False sense of security: everything looked right on paper, but it still went wrong!

Significant investments have been made in information security. All necessary certifications have been obtained. Policies have been established that outline retention periods, access rights, and incident management. The IT vendor has implemented multi-factor authentication (MFA). The auditor has visited and is satisfied: all the boxes have been checked.
And then you read in the media that a hack has taken place after all at a major, nationally recognized organization! Find out why this happened and what you can do about it here:
Certificates as a shield
A cyberattack can happen to anyone. Why do things go wrong? Often because policy and reality don’t really align. It often seems that waving an ISO or NEN certificate, for example, is seen as the end of the discussion: now everything is in order. There’s a methodology, there are processes, and there’s an audit trail. In practice, however, relying on certificates and procedures often proves to be insufficient and not secure enough.
You can compare it to signing a contract: both the customer and the supplier are pleased. However, once both parties have signed and the necessary “checkmarks” have been made, that’s when the real work begins. You won’t know whether what’s on paper is actually being fulfilled until afterward—unless you set aside enough time along the way to measure progress. Relying too heavily on the assumption that “everything is correct” can have serious consequences. Especially when it comes to safety, you must continuously monitor and make adjustments.
Data in the Wild
We’ll explain how policy and reality can be a complex pair using an example: the policy states that customer data may be retained for a maximum of two years after the end of the contract. This is clearly outlined in the privacy statement. The policy includes a section dedicated to data cleansing. So far, there is confidence that customer data is being handled professionally.
But where is all that data stored? In the CRM system? In an old ticketing system? In backups? In exports that were once saved to Excel? In test environments? In email inboxes? In log files? As soon as information becomes scattered across multiple systems, copies, and shadow files, complying with retention periods becomes a complex task. The reality is that deleting everything at once has become virtually impossible.
Furthermore, it may be questionable whether there is sufficient oversight of policy implementation: Is every employee aware of it—for example, the team of new hires who have just completed their onboarding? Centralizing information and ensuring the continuity of knowledge sharing have (suddenly) proven to be of a value that should not be underestimated.
Monitoring is enabled
Even 24/7 monitoring of networks, systems, and applications is no guarantee of optimal security. The proof? Despite the fact that tools have been purchased, dashboards have been set up, and log files are being collected, it turns out in practice that cybercriminals can remain active in networks for weeks or months—without being detected. So you might ask yourself how well processes and measures actually work in practice. Do we review our processes and technical measures at least once a year? Do we draw the right conclusions from the results of our analyses? Does gaining new insights always mean we’re making the right adjustments?
“In most cases, cyberattacks succeed not because of innovative techniques used by criminals, but simply because organizations fail to maintain basic cybersecurity hygiene. Overdue IT maintenance, weak identity security, and inadequate monitoring are among the causes.”
Effective 24/7 monitoring requires more than just a SOC contract or a tool that generates alerts. It requires clear scenarios: what do we consider to be abnormal behavior? Which signals are truly critical to us? When do we intervene, and who takes the lead? This also includes periodically testing your own vigilance. It’s not just about checking whether alerts are coming in, but also practicing to ensure they’re interpreted correctly. So be prepared to take extra steps—to check, verify, assess, and not simply trust blindly.
The Human Factor
In addition, we would like to emphasize that, following an incident, the focus should not be limited to additional technical resources, modified procedures, or, for example, more comprehensive cybersecurity insurance. For instance, a contingency plan that takes an exclusively technical approach (isolating, blocking, resetting) overlooks a crucial dimension: the human aspect.
If you don’t think about how to support an employee who made a mistake under pressure (imagine being in their shoes!), you run the risk of losing this valuable employee. Moreover, this can have a negative impact on the rest of the organization.
The same applies to affected customers, employees, or other stakeholders; Is sufficient attention being paid to the impact of the incident on their lives? How do you communicate with them?
Prevention
Our conclusion is that no certificate can guarantee complete security: it is merely a foundation on which you can build something solid—or something that could collapse. True security only arises when the structure is firmly embedded within the organization, enabling the organization to know where its information is located, who is responsible, and how policies are continuously tested against real-world practice. Security is not an annual audit, but an ongoing process of staying alert, keeping up with current developments, asking probing questions, and making timely corrections.
You can prevent a false sense of security by continuously scrutinizing the entire ecosystem of information management, technology, work processes, and human behavior.
Only then can you make a difference when it really counts.