Cybersecurity used to be a concern for governments and multinationals. That has changed. Dutch small and medium-sized enterprises, organizations with 10 to 250 employees, are squarely in the firing line.
According to ABN Amro, one in five Dutch companies suffered damage from a cyberattack in 2024. A separate study by Mastercard found that one in four SMEs has already fallen victim. With roughly 55,000 SMEs in the Netherlands, that is between 11,000 and 13,750 incidents a year. They mean financial loss, disruption and reputational harm.
Why SMEs are attractive targets
Large organizations have been investing heavily in security for years. SMEs, by contrast, often have limited budgets, smaller teams and a heavy reliance on external IT providers. Many underestimate the financial risk, which leads to late or insufficient action.
Rabobank puts the average cost of an SME incident, including response and recovery, at around €300,000. ESET estimates €270,000. Research by the Dutch police shows that SMEs with cyber insurance are preferred targets: insured companies end up paying 2.8 times more in ransom than uninsured peers.
Insured companies pay 2.8 times more in ransom than uninsured peers.
Then there is the supply chain effect, which is less obvious. SMEs sit inside larger ecosystems, and attackers see them as stepping stones toward bigger targets. One vulnerable SME can open the door to a much larger organization.
Falling victim to low-sophistication attacks
Even without advanced malware or nation-state tooling, SMEs remain exposed. The biggest risk is still the inbox. According to KPN, phishing attempts against companies increased tenfold in a single year. It takes one employee clicking one link to hand over access to systems or credentials.
The CrowdStrike SME Security Survey confirms the pattern: awareness of the risk is high, actual protection lags. Owners know that phishing, ransomware and credential leaks are serious. They have not yet organized the defense.
Collaboration is moving it up the agenda
It is not all bad. Municipalities and industry associations report partnerships designed to raise SME resilience, and they make the same point: cybersecurity has to be chefsache, a board-level responsibility rather than something delegated to an intern or outsourced without oversight.
Embedding it structurally means more than technical fixes. It means governance, training, working with industry peers, and continuous visibility into risk.
What we see organizations struggle with
- Heavy dependence on an IT provider, with no clear accountability for security.
- Poor visibility into external risk such as credential leaks or shadow IT.
- Policies that exist on paper but are not implemented.
- Limited budget, which pushes security further down the list.
These explain why SMEs stay exposed even when they are aware of the risk and want to fix it.
Practical steps
Improving resilience does not require an expensive Security Operations Center. Pragmatic measures already remove a large share of the risk.
- Take stock of systems and data. Security starts with knowing what you have to protect.
- Enable multi-factor authentication wherever it is available.
- Use a password manager to prevent reuse.
- Create and test backups regularly. An untested backup is not a backup.
- Train staff continuously with short practical sessions and phishing simulations.
- Monitor your digital footprint for leaks, phishing domains and vulnerable exposed systems.
From cost to condition of doing business
Each measure is small on its own. Together they are a foundation. What still needs to change is the framing.
Many SMEs treat security as pure cost. It is becoming a condition of doing business. Larger clients demand proof of resilience across their chains. Insurers are tightening requirements and refusing cover without MFA or backups. Customers increasingly prefer suppliers who can show they take it seriously.

