Skip to content
Back to WikiIncident Types

Data Breaches

A data breach occurs when sensitive, protected, or confidential information is accessed, disclosed, or stolen by unauthorized individuals. Breaches can result in significant financial, legal, and reputational damage.

Common causes of data breaches

Compromised credentials account for the majority of data breaches: weak passwords, credential stuffing, and phishing all contribute. Misconfigured cloud services and databases expose data to the public internet. Software vulnerabilities allow attackers to exploit unpatched systems. Insider threats, both malicious and accidental, remain a significant source of data exposure. Third-party vendor compromises can provide attackers indirect access to your data.

Regulatory obligations

Under the GDPR (AVG in Dutch), organisations must notify the Autoriteit Persoonsgegevens (AP) of qualifying personal data breaches within 72 hours of becoming aware of them, under article 33. If the breach is likely to result in a high risk to individuals' rights and freedoms, affected data subjects must also be informed directly in clear language, under article 34. The AP can impose fines up to €20 million or 4% of global annual turnover for non-compliance.

Beyond the AVG, sector-specific rules apply: NIS2, transposed into Dutch law as the Cyberbeveiligingswet (Cbw), for essential and important entities (24-hour early warning, 72-hour incident notification, one-month final report to the sector supervisor and NCSC-NL), DORA for financial institutions, PCI DSS for payment card data, and the Wegiz for healthcare.

Breach response process

Contain the breach: revoke active sessions on compromised accounts, isolate affected hosts from the network, block the attacker's IP ranges at the perimeter, and close the confirmed initial access vector. Assess the scope: what personal data categories were exposed, how many records, and who is affected. Preserve evidence for forensic investigation: sign-in logs, mailbox audit logs, EDR telemetry, firewall and proxy logs, memory images where relevant, and disk snapshots. Notify the Autoriteit Persoonsgegevens (AP) within 72 hours under article 33 of the AVG (GDPR), and sector supervisors plus NCSC-NL if NIS2 applies. Inform affected data subjects directly when the breach poses a high risk to their rights and freedoms (article 34). Implement remediation. Conduct a post-incident review to prevent recurrence.

Long-term impact

Data breaches have consequences that extend years beyond the initial incident. Customer trust erosion leads to lost business. Regulatory fines and legal costs accumulate. Stolen data may be used for identity theft, fraud, or further attacks. Insurance premiums increase. Competitive advantage may be lost through exposed intellectual property.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now