Figures · CBS · AP · NCSC
Cyber incidents in the Netherlands: the figures for organisations
What the Dutch government measures, how it is counted, and what the same sources say helps. Every figure shows its source and year.
Updated on 6 October 2026. We update this page at least twice a year, when the sources publish a new edition. All sources are in Dutch.
Four figures, and what helps
Fewer businesses have a cyber incident than in 2016. At the same time, organisations report more data breaches caused by cyber attacks, mostly through taken-over accounts.
What happens
4%
of Dutch businesses had a cyber incident caused by an outside attack in 2024.
Down In 2016 it was 11%.
CBS, Cybersecuritymonitor 2025 · figure for 2024
What helps
Statistics Netherlands (CBS) finds that businesses are more resilient when they take several measures at once. Of businesses with 250 or more employees, 86% took ten or more of the twelve measures surveyed. Among businesses with 2 to 10 employees it was 13%.
CBS, Cybersecuritymonitor 2025 · figure for 2025
What happens
2,428
data breaches caused by a cyber attack were reported to the Dutch Data Protection Authority (AP) in 2025.
Up In 2024 there were 1,537, leaving out the 5,407 reports that followed a single attack on one supplier.
AP, Datalekkenrapportage 2025 · figure for 2025
What helps
The AP lists these measures: a second factor on employees’ email accounts, filtering email and network traffic, and giving employees access only to what they need for their work.
AP, Datalekkenrapportage 2025 · figure for 2025
What happens
1,742
times in 2025 an attacker took over one or more accounts, according to breach reports to the AP. The AP says this almost always starts with phishing.
Up In 2024 it happened 607 times.
AP, Datalekkenrapportage 2025 · figure for 2025
What helps
People will keep making mistakes, the AP writes. So put technical measures in place, such as a second factor, and teach employees to watch for messages that push for speed, for the real address behind a link, and for the sender.
AP, Datalekkenrapportage 2025 · figure for 2025
What happens
65
ransomware incidents were reported to the police in 2025. In 40 incidents an incident response firm helped. Not every victim reports a crime, so the real number is probably higher.
NCSC, Jaarbeeld Ransomware 2025 · figure for 2025
What helps
The Dutch NCSC: backups and insurance do not prevent damage. Get the basic measures in place. Attackers mostly got in through a vulnerability or a taken-over account.
NCSC, Jaarbeeld Ransomware 2025 · figure for 2025
Who: by size of business
Large businesses have incidents more often than small ones. In every size class the share has gone down since 2016. For businesses with 250 or more employees it stayed the same from 2023 to 2024.
Table showing, per size class, the percentage of businesses with a cyber incident in 2016, 2023 and 2024, and the difference between 2016 and 2024.
| Employees | 2016 | 2023 | 2024 | Change |
|---|---|---|---|---|
| 2 to 10 | 9% | 4% | 3% | -6 |
| 10 to 50 | 18% | 7% | 6% | -12 |
| 50 to 250 | 29% | 10% | 8% | -21 |
| 250 or more | 39% | 16% | 16% | -23 |
| All businesses | 11% | 5% | 4% | -7 |
Sum of incidents with and without costs, which CBS publishes separately. Because of rounding, a total can be one point off. Change: from 2016 to 2024, in percentage points.
See where your organisation stands with the NIS2 self-assessment
What works
CBS finds that businesses become more resilient when they take several measures at once. Small businesses do so far less often than large ones.
Table showing, per size class, the percentage of businesses that took ten or more of the twelve cyber security measures surveyed.
| Employees | Share | Share |
|---|---|---|
| 2 to 10 | 13% | |
| 10 to 50 | 38% | |
| 50 to 250 | 68% | |
| 250 or more | 86% | |
| All businesses | 19% |
The Dutch Cyber Security Assessment 2025 (CSBN) puts it this way: the basic principles of the NCSC and the Digital Trust Center are still an efficient defence against a large share of cyber attacks. Its advice to an average organisation is to start there. NCTV/NCSC, Cybersecuritybeeld Nederland 2025.
Numbered list of the five basic principles from the NCSC and the Digital Trust Center.
- Map your risks. Then you know what to protect and which measures fit.
- Encourage safe behaviour. Make employees aware of risks and make it safe for them to report incidents.
- Protect systems, devices and applications. Choose secure settings and keep an eye on your environment.
- Manage access. Give employees access only to the data and services they need for their work.
- Be prepared. Practise scenarios, make regular backups and test them.
See where your organisation stands with the NIS2 self-assessment
How we count
Every figure comes from a public source of the Dutch government. Here is what each source measures and what it does not.
| Source | Published | What it measures | Reuse |
|---|---|---|---|
| CBS, Cybersecuritymonitor 2025 | 28 May 2026 | A survey of businesses with two or more people working there. It covers incidents the business noticed and reported in the survey. | CC BY 4.0 |
| AP, Datalekkenrapportage 2025 | 8 July 2026 | Reports of data breaches, not incidents. One attack on a supplier can lead to hundreds of reports. Since 2024 more organisations may file a bulk report, and more breaches have been reported since. | quoting with attribution |
| NCSC, Jaarbeeld Ransomware 2025 | 25 February 2026 | Crimes reported to the police and incidents handled by incident response firms. A lower bound: not every victim reports or calls in such a firm. | CC0 |
| NCTV/NCSC, Cybersecuritybeeld Nederland 2025 | 26 November 2025 | The annual threat assessment. Mostly descriptive, with few figures by business size. | CC0 |
| NCSC/DTC, De 5 basisprincipes van digitale weerbaarheid | March 2025 | Not a figure: the basic measures the NCSC and DTC recommend together. | CC0 |
- The AP’s 2025 annual report gave 44,374 reported breaches. After correction, its data breach report arrives at 39,407 (37,839 in 2024). We use the corrected number.
- We do not use the widely shared claim that 60 percent of small businesses close within six months of a cyber attack. The organisation it is attributed to says it did not come from its research and that its origin cannot be verified. Statement by the National Cyber Security Alliance, 8 May 2022.
- Figures about citizens, such as the number of victims of online fraud, are not on this page. It is about organisations.
- The sources do not endorse this page. We do not reuse their logos or images.
New editions come from the NCSC in February, CBS in May or June, the AP in July and the NCTV and NCSC in the autumn. We update this page after each one.
Where secctl.io fits in
secctl.io helps with two of the five basic principles today, and with a third later.
- Safe behaviour (principle 2). Awareness trains employees on what they don’t know yet. A baseline test sets where each person starts, and you see how every team is doing.
- Access and systems (principles 3 and 4). The Active Directory assessment shows which paths an attacker could take through your Windows network, and what to do about them. We only test with your written permission and within the scope we agree together.
- Mapping risks (principle 1). That will be RiskCompass, a risk register. It is not available yet.