Recent cyberattacks show how little organisations really know during an incident

Your systems have been breached. The alarm has been raised. But you don't know where the attacker is, which systems they have accessed, or what information they have seen or taken. You may not even know whether they are still active or have already left. Yet decisions cannot wait. Do you escalate to crisis level? Do you inform customers? Do you contact the regulator? 

This is not a hypothetical scenario. It is what recent major cyber incidents, including several in the Netherlands, have brought into sharp focus. 

At organizations such as Odido, the Public Prosecution Service and ChipSoft, it became clear how difficult it can be to establish a reliable picture of events while an incident is still unfolding.

Senior leaders had to communicate before the full technical reality was known. In some cases, they later had to add to or revise those communications. That is not a sign of incompetence. It shows just how difficult it is to quickly understand the scale, impact and risk of an attack while it is still happening.

The biggest concern isn't whether organizations pay

When ransomware is involved, public debate quickly focuses on whether an organisation should pay. Ransomware is software that locks or encrypts systems and demands payment to restore access. Naturally, this raises legal, social and ethical questions.

But the debate can distract from a more fundamental issue: during an incident, most affected organizations do not yet know what is actually happening. The question is not simply whether to pay. The more pressing question is whether an organization understands enough to make responsible decisions in the first place. 

The attacker knows more than the defender

Imagine a burglar in a museum. The burglar knows which galleries they have entered. The museum does not know which rooms have been searched, what has been touched, or whether the crown jewels are still there.

That is the position many organizations find themselves in during a cyber incident. Is the attacker still active? Have they collected data or already taken it outside the organization? Have critical systems or backups been compromised? Is the incident likely to lead to extortion, data theft or prolonged disruption?

The challenge is not technology alone. The real question is whether an organization can interpret the available signals quickly enough to take focused action while the incident is still underway. 

The question of who is responsible often matters later

Alongside the debate on payment, much attention is also given to who is behind an attack. Is it a criminal group, a state actor or a hacktivist? It's a logical question, but it is rarely useful in the first hours of an incident.

Attribution is also becoming increasingly difficult. Our 2026 Trend Report shows that different types of attackers are increasingly using the same techniques, infrastructure and methods. State actors use familiar approaches to avoid drawing attention, while financially motivated groups often adopt more sophisticated tactics to increase their impact. As a result, an attack technique says less and less about an attacker’s intent, objective or risk profile.

In ransomware attacks, the attacker’s identity may sometimes become clear quickly once a ransom note appears. But by then, the attack has usually already succeeded. The question, ‘Who is the attacker?’, provides context, but offers little practical direction during the incident itself. More important is the ability to assess how far the attacker has progressed, what impact is likely, and what action is needed immediately. 

From an alert to real understanding

Organizations need a security team, often called a Security Operations Center or SOC, that does more than raise an alert. During an incident, that team must be able to investigate quickly and thoroughly.

A SOC should be able to interpret technical signals and turn them into clear answers for senior leadership: 

  • How far has the attacker progressed?

  • Which systems or data have been affected?

  • What impact is likely?

  • What action is needed now?

This requires preparation before an incident occurs. Organizations need to know what information must be available to assess an incident quickly. They need to know which measures can be taken if an attack escalates. And they need to understand which technical findings should lead to which leadership decisions. This is where many organizations struggle in practice. 

The uncomfortable truth is that many Security Operations Centers are not yet set up to provide rapid insight during a serious incident. Alerts may be available, but the underlying log and telemetry data is often fragmented, incomplete or difficult to access when deeper investigation is needed. 

That creates delays at precisely the moment when senior leaders need clear, reliable information. The question of who is behind an attack will remain relevant. So will the debate about paying in ransomware incidents. But neither determines how effectively an organization responds when the time comes.  

What matters most is how quickly an organization can understand what is happening, assess the likely impact, and decide what needs to be done next. So ask yourself this: if your organization was attacked tomorrow, how long would it take before your senior leadership had a reliable view of the damage? If the answer is ‘too long’ or ‘we don't really know’, that is probably where your greatest risk lies. 

Keep me informed

Sign up for the newsletter