A phishing simulation showed that even when people know what to do, there is often no correct decision to make. Organisations respond by managing reactions instead of fixing the conditions that caused the problem.
When one person consistently carries operational recovery, troubleshooting and undocumented infrastructure knowledge, organisations mistake dependency for stability.
From a 9600 bps modem in Lelystad to the server rooms of XS4ALL and Leaseweb, I watched technical authority get replaced by compliance theater and PowerPoint circles. The operator didn’t retire. He got managed out.
The European Commission ran its infrastructure on AWS while writing sovereignty frameworks for everyone else. Now 350GB is gone. This was not a surprise.
Een waarschuwing voor organisaties: in de zomer neemt mentale vermoeidheid toe, waardoor security-risico’s stijgen, ondanks dat systemen operationeel blijven.
A decade of Dutch digital sovereignty surrendered through procurement. From the failed Rijkscloud to the CLOUD Act, and now a state secretary who confirms it in writing and presses on anyway.
Mobile authenticator vulnerabilities expose a fundamental truth. Securing the endpoint OS while leaving the phone untouched is security theater. Here is what actually works.