Digital resilience: lack of monitoring, practice discipline and chain security hinders maturity
Dutch organizations rate their digital resilience an average of 7.1. However, digital threat monitoring, crisis exercises, and supply chain security remain inadequate. This is evident from KPN's "Cyber Resilient Netherlands 2026" survey, which included more than 250 IT and security professionals from large organizations in vital sectors such as energy, healthcare, government, and financial services. The score demonstrates that organizations are making progress, but also that further strengthening remains necessary. Improving these foundations plays a crucial role, especially in sectors where outages or disruptions have a direct impact on essential services.
Chantal Vergouw, Chief Business Market and member of the Board of Management at KPN: “The research reveals a striking difference: IT and security professionals, who keep our systems running daily, consistently rate their organization's maturity lower than management. They see where the problems lie: governance, security monitoring, and crisis planning. Cyber resilience hinges on clearly defined ownership and decision-making. Without this, vulnerabilities remain untapped and incidents are resolved ad hoc. This confirms what we all feel: there's work to be done.”
Top 5 strategic priorities
- Comply with stricter laws and regulations (43%)
- Ensuring safe AI use within the organization (37%)
- Making employees aware of risks and promoting safe behavior (27%)
- Securely set up and manage cloud environments (22%)
- Properly manage and control identities and access (21%)
Compliance with stricter European laws and regulations is the most frequently cited priority. The research also shows that organizations are already experimenting with AI, while governance around responsibilities, monitoring, and decision-making is not always in place. Threats such as phishing, ransomware, and social engineering are driving employee awareness. Furthermore, the emphasis on cloud security and access management underscores the need for organizations to maintain control over their digital environment.
Biggest risks according to professionals in practice
In addition to strategic priorities, professionals identify multiple risks in daily practice. Human behavior is often cited: click behavior, limited awareness, and optimism bias regularly lead to incidents, partly because training and follow-up are not always structured. The use of AI also brings new concerns, such as uncontrolled tool use, data risks, deception, and AI attacks. Furthermore, many organizations have limited visibility into suppliers and SaaS services, resulting in underexposed supply chain risks. Outdated systems, unauthorized tools, and a lack of ownership increase the attack surface, while unclear roles and insufficiently secured governance hinder structured risk management.
When strengthening digital resilience, detection and preparation play a key role. A third of organizations monitor digital threats insufficiently or only very fundamentally, often resulting in delayed incident detection. Furthermore, 30 percent rarely or never practice cyber incidents, while 67 percent indicate they feel prepared.
Recommendations for structural resilience
The research results show that further strengthening cyber resilience primarily lies in concretely organizing the foundation and daily operations. Organizations that make progress ensure control over access management, updates, and monitoring, and structurally involve suppliers and supply chain partners. Clearly defined ownership and management involvement also prove important: when risks are explicitly discussed and assessed at the board level, responsibilities can be more clearly assigned and followed up more quickly.
In addition, regularly practicing realistic incident scenarios makes all the difference, because plans only become valid when they've been tested in practice. Finally, the increasing use of AI requires clear guidelines and conscious use, so employees can work safely without introducing new vulnerabilities.
Structural cyber resilience requires an investment of time, effort, and budget. Thirty-eight percent of respondents indicated that their current security budget is insufficient, while two-thirds expect it to increase in the coming period. Over the next twelve months, organizations expect to invest primarily in security monitoring and detection (35 percent), identity & access management (26 percent), and developing a security roadmap and strategy (24 percent).
About the research
The Cyber Resilient Netherlands 2026 study was conducted by Security Innovation Stories on behalf of KPN. The publication of Cyber Resilient Netherlands 2026 coincides with NLSecure[ID], which takes place on Tuesday, January 20, 2026. This annual event brings together executives, IT, and security professionals to discuss digital resilience. The study combines 19 in-depth interviews with CISOs, CIOs, and security managers, and a quantitative survey of more than 250 IT and security professionals. The respondents work for medium-sized and large organizations, primarily in critical infrastructure sectors, including government, healthcare, industry, energy, transport & logistics, and financial services.