Figures · CBS · AP · NCSC

Cyber incidents in the Netherlands: the figures for organisations

What the Dutch government measures, how it is counted, and what the same sources say helps. Every figure shows its source and year.

Updated on 6 October 2026. We update this page at least twice a year, when the sources publish a new edition. All sources are in Dutch.

Four figures, and what helps

Fewer businesses have a cyber incident than in 2016. At the same time, organisations report more data breaches caused by cyber attacks, mostly through taken-over accounts.

  1. What happens

    4%

    of Dutch businesses had a cyber incident caused by an outside attack in 2024.

    Down In 2016 it was 11%.

    CBS, Cybersecuritymonitor 2025 · figure for 2024

    What helps

    Statistics Netherlands (CBS) finds that businesses are more resilient when they take several measures at once. Of businesses with 250 or more employees, 86% took ten or more of the twelve measures surveyed. Among businesses with 2 to 10 employees it was 13%.

    CBS, Cybersecuritymonitor 2025 · figure for 2025

  2. What happens

    2,428

    data breaches caused by a cyber attack were reported to the Dutch Data Protection Authority (AP) in 2025.

    Up In 2024 there were 1,537, leaving out the 5,407 reports that followed a single attack on one supplier.

    AP, Datalekkenrapportage 2025 · figure for 2025

    What helps

    The AP lists these measures: a second factor on employees’ email accounts, filtering email and network traffic, and giving employees access only to what they need for their work.

    AP, Datalekkenrapportage 2025 · figure for 2025

  3. What happens

    1,742

    times in 2025 an attacker took over one or more accounts, according to breach reports to the AP. The AP says this almost always starts with phishing.

    Up In 2024 it happened 607 times.

    AP, Datalekkenrapportage 2025 · figure for 2025

    What helps

    People will keep making mistakes, the AP writes. So put technical measures in place, such as a second factor, and teach employees to watch for messages that push for speed, for the real address behind a link, and for the sender.

    AP, Datalekkenrapportage 2025 · figure for 2025

  4. What happens

    65

    ransomware incidents were reported to the police in 2025. In 40 incidents an incident response firm helped. Not every victim reports a crime, so the real number is probably higher.

    NCSC, Jaarbeeld Ransomware 2025 · figure for 2025

    What helps

    The Dutch NCSC: backups and insurance do not prevent damage. Get the basic measures in place. Attackers mostly got in through a vulnerability or a taken-over account.

    NCSC, Jaarbeeld Ransomware 2025 · figure for 2025

Who: by size of business

Large businesses have incidents more often than small ones. In every size class the share has gone down since 2016. For businesses with 250 or more employees it stayed the same from 2023 to 2024.

Table showing, per size class, the percentage of businesses with a cyber incident in 2016, 2023 and 2024, and the difference between 2016 and 2024.

Employees201620232024Change
2 to 109%4%3%-6
10 to 5018%7%6%-12
50 to 25029%10%8%-21
250 or more39%16%16%-23
All businesses11%5%4%-7

Sum of incidents with and without costs, which CBS publishes separately. Because of rounding, a total can be one point off. Change: from 2016 to 2024, in percentage points.

Fig 1Businesses with a cyber incident caused by an outside attack, in percentCBS, Cybersecuritymonitor 2025

See where your organisation stands with the NIS2 self-assessment

What works

CBS finds that businesses become more resilient when they take several measures at once. Small businesses do so far less often than large ones.

Table showing, per size class, the percentage of businesses that took ten or more of the twelve cyber security measures surveyed.

EmployeesShareShare
2 to 1013%
10 to 5038%
50 to 25068%
250 or more86%
All businesses19%
Fig 2Businesses that took ten or more of twelve measures, 2025, in percentCBS, Cybersecuritymonitor 2025

The Dutch Cyber Security Assessment 2025 (CSBN) puts it this way: the basic principles of the NCSC and the Digital Trust Center are still an efficient defence against a large share of cyber attacks. Its advice to an average organisation is to start there. NCTV/NCSC, Cybersecuritybeeld Nederland 2025.

Numbered list of the five basic principles from the NCSC and the Digital Trust Center.

  1. Map your risks. Then you know what to protect and which measures fit.
  2. Encourage safe behaviour. Make employees aware of risks and make it safe for them to report incidents.
  3. Protect systems, devices and applications. Choose secure settings and keep an eye on your environment.
  4. Manage access. Give employees access only to the data and services they need for their work.
  5. Be prepared. Practise scenarios, make regular backups and test them.
Fig 3The five basic principles of digital resilienceNCSC/DTC, De 5 basisprincipes van digitale weerbaarheid, 2025

See where your organisation stands with the NIS2 self-assessment

How we count

Every figure comes from a public source of the Dutch government. Here is what each source measures and what it does not.

Sources for this page
SourcePublishedWhat it measuresReuse
CBS, Cybersecuritymonitor 202528 May 2026A survey of businesses with two or more people working there. It covers incidents the business noticed and reported in the survey.CC BY 4.0
AP, Datalekkenrapportage 20258 July 2026Reports of data breaches, not incidents. One attack on a supplier can lead to hundreds of reports. Since 2024 more organisations may file a bulk report, and more breaches have been reported since.quoting with attribution
NCSC, Jaarbeeld Ransomware 202525 February 2026Crimes reported to the police and incidents handled by incident response firms. A lower bound: not every victim reports or calls in such a firm.CC0
NCTV/NCSC, Cybersecuritybeeld Nederland 202526 November 2025The annual threat assessment. Mostly descriptive, with few figures by business size.CC0
NCSC/DTC, De 5 basisprincipes van digitale weerbaarheidMarch 2025Not a figure: the basic measures the NCSC and DTC recommend together.CC0
  • The AP’s 2025 annual report gave 44,374 reported breaches. After correction, its data breach report arrives at 39,407 (37,839 in 2024). We use the corrected number.
  • We do not use the widely shared claim that 60 percent of small businesses close within six months of a cyber attack. The organisation it is attributed to says it did not come from its research and that its origin cannot be verified. Statement by the National Cyber Security Alliance, 8 May 2022.
  • Figures about citizens, such as the number of victims of online fraud, are not on this page. It is about organisations.
  • The sources do not endorse this page. We do not reuse their logos or images.

New editions come from the NCSC in February, CBS in May or June, the AP in July and the NCTV and NCSC in the autumn. We update this page after each one.

Where secctl.io fits in

secctl.io helps with two of the five basic principles today, and with a third later.

  1. Safe behaviour (principle 2). Awareness trains employees on what they don’t know yet. A baseline test sets where each person starts, and you see how every team is doing.
  2. Access and systems (principles 3 and 4). The Active Directory assessment shows which paths an attacker could take through your Windows network, and what to do about them. We only test with your written permission and within the scope we agree together.
  3. Mapping risks (principle 1). That will be RiskCompass, a risk register. It is not available yet.
Try it free for 30 days30 days, no payment details. It stops by itself if you don’t choose to continue.
Take the NIS2 self-assessmentTen questions, and you see the result straight away.