Alert Online Kick-off event 2026: What Happens When Things Go Wrong?
What happens in the first 24 hours of a major cyber incident? Who makes the decisions, how can organisations keep essential processes running, and what role can AI play before, during and after an attack? These questions took centre stage during the official kick-off of Cybersecurity Month 2026 on 1 October at KPN in Hilversum.
Under the theme “What if things go wrong?”, the kick-off connected current developments in legislation and policy with the Dutch cyber threat landscape and the daily reality of organisations. The programme looked at cyber incidents from the perspective of attackers, explored the role of AI during different stages of an incident, and focused on human behaviour under pressure.
Cyber resilience: keeping operations running
Many organisations are investing in their digital security foundations. Yet unknown vulnerabilities, dependencies in the supply chain, unexpected disruptions and human behaviour can still bring essential processes to a standstill.
Cyber resilience is therefore about more than preventing and containing incidents. It is also about continuity and recovery. Which processes need to continue under all circumstances? Which suppliers and systems does an organisation depend on? What alternatives are available, and have they actually been tested?
These questions formed the basis of the kick-off programme, and brought together perspectives from government, business, cybersecurity, behavioural science and incident response.
From the threat landscape to human behaviour
The programme also explored how people make decisions when faced with cyber threats. This connected directly to the findings of the National Cybersecurity Survey 2026, which was developed by Alert Online in collaboration with Behavior Change Group.
The research shows a clear gap between knowing what secure online behaviour looks like and consistently putting it into practice. On average, people apply only around one third of recommended secure behaviours consistently. For example, only 16% of consumers always use two-factor authentication, while many people do regularly check emails and senders, actions that require less effort.
The growing use of AI adds another layer of complexity. AI can make phishing emails, websites and manipulated media increasingly convincing, while employees are also using AI tools in the workplace without always knowing which tools are permitted or what information can safely be shared.
According to the research, secure behaviour therefore needs to become easier, more familiar and embedded in the way people and organisations work.
“AI is making it increasingly difficult to distinguish between what is real and what is fake. That is why secure online behaviour needs to become automatic: use two-step authentication, go directly to the website or app when in doubt, and report it if you have clicked on a suspicious link.”
Marjolijn Bonthuis-Krijger, Programme Director at ECP | Platform for the Information Society
Programme: What if things go wrong?
The afternoon brought together a range of perspectives on cyber resilience and secure behaviour:
- Leah Postma, Management Team member for Digital Economy at the Ministry of Economic Affairs, opened the programme by addressing why digital security is fundamental to a strong digital economy.
- Jeffrey Leusink-Nicolai, Executive Vice President & CISO at KPN, explored why digital resilience is no longer an IT issue, but a matter of continuity for the Netherlands as a whole. From KPN's Security Operations Centre, he looks at the role of cybersecurity in protecting essential operations.
- Eefje Zents, Director of Cooperation for Digital Resilience at the Dutch National Cyber Security Centre (NCSC), connected the current threat landscape and new legislation to a crucial question: how can organisations keep essential processes running when an incident occurs? She also highlighted the importance of cooperation and information sharing within the Dutch Cyber Resilience Network.
- Rogier Fischer, co-founder and CEO of Hadrian, looked at how an AI cyber pandemic could unfold. He explored how an attack involving AI agents could spread through models, credentials and computing resources, and what organisations can do now to prepare for this emerging scenario.
- Tim Murck (HeroCenter) and Inge van der Beijl (Northwave) demonstrated the approach behind CyberHeroes and explored how organisations can get employees genuinely engaged with cybersecurity. Their approach combines behavioural activation, gamification and current cybersecurity knowledge.
- Bob van Dam, behavioural psychologist and senior lecturer at Behavior Change Group, explored the psychology behind secure cyber behaviour and shared insights from the National Cybersecurity Survey 2026. Why isn't knowledge enough, and what can help consumers and employees consistently act more securely?
- Moderator Marjolijn Bonthuis-Krijger (ECP) guided the afternoon and closed with an open stage, where partners highlighted their activities during Cybersecurity Month. The session marked the official start of Cybersecurity Month 2026.
From prevention to resilience
The kick-off underlines a broader shift in cybersecurity: organisations cannot rely solely on preventing every incident. Resilience means being prepared to respond, continue and recover when security measures fail, or circumstances change.
That requires strong technical foundations, but also cooperation, clear decision-making, tested alternatives and people who know how to act when pressure is high.
With the official start of Cybersecurity Month 2026, partners across the Netherlands are once again joining forces to strengthen digital resilience, not only by preventing incidents, but by preparing for what happens when things go wrong.