Tomorrow's Threats, Yesterday's Playbook
24th November 2026 • Novotel Amsterdam City, Netherlands
As legacy, human-paced security meets next-generation adversaries, how can already stretched security teams keep up?
Under Sustained Digital Attack
The Benelux region has entered a new and more dangerous phase of the cyber threat landscape. What was once a story of isolated breaches has become one of continuous, industrialised compromise — and the past twelve months have provided stark proof.
In February 2026, the Netherlands suffered what many analysts consider the most significant cybersecurity incident in Dutch history: the breach of telecom provider Odido, in which the ShinyHunters group used multi-stage social engineering — impersonating internal ICT staff to bypass multi-factor authentication — to exfiltrate the records of more than 6.5 million customers and 600,000 businesses.
In Belgium, a ransomware attack on AZ Monica hospital exposed a deeper structural weakness: at least five Belgian hospitals were impacted through a single shared patient registration software supplier, with roughly 71,000 patient records surfacing on the dark web. These organisations were not directly hacked — they were connected to someone who was.
In Luxembourg, in March 2026, attackers accessed data on state-managed devices at Luxembourg's central government IT centre (CTIE), prompting an emergency cabinet review.
These are not outliers. They are data points on a steep upward curve. European organisations now face the sharpest regional growth in cyber threats globally, with weekly attack volumes running 58% higher than just two years ago.
The geopolitical dimension is intensifying in parallel: Microsoft analysis shows Russian state-aligned cyber operations against NATO countries surged 25% in a single year, with Belgium and the Netherlands both ranking among the top targets.
And CISOs face a threat environment where both the volume and the sophistication of attacks are compounding simultaneously - and where the average dwell time between compromise and detection means that, for many organisations, extraction is complete before impact is even visible.
Conventional, human-paced defence cannot keep up with machine-paced offence. Signature-based tools, periodic reviews and manually triaged alerts were designed for a threat landscape that no longer exists. Organisations across the Benelux — from multinational headquarters and financial institutions to the SMEs that make up the backbone of the regional economy, and which now absorb the majority of attacks — must respond in kind: with Al-augmented security capabilities that detect anomalies in real time, correlate signals across cloud, endpoint and supply chain, and respond at machine speed.
Regulatory momentum reinforces the urgency, with NIS2 obligations now being enforced across all three countries and cyber insurers making capabilities such as EDR, MFA and tested incident response plans preconditions of cover.
This is the context in which we are convening the e-Crime and Cybersecurity Congress, Benelux: a dedicated regional forum bringing together the Benelux cybersecurity community — practitioners, decision-makers, regulators and solution providers — to confront this escalation head-on.
The e-Crime & Cybersecurity Congress Benelux will put delegates and vendors at the centre of the region's most urgent business conversation, in front of an audience actively seeking the next generation of defences. The threat has been upgraded. So how will the region's defences will be upgraded to match?
Key Themes: Building Better Security
Pre-emptive security, a change in operating model
Under a preemptive security model, timing is critical — success hinges on identifying and neutralising threats before they escalate into live incidents. Internal telemetry alone isn't enough for security operations to achieve this. They also need real-time, external context on emerging threats — but where does that come from?
Security Posture Management 2.0
Traditional security tooling assumes a stable estate. Cloud-native environments break that model - thousands of containers, functions and services spin up and vanish in minutes, visible only through APls. Point-in-time scans and siloed alerts can't keep pace. So what does managing security posture mean in that world - continuous context and prioritised risk, or just more tickets?
See your surface: continuous attack surface discovery
You need visibility into your external attack surface as adversaries see it - every exposed asset, service and entry point - refreshed continuously, not captured in a static inventory. Each asset should also be risk-ranked against live threat and vulnerability data, so remediation targets what attackers will actually hit first. Is this feasible and cost effective?
Getting the most out of automation
Security still drowns in manual work - and SOAR promises salvation: pulling data from SIEMs, EDRs, firewalls, cloud APls, and threat intel feeds, orchestrating responses through prebuilt integrations and "intelIigent" playbooks. But integrations break, and automating a bad process just makes mistakes faster. What does SOAR actually deliver in the real world?
Adversary simulation and behavioural analysis
Automated adversary simulation Identifies telemetry blind spots. They provide prioritized remediation guidance and control effectiveness metrics. They track progress trends and validate security RO ls as wel I as providing board and audit reporting. How well do they work in practice?
Whose Cloud risk is it anyway?
Cloud platforms may be secure, but customer-side risk isn't: misconfigured storage and permissions, sprawling APls, federated identity gaps and misread shared-respon sibility boundaries leave environments hard to map, let alone secure. So is CSPM/CIEM tooling the answer? What about consolidating into CNAPP/CWPP? And how do you extend controls into SaaS providers and MSSPs? Can vendors help?
Key Themes: Building Better Security
Identity, authority, and control for non-human actors
CISOs must rethink core identity and governance frameworks, including the adoption of robust agent identity models (spanning machine, service, and workload identities), and clearly defined delegation structures that determine what authority an agent holds and who grants it. What technologies can help them maintain visibility and control?
Data protection and leakage risks
What does "insider threat" mean when the actor is non-human? For CISOs, the focus shifts to monitoring the behaviour of agents as well as users, developing capabilities to detect anomalous machine activity, and establishing effective controls that balance guardrails, detection, and containment. Do you need Al defences to do that?
Data protection and leakage risks
What does "insider threat" mean when the actor is non-human? For CISOs, the focus shifts to monitoring the behaviour of agents as well as users, developing capabilities to detect anomalous machine activity, and establishing effective controls that balance guardrails, detection, and containment. Do you need Al defences to do that?
Who needs to be quantum-ready?
Anyone responsible for long-lived sensitive data or critical infrastructure has a quantum problem. That means banks, governments, telecoms, energy, healthcare whose datasets need to last decades. If your encryption protects value over time, you need crypto--agility and a migration path now, not when quantum arrives. How does this work in the real world?
Integrity and the Al-enabled supply chain
Al-native operating models imply dependence on a complex supply chain of foundation models, internal systems, and external APls and orchestration layers that collectively produce legal work. Imagine the consequences of hacking such a system. So how do CISOs stop that happening?
Intelligent Threat Detection
CISOs now must build a single coherent security program that simultaneously satisfies divergent regulatory demands; they must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret differently later; they face unrealistic expectations around incident reporting; and they face personal liability. Can RegTech help?