NIS2 guideline: what does management need to know?
Geplaatst op: 29 January 2024

At a time when cyber threats are becoming increasingly advanced, the European Union introduced the NIS2 Directive as a measure to strengthen the cybersecurity and digital resilience of EU member states. As a successor to the original NIS directive, NIS2 brings with it some new obligations and challenges that require immediate management attention within organizations. This article highlights the key points of NIS2 and what top management needs to know to ensure compliance and optimal preparation.
Comprehensive sectoral coverage
The NIS2 directive is not just limited to traditionally vital sectors such as energy, transportation and health-care, but now extends to other sectors including government and digital service providers. This means that a wider range of organizations are now within its scope and must comply with the new cyber security standards.
Supply Chain Responsibility
Companies covered by NIS2 must also take measures to ensure that the security of their suppliers and partners is secured. We call this supply chain responsibility. This could have a major impact on suppliers to these sectors. In practice, we will see that under the NIS2, sectors will place more requirements on their suppliers and it will become a testing criteria in procurements.
Obligations
Core obligations under the NIS2 include a duty of care and incident reporting. Organizations are required to conduct their own risk assessment and take appropriate measures based on that assessment to protect their services and information. For incidents that (may) significantly disrupt service delivery, there is a duty to report within 24 hours to the supervisor. Furthermore, cyber incidents must also be reported to the CSIRT for help and assistance.
Supervision and enforcement
The NIS2 Directive provides for independent monitoring of compliance with its obligations. It is important for management to understand who the regulators are and how enforcement will be implemented in practice, including the potential fines and penalties for noncompliance.
Preparing for NIS2
Preparation is critical to comply with the NIS2 guideline. This includes updating existing cybersecurity policies and procedures, strengthening incident response plans, and ensuring sufficient resources and expertise to meet its obligations. The basis for preparing for NIS2 can be found in existing information security frameworks, such as the Government Information Security Baseline (In Dutch Baseline Informatiebeveiliging Overheid, or BIO) for government agencies.
Communication and training
The people in your organization are one of the most important aspects when it comes to preventing successful cyber attacks. It is therefore essential that management ensure broad awareness and understanding of NIS2 obligations within the organization. This can be achieved through training, information sessions and ongoing communication about the changes brought about by NIS2.
In short…
The NIS2 directive brings new obligations and challenges that require a proactive approach from management. A thorough understanding of the directive, its obligations and the potential consequences of noncompliance is critical to ensuring cyber resilience and minimizing risk. By taking action now and creating a solid plan, organizations can position themselves to not only comply with the NIS2 directive, but also to strengthen their overall cyber security posture in light of the evolving cyber threat landscape.
NIS2 brochure
Detailed information about NIS2 can be found in our NIS2 brochure. It can be downloaded at the bottom of this page.
A hack is a risk for any business, so be prepared!
Geplaatst op: 29 January 2024

The idea that only large companies are targets of cyber attacks is outdated. Every organization, including yours, can become a target. Even with solid cybersecurity measures in place, incidents, such as system failures or ransomware, can occur.
Cyberveiligheid is niet meer slechts een zaak voor technici, maar een organisatie brede verantwoordelijkheid en dient scherp op het vizier te staan van de directie en de managementleden. Het onderwerp blijft echter abstract voor velen en vereist duidelijkere uitleg over hoe men deze verantwoordelijkheid kan dragen en regelmatig kan toetsen. In dit stuk presenteren we enkele cruciale stappen om je onderneming te wapenen tegen cyberdreigingen en de operationele continuïteit te waarborgen.
Risk management is the starting point of good security management. Understanding your cyber risks is crucial. This process is similar to how you evaluate risks around fire safety. In three steps, you can assess your risks:
Step 1: Define business goals and identify essential information/data.
Identify critical information needed for your production or service, including data, assets, applications and services.
Step 2: Identify causes, risks and financial impact.
What could threaten the continuity of your organization and what would be the financial impact if a risk materialized?
Step 3: Determine actions to be taken.
How quickly can you detect an incident and inform relevant stakeholders? On average, it takes 197 days for a company to become aware of a breach, sometimes it even takes up to 3 years. Analyze existing procedures and identify additional measures to reduce risks.
Some basic measures – also called cyber hygiene – should be implemented by every organization. This is not only for the organization itself or its employees, but also for its customers and partners. A hacker doesn’t always walk the straight path. Over the years a supply chain attack has become increasingly common. In which a hacker looks for a supplier of an eventual target that is vulnerable to get in through that route. This leads to huge reputational damage and can also cause high financial claims.
Research shows that 60% of SMEs that are victims of a hack fail within six months due to operational disruptions, loss of customers, high recovery costs and emotional stress. Reputational damage often makes the situation worse. While not every cyber attack is catastrophic, it can take weeks to months for normal business operations to resume, resulting in significant revenue loss.
In the event of a cyber incident, executives can be held personally liable for damages suffered. This emphasizes the importance of proper preparation and risk management to reduce personal and organizational financial risks.
Would you like more explanation on this topic? Or do you need help organizing and structuring a cyber secure business? If so, feel free to contact us!
The importance of security awareness
Geplaatst op: 29 January 2024

With the increasing number of cyberattacks and organizations falling victim to a cyberattack, the question is not ‘if’, but ‘when’. Especially when organizations don’t improve their IT-security. Security awareness, or workplace awareness, plays a crucial role in improving an organisation’s (online) security. In this article, you will read more about the different levels of awareness and how to apply them in practice.
Introdution – The journey towards a secure organization
More and more, the news is reporting about large organisations and companies that have fallen victim to a cyber attack. For example, the The Dutch Data Protection Authority saw an explosion in the number of data breach reports in 2021, and the number of ransomware attacks has increased by 33% in recent years, according to the annual report of the Public Prosecutor’s Office. That’s double compared to the previous year. Yet a lot of organizations lags behind when it comes to cyber security. For example, the report “Cybersecurity awareness in the European Union” showed that many employees are unaware of the risks of cyber attacks and only a small proportion of employees are trained in cybersecurity.
In this article, we explain in three steps how to better protect employees so that they contribute to the security of your organisation. Each level has its own steps, tips & tricks, but some levels will overlap here and there.
What exactly is a cyber attack?
A cyberattack refers to destroying, changing, or gaining access to (personal) data of an organization, without the permission of the organization. For example:
- Your USB flash drive with sensitive data from customers gets stolen;
- A hacker breaks into your computer network and steals (personal) data;
- Any type of ransomware.
Hackers that break into the network of an organization and acquire sensitive data are more common than often thought. To make matters worse, according to research from Cisco, about 60% of cyberattack victims go bankrupt within 3 years after the attack. Almost all organizations depend on their digital data. It has a huge impact if this data leaks or gets damaged. We often see a long-term impact on business operations from a cyber attack. This could result in immediate operational loss, claims for damages due to inability to fulfil obligations or serious reputational damage. There are also hefty recovery costs and investments involved in a cyber attack so that security weaknesses can be closed. The combination of these issues put the survival of the organisation at risk. It’s not necessarily the cyber attack in itself that leads to bankruptcy, it’s the road towards recovery and the costs involved that kill these organizations. When it comes to cyber security it’s always better to be safe than to be sorry.
What forms of cybercrime are most common in organizations and what is the damage?
For the past years a lot of us have been working from home, and the majority of business conversations have been taking place online. While this way of working had positive effects, it also opened the door for data leaks and cybercrime. Perhaps you’re already familiar with the most common types of cyber crime, perhaps not. In any case, here’s an overview:
Malware
Malware is an umbrella term for software like viruses, spyware, and Trojan horses. Malware usually ends up on a computer or network when employees click on a link or document that contains this software. Because the work traffic of many organizations has been from home in recent years, we have seen an increase in malware attacks.
Ransomware
Ransomware is a nasty form of malware. It prevents people within the organization from accessing important documents or processes that are essential for the organization to keep running. Often a large ransom is demanded from the organization to regain access.
Phishing
Phishing is probably one of the most common forms of cybersecurity today. Both privately and professionally, we see more and more people falling victim to the psychological game hackers play during a phishing attack. They often pose as a well-known supplier or company and then ask for important details. Remote working has given a boost to the increase of phishing.
Password hacks
Password hacks are a little different of nature. These attacks use intelligent programs that can guess weak passwords. Another method of accessing employee passwords is keylogging. Here, common keystrokes on a computer are ‘remembered’ without permission. Employees that use the same password to get access to multiple platforms are at higher risk to get hacked.
The consequences of a cyberattack
It’s evident that the consequences of a cyberattack have a major impact. Identity theft due to a cyberattack is no joke, nor are the loss of sales or reputational damage. A few things that influence the impact of a cyberattack:
- How quickly can you recover: If the organization has the procedures in order and can recover quickly from an attack, this significantly reduces the impact. A temporary (short) disruption can often be managed well.
- Special characteristics of the organization: To illustrate, when a hospital gets attacked, the risks are a lot higher than when data gets leaked at the local newspaper office.
- Duration of the attack: Sometimes a hacker has been in for days or weeks. If this is not detected, the damage can be very targeted and even impair recovery capabilities.
How do I make my employees aware of the risks?
Cyber risks come in different shapes and sizes. They all ask for a different approach. By actively involving employees in the company’s security, many of these cyber risks can be prevented. But exactly what levels of cyber-awareness are there and what should you pay attention to for each level?
Security Awareness Maturity Model (SAMM)
The Security Awareness Maturity Model (SAMM) is a model for measuring and improving employee security awareness within organizations. Developed by the Software Assurance Forum for Excellence in Code (SAFECode), the model provides organizations with a framework for establishing, maintaining and improving their security awareness programmes.
SAMM consists of five levels, each with its own set of criteria and objectives:
- Unaware: In this level, there is no security awareness programme or the programme is immature and unstructured.
- Reactive: In this level, there is a basic security awareness programme in place that focuses on responding to specific incidents or events.
- Proactive: In this level, there is a more formal and structured security awareness programme in place that focuses on proactive risk management and incident prevention.
- Optimized: In this level, the security awareness programme is fully integrated into the business processes and culture and there is a continuous improvement cycle.
- Leading: In this level, the organisation is a leader in security awareness, with an innovative and advanced programme that goes beyond best practices and focuses on the latest threats and technologies.

Phase 1: Unaware
This phase focuses on providing knowledge about the basics of cyber security and how employees can protect themselves against it. Indeed, employees are unaware that they are targets of cyber criminals and that their actions have a direct impact on organizational security. They are not familiar with the organization’s security policies and can therefore easily become victims of attacks. In this phase, focus on the basics. This could include using strong passwords, recognizing phishing emails, keeping software up-to-date and using secure networks.
Phase 2: Reactive
This is the phase where security awareness consists merely of a list to be ticked off. Where the company just wants to meet specific compliance and audit requirements. Training only happens annually or incidentally. Employees have little certainty about the organization’s policies and their role in protecting the organization’s data and intellectual property.
Policy development and training are crucial for improving cyber security at this stage. Developing and implementing an information security policy with guidelines for secure IT use and data protection is essential. In addition, providing basic security training to employees is important to make them aware of cybersecurity principles and potential threats. These measures lay the foundation for stronger cybersecurity and promote a culture of awareness and accountability.
Phase: Proactive
Organizations that reach this stage can be rightly proud, as many are already bogged down in the second stage. In this phase, the programme identifies the relevant topics to be covered in security awareness training. The aim is to create training that has maximum impact on the organisation’s mission. This goes beyond annual training; it requires continuous improvement throughout the year.
Phase 4: Optimized
At this stage, organizations have stable processes, resources and management support for longevity, including annual evaluation and optimization. At this stage, the security awareness program is an integral part of the corporate culture, current and encourages employee involvement. To achieve this level, you will conduct regular measurements and evaluations to assess the effectiveness of the security awareness program. This can be done through assessments, surveys and simulations of phishing attacks, for example. Analyze the results of measurements and evaluations and use this information to continuously improve the security awareness program. Identify weaknesses and implement targeted measures to address them.
Phase 5: Leading
In this final phase, the program is supported by statistics, making progress visible and the effect measurable. This allows the program to be continuously improved and show results. But not only measurability is important at this stage. Integrate security awareness into the broader business processes and culture. Work with other departments, such as HR and IT, to include security awareness in the onboarding process of new employees and in daily operations.
SAMM-model as a guide
At a time when cyber attacks are becoming more common and organizations are vulnerable, it is crucial to strengthen IT security. This article has shown that security awareness, or workplace awareness, plays a vital role in improving an organization’s online security. Making employees aware of the risks and involving them in security measures can prevent many of the cyber risks. The Security Awareness Maturity Model (SAMM) provides a framework for measuring and improving awareness levels, whereby organizations can strive to achieve industry-leading levels of security awareness. Preventing cyberattacks is always better than having to repair the damaging effects afterwards. By taking the right measures and engaging employees, organizations are better able to guard against the growing threat of cybercrime.
Need help?
We at OpenSight believe that good preperation is more that half the battle. Cybersecurity is not a one-time activity, but a constant process, as cybercrime is constantly evolving. We strive to increase your organization’s digital resilience. To achieve this, we train people, build processes and provide technology that makes a difference.
We are here to improve the security of your business or organization. Together with our strategic partners, we ensure a complete approach so that we can provide clients with the best advice. Collaboration is essential here to arrive at the right solution for your organization. There is an appropriate solution for every challenge.
So whether you’re looking for improved manageability, optimal recovery from a disaster, or prefer to take your security as a managed service, OpenSight is your partner! Contact us for personal advice.
Assessment Services: Quick insight into your cyber security
Geplaatst op: 24 January 2024

Cybersecurity is essential, but it is difficult to determine which investments will have the biggest impact on your organisation. OpenSight provides assessments and audits to understand your security status:
Quickscan
OpenSight’s quick scan provides quick and thorough insight into security status with a focus on the top 20 critical security controls according to industry standards. The aim is to identify potential vulnerabilities for immediate improvements. The benefits are a fast, efficient scan focusing on critical security aspects and proactive identification of weaknesses.

Security Audit
Strengthen cybersecurity with a comprehensive audit that reveals potential weaknesses and emerging threats. This assessment provides accurate risk assessment for prioritisation, ensures compliance with cybersecurity laws and regulations, strengthens security layers by addressing vulnerabilities, and fosters a proactive cybersecurity culture. Results serve to guide future planning and investment in a robust long-term security strategy, without compromising data integrity.
Security awareness
Increase resilience against cyber threats by raising staff awareness of cybersecurity. Vulnerability identification and training prevent human error, show ernesty in cybersecurity and strengthen stakeholder trust. It is a wise business investment to protect the organisation.
Assessment Services brochure
Find out how OpenSight can help with assessment services. Contact us or download the brochure at the bottom of this page to find out more.
NIS2: new European directives for cyber security
Geplaatst op: 24 January 2024

From January 2023, new European directives for cybersecurity, the Network and Information Security 2 (NIS2), will apply. These guidelines have major implications for companies and organizations in Europe, including the Dutch business community. This is because the NIS2 guidelines apply to a wide range of sectors, not just the vital sectors as with the predecessor NIS.
It’s important that companies comply with the NIS2 directives. Not just to avoid high fines that amount to 2% of annual sales, but more importantly, to ensure digital security and prevent cyber attacks. The NIS2 directives require companies and organizations to take their digital security to a higher level and adapt to increasing cybercrime threats.
On this page (and in more detail in our brochure at the bottom of this page) you can read about what the NIS2 entails, which sectors are covered by the directives, the consequences of non-compliance and how to prepare for the NIS2 as a company or organization.
What’s NIS?
The NIS regulation is the first cybersecurity regulation in Europe (and has been in effect in the Netherlands since 2018). The purpose of the NIS is to ensure a common level of security for network and information systems within the European Union. This is achieved by requiring member states to adopt and implement appropriate security measures that reduce the risks of cyber attacks and limit their consequences.
NIS focuses on companies and organizations operating in vital sectors, such as energy, transportation, healthcare, and financial services. Sectors that are critical to keeping our economy and society running and therefore need a higher level of security.
Another goal of the NIS is to strengthen cooperation among EU member states on cyber security. The directive requires member states to designate a national NIS authority and have it cooperate with other European authorities.
In short, the purpose of the NIS directive is to improve the cyber security of the EU’s vital sectors and strengthen cooperation among member states in the field of cyber security. But with the increase in cyber attacks, the NIS no longer appears to provide sufficient security. Therefore, in 2020, the European Commission introduced NIS2 as the new EU security strategy.

Difference between NIS and NIS2
Whereas the NIS focuses on large enterprises in vital sectors, the NIS2 goes beyond that. That means the NIS2 will have a major impact on European business community. The NIS2 focuses on three pillars of security:
- Security risk mapping;
- Protection and detection to mitigate risks;
- And mitigating the consequences of cyber incidents.
Where companies previously could get away with simply complying with the GDPR (AVG) and other basic rules, with the introduction of the NIS2, they must pull out all the stops to comply with the new guidelines. It’s therefore important for companies to be aware of the NIS2 and prepare accordingly in order to improve their cyber security to reduce the impact of cyber attacks.
Although the NIS directives are still relatively young, research by the EU Agency for Cybersecurity (ENISA) indicates that implementation of the NIS directive in Europe has already led to significant improvements in cybersecurity. Some facts and figures from this study are:
- 96% of member states have implemented national legislation to transpose the NIS Directive into national law.
- 92% of national authorities have dealt with at least one cybersecurity incident.
- 83% of organizations covered by the NIS Directive have implemented security measures to reduce cybersecurity risks.

To whom does the NIS2 apply?
The NIS2 is intended for all member states of the European Union. So all organizations and companies based in these member states that offer digital services or provide essential services must start complying with the NIS2. This covers a wide range of sectors, including energy, transportation, healthcare, finance, digital infrastructure and more. Unlike the original NIS directive, the NIS2 has a much broader scope and applies to a wide variety of organizations and businesses including:
- Providers of essential services (e.g., energy, transportation, banking, healthcare, drinking water supply, digital infrastructure).
- Digital service providers (e.g., online marketplaces, search engines and cloud computing providers).
- Government agencies (both national and local).
The specific criteria for which organizations and companies are covered by the NIS2 vary by state. The specific criteria for which organizations and companies are covered by the NIS2 vary by state. In the Netherlands, the central government has defined the sectors to which NIS2 applies; these can be found online Download the brochure to discover the full list of sectors.
An important difference from the first NIS Directive is that organizations are automatically covered by the NIS2 Directive if they are active in any of the above sectors and can be characterized as an “essential” or “significant” entity according to the criteria below. Unlike the CER Directive, the NIS2 Directive does not involve designation by ministries.
Transitioning to NIS2
The National Cyber Security Centre (NSCS) has drawn up a timeline for translating the CER and NIS2 guidelines into national legislation. You can see this full timeline in our brochure at the bottom of the page.
Why OpenSight ?
Calling in a specialist is the wisest choice and saves a lot of time. The knowledge and experience of a specialist ensure a worry-free process. By taking OpenSight as a partner, you can be sure that the knowledge and experience is there to ensure the best possible process.
Knowledge
OpenSight has been dealing with cybersecurity for companies for years. Originated out of an interest, developed into a passion and eventually formed into a company with helping services.
Experience
Numerous companies have previously partnered with OpenSight and as a result have achieved great successes regarding cybersecurity. From improved business processes to certifications and from consulting to implementations.
Documentation
Clear and accurate documentation is the foundation of cybersecurity. From the plan of action to checkpoints to recording calamities that have occurred and been resolved. In fact, most documentation is necessary for achieving and maintaining certifications. It also increases visibility into the progress and status of the management system.
Time Saving
With compliance software and help from OpenSight, you can minimize the pressure on the organization which saves an enormous amount of time. For example, the scheduling of regular tasks that happen automatically according to the set frequency and other automations.
Integrations
Integrations with Microsoft Teams or Slack are frequently requested options. This allows tasks arising from management to be distributed within the organization. Uit onze ervaring blijkt dat veel organisaties baat hebben bij het gebruik van dergelijke integraties en het onderhouden van bijvoorbeeld hun NIS2 managementsysteem. NIS2 is one of the frameworks that can be chosen to guide monitoring. OpenSight can provide these valuable integrations.
Download the NIS2 brochure
With OpenSight’s service you can easily follow the NIS2 guidelines. You get access to experienced experts, independent advice and practical support in implementing security measures and management systems. Enter your details below to download the brochure and find out how our NIS2 service can help your organization.
Supply chain security: a critical aspect of cyber security
Geplaatst op: 24 January 2024

Supply chain security is a critical aspect of cyber security that companies cannot overlook. In the today’s world the Supply Chain forms a complex network of interconnected systems, technologies and partners. This complexity makes it vulnerable to cyberattacks, with serious consequences for companies, such as loss of sensitive information, intellectual property and financial loss.
In this blog, we will explore the importance of supply chain security to cyber security, the risks associated with supply chain attacks and the measures companies can take to strengthen supply chain security.
Associated risks
Supply Chain attacks are becoming increasingly more common and pose a serious threat to businesses. These attacks target a company’s supply chain partners such as suppliers, subcontractors or third-party service providers to gain access to their systems and data. Once the attacker has gained access to the partner’s systems, it can be used to penetrate the target company’s systems and steal sensitive data or disrupt business operations.
The consequences can be disastrous, for example:
- Data Theft: Cybercriminals can steal sensitive information, such as customer information, trade secrets and intellectual property, also from partners, which can lead to considerable financial and reputational damage.
- Ransomware attacks: Hackers can install ransomware on the supply chain partner’s systems encrypting data and demanding a ransom for release. If the business depends on this partner to function, the ransomware attack can cause significant disruptions.
- Interruption of operations: Cyber attacks on partners can lead to interruptions of business, which can result in considerable financial and reputational damage.

The Importance of Supply Chain Security for cyber security
Supply Chain Security is an essential part of cyber security because it involves securing the entire ecosystem of suppliers, partners and vendors on which a company depends for its business operations. A cyber attack on one of these partners can have far-reaching consequences such as loss of customer information, reputational damage and legal responsibility. Moreover, many companies are now using cloud-based services, which increases the risk of cyberattacks on the supply chain. Since cloud service providers are responsible for managing the infrastructure, data and applications, a security incident in their systems could potentially affect all businesses that depend on their services.
The advantages of Supply Chain Security
By taking a proactive approach to supply chain security, companies can effectively manage the risks that can affect them. This includes building stronger relationships with suppliers and partners, and developing a clear understanding of each other’s security needs and responsibilities. As a result, companies can gain better visibility into early warning signs of potential incidents that could affect the organization and identify possible dependencies on a few suppliers. With effective cyber security, companies are also able to increase their chances of winning supplier contracts, particularly those from the government where security requirements are often mandatory. By implementing a robust security framework and regularly assessing and auditing supply chain partners, companies can ensure that they and their partners are meeting required security standards. This can help build trust with customers and stakeholders while reducing the risks associated with supply chain attacks.
Measures to strengthen the security of the Supply Chain
To improve the Supply Chain security, companies can take the following measures:
- Perform a risk assessment. Companies must identify and assess the risks associated with their supply chain partners. In doing so, they should evaluate security measures, vulnerabilities and potential impact on business operations.
- Implement a security framework: Companies should establish a security framework that sets standards for supply chain partners. This framework should include requirements for access management, incident response and security awareness training.
- Monitor Supply Chain partners: companies should regularly monitor their Supply Chain partners for security breaches and anomalies. To do so, they must also establish a process for reporting and responding to security incidents.
- Conduct regular audits: Companies should conduct regular audits of supply chain partners to ensure they are adhering to the established security framework. These audits should include vulnerability assessments and penetration testing.
- Consider cyber insurance: Cyber insurance can provide a company with financial protection in the event of a cyberattack on supply chain partners. This insurance can cover the cost of data recovery, legal fees and reputational damage.
Collaboration is Key
In short, Supply Chain Security is a critical aspect of cyber security and shouldn’t be overlooked. With the increasing complexity of the Supply Chain ecosystem and the and rise of cloud-based services, the risk of cyber attacks on the Supply Chain is greater than ever. By implementing a robust security framework, monitoring Supply Chain partners, and conducting regular audits, companies can strengthen the Supply Chain security and protect themselves against the devastating effects of Supply Chain attacks.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Incident Management: How to respond to and mitigate disruptions
Geplaatst op: 18 January 2024

Incident management for cyber security is the structured process of detecting, analyzing, responding to and recovering from cyber security incidents. The goal is to minimalize the impact of attacks and to be able to recover quickly. This includes detection, evaluation, monitoring, forensics and improvements to prevent future incidents.
Why is it advisable to plan the response to cyber incidents in advance?
Pre-planning the response to cyber incidents is essential to minimize the impact of such incidents in the organization. This includes the identification of potential cyber threats and vulnerabilities, the development of a response plan outlining the roles and responsibilities of the various teams, the establishment of communication channels, and the regular training and practice sessions to make sure everyone knows what to do in case of a cyber security incident. By planning ahead, organizations can improve resilience to cyber threats and ensure a quick and effective response when an incident occurs.

Benefits of incident management in cyber security
Incident Management is a crucial aspect of cyber security and helps organizations detect, respond and recover from cyber incidents. Here are some of the benefits of incident management:
- Quick solution: Effective incident management allows organizations to quickly identify potential security incidents using automated tools, monitoring systems and threat intelligence.
- Rapid response: With an incident management plan, organizations can respond quickly to cyber incidents, limit the damage and prevent further spread of the attack.
- Minimizes the impact: Incident management helps minimize the impact of a security breach through a systematic approach to identify, contain and recover from the incident.
- Reduces downtime: A well-executed incident management plan can minimize downtime due to a security breach and ensure that the organization ca return to normal operations more quickly.
- Maintains reputation: Cyber security incidents can have a devastating effect on the reputation of an organization. Incident management helps organization to react proactively and effectively on incidents, which can help maintain their reputation and retain customer trust.
- Regulatory compliance: Many regulations require organizations to have a robust incident management plan. Implementing an incident management plan can help organizations comply with regulations.
Incident management is an essential aspect of cyber security that can help organizations prepare for cyber security incidents and help with detecting of and responding to threats and vulnerabilities. It allows organizations to minimize the effects of a security breach, to protect their reputation and to comply with regulations.
Guidelines for organizations for incident management
- Co-operation and co-ordination: Effective incident management requires co-operation and co-ordination between various teams such as, IT, Security, Communication, Legal department and HR. It is also essential to have clear roles and responsibilities, communication channels and escalation procedures to ensure a smooth and efficient incident response.
- Involvement of the relevant department: When creating cyber incident response plans, it’s crucial to involve the right people, including security personnel, legal department and HR personnel, PR representatives and suppliers/vendors.
- Right connections: For effective incident management, it is important to link incident response plans with disaster recovery, business continuity and crisis management plans, and to have the necessary capabilities in place.
- Clear roles and responsibilities: Everyone’s roles and responsibilities should be clearly defined and understood, and they should receive appropriate training. Specific individuals or incident responders should be designated and authorized to manage incidents, with clear job descriptions for decision-making.
- Detection methods: Logging, monitoring, reports of employees or third parties and escalation criteria need to be established.
- Conduct regular tabletop exercises: Tabletop exercises involve a simulated scenario in which members of the response team discuss their roles and responsibilities and the steps they would take to manage the incident. This type of exercise helps identify gaps in the plan and improves communication and cooperation among team members.
- Conduct simulation training: Simulation training exercises mimic a real incident and allow the response team to test their capabilities and processes in a realistic environment. This type of exercise helps refine the plan and identify areas that need improvement.
- Involve suppliers and third parties: Suppliers and third parties can be involved in cyber security incident, so it’s important to also involve them in the simulation training and exercises. This ensures that everyone involved in managing an incident is familiar with the plan and can act effectively.
- Document Results: Documenting results of every exercise and training helps identifying areas of improvement and registers the progress.
- Constant improvement: Use the results of exercises to continuously improve and update the response plan as needed. Incorporate new threats and risks as they arise and ensure the plan remains current and relevant.
Prevent incidents with strict incident management
In short, incident management is a critical process for any organization looking to minimize the impact of disruptions and ensure business continuity. By being prepared, having a plan and executing that plan effectively, organizations can respond quickly and effectively to incidents and minimize the impact on operations and reputation.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Robust logging and comprehensive security monitoring
Geplaatst op: 8 January 2024

By designing systems with incident detection and investigation in mind, implementing robust logging and having a comprehensive security monitoring and incident response strategy, the security and resilience of systems can be improved and the impact of security incidents minimized.
It’s important to have a security monitoring strategy, in order to effectively detect and investigate incidents. This includes actively analyzing logs and other data sources to identify patterns or behaviors that may indicate a security incident. By monitoring systems this way, potential threats can be identified and reacted to quickly, minimizing the impact of security incidents.
In addition to monitoring, it’s important to have incident response procedures in place. This includes defining roles and responsibilities, establishing communication channels and creating a plan for controlling and mitigating security incidents. Having these procedures in place allows one to respond quickly to incidents and minimize their impact on systems and the organization.
The implementation of robust logging and security monitoring has multiple advantages, such as:
- Improved situational awareness: Good logging provides a comprehensive overview of system activity and usage, so you can better understand how relevant systems are being used and identify potential security risks.
- Early detection of threats: Monitoring allows one to actively analyze logs and other data sources to detect patterns or behaviors that may indicate a security risk, so that incidents can be detected and responded to before they escalate.
- Additional layer of defense: Security monitoring introduces an additional layer of defense for systems, offers an early warning system for potential security incidents and helps staying ahead of evolving threats with taking robust logging in mind.
- Effective reaction on incidents: By actively monitoring systems for logging, you can react quickly to early signs of breaches before they can cause significant damage.

How to develop a an effective logging and monitoring strategy for your organization
- Understand the objective: When it comes to logging and monitoring, it’s important to start by understanding the objectives. Think about the context of the system, the threats confronting the organization and the resources available to a company. Based on this information organizations can decide which level of monitoring is appropriate for their system.
- Adjust the monitoring strategy: Adjust the monitoring strategy to the specific needs of the organization. For example, if the organization is exposed to frequent cyberattacks, it may need to invest in security operations that can detect and respond to sophisticated attacks. On the other hand, if you have limited resources, simply collecting logs in the event of a data breach incident may be the most appropriate approach for the organization.
- Responding to incidents: Regardless of the level of monitoring chosen by an organization, the ability to react to incidents must be top priority. To do this effectively, logs and other data with crucial information in case of an incident should be collected.
- Proactive and watchful: The key to effective registration and intensive care is being proactive and watchful. By regularly reviewing and refining logging and monitoring practices, organizations can stay ahead of evolving threats and respond quickly to security incidents.
Ensuring that logs can be accessed and analyzed as needed
- Fast Access: It’s important to know where logs are stored and to have the right access to be able to search through them. In case of an incident you’ll be able to get to relevant log data quickly.
- Storage policy: It’s also important to ensure that logs are stored long enough to answer questions being asked during an incident. How long you keep log data can vary by source, depending on factors such as storage costs and availability and usability of different data types. Be sure to plan storage space to avoid disk overflow and service failure.
- Regularity: By regularly checking your logging systems, you can be confident that your logs capture the data you need.
- Protection: It’s important to protect logs from tampering to ensure that they accurately reflect what happened. For example, by taking measures to prevent unauthorized access and modification so that logs provide a reliable record of events.
Integrating insights from real incidents in monitoring solutions
By integrating insights from real incidents into logging and monitoring solutions, you can identify gaps in the logging and monitoring strategy and improve the systems’ ability to detect and respond to security incidents. Analyzing previous incidents can deliver valuable information about attack patterns and strategies that are being used by threats. By incorporating these insights into surveillance solutions, organizations can strengthen security and reduce the impact of future incidents.
In short…
To improve the security and resilience of systems, organizations must consider incident detection and investigation in their design. This includes implementing robust logging and a comprehensive security monitoring and incident response strategy. By actively monitoring logs and other data sources, organizations can quickly identify and respond to potential threats. Overall, this approach helps minimize the impact of security incidents and improve the security and resilience of systems.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Data Security – Secure vulnerable data
Geplaatst op: 8 January 2024

In this digital age it’s crucial to protect data against unauthorized access, alteration, or removal. This requires implementation of data security protocols during transfer and at rest, effective end-of-life remediation procedures, and consideration of data security measures and third-party warranties. It is also important to protect your systems from the increasing wave of ransomware attacks. From isolated and current to offline backups, this blog will show you how organizations are implementing a comprehensive data security framework.
Benefits of data security
Data security is important because it makes sure sensitive information stays protected against possible threats such as hackers or malware. It provides peace of mind by ensuring that data can be quickly restored in the event of a failure or outage. This can happen, for example, if a system is attacked by a virus or if the server on which the data is stored breaks down. By making regular backups and storing them in a secure location, access to critical data can be quickly restored even if the original data is lost. It is also important to secure old or reused storage media to prevent sensitive information from falling into the wrong hands, even after it has been deleted.
Best practices for protecting information and vulnerable data
- Identify the risks: To protect data effectively, it’s crucial to identify the risks and implement appropriate protection. Start with identifying which data is present, where it is stored, and which data is most sensitive. Consolidate data where possible and avoid storing unnecessary data. If you replicate or cache data, make sure all copies are adequately protected. Distributed data, such as files on users’ desktops, can be easier for attackers to find and harder to control.
- Secured, coded, and authenticated application protocols for data security: Ensure that data is properly protected in transit by using secure, encrypted and authenticated application protocols. Where necessary, use virtual private networks (VPNs) for network layer encryption. Apply physical and logical access controls to protect data at rest, including disk encryption on laptops and removable media. Use file encryption and digital rights management (DRM) solutions to restrict access to data, especially when data must be shared externally.
- Standardized cryptographic algorithms for data security: To properly protect data, it is important to use current standardized cryptographic algorithms. Old or non-standardized algorithms offer less protection and may provide a false sense of security. Ensure that cryptographic materials, such as certificates and keys, are protected from unauthorized access.
- Define interfaces for data security: Define interfaces for data security that allow access to sensitive information and only expose the necessary functionalities to reduce the chance of abuse by attackers. Limit access to bulk datasets and allow users to perform arbitrary queries on sensitive datasets only if there is a legitimate business need and it is carefully controlled.
- Get third-party guarantees for data security: Get third-party guarantees for data security if you rely on others to protect your data, such as with cloud services or in your supplier. Understand what steps you can take to protect your data and seek third-party assurances. Consider your legal responsibilities, including any regulations that apply to your industry.

Best practices for effective data backups for Data Security
Making a back-up of information and data is essential for data security. That way, an organization can recover more quickly after incidents or cyberattacks. Follow these best practices to ensure that back-ups are effective and reliable:
- Determine what data is essential to the business and ensure that it is backed up regularly. This includes business data as well as any configuration data necessary for the operation of the business systems.
- Store multiple backups of important files in different locations. That means you should have at least 3 copies of the data stored on 2 different devices, with at least 1 copy in a remote location.
- Keep an offline backup separate from the internal network or in a cloud service designed for this purpose. Restrict access to credentials and servers used for backups to prevent attackers from targeting the backups.
- Keep backups over a period rather than a single rolling backup. This provides better protection if a virus or damage to the system goes undetected before the backup is overwritten.
- Test backups regularly to ensure they are effective and reliable. Make sure you know how to restore files from a backup before you actually need to.
- Reduce the risk of reinfection when restoring data from backups by reinstalling executable files from trusted sources rather than restoring from a backup. Make sure operating systems and application software are up to date on the target systems and that files are scanned with up-to-date antivirus software when they are restored.
Proper sanitization ensures that sensitive data is securely and permanently deleted
- It’s important to have an extensive policy for the correct treatment of data and information when it’s no longer being used. This policy should address reusage, reparation, removal and destruction of all storage media and devices that are able to store data. Printers, photocopiers, monitors and TVs are also part of this.
- Ensure that redundant data and information get erased safely and permanently. Failure to clean storage media puts the organization at greater risk of data breaches, which can lead to legal and reputational damage.
- When purchasing devices, it’s important to keep in mind the costs and efforts involved in sanitizing data storage devices and/or media when they are no longer needed.
- In some cases, destruction is the only option. In such cases, remember to remove any labels or markings on the device or indicating the nature of the data even before the device is destroyed.
- The procedures and equipment for sanitization and destruction should be monitored and tested regularly to ensure they are effective and comply with relevant laws and regulations.
In short…
Robust backup and security policies are critical for organizations to ensure data security and increase confidence in recovery. By implementing best practices for data security and backup procedures, regardless of where the data resides, you as an organization ensure that your backups are reliable and effective. In the event of any incidents, this will help you recover a lot faster.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
