Blog
Log files and NEN 7513: The forgotten child that leads to the highest GDPR fines
Summary for the quick reader: Many healthcare organizations focus on the new NEN 7510:2024 (policy), but neglect NEN 7513 (logging). This is an expensive...
Rob Veen · 26-8-2026
Ransomware and NEN 7510: Why Your Internal Audit Is Missing the Kill Switch
Summary for the quick reader: A traditional NEN 7510 internal audit often focuses on policy documentation (compliance), while modern ransomware attacks...
Rob Veen · 26-8-2026
Why healthcare workers ignore your security policy (and you pay the price)
When healthcare staff violate security rules (such as sharing passwords or using WhatsApp for patient photos), this is often a symptom of unworkable IT...
Rob Veen · 26-8-2026
10 Open Source Security Tools SMBs Can Implement Right Away
Most SMBs do not have a shortage of security policies. They have a shortage of working measures.
Jordy Bouwknegt · 13-6-2026
Phishing and ISO 27001 for Dutch SMEs
For Dutch SMEs, phishing is not an 'awareness topic', but a practical line of attack leading to account takeover, payment fraud, data theft, supplier abuse,...
Jordy Bouwknegt · 5-6-2026
Deep Dive: ISO 27001:2022 Logical Access Security
In this article, we focus on controls A.5.15 through A.5.18 and A.8.2 through A.8.5, which cover access management, identity management, authentication...
Jordy Bouwknegt · 9-3-2026
What is ISO 27001 Annex A in plain language?
You are working on ISO 27001, the international standard for information security. You know the theory: you need to identify your risks, set out your...
Rob Veen · 10-11-2025