A combined software and human expert managed service for vendor security risk management, keeping your entire supplier portfolio continuously monitored, not just once a year like traditional assessments.
75% of companies were hit by a supply chain attack last year. Every company has a digital supply chain, and every company is part of someone else’s. You probably know your ten direct suppliers, but the two hundred to four hundred behind them stay in the dark. Nobody expects another dependency to be critical for their operations, until it is.
Taking control starts with having insights.
Agilitec is een Nederlands softwarebedrijf dat productieomgevingen efficiënter én OT-technisch veiliger maakt. Als distributeur van octoplant helpt Agilitec productiebedrijven met veilig beheer, back-up en versiebeheer van industriële software en automatiseringssystemen. Daarnaast ontwikkelt Agilitec MyPlantFloor, een MES/OEE-platform voor het verbeteren van productieprocessen.
Aikido is the no-nonsense security platform for developers. The all-in-one security platform that covers you from code-to-cloud and helps you get security done. Engineering teams execute faster with Aikido thanks to centralized scans, aggressive false positive reduction, automatic risk triaging & fixing, risk bundling, and easy step-by-step risk fixes. Aikido makes security simple and doable for developers, so companies can win customers, grow up-market, and ace compliance. Don’t just get security done fast, get it done automatically.
Alistar is een Europese full-service technologiepartner die organisaties helpt om hun digitale ambities waar te maken. Door menselijk inzicht, data en technologie samen te brengen, ontwikkelen we slimme oplossingen die processen versnellen, schaalbaarheid vergroten en duurzame groei mogelijk maken. Altijd strategisch. Altijd mensgericht.
Arda helpt organisaties om medewerkers bewust te maken van cyber security en gegevensbescherming. Het platform combineert e-learning, interactieve films, casuïstiek, expert interviews en serious games. Onze films werken met storytelling op basis van echte Nederlandse acteurs. De verhalen zijn gebaseerd op lokale, herkenbare incidenten en situaties. Door die afwisseling blijft informatiebeveiliging top of mind en leren medewerkers wat ze moeten doen bij bijvoorbeeld phishing, ransomware en datalekken.
Het programma is geschikt voor de hele organisatie, met aanvullende leerlijnen voor rollen die meer specifieke kennis nodig hebben, zoals IT, management en financieel specialisten. Daarmee voldoe je aan wet- en regelgeving en normen zoals de NIS2, CBW, AVG, ISO 27001, NEN 7510, BIO en het normenkader IBP.
Arda wordt ingezet door een grote diversiteit aan organisaties, met een extra focus op onderwijsinstellingen, overheden en zorginstellingen. Deelnemers waarderen de trainingen gemiddeld met een 8,6.
Kom langs op de stand voor een demo en ontdek hoe informatieveilig werken een tweede natuur wordt.
Armis from ServiceNow protects the entire attack surface and manages an organization’s cyber risk exposure in real time. In a rapidly evolving, perimeter-less world, Armis ensures that organizations continuously see, protect and manage all critical assets – from the ground to the cloud. Armis secures Fortune 100, 200 and 500 companies as well as national governments, state and local entities to help keep critical infrastructure, economies and society stay safe and secure 24/7.
About Atos
Atos is the Atos Group brand dedicated to AI-powered, secure, end-to-end digital services. Atos designs, develops, and operates critical digital environments that drive performance, resilience and sovereignty, helping public and private organizations worldwide retain control over their data and infrastructures, while meeting regulatory requirements.
With more than 52,000 employees serving over 4,500 clients across 54 countries, Atos helps modernize core IT systems, accelerate cloud and data transformation, strengthen cybersecurity, and deliver secure digital workplace environments to support its clients, its employees and society. Atos also provides consulting and advisory services through its Atos Amplify brand.
A trusted partner in operating complex and mission-critical environments, Atos supports organizations across highly regulated and sovereign contexts.
About Atos Group
Atos Group is a global leader in digital transformation with c. 54,000 employees and annual revenue of c. €7.2 billion, operating in 54 countries under two brands – Atos for services and Eviden for products and systems. European number one in cybersecurity and a leader in cloud, Atos Group is committed to a secure and decarbonized future and provides tailored AI-powered, end-to-end solutions for all industries. Atos Group is listed on Euronext Paris.
Attic Security protects organisations that run on Microsoft 365.
Three out of four Defender alerts are rated Low or Informational, and nobody looks at them. That is where attacks like Business Email Compromise hide. Our AI SOC analyst IVON investigates every alert, day and night, and writes the outcome back into Defender.
– Works on Microsoft 365 Business Premium, no E5 needed
– Self-service setup in 5 minutes, cancel monthly
– Built and hosted in the EU, models are not trained on your data
Test it on an incident from your own environment: https://attc.to/ivoncybersec
Visit us at our stand and see IVON at work.
Information security is not just about technology and rules, but primarily about human factor.
Awareways supports organizations in structurally reinforcing secure behavior, in a way that fits their needs.
Security, privacy, and AI awareness. From compliance to culture, through measurable behavior change.
Een cyberincident volledig uitsluiten? Dat kan niemand.
Maar je kunt wél zorgen dat je organisatie voorbereid is.
Dat dreigingen zo vroeg mogelijk worden herkend, dat
je weet wat je moet doen als het misgaat en dat snel kan
worden achterhaald wat er precies is gebeurd.
Daarom verbinden Unica ICT en BDO hun expertise.
Unica ICT helpt organisaties hun digitale omgeving te
beschermen, continu te monitoren en snel te reageren
op dreigingen. BDO brengt specialistische expertise in
op het gebied van Digital Forensics & Incident Response
wanneer diepgaand onderzoek nodig is.
We believe people make organisations more resilient when risk-aware working becomes second nature
Technology and processes are essential to information security and are only truly effective when people recognise risks and make secure choices. Employees handle information, use systems and make daily decisions that strengthen or weaken an organisation’s resilience.
Our mission is to relieve organisations of the burden of managing security awareness and behaviour, so that a culture emerges in which risk-aware working becomes second nature. This requires more than e-learning modules, standalone training, phishing tests or an annual campaign. Only by understanding business risks, behaviour and programme maturity.
We therefore developed Bright®: our approach to systematically developing, measuring and embedding risk-aware behaviour. Bright® comprises four interconnected phases: Assess, Educate, Direct and Sustain.
The Bright Security Awareness Management System (SAMS) supports the approach through its integrated control framework and maturity model. This enables us to assess how mature an organisation is in governing, delivering and improving security awareness. We examine governance, responsibilities, processes, measurement, intervention design and planning, and programme embedding across four levels: Ad hoc, Awareness, Behaviour and Culture.
We combine these insights with risk workshops, interviews, simulations, behavioural data, and cyber skills and cyber culture surveys. Our persona-based approach provides the consistent thread: we distinguish target groups by role, context and risk profile, allowing risks and data to determine where and how interventions will have the greatest impact.
“Als jij onzichtbaar blijft, wordt de wereld niet veiliger.”
Veel securitybedrijven zijn terughoudend om te vertellen wat ze doen, laat staan wat ze verkopen. Ze zijn bang om opdringerig over te komen en blijven daardoor onzichtbaar voor de mensen die hen nodig hebben.
Wij zorgen dat je die stap wel zet, met de juiste boodschap, voor de juiste persoon, via het juiste kanaal.
Alleen dan maak je echt impact.
BMGRIP is een fullservice consultancy kantoor op het gebied van informatiebeveiliging, privacy en continuity. Met ongeveer 25 betrokken collega's bieden we hoogwaardige oplossingen aan diverse organisaties, waaronder (inter)nationale ondernemingen, financiële instellingen en zorginstellingen.
Al meer dan 10 jaar versterken wij organisaties op het gebied van information security, privacy en business continuity, vertrouwd door 1.500+ klanten in zorg en informatietechnologie. Onze kracht ligt in het bieden van inzicht, samenhang en grip. We combineren inhoudelijke kennis van normen met duurzame implementatie en integratie in jouw organisatie. Onze aanpak in het kort: uw processen staan centraal, niet de wet- en regelgeving; risicogebaseerd inrichten zorgt voor gericht resultaat én risicoverlaging; projectmatig organiseren zorgt voor structuur, heldere doelen en strakke deadlines. Als onderdeel van Kader helpen we organisaties verantwoord te moderniseren.
Onze diensten (drie blokken):
Normen & wetgeving: ISO 27001, NEN 7510, ISO 27701, ISO 22301, ISO 9001, ISAE 3402, SOC 2, AVG/GDPR, NIS2/Cyberbeveiligingswet, BIO, MDR.
Sectoren: zorg · IT & SaaS · overheid en semi-overheid · MSP's en dienstverleners.
Who is BSI?
BSI is one of the world's leading certification bodies, helping organizations achieve and maintain internationally recognized management system certifications.
For organizations looking to strengthen their cybersecurity and information security governance, BSI provides accredited certification against standards such as ISO/IEC 27001, ISO/IEC 27701, ISO 22301 and ISO/IEC 42001. Our independent certification services help organizations demonstrate compliance, meet customer and regulatory requirements and continually improve their management systems.
Alongside certification, BSI delivers comprehensive training courses covering information security, privacy, business continuity, AI governance and auditing. Whether you are new to ISO standards or preparing to become an internal or lead auditor, our expert-led courses provide practical knowledge that can be applied immediately. Interested in a training course with 40% discount? Come by our stand!
Our auditors and trainers work with organizations of all sizes. From fast-growing technology companies to multinational enterprises and public sector organizations.
We're here to help you understand standards, prepare for certification and maintain compliance in an increasingly demanding regulatory landscape.
If you're considering certification, preparing for ISO/IEC 27001, navigating new regulations such as NIS2, or looking to develop your team's expertise, visit the BSI stand to discover how our certification and training services can support your next step.
We're happy to help, even if it's just one conversation.
***
As an organization without shareholders, we reinvest our profits to achieve the difference we want to see in the world. Our purpose-led approach attracts other organizations and thought-leaders to work with us. Our stakeholders and clients value our impartiality, global reach, and leading-edge expertise. We give organizations of all sizes the confidence to explore, grow, and prepare for the challenges ahead. We form strong collaborations and partnerships with experts, businesses, governments, and non-governmental organizations to deliver a positive impact.
CCRC (Cyber Chain Resilience Consortium) is een onafhankelijk platform dat organisaties ondersteunt bij het versterken van hun cyberweerbaarheid door middel van realistische cybercrisisoefeningen, simulaties en kennisdeling. CCRC brengt publieke en private organisaties samen om samenwerking binnen digitale ketens te versterken, risico’s te beperken en organisaties optimaal voor te bereiden op cyberincidenten. Met een praktijkgerichte aanpak draagt CCRC bij aan een veiliger en weerbaarder digitaal Nederland.
A global player
Cegeka has evolved into a global technology provider, serving over 2,500 customers worldwide. Our comprehensive offerings include application services, business solutions, quality engineering, data and AI, digital workplaces, cyber resilience, networking & regulatory, and hybrid cloud.
With a presence in the Benelux, Germany, Austria, Romania, Moldova, Italy, Sweden, Greece, Denmark, France, the United Kingdom, the United States, Colombia, and India, Cegeka boasts a workforce of over 9,000 employees.
Cegeka remains a family-owned company, headquartered in Hasselt, Belgium.
Checkdone IT is an independent IT security partner focused on one core objective: bringing clarity, control and direction to complex security environments. In a market full of noise, overlapping tools and conflicting advice, we help organisations understand where they stand and what truly matters.
Security is often approached as a collection of technologies. In reality, the challenge lies elsewhere. It is about insight into risks, clear policies and procedures, an overview of the full landscape and control over decisions. Without that, organisations invest heavily but still lack confidence.
We work differently. Fully independent, we act solely in your interest. We analyse your environment, identify real risks and translate them into clear, practical steps. From strategy to implementation, we take ownership and ensure that decisions actually work in practice.
Our approach is integrated. Technology, policy and compliance are always connected. By aligning these elements, we help organisations move from fragmented security towards a structured and manageable approach.
The result is simple: clarity in choices, control over risks and confidence in your security.
This event will be hosted together with our partners: SecuMailer, Segura, Torq, Labyrinth and ZeroFox
Cognyte, a global leader in investigative analytics solutions, helps government agencies and other organizations uncover mission-critical insights and make smarter, faster decisions with Actionable Intelligence for a Safer World®.
LUMINAR is an all-in-one external threat intelligence solution for CTI, DRP, and EASM. It combines an AI-powered platform that automates large-scale threat discovery, correlation, and prioritization with an embedded proactive expert human layer that delivers tailored threat intelligence, aligns findings to business risk and priorities, guides response, and supports remediation.
We’re Colt. We own and operate exceptional digital infrastructure which powers the global AI economy, connects societies, builds communities and transforms lives. Thousands of colleagues in 65+ offices across Europe, Asia, and North America share a deep commitment to delivering an outstanding experience and making every interaction effortless for our customers.
Customers and partners choose our award-winning fibre infrastructure, digital platforms and security solutions, delivered across a network that spans continents and crosses oceans. We’re Europe’s largest B2B operator: we connect 40+ countries, 32,000 enterprise buildings, 275+ points of presence, and 12 cable landing stations and we manage eight subsea cable systems. We also co-manage AS3356 – the most widely peered network in the world.
Founded in London over 30 years ago, we’re privately funded and driven by values of fairness, inclusion and equity. We’re known for our urgent call for social and sustainable change and we're guided by our purpose in everything we do: creating effortless connections and extraordinary outcomes for our customers, communities and people. Be a part of our story: come on over to www.colt.net or join our amazing communities at LinkedIn, Instagram, TikTok, Facebook and YouTube. Media enquiry? Email us at pressqueries@colt.net.
We help cybersecurity and risk teams automate up to 80% of their GRC workload (compliance, risk management, audit preparation), which is still often handled manually or across multiple tools.
Our platform allows you to manage multiple frameworks like RGPD, ISO 27001, NIS2 and many others in one place, with controls mapped once and applied across all regulations. This significantly reduces duplication, improves visibility, and makes audit readiness much faster.
Everything is fully no-code, meaning your team can adapt risk models, controls, and reporting in real time without relying on IT or external support.
The goal is simple: less time spent on reporting and compliance, more time actually managing risk and cover the company.
Compumatica secure networks B.V. is een 100% Nederlandse fabrikant en reseller van cybersecurityoplossingen, gespecialiseerd in de bescherming van "data in rest" en "data in transit".
Wij bieden organisaties die autonomie en soevereiniteit nastreven, beveiliging op het hoogste niveau: volledige transparantie over de herkomst van de technologie en over wie er toegang toe heeft – zonder backdoors. Deze uitgangspunten vormen de kern van onze missie: "To protect what matters most."
Onze klanten bevinden zich zowel binnen als buiten Nederland; onze producten worden ingezet in meer dan 180 landen wereldwijd. Compumatica richt zich primair op overheidsmarkten – waaronder Defensie, ministeries en ambassades – evenals op organisaties binnen de kritieke en vitale infrastructuur, zoals olie & gas, manufacturing, energie (inclusief kerncentrales), infrastructuur (bruggen, sluizen en tunnels), maritiem, en de voedselproducerende industrie.
Ons portfolio omvat onder meer cryptoboxen, data diodes, special purpose firewalls, mailencryptie-oplossingen en hardware security modules (HSM's).
Compumatica is een erkend ABDO/ABRO-bedrijf, levert gecertificeerde oplossingen volgens AIVD/uWBH, en is één van de zeven Nederlandse ondernemingen die deelnemen aan het Nationale Cryptostrategie-programma (NCS) van de Nederlandse overheid.
Crimson7 is an offensive security company built on one premise: point-in-time testing cannot prove you are defended today. A pentest or a one-off red team is a snapshot, and detections drift and break silently the moment the report is filed.
We work in Adversarial Exposure Validation, the Gartner category for validating exposure continuously against real adversary behavior. The discipline is our own: validate behavior, not tools, and prove your detections fire rather than assume they do.
One platform runs that loop from both sides. HackerFlow covers the attack side: it simulates real adversary techniques with live command-and-control infrastructure, confirms whether your EDR and SIEM detections actually fire, and delivers remediation as Detection-as-Code and Response-as-Code instead of a PDF report. 7Hunter covers the defensive side, with threat hunting on Microsoft Sentinel backed by 8,000+ pre-built KQL queries and 75+ investigation runbooks. Around them we run threat-led red teaming, detection engineering and managed continuous purple teaming. Everything maps to MITRE ATT&CK and aligns to DORA and NIS2.
Come by stand 11.C015 and we will look at whether we can run a free proof of value on your own environment. Joey and Atilla present twice in Masterclass theater 2, both days at 12:30: Always Under Attack on Wednesday, Never Hunt Alone on Thursday.
Wie wij zijn
Cyber Security Challengers is een team van cybersecurity-specialisten voor organisaties die cybersecurity serieus nemen. Wij geloven niet in kant-en-klare oplossingen, maar in partnerschap: wij werken naast bestuurders en in security teams, niet los daarvan.
We helpen bestuurders hun verantwoordelijkheid op het cyberdomein daadwerkelijk dragen. Niet uit angst voor boetes, maar om regie te krijgen over de eigen veiligheid.
Hoe wij werken
Wij hanteren een vast groeimodel: van nulmeting, via implementatie van maatregelen, naar duurzame governance. Elke fase bouwt op de vorige. De nulmeting brengt risico's en volwassenheid in kaart, de implementatiefase voert de bijbehorende maatregelen door, de governancefase borgt dat die maatregelen blijven werken door periodieke toetsing en bijsturing.
Wij werken risicogebaseerd: niet alles is even urgent. Prioriteiten stellen we organisatorisch, mensgericht, fysiek en technologisch tegelijk, nooit los van elkaar. Een kwetsbaarheid in een kritiek systeem weegt zwaarder dan een verouderd beleidsdocument, en de aanpak volgt die volgorde.
Compliance volgt
Bestuurders dragen verantwoordelijkheid voor cybersecurity. Die kan niet gedelegeerd worden, wel gedragen worden met de juiste kennis, een uitgebreid netwerk en onze praktische inzet. Wanneer het fundament op orde is, volgt naleving van BIO2, ISO 27001 en NIS2/Cbw als vanzelf uit dat fundament, in plaats van als losse exercitie.
CISO-as-a-Service
Voor structurele ondersteuning zetten we CISO-as-a-Service in: een vast aanspreekpunt met een directe lijn naar uw bestuur en uw directie, kwartaalrapportage aan de raad van bestuur, en opschalen bij incidenten. Zo krijgt een organisatie de slagkracht van een ervaren CISO, inclusief het netwerk aan vakgenoten en gespecialiseerde partners dat daarbij hoort, zonder de vaste kosten van een intern team.
Uit deze aanpak ontstaan duurzame relaties: met vakgenoten, klanten en leveranciers die elkaar versterken. Het resultaat is meetbaar: aantoonbare naleving, een werkend fundament en een daadwerkelijk weerbare organisatie die bij de volgende audit niet hoeft te improviseren.
Cyemptive Technologies — pre-emptive security for critical infrastructure
Cyemptive is the pre-emptive security company that continuously returns critical systems to a known-good state — so continuity no longer depends on how fast your team spots an attacker.
Detection-based security starts working the moment something is noticed. That is the moment the damage has already begun.
Cyemptive works the other way around: our patented technology continuously restores systems to a verified clean state, neutralising threats — including zero-day, AI-driven and quantum-era attacks — across endpoint, perimeter and everything in between, whether or not an attack is ever detected.
The result is what our customers actually care about: resilience, sovereignty and continuity. You keep control over your own data and chain of custody. We do not need to own or interpret that data to deliver the outcome.
Sovereign by design. Cyemptive's European headquarters is located at the HSD Campus in The Hague, with services delivered from Dutch/EU data centres — supporting NIS2, Cbw and Dutch sovereignty requirements. We work with PCSI/TNO, Security Delta (HSD), Innovation Quarter and the wider Campus community.
Meet us at Cybersec Netherlands. Founder and CEO Rob Pike presents a working demonstration, not a product tour. Visit us at the HSD Meeting Zone, to discuss a Proof of Concept against your own requirements.
DataBee®, a Comcast company, helps Global 2000 organizations turn fragmented security, risk, and compliance data into a trusted foundation for cyber risk management, especially important as AI accelerates risk. Its portfolio includes continuous controls monitoring, exposure management, security threats, inventory, user access review, and DataBee RiskFlow™ for AI-powered risk insights.
We are an OT cybersecurity company focused on securing and modernising the industrial environments that underpin critical national infrastructure. Our phoenix platform brings security, visibility, resilience, access and transformation capabilities together at the edge and across distributed estates. At Cybersec Netherlands, we are exhibiting alongside OnLogic to demonstrate a complete solution combining phoenix with industrial edge hardware. Designed for the realities of operational technology, the solution integrates with existing environments and provides visibility and control across sites. This enables operators to strengthen cyber resilience, simplify operations and take a scalable approach to secure OT modernisation without disrupting essential operations.
DNV is one of the world’s leading certification bodies. Through management system certification, supply chain assurance and training services, we help companies manage risks, assure compliance and build competence in organizations, supply chains and people. Working with companies in all sectors – from food and beverage to ground and air mobility, ICT and general industries – DNV’s digitally enabled services and customer journey help companies operate sustainably and meet stakeholder demands.
DNV’s digitally enabled certification, assurance and training services help customers manage risks, make critical decisions and continually improve. Whether tackling quality, environmental, safety, social & ethical or security challenges, DNV combines technical, industry and risk management expertise to build confidence, continuity, and resilience.
Driven by its purpose, to safeguard life, property, and the environment, DNV helps tackle the challenges and global transformations facing its customers and the world today and is a trusted voice for many of the world’s most successful and forward-thinking companies.
DXC Technology is an enterprise technology and innovation partner helping global enterprises and public sector organisations run efficiently and modernise their systems. With more than 60 years of experience, DXC modernises, secures and operates some of the world’s most complex technology estates.
Our end-to-end capabilities span AI, cloud and infrastructure, cybersecurity, enterprise applications and managed services, helping organizations keep critical systems resilient, compliant, scalable and protected while preparing for what’s next.
"Who can access what within my organisation?"
Elimity enables organisations to answer this crucial question within days, not months.
With provable control over user access essential for NIS2, DORA, and ISO 27001 compliance, Elimity gives you the fastest way to see who—human and non-human identities, including AI agents – has access across your IT landscape.
Our Identity Visibility and Intelligence Platform (IVIP), Elimity Insights, is trusted by organisations like Monuta, OceanCo, Liantis, and Belfius:
Agilitec is een Nederlands softwarebedrijf dat productieomgevingen efficiënter én OT-technisch veiliger maakt. Als distributeur van octoplant helpt Agilitec productiebedrijven met veilig beheer, back-up en versiebeheer van industriële software en automatiseringssystemen. Daarnaast ontwikkelt Agilitec MyPlantFloor, een MES/OEE-platform voor het verbeteren van productieprocessen.