Menu

Cybersecurity Awareness: Why a stand-alone training course is never enough

Geplaatst op: 13 October 2025

cybersecurity awareness 2025

The digital threats that businesses face today are greater and more varied than ever before. Hackers are constantly developing new methods, from sophisticated phishing campaigns and ransomware to deepfake attacks and social engineering. The question is no longer whether your organization will be attacked, but when.

Although technical measures such as firewalls and antivirus software are important, they are only part of the solution. Cybercriminals are increasingly targeting the human factor: employees who click on the wrong link or respond to a suspicious request.

That’s why cybersecurity awareness is essential!

What does cybersecurity awareness mean?

Cyber awareness goes far beyond simply knowing that ‘hackers exist’. It is about developing a security-conscious workplace culture, in which employees:

  • Recognize and understand risks (phishing, malware, social engineering).
  • Know how to act safely in everyday situations.
  • Staying alert even when the workload is high or the attack is subtly packaged.

Awareness is therefore not a one-off training course or checklist, but an ongoing process of learning and application.

The dangers of not paying attention to cybersecurity

Many organizations still underestimate the impact of untrained employees. Some facts:

  • Human error accounts for 74% of all data breaches (according to recent security reports).
  • Phishing remains the most popular method of attack: a single click can grant access to entire corporate networks.
  • The financial damage caused by a single incident can quickly amount to tens of thousands of euros, not to mention the potential reputational damage and fines under the GDPR.

As you can see, even the strongest IT environment can be undermined by a single inattentive employee.

Why one cyber security awareness training is not enough

Many companies invest in an annual e-learning or one-off workshop. The problem?

  • Information fades quickly without repetition.
  • Cyber threats are constantly evolving, so what was relevant last year is now obsolete.
  • Employees become less alert when there are no regular triggers.

Awareness only works if it is part of the company’s DNA: short, relevant and repeated training, supplemented with practical simulations such as phishing tests.

What does ongoing awareness look like?

A successful program consists of several layers:

  1. Regular micro-learnings: short training sessions linked to current threats.
  2. Simulations: such as phishing tests to see how employees react in practice.
  3. Campaigns: posters, videos and internal communications that keep the theme alive.
  4. Measure and improve: insight into click behavior, awareness scores and areas for improvement.

This makes awareness a cyclical process rather than an annual tick-box exercise.

The role of OpenSight and KnowBe4

At OpenSight, we believe that an organization can only be truly secure if people are part of the defence. That is why we work together with KnowBe4, the global market leader in security awareness.

What makes this approach unique?

  • Access to a library full of training content, available in multiple languages and styles.
  • Gamification and campaigns that really appeal to employees (like this year’s 80s arcade theme).
  • Reports and metrics that show where risks lie and how they are reduced through training.

With this combination, we make security awareness fun, understandable and effective.

Cybersecurity Awareness Month

October is Cybersecurity Awareness Month worldwide. We are seizing this opportunity to raise awareness among organizations concerning the role their employees play. In collaboration with KnowBe4, OpenSight is organizing a free webinar in which we will take a closer look at:

  • How to create support among management and employees.
  • The latest cyber threats and how criminals operate.
  • Practical ways to improve awareness structurally.

Cybersecurity is never “done”

As cybercrime never stops, neither can cybersecurity awareness. A one-off training course can create a false sense of security. In contrast, continuous programs build a human firewall that keeps pace with the times.

Would you like to know how you can achieve this in your organisation?
Register for our webinar during Cybersecurity Awareness Month and discover how you can structurally embed awareness in your corporate culture.

Lees meer

Webinar: Cybersecurity Awareness

Geplaatst op: 13 October 2025

cyber security awareness 2025 webinar header

October is all about Cybersecurity Awareness Month. Together with our partner KnowBe4, OpenSight is organizing an inspiring webinar in which we show why awareness around cybersecurity is indispensable for any organization.

During this webinar you will discover:

  • Why cybersecurity awareness is more than one-off training and how ongoing programmes keep your employees alert to phishing, deepfakes and other current threats;
  • Through a demonstration how to use KnowBe4, the tool that is ideal for becoming and remaining alert;
  • All the answers to any questions you may still have.

There are only a limited number of places available so register today and learn how to better protect your organization. This webinar will be held in Dutch.

Want more background information? Then also read our extensive article on the importance of ongoing cybersecurity awareness.

Lees meer

Cyber security checklist for small businesses

Geplaatst op: 3 September 2025

Why small businesses need to work on their cyber security now (and how to get started)

Cybercriminals have already stopped putting all their work into the big guys. Small businesses are now the ideal target. why is this? Because they are often just a little less well prepared. No extensive IT department. No 24/7 security monitoring. And often in possession of just enough technology to be vulnerable, but not enough to shield that vulnerability.

Sound familiar? Then this checklist is definitely for you too.

We provide 10 practical tips to help you boost your cyber resilience today. They are practical, proven and specially tailored to the challenges faced by smaller organizations. Good cyber security is not a luxury — it’s a necessity. It’s a prerequisite for doing business safely.

1. First, take a critical look at your current security

A good defence starts with an overview. Do you know where your sensitive data is stored? Who has access to it? What would happen if a laptop went missing or someone walked into the office without ID?

These kinds of fundamental questions form the basis for a secure digital infrastructure.

2. Passwords should not be a weak link

Poor passwords are digital open doors. Make sure your employees use strong, unique passwords. Set up multi-factor authentication (MFA) and update passwords regularly. You may also wish to consider additional security measures such as biometrics, badges, or tokens. The more layers of security, the better.

3. Follow your data like a shadow

Data is the beating heart of your business. From customer information to quotations. Map out where your data lives (locally, in the cloud, on mobile devices) and protect it with modern endpoint security. Smart tools recognize threats in real time and intervene automatically.

4. Encrypt everything of value

Ensure that all your data (including data in transit and stored data) is encrypted. This will keep it unreadable, even if it falls into the wrong hands.

5. Don’t assume that the cloud will take care of everything

Although the cloud is convenient, it is not inherently secure. You are still responsible for what happens in your cloud environment. So make sure you secure your accounts, APIs and containers. In short: secure everything.

6. Working from home? Set up a VPN

Working remotely is the new normal. But you don’t want your data travelling with you over unsecured networks in cafés or trains. A VPN encrypts traffic and makes remote access a lot more secure.

7. Updates? Don’t delay — automate them!

Every uninstalled update poses a risk. It’s also one that cyber criminals are actively looking for! Automate updates wherever possible. It’s a small effort that can prevent a lot of misery.

8. Protect every device that connects

Laptops, phones, tablets, even smart printers. Every device is a potential target. Good endpoint security detects and blocks suspicious activity before it does any damage.

9. Know what to do if things go wrong

Your incident response plan is your roadmap for dealing with a hack or data breach. Stay organized and don’t panic. Ensure that everyone knows what to do, and practice this scenario at least once a year.

10. Train your people and repeat this regularly.

Technology helps, but people make the difference. Make sure your team knows what phishing looks like, why they should lock their screen and what ‘zero trust‘ means in practice. Repeat. Repeat. Repeat.

Can’t quite figure it out?

We are here to help. Cybersecurity doesn’t have to be complicated — as long as you know where to start. If you want to go beyond this checklist, OpenSight can help. We offer everything from risk scans and training sessions to advanced cloud security and real-time monitoring, helping you to grow without worry.

Schedule a no-obligation consultation with our specialists for more information.

Lees meer

Cybersecurity in 2025: Why the Commvault & CrowdStrike integration is essential for your organization

Geplaatst op: 7 May 2025

Cyber threat grows. Are you prepared?

The digital world is changing at lightning speed and with it the landscape of cyber threats. From ransomware to sophisticated phishing and zero-day attacks, the risks to organisations are increasing by the day. Small and medium-sized enterprises (SMEs) in particular are an attractive target for cybercriminals, as there is often less investment in modern security.

IT managers and CISOs face an obvious challenge: how do you build a resilient IT environment that not only detects attacks, but also recovers from them quickly? The answer lies in smart integrations, like the one between Commvault and CrowdStrike. That is something OpenSight is happy to help you with.

What makes this cybersecurity integration unique?

The combination of Commvault Cloud and CrowdStrike Falcon® provides organizations with a powerful, integrated solution for cyber detection, incident response and data loss recovery. This collaboration is not just a technical link, but a strategic defense tool that directly contributes to your cyber resilience.

1. Early detection of threats

CrowdStrike’s real-time threat intelligence recognises even the most sophisticated attacks early. Think fileless malware or lateral movements of an attacker within your network. You often don’t see these with traditional antivirus or EDR tools.

2. Insight into contaminated and clean data

Commvault uses this threat intelligence to quickly identify which systems and data have been compromised, and which are still ‘clean’. This way, you know immediately what can be safely restored, without reactivating ransomware during a restore.

3. Fast, controlled recovery processes

Cleanroom Recovery lets you test cyber recovery plans safely in a simulated environment. This ensures that your organization is truly prepared for an attack.

The risks of waiting: why acting now is necessary

Many organizations wait until it is too late and pay a high price for it. For instance:

  • Day-long downtime of critical systems.
  • Sensitive customer data ending up on the street.
  • hefty fines due to non-compliance.
  • Unrepairable reputational damage.

Cyber attacks are no longer a matter of ‘if’, but ‘when’. That’s why investing in a smart, integrated defense is no longer a luxury – it is a dire necessity.

Why choose OpenSight?

As a certified partner of both Commvault and CrowdStrike, OpenSight offers unique additional value:

  • Expertise in implementation of both platforms and their integration.
  • Customized guidance, from strategic advice to technical implementation.
  • Proactive monitoring and optimization of your cyber resilience environment.
  • Short lines and clear communication, we are your brainstorming partner.

We work with SMEs, healthcare institutions, educational organizations and companies in industry on a daily basis. We understand your challenges and deliver solutions that fit your budget and ambitions.

Cyber resilience starts with the right choices

Do you want to not only survive a cyber attack, but emerge stronger? Then integrating Commvault and CrowdStrike is the smart choice. And OpenSight is the right partner to make that choice a reality.

Don’t let your organization be caught by surprise. Take the step today towards a robust, future-proof cybersecurity strategy.

Schedule a free strategy session with our experts and find out how your organization will become truly resilient to cyber threats in 2025.

Would you like more and in-depth information on this Commvault and Crowdstrike integration? Then download the Solutions Letter at the bottom of this page.

Lees meer

Webinar ‘Awareness Training’

Geplaatst op: 2 April 2025

webinar awareness training

What are we going to talk about?

Lees meer

Improved cyber resilience with Commvault and CrowdStrike

Geplaatst op: 1 April 2025

integratie commvault crowdstrike header

Last week, two of our key vendors further strengthened their collaboration. We from OpenSight are pleased to see the integration and consolidation continue within our commited vendors.

Commvault en Crowdstrike

Commvault, a leading player in data protection and cyber resilience for hybrid cloud environments, has announced a strategic partnership with CrowdStrike to integrate their advanced cyber security platform, Falcon. This collaboration is aimed at improving cyber threat detection and ensuring rapid recovery, thereby providing businesses with better protection against modern cyber attacks.

By using CrowdStrike’s comprehensive threat intelligence and security data, combined with Commvault’s cloud-first capabilities, this integration provides joint customers with an additional layer of security. This is achieved through real-time threat insights, faster detection and remediation processes.

Benefits of the integration

  • Proactive threat detection: Using CrowdStrike’s AI-driven insights and Indicators of Compromise (IOCs), organisations can identify threats early and respond quickly to mitigate damage.
  • Faster recovery of clean data: Companies can quickly restore their systems by locating the last known clean version of their data, minimizing disruptions.
  • Seamless collaboration: The integration creates smoother workflows between security operations (SecOps) and IT operations (ITOps) teams, leading to more effective threat response and recovery.
  • Continuous operation: By reducing recovery time and downtime, companies can keep their critical services running even during complex cyberattacks.

Strengthening the Cybersecurity Ecosystem

This partnership with CrowdStrike reflects Commvault’s ongoing commitment of expanding its cyber security ecosystem. The company is actively working with leading security providers to develop comprehensive solutions to detect, mitigate and recover from cyber attacks. By integrating their respective strengths, Commvault and CrowdStrike aim to provide companies with a solid defence against cyber threats, enabling them to recover quickly and mitigate damage.

If you want to know more about this integration, feel free to contact us.

Lees meer

The NIST ‘Recover’ Domain – The importance of a good Disaster Recovery Plan

Geplaatst op: 29 August 2024

Last month was another one of those days, there was a global disruption caused by a bug in software. Unfortunately, the error turned out to be so severe that Windows machines went into a blue-screen of death (BOSD). So even though CrowdStrike had fixed the issue within 90 minutes and stopped pushing the faulty update, the damage had been done. I sympathise with the IT departments that had to deal with this as this must have caused massive chaos. This incident, where problems with CrowdStrike security software led to computer system failures worldwide, highlights the need for a robust Disaster Recovery (DR) plan. This article discusses the importance of a good DR plan and highlights the essential steps: inventory, plan, test, learn and repeat.

Inventory: understand what you need to protect

The first step in creating an effective DR plan is taking an inventory. This involves making a complete and detailed list of all critical IT assets within your organization.

This includes servers, network equipment, software applications, data storage and even physical locations. Understanding which systems and data are critical to your core processes helps prioritize protection measures, as well as develop a plan.

When taking inventory, it is important to also identify dependencies between systems. This means understanding how different components of your IT infrastructure are connected and how a failure in one system can impact other systems. It’s advisable here to look especially at the organization’s core processes and, from that perspective, determine how to get these processes back up and running when things go wrong.

Plan: develop a strategic DR plan

With a thorough inventory, you can move on to the planning phase. A strategic DR plan should include clear procedures for different disaster scenarios, such as natural disasters, cyber attacks, hardware failures and human error. It is essential to assign specific responsibilities to team members and ensure that everyone knows what is expected of them in case of an emergency.

A good DR plan also includes a communication plan. This plan should describe how to communicate internally and externally during and after a disaster. The CrowdStrike incident highlights the importance of transparent communication to prevent panic and keep customers and partners informed of the recovery measures taken.

Test: ensure regular exercises

A DR plan is only as effective as the testing you do. Regular tests are crucial to verify that your plan works in practice. This can range from tabletop exercises, where you theoretically walk through disaster scenarios, to full-scale tests where you assess the operation of your DR plan in a realistic situation.

Testing your DR plan helps identify weaknesses and potential bottlenecks. By uncovering these problems before a real disaster strikes, you can ensure that your plan remains up-to-date and effective.

Learn: draw lessons from every incident

After every test or actual disaster, it’s important to carry out an evaluation and learn from the experience. This process includes analyzing what went well, what did not go well and what improvements can be made. Learning from incidents and tests helps to continuously improve and adapt your DR plan to new threats and technologies.

Repeat: continuous improvement and updating

Developing a DR plan is not a one-off task. It is an ongoing process that needs to be repeated and updated regularly. Technologies evolve, new threats emerge and business needs change. By regularly reviewing and updating your DR plan, you can ensure that you are always prepared for the latest challenges.

The CrowdStrike incident highlights how vulnerable even the most sophisticated IT systems can be and how important it is to have a robust and up-to-date DR plan. By taking inventory, planning, testing, learning and repeating, you can minimize the impact of disasters and ensure the continuity of your business processes. The IT chain is only as strong as its weakest link!

Of course, it is good to keep in mind that despite CrowdStrike causing this catarostrophic incident, they still prevented more downtime for customers than they caused.

OpenSight Back To School Series

During the OpenSight Back To School Series, we publish weekly blogs diving deeper into the five NIST Security Domains:

  1. Identify
  2. Protect
  3. Detect
  4. Respond
  5. Recover

By implementing the measures associated with these domains, you can reduce the likelihood of cyber attacks and the impact of potential incidents.

Lees meer

The NIST ‘Identify’ Domain – The Foundation of Cybersecurity

Geplaatst op: 27 August 2024

This blog addresses an important part of cyber security: the NIST Cybersecurity Framework. This framework has five domains, each addressing a different aspect of cyber security. Let’s start at the beginning with the first domain: ‘Identify’ and the 5 main sub-topics within this domain: Asset Management, Risk Management, Supply Chain Management, Data Classification, and Cyber security Roles and Responsibilities. These topics form the foundation from which you build all your cyber security measures. If you get this right you’re well on your way to protecting your organization.

Asset management: knowing what you’ve got

Asset Management is all about knowing what you’ve got. Think of every device, system, software, and bit of data your company uses. It’s the first step in the ‘Identify’ domain for a reason. It’s tough to protect something if you don’t even know it’s there. Just like when you do a big spring clean, you need to know what’s in your house before deciding what’s important and what can go. Keeping an inventory helps you figure out which assets are most critical and need the most protection. It also helps avoid surprises when something goes wrong.

4 tips for successful Asset Management:

  • Take a full inventory: Start with a detailed list of all physical and digital assets. Automated tools can make this less labor-intensive, which makes keeping your inventory up-to-date easier.
  • Categorize Your Assets: Classify assets based on their importance to your business and their risk sensitivity.
  • Keep your inventory up-to-date: Perform regular new scans and audits, especially after major changes or purchases.
  • Label your assets: use labels or barcodes to easily identify and track your assets..

Risk Management: Detect problems before they happen

Once you know what your assets are, you need to think about risks. Risk Management is about identifying and understanding the potential threats to your assets. Get creative with “what if” scenarios. Ask questions like: What if there’s a data breach? What if a critical server crashes? A good risk management strategy prepares you for the unexpected and minimizes the impact of potential incidents.

How do you succesfully apply Risk Managament?

  • Perform regular Risk Assessments: Analyze your systems and processes regularly to identify and prioritize risks.
  • Use a Risk Management Framework: Implement a structured framework, like NIST, COSO or ISO 27001, to manage your risks.
  • Involve the entire organization: Make risk management an organization-wide responsibility, instead of leaving it to the IT department.
  • Develop Incident Response Plans: Create and practice incident response plans so you can react quickly to security incidents.
  • Stay on top of new threats: Keep yourself and your team constantly updated on the latest threats and developments in the cyber security world.

Supply Chain Management: keeping an eye out on your partners

Your cyber resilience is only as strong as your weakest link, and we’ve become increasingly connected and dependent on our connections with others. To properly protect yourself, you must strengthen all links. This includes suppliers and partners. Supply Chain Management means paying attention to the cybersecurity measures and resilience of your suppliers and partners. It’s about knowing who has access to your data and systems and ensuring they follow the same strict security measures as you do. This helps prevent security issues outside your direct control.

5 Tips for Effective Supply Chain Management:

  • Screen your suppliers: Do your research before adding a new supplier
  • Set clear requirements: Clearly state the security measures you expect from your suppliers and formalize them in contracts.
  • Continuous monitoring: Continue to keep an eye on your suppliers’ cyber security practices.
  • Regular Communication: Maintain open and regular communication with your suppliers about security expectations and updates.
  • Conduct Audits: Schedule periodic audits of your most critical suppliers to ensure they continue to meet your requirements.

Data Classification: knowing what needs protection

Not all data is created equal. Data Classification is about organizing your data based on sensitivity and importance to the business. The classification is based on the confidentiality and sensitivity of the information. In essence, it comes down to how much impact an incident involving the confidentiality, integrity or availability with this information, has on the organization. Personal customer data, for example, needs more protection than a picture of a company outing. By properly classifying your data, you ensure that you provide the right protection where it’s most needed.

How to effectively implement Data Classification:

  • Define classification levels: Establish clear categories for your data, such as public, internal, confidential and strictly confidential.
  • Use labels: Label your data automatically based on their classification to reduce manual errors.
  • Implement access control: Limit access to sensitive data to only those employees who really need it. And monitor and use and disseminate this information (DLP).
  • Keep the Policy Up-to-Date: Regularly review and update the data classification policy to keep up with new threats and be able to take appropriate action.

Cybersecurity Roles and Responsibilities: Who Does What?

A strong cybersecurity strategy isn’t just about technology; it’s also about people. Cybersecurity involves everyone in the organization. It’s crucial to define clear roles and responsibilities so everyone knows what’s expected of them. From the IT department to the executive team, everyone has a role to play. Clear responsibilities ensure no confusion about who does what during an incident.

How do you get clear what the cyber security roles and responsibilities are within your organization?

  • Define Roles and Responsibilities: Make a list of who is responsible for which aspects of cybersecurity. Include these roles and responsibilities in employees job descriptions.
  • Communicate clearly: Make sure everyone understands what responsibilities they have and why.
  • Training and awareness: Offer regular training to make employees aware of their role in security. Ensure management is involved and supports cybersecurity so the whole team sees the importance.
  • Evaluate and Improve: Regularly evaluate your cybersecurity roles and responsibilities to keep them relevant and effective.

In short…

The “Identify” domain of the NIST Cybersecurity Framework is like building a solid foundation for a house. Without it, everything you build runs the risk of collapsing. By focusing on Asset Management, Risk Management, Supply Chain Management, Data Classification, and Cybersecurity Roles Responsibilities, you lay the foundation for a strong and resilient cybersecurity stance. Having these things in order increases the organization’s cyber resilience, making you more resistant to incidents.

If you need advice or help with implementing the ‘Identify’ domain in your organization, feel free to reach out. We at OpenSight are happy to help!

OpenSight Back To School Series

During the OpenSight Back To School Series, we publish weekly blogs diving deeper into the five NIST Security Domains:

  1. Identify
  2. Protect
  3. Detect
  4. Respond
  5. Recover

By implementing the measures associated with these domains, you can reduce the likelihood of cyber attacks and the impact of potential incidents.

Lees meer

OpenSight at the KVK Online session: software-updates

Geplaatst op: 1 July 2024

teaser opensight te gast bij kvk online sessie

On the 25th of June, we will be guest speakers at the KVK Online session: software updates.

The session will take place online from 12:30 to 13:00 and is completely free.
Sign up directly here.

Keep your door closed to hackers

Every year, one in five entrepreneurs is a victim of cybercrime. For example through hacking, where criminals break into your computer. This is often done via vulnerabilities in non-updated software. Find out how software updates prevent hackers from exploiting these vulnerabilities.

Updates keep your software working properly and safe. Regularly and quickly updating your software prevents hackers from breaking into your computer. That way, they can’t steal your money or data. Or secretly install ransomware.

During this online session at KVK, we will really get into all of this. We discuss what exactly software updates are. And why it is important to install updates immediately. Especially when it comes to security updates. You will get tips on how to keep your systems up-to-date and where to start.

“Not installing updates is like walking around with a hole in your shoe. Nothing the matter when the weather is nice, but when it rains you’ll regret not just stopping by the shoemaker”

Marcel Krommenhoek

Do you have any questions during the broadcast? Then ask these live via chat.

For who is this session?

This online session is aimed at sole traders and small SMEs working on their digital security.

Preparation

Read up in advance so that you take in all the information during the online event even better. We recommend you read the following article:
Software updates: keep the door locked for hackers.

Attending the event

Sign up directly via this link and join this session.

Lees meer

Deze website maakt gebruik van cookies

Er worden cookies gebruikt om functionaliteiten op de website mogelijk te maken, statistieken bij te houden, gebruikersvoorkeuren op te slaan en voor marketingdoeleinden.

Bekijk hier onze privacyverklaring
ALLES ACCEPTEREN
ALLES WEIGEREN
WIJZIGEN

Deze cookies zijn noodzakelijk om de website te laten functioneren en kunnen daarom niet worden uitgeschakeld.

Deze cookies verzamelen anonieme data waarmee we statistieken kunnen analyseren en de website kunnen verbeteren.

Deze cookies bewaren persoonlijke voorkeuren zoals taal of regio om het gedrag en design van de website op af te stemmen.

Deze cookies maken het mogelijk om (gepersonaliseerde) advertenties te tonen.

OPSLAAN