// BRIEFING

Your website is a front door. Je website is een voordeur.

The public website and the customer portal are the most exposed systems we own. Anyone on earth can knock, day and night — in plain language: four ways they get in, and the single control that stops each one. De publieke website en het klantportaal zijn de meest blootgestelde systemen die we hebben. Iedereen ter wereld kan aankloppen, dag en nacht — in gewone taal: vier manieren waarop ze binnenkomen, en welke maatregel elk daarvan stopt.

// STEP 01STAP 01

A search box that talks straight to the database. Een zoekvak dat rechtstreeks met de database praat.

injection / untrusted input treated as a command injectie / invoer van buiten uitgevoerd als opdracht
SEARCH FIELDZOEKVELD
🧑‍💻
Anyone onlineIedereen online
🗄️
Customer databaseKlantendatabase
search: winter shoeszoek: winterschoenen search: ' GIVE ME EVERYTHING --zoek: ' GEEF ME ALLES --
📄
📄
📄
📄

Every form on our website — search, login, contact, order tracking — takes text from a stranger and hands it to our systems. If the code behind the form does not strictly separate what the visitor typed from what the system should do, the visitor can type instructions. A crafted search term becomes “show me every customer”. A crafted username becomes “make me an administrator”. No password is guessed, no server is hacked; the website simply does what it was asked.

Business impact: the entire customer database leaves through the front page, often in one request. This is a personal-data breach under GDPR with a 72-hour notification clock, plus the customer letters, the press questions, and the brand damage of “they left the door open”. The defect is decades old and completely preventable; finding it in our own code costs a fraction of finding it in the news.

Elk formulier op onze website — zoeken, inloggen, contact, orderstatus — neemt tekst aan van een vreemde en geeft die door aan onze systemen. Als de code achter het formulier niet strikt scheidt wat de bezoeker typte van wat het systeem moet doen, kan de bezoeker opdrachten typen. Een slim gekozen zoekterm wordt “laat me alle klanten zien”. Een slim gekozen gebruikersnaam wordt “maak mij beheerder”. Er wordt geen wachtwoord geraden, geen server gehackt; de website doet gewoon wat hem gevraagd wordt.

Bedrijfsimpact: de volledige klantendatabase vertrekt via de voorpagina, vaak in één verzoek. Dit is een datalek onder de AVG met een meldtermijn van 72 uur, plus de brieven aan klanten, de vragen van de pers en de reputatieschade van “ze hadden de deur open laten staan”. De fout is decennia oud en volledig te voorkomen; hem vinden in onze eigen code kost een fractie van hem terugvinden in het nieuws.

WHOLE DATABASE · ONE REQUEST · NO LOGINHELE DATABASE · ÉÉN VERZOEK · GEEN INLOG FIX: SECURITY TESTING BEFORE RELEASE + WEB APPLICATION FIREWALLOPLOSSING: BEVEILIGINGSTESTS VÓÓR RELEASE + WEBAPPLICATIEFIREWALL
// STEP 02STAP 02

The plugin everyone forgot. De plug-in die iedereen vergat.

outdated web software / known holes, public instructions verouderde websoftware / bekende gaten, openbare handleiding
WHAT THE SITE IS MADE OFWAAR DE SITE VAN GEMAAKT IS
CMScorekern2026.3
FormsFormulierenpluginplug-in8.1
3 YEARS OLD3 JAAR OUDGalleryGalerijpluginplug-in2.4
ThemeThemadesignontwerp5.0
Serverweb stackwebstackLTS
🕳️HOLE PUBLISHED · SCANNERS FIND IT IN HOURSGAT GEPUBLICEERD · SCANNERS VINDEN HET IN UREN

A website is not one thing. It is a content system, a dozen plugins, a theme, a web server and the libraries underneath — each written by someone else, each with its own release schedule. When a hole is found in any of them, the fix and the description of the hole are published together. From that moment, automated scanners sweep the entire internet for sites still running the old version. The gallery plugin an agency installed years ago, for a campaign nobody remembers, is exactly what they find.

Business impact: full control of the website — defacement, a fake login page under our own domain, malware served to every visitor, or a quiet foothold from which the attacker looks for a path inward. The uncomfortable truth is that nobody had to be clever. The instructions were public, and the fix had been available for months.

Een website is niet één ding. Het is een contentsysteem, een dozijn plug-ins, een thema, een webserver en de bibliotheken daaronder — elk door iemand anders geschreven, elk met een eigen releaseritme. Wordt er in één van die onderdelen een gat gevonden, dan worden de reparatie en de beschrijving van het gat samen gepubliceerd. Vanaf dat moment doorzoeken automatische scanners het hele internet naar sites die nog op de oude versie draaien. De galerij-plug-in die een bureau jaren geleden installeerde, voor een campagne die niemand meer kent, is precies wat ze vinden.

Bedrijfsimpact: volledige controle over de website — bekladding, een nep-inlogpagina onder ons eigen domein, malware voor elke bezoeker, of een stil bruggenhoofd van waaruit de aanvaller een weg naar binnen zoekt. De ongemakkelijke waarheid: niemand hoefde slim te zijn. De handleiding was openbaar, en de reparatie was al maanden beschikbaar.

PUBLIC RECIPE · AUTOMATED · FOUND IN HOURSOPENBAAR RECEPT · GEAUTOMATISEERD · IN UREN GEVONDEN FIX: INVENTORY + PATCH THE WEB STACK IN DAYSOPLOSSING: INVENTARIS + WEBSTACK BINNEN DAGEN PATCHEN
// STEP 03STAP 03

Our customers' accounts, opened with someone else's leak. De accounts van onze klanten, geopend met het lek van een ander.

account takeover / credential stuffing accountovername / credential stuffing
LOGIN PAGE · 03:00INLOGPAGINA · 03:00
🤖
Bot networkBotnetwerk
🔐
Customer portalKlantportaal
anna@… ✔ j.deVries@… ✔ m.bakker@… ✔
🔑
🔑
🔑
🔑

Billions of e-mail and password pairs from other companies' breaches circulate freely. People reuse passwords, so a bot network tries those pairs against our login page — millions of attempts a night, spread across thousands of addresses so no single one looks suspicious. A small share works. The attacker is now inside real customer accounts: order history, saved addresses, stored payment methods, loyalty balances, and the ability to change the delivery address on the next order.

Business impact: fraud that we refund, loyalty points that vanish, customers who blame us — correctly, from their point of view, because it happened on our site. Support costs spike, chargebacks follow, and “was your account hacked?” becomes a headline about us, not about the site where the password actually leaked. A login page that only checks the password is a login page that checks nothing the attacker does not already have.

Miljarden combinaties van e-mailadres en wachtwoord uit lekken bij andere bedrijven circuleren vrij. Mensen hergebruiken wachtwoorden, dus een botnetwerk probeert die combinaties op onze inlogpagina — miljoenen pogingen per nacht, verspreid over duizenden adressen zodat geen enkel adres opvalt. Een klein deel werkt. De aanvaller zit nu in echte klantaccounts: bestelhistorie, opgeslagen adressen, bewaarde betaalmethoden, spaarsaldo's, en de mogelijkheid om het bezorgadres van de volgende bestelling te wijzigen.

Bedrijfsimpact: fraude die wij terugbetalen, spaarpunten die verdwijnen, klanten die ons de schuld geven — terecht, vanuit hun perspectief, want het gebeurde op onze site. Supportkosten schieten omhoog, chargebacks volgen, en “is uw account gehackt?” wordt een kop over ons, niet over de site waar het wachtwoord werkelijk lekte. Een inlogpagina die alleen het wachtwoord controleert, controleert niets wat de aanvaller niet al heeft.

FRAUD ON OUR SITE · OUR REFUNDS · OUR HEADLINEFRAUDE OP ONZE SITE · ONZE TERUGBETALINGEN · ONZE KRANTENKOP FIX: PASSKEYS OR MFA FOR CUSTOMERS + RATE LIMITS + BOT MANAGEMENTOPLOSSING: PASSKEYS OF MFA VOOR KLANTEN + LIMIETEN + BOTBEHEER
// STEP 04STAP 04

Our page, their code. Onze pagina, hun code.

web skimming / third-party scripts on checkout and login web skimming / scripts van derden op afreken- en inlogpagina
CHECKOUT PAGEAFREKENPAGINA
analytics.js chat-widget.js fonts-cdn.js cookie-banner.js
💳
CustomerKlant
🛒
Our checkoutOnze kassa
💳
🕵️COPY OF EVERY CARDKOPIE VAN ELKE KAART

Our checkout and login pages load code from other companies: analytics, a chat widget, fonts, a cookie banner, a review badge. That code runs in the customer's browser with the same rights as our own — it can read every field on the page. When one of those suppliers is compromised, or a domain they used expires and is bought by someone else, the script is quietly swapped. Payments still succeed. The customer sees nothing. But every card number and password typed on our page is also sent to a third party.

Business impact: card-brand fines and forced re-certification, the cost of reissuing thousands of cards, a mandatory breach notification, and a story in which our name is on the page where the theft happened — even though the code was not ours. Every script we allow on a payment or login page is a supplier we have handed the keys to. Most companies cannot list them.

Onze afreken- en inlogpagina's laden code van andere bedrijven: analytics, een chatwidget, lettertypen, een cookiebanner, een reviewbadge. Die code draait in de browser van de klant met dezelfde rechten als onze eigen code — ze kan elk veld op de pagina lezen. Wordt één van die leveranciers gehackt, of verloopt een domein dat zij gebruikten en koopt iemand anders het, dan wordt het script stilletjes vervangen. Betalingen slagen gewoon. De klant ziet niets. Maar elk kaartnummer en wachtwoord dat op onze pagina wordt getypt, gaat óók naar een derde.

Bedrijfsimpact: boetes van de kaartmaatschappijen en verplichte hercertificering, de kosten van duizenden nieuwe kaarten, een verplichte datalekmelding, en een verhaal waarin onze naam op de pagina staat waar de diefstal plaatsvond — ook al was de code niet van ons. Elk script dat we toelaten op een betaal- of inlogpagina is een leverancier aan wie we de sleutels hebben gegeven. De meeste bedrijven kunnen ze niet opsommen.

INVISIBLE TO CUSTOMER · INVISIBLE TO US · CARD-BRAND FINESONZICHTBAAR VOOR KLANT · ONZICHTBAAR VOOR ONS · BOETES KAARTMAATSCHAPPIJEN FIX: SCRIPT INVENTORY + INTEGRITY CHECKS + CONTENT SECURITY POLICYOPLOSSING: SCRIPTINVENTARIS + INTEGRITEITSCONTROLE + CONTENT SECURITY POLICY
// CONTROLSMAATREGELEN

What actually stops this. Wat dit daadwerkelijk stopt.

a short list — most of it is discipline around what we already run een korte lijst — het meeste is discipline rond wat we al draaien
DEFENCE STACKVERDEDIGINGSLAGEN
WAF + BOTS PATCH CLOCKPATCHKLOK PENTESTPENTEST PASSKEYS SCRIPT CONTROLSCRIPTCONTROLE
ControlStopsIn one line
WAF + bot managementInjection (01), Takeover (03)A filter in front of the site that blocks known attack patterns and tells human visitors from bot floods.
Patch clockUnpatched (02)An inventory of every component the site runs, and a rule that web-facing holes are closed within days, not quarters.
Testing before releaseInjection (01)Automated security checks in the build, so a dangerous form never reaches production.
Yearly pentestAll fourSomeone paid to break in, once a year and after every major change, reporting to us before anyone else finds it.
Passkeys / MFATakeover (03)Customer logins that a leaked password alone cannot open, plus limits on how many attempts one address may make.
Script controlSkimming (04)A named list of every third-party script on payment and login pages, integrity checks so a swapped file is refused, and a content security policy so data can only go where we say.
SeparationUnpatched (02)The website lives in its own zone: a compromised page cannot reach the office network or internal systems.
Admin loggingAll fourEvery login and change in the site's admin panel recorded and reviewed — the difference between “we were breached” and “we know what they did”.
Disclosure pageBlind spotsA public address where security researchers can report a hole, so we hear it from them first, not from a leak site.
MaatregelStoptIn één zin
WAF + botbeheerInjectie (01), Overname (03)Een filter vóór de site die bekende aanvalspatronen blokkeert en menselijke bezoekers onderscheidt van botstromen.
PatchklokVerouderd (02)Een inventaris van elk onderdeel dat de site draait, en de regel dat gaten aan de internetkant binnen dagen dicht zijn, niet binnen kwartalen.
Testen vóór releaseInjectie (01)Automatische beveiligingscontroles in de build, zodat een gevaarlijk formulier nooit in productie komt.
Jaarlijkse pentestAlle vierIemand die betaald wordt om in te breken, jaarlijks en na elke grote wijziging, en aan ons rapporteert voordat een ander het vindt.
Passkeys / MFAOvername (03)Klantinlogs die met alleen een gelekt wachtwoord niet opengaan, plus een limiet op het aantal pogingen per adres.
ScriptcontroleSkimming (04)Een lijst met elk script van derden op betaal- en inlogpagina's, integriteitscontrole zodat een vervangen bestand wordt geweigerd, en een content security policy zodat gegevens alleen gaan waar wij dat zeggen.
ScheidingVerouderd (02)De website staat in een eigen zone: een gehackte pagina kan niet bij het kantoornetwerk of interne systemen.
BeheerloggingAlle vierElke inlog en wijziging in het beheerpaneel vastgelegd en bekeken — het verschil tussen “we zijn gehackt” en “we weten wat ze deden”.
MeldpaginaBlinde vlekkenEen openbaar adres waar beveiligingsonderzoekers een gat kunnen melden, zodat wij het eerst van hen horen en niet van een leksite.
The board-level point: the website carries our brand and our customer data at the same time, and it is the one system every attacker on earth can reach without asking. Two questions settle whether we are in control: when did someone last try to break it on our behalf, and who is paged — by name — when it breaks for real? De kern voor de directie: de website draagt ons merk en onze klantgegevens tegelijk, en het is het ene systeem dat elke aanvaller ter wereld kan bereiken zonder te vragen. Twee vragen bepalen of we in controle zijn: wanneer heeft iemand er voor het laatst namens ons op ingebroken, en wie wordt er — bij naam — gebeld als het echt misgaat?
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

The website is reachable by everyone, scanned by bots around the clock, and rebuilt by agencies more often than it is tested.De website is voor iedereen bereikbaar, wordt dag en nacht door bots gescand en wordt vaker door bureaus verbouwd dan getest.

ImpactImpactHighHoog

Customer data or card numbers leaked under our own brand: notification duties, refunds and card-brand fines, and a defaced or weaponised site in the meantime.Klantgegevens of kaartnummers gelekt onder ons eigen merk: meldplichten, terugbetalingen en boetes van kaartmaatschappijen, en ondertussen een bekladde of misbruikte site.

Residual after controlsRestrisico na maatregelenMediumMiddel

New flaws keep appearing. A patch clock, testing before release, passkeys and script control turn a breach into a blocked attempt or a contained incident.Nieuwe fouten blijven komen. Een patchklok, testen vóór release, passkeys en scriptcontrole maken van een lek een geblokkeerde poging of een beheersbaar incident.

Risk ownerRisico-eigenaarCMO / CDOCMO / CDO

Whoever owns the website and the portal owns this risk, with the CISO as second line. Not the agency, not the hosting provider.Wie eigenaar is van de website en het portaal, is eigenaar van dit risico, met de CISO als tweede lijn. Niet het bureau, niet de hostingpartij.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

Days since the last penetration test of the site and portal · days to patch a critical flaw in the web stack · % of customer logins protected by passkeys or MFA · number of third-party scripts on payment and login pages, and how many have an integrity check.Dagen sinds de laatste pentest van site en portaal · dagen tot een kritieke fout in de webstack is gepatcht · % klantinlogs beschermd met passkeys of MFA · aantal scripts van derden op betaal- en inlogpagina's, en hoeveel daarvan een integriteitscontrole hebben.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“A flaw in the public website or customer portal — in our code, an outdated component, weak customer logins or a third-party script — exposes customer and payment data and hands an attacker control of our brand's front door.”“Een fout in de publieke website of het klantportaal — in onze code, een verouderd onderdeel, zwakke klantinlogs of een script van derden — legt klant- en betaalgegevens bloot en geeft een aanvaller de controle over de voordeur van ons merk.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
GDPR · PCICustomer data leaking through the website is a personal-data breach: notify the authority within 72 hours and affected customers when the risk to them is high. If cards are skimmed on our page, the card brands' PCI DSS rules apply to us as the merchant, with forensic investigation, fines and possible re-certification.The agency, hosting provider and SaaS platform behind the site are processors. Their data-processing agreement must oblige them to report a breach to us without undue delay; check that the clause exists and that a phone number is behind it.Start the 72-hour clock at the moment we became aware, not when we finished investigating. Card skimming triggers a separate notification to the acquirer and card brands. Confirm scope and wording with legal.
NIS2If we fall under NIS2, the website and portal are part of the network and information systems we must protect: vulnerability handling, secure development, supply-chain security and MFA are named measures, and management is accountable for them.There is no NIS2 certificate. Ask the agency and hosting provider how they patch, test and separate our site from others, and put their duty to warn us of incidents in the contract.A significant incident — a public service outage or a large customer-data leak — means early warning to the national authority within 24 hours, full notification within 72 hours, and a final report within a month.
DORAFor financial entities: if the customer portal supports a critical or important function, it falls under the ICT risk framework, its providers go in the register of ICT third parties, and it is in scope for resilience testing including threat-led penetration tests.The report is input, not a substitute. Critical ICT providers behind the portal need the contractual clauses DORA prescribes, including audit rights, incident reporting and an exit strategy.A major ICT incident on the portal: initial notification to the supervisor within hours of classification, intermediate report within 72 hours, final report within a month. Clients must be informed when the incident affects them.
SOC 2If the platform behind our site is ours to certify: change management, vulnerability management and logical access are the controls an auditor will test against this scenario. Every exception, including a missed patch window, is printed.Read the system description first: is our website's platform even in scope? Then check the period and the exceptions, and read the complementary user entity controls — the plugins, scripts and customer login settings are usually ours to manage.The incident appears in the platform provider's next report as a deviation, and our customers will ask for a bridge letter and our root-cause analysis, whether the flaw was in their platform or in our plugin.
ISAE 3402Assurance over outsourced processes relevant to financial reporting. The web layer is rarely in scope unless the portal itself processes transactions such as payments or orders that feed the books.Read the control objectives. If the website and portal are not among them, the report says nothing about injection, patching of the web stack or customer logins, however reassuring the opinion looks.The service organisation must disclose the incident to the user auditors if it touched a process in scope. If we are the service organisation, expect it in our opinion and in our customers' audits.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
AVG · PCIKlantgegevens die via de website lekken zijn een datalek: melden bij de Autoriteit Persoonsgegevens binnen 72 uur, en aan de getroffen klanten als het risico voor hen hoog is. Worden kaarten op onze pagina geskimd, dan gelden de PCI DSS-regels van de kaartmaatschappijen voor ons als handelaar, met forensisch onderzoek, boetes en mogelijk hercertificering.Het bureau, de hostingpartij en het SaaS-platform achter de site zijn verwerkers. Hun verwerkersovereenkomst moet hen verplichten een lek onverwijld aan ons te melden; controleer of die bepaling er staat en of er een telefoonnummer achter zit.De 72 uur beginnen op het moment dat wij ervan wisten, niet wanneer het onderzoek klaar was. Skimming van kaarten vraagt een aparte melding aan de acquirer en de kaartmaatschappijen. Bevestig reikwijdte en formulering met legal.
NIS2Vallen wij onder NIS2, dan horen website en portaal bij de netwerk- en informatiesystemen die we moeten beschermen: kwetsbaarheidsbeheer, veilige ontwikkeling, ketenbeveiliging en MFA zijn benoemde maatregelen, en het bestuur is daarvoor aansprakelijk.Er bestaat geen NIS2-certificaat. Vraag het bureau en de hostingpartij hoe zij patchen, testen en onze site scheiden van andere, en leg hun plicht om ons bij incidenten te waarschuwen vast in het contract.Een significant incident — een publieke dienst die uitvalt of een groot lek van klantgegevens — betekent vroegtijdige waarschuwing aan de toezichthouder binnen 24 uur, volledige melding binnen 72 uur en een eindrapport binnen een maand.
DORAVoor financiële instellingen: ondersteunt het klantportaal een kritieke of belangrijke functie, dan valt het onder het ICT-risicokader, gaan de leveranciers ervan in het register van ICT-derden, en is het in scope voor weerbaarheidstesten, inclusief dreigingsgestuurde penetratietests.Het rapport is input, geen vervanging. Kritieke ICT-leveranciers achter het portaal vereisen de contractbepalingen die DORA voorschrijft, inclusief auditrechten, incidentmelding en een exitstrategie.Een ernstig ICT-incident op het portaal: eerste melding aan de toezichthouder binnen enkele uren na classificatie, tussenrapport binnen 72 uur, eindrapport binnen een maand. Klanten moeten worden geïnformeerd als het incident hen raakt.
SOC 2Is het platform achter onze site het onze om te certificeren, dan zijn wijzigingsbeheer, kwetsbaarheidsbeheer en logische toegang de maatregelen die een auditor tegen dit scenario toetst. Elke afwijking, ook een gemiste patchtermijn, staat in het rapport.Lees eerst de systeembeschrijving: valt het platform van onze website überhaupt binnen de scope? Controleer daarna de periode en de afwijkingen, en lees de complementary user entity controls — de plug-ins, scripts en instellingen voor klantinlogs zijn meestal onze verantwoordelijkheid.Het incident verschijnt in het volgende rapport van de platformleverancier als afwijking, en onze klanten vragen om een bridge letter en onze oorzaakanalyse, of de fout nu in hun platform zat of in onze plug-in.
ISAE 3402Zekerheid over uitbestede processen die relevant zijn voor de financiële verslaggeving. De weblaag valt zelden binnen de scope, tenzij het portaal zelf transacties verwerkt, zoals betalingen of bestellingen die in de boeken landen.Lees de beheersdoelstellingen. Staan website en portaal er niet bij, dan zegt het rapport niets over injectie, patchen van de webstack of klantinlogs, hoe geruststellend het oordeel ook leest.De serviceorganisatie moet het incident melden aan de auditors van haar klanten als het een proces binnen de scope raakte. Zijn wij zelf de serviceorganisatie, verwacht het dan in ons oordeel en in de audits van onze klanten.