# What happened Dutch intelligence and security organisations have issued a joint public warning that widely accessible generative tools are being used by criminals to automate and streamline cyberattacks. The letter was signed by the General Intelligence and Security Service (AIVD), the Military Intelligence and Security Service (MIVD), the National Cyber Security Centre (NCSC), the National Coordinator for Counterterrorism and Security (NCTV), the police, the Public Prosecution Service, and CIO Rijk.
# Why it matters
# Practical recommendations The signatories set out concrete defensive steps targeted at business leaders and institutions:
- Keep systems up to date and fix known vulnerabilities promptly.
- Closely monitor IT networks for unusual activity that could indicate compromise.
- Ensure executives and boards understand current threat developments and accept responsibility for cybersecurity decisions.
- Invest in the human factor: awareness programs, behaviour and culture change, and routine reporting of incidents to authorities.
These are framed as basic measures that raise the cost and reduce the success rate of automated attacks.
# What criminals can do with generative tools According to the organisations, available generative tools are already sufficient for many malicious tasks: producing malware that steals or encrypts data, and generating convincing phishing emails designed to capture credentials or other sensitive information. Tool developers have implemented safeguards, but incidents and breaches still occur.
# Who should take action The letter addresses business leaders, public institutions, and IT teams. The message is that cybersecurity is not solely an IT problem but a shared responsibility across organisations. The authorities urge faster adoption of basic cyber defences and timely reporting so that national response and law enforcement can act.
# Immediate steps for organisations Leaders should prioritise a short checklist:
- Verify patch management processes and timelines.
- Implement continuous network monitoring and anomaly detection where feasible.
- Run targeted staff training on phishing and credential security for employees with access to sensitive systems.
- Establish or clarify incident reporting channels to NCSC, police, or relevant authorities.
# Bottom line Widely available generative tools lower the effort required to prepare and launch cyberattacks. Dutch security bodies are calling for urgent, practical improvements in basic cyber hygiene, executive oversight, staff awareness, and incident reporting to reduce the national risk profile.