multifactorauthenticatie. Het bestuur moet zelf training volgen en de maatregelen goedkeuren. Bevestig de reikwijdte met legal.Er bestaat geen NIS2-certificaat. Vraag hoe de leverancier zijn medewerkers traint, of zijn inlogs phishingbestendig zijn, en hoe hij instructies verifieert die van u lijken te komen.Een grootschalige accountovername of fraude kan een significant incident zijn: vroegtijdige waarschuwing binnen 24 uur, volledige melding binnen 72 uur, eindrapport binnen een maand. Bevestig de drempels met legal.
DORAVoor financiële instellingen: een ICT-bewustwordingsprogramma en weerbaarheidstraining voor alle medewerkers, inclusief het bestuur, plus sterke authenticatie voor toegang tot ICT-systemen.Vraag wat hun rapport zegt over phishingresultaten van hun medewerkers en over hoe zij een betaal- of wijzigingsinstructie van u verifiëren voordat ze die uitvoeren.Betaalfraude via overgenomen accounts kan een ernstig ICT-incident zijn: eerste melding binnen enkele uren na classificatie, tussenrapport binnen 72 uur, eindrapport binnen een maand.
SOC 2Als u er zelf een afgeeft: bewustwordingstraining, logische toegang en MFA worden over een periode getest (Type II). Een slechte oefentrend of een beheerder zonder MFA wordt een afwijking op papier.Lees eerst de afwijkingen op bewustwording en toegang. CEO-fraude bij een leverancier kan ook uw betalingen omleiden: controleer hoe zij gewijzigde betaalgegevens verifiëren.Een overname of fraude verschijnt in het volgende rapport als afwijking, de auditors testen de respons, en klanten vragen om een bridge letter en een oorzaakanalyse.
ISAE 3402Zekerheid over uitbestede processen die relevant zijn voor de financiële verslaggeving, met nadruk op autorisatie van instructies. Bewustwordingsmaatregelen staan er alleen in als de serviceorganisatie ze in scope heeft gezet.Stel één vraag: hoe verifiëren zij een gewijzigd bankrekeningnummer of een dringende betaalinstructie die per e-mail binnenkomt? Staat het antwoord niet in het rapport, vraag het dan schriftelijk.Een betaling op een vervalste instructie is een falende beheersmaatregel die de serviceorganisatie moet melden aan de auditors van haar klanten, en die in haar oordeel terechtkomt.