Organisations are investing millions in security operations centres, threat intelligence, Zero Trust, endpoint protection and AI-driven detection. Yet ransomware, data breaches and digital disruption remain widespread. At Cybersec Netherlands 2026, Arno Reuser of OSINT Solutions asks a fundamental question: are we focusing our attention on the right areas?
Cybersecurity is more mature than ever. Organisations are investing millions in security operations centres, threat intelligence, Zero Trust, endpoint protection and AI-driven detection. Yet ransomware attacks, data breaches and digital disruption remain part of everyday reality.
The question is therefore not whether we are investing in cybersecurity, but whether we are focusing our attention on the right areas.
The response to almost every new threat is similar: a new tool, an additional security layer or a more advanced detection technology. Technological innovation is essential, but cybersecurity is increasingly being approached as a purely technical challenge.
And that is exactly where the problem lies, according to OSINT specialist Arno Reuser. On 10 September, he will address this dilemma in his keynote at Cybersec Netherlands 2026.
Assumptions
Most successful attacks do not start with a highly sophisticated technical exploit, but with human behaviour. An employee clicks on a convincing phishing email. A password is reused. A request is approved without proper verification. Or someone simply sees security measures as an obstacle to getting their work done.
That does not mean users are the problem. On the contrary. It means organisations often build their defences around the assumption that people will always behave securely. In practice, that assumption rarely holds.
An organisational challenge
Nevertheless, the emphasis continues to be placed primarily on technology. Security awareness is often reduced to mandatory e-learning or periodic phishing tests, while secure behaviour requires much more.
It is about organisational culture, leadership, ownership and designing processes in which the secure choice becomes the natural choice. Cybersecurity is ultimately not only an IT challenge, but an organisational one.
“As long as the human factor remains an afterthought, organisations will continue investing in treating the symptoms.”
This creates a striking paradox. We are becoming increasingly effective at detecting attacks, but far less effective at preventing the conditions that allow attackers to succeed.
Keynote by Arno Reuser
This idea is at the heart of Arno Reuser’s keynote at Cybersec Netherlands 2026.
Under the title “You Are All Wrong: Cybersecurity Is Failing, and It’s Not the Hackers”, he will challenge the cybersecurity industry on 10 September at 12:40.
According to Reuser, the greatest threat to cybersecurity is not the cybercriminal, but our limited way of thinking about security. As long as organisations continue to rely primarily on technical solutions while neglecting the human side, the gap between cybersecurity investment and actually becoming more secure will continue to grow.
During his keynote, Reuser will use current real-world examples to highlight some of the biggest blind spots and explain why a fundamentally different approach to cybersecurity is necessary.
Not by making technology less important, but by making it part of a broader strategy in which people, organisations and technology are inseparably connected.