They used to be each other’s main competitors at different law firms, but Rosalie Brand and Erik Jonkman recently joined forces at Kennedy Van der Laan in what has become the largest legal cybersecurity practice in the Netherlands in one stroke. With their team they offer clients round-the-clock help with cyber risks and incidents, from data breaches and ransomware to invoice fraud. This way the duo wants to help organisations become legally resilient in an ever-evolving landscape full of threats.
"Cybercriminals still find plenty of low-hanging fruit." - Rosalie Brand
Also in 2025, cybersecurity requires the unabated attention of in-house lawyers, because in Brand’s opinion developments in cyberland will also take off this year. “Since criminals are constantly changing tactics, organisations should be on the alert all the time. This will certainly not slow down under the influence of AI. The legislator is not standing idle either. As organisations are confronted with more and stricter requirements to keep their cyber risks at bay, cybersecurity is becoming a significant responsibility of in-house lawyers.”
Several studies have shown that organisations believe the dealing with cyber threats to be one of their major challenges. “Small wonder”, Jonkman says. “Many organisations are already so digitised that a disruption of their IT systems directly threatens their business operations. A persistent misunderstanding is that cybercriminals are only after big companies with many data. We assist very diverse organisations in almost all sectors on a daily basis.”
Brand explains that in the cyber incidents they see – the Amsterdam law firm is constantly working on approx. ten cases – basic hygiene is all too often not in order. “Nine times out of ten, a cyberattack starts in the same way: criminals use a vulnerability, a bad password, or a phishing message. Once they are in, many parties lack the effective tools to stop the attack.” On the other hand, Brand sees more and more businesses with better back-ups. “But those who do not have their house in order will be attacked sooner or later. Cybercriminals still find plenty of low-hanging fruit.”
Legislation gains momentum
No matter the extent of preparation, many in-house lawyers will have to take several steps this year to improve their cybersecurity and to prepare for the new ‘Cybersecurity Act’. This Act – the Dutch implementation of the European NIS2 Directive – is expected to take effect in Q3 of this year.
“An estimated 8,000 organisations in the Netherlands will have to comply with the new requirements, from waste processors to drinking water companies, but also certain IT service providers and several businesses in the manufacturing and logistics sector”, Jonkman says. “There is a duty of care to manage cyber risks. Moreover, organisations will have to monitor proper compliance in their supply chains as well.”
Brand: “The Cybersecurity Act comes with several important duties for organisations. One of these is that incidents must be reported to the supervisory authority within 24 hours. This differs substantially from the data breach notification requirement we are accustomed to and familiar with from the General Data Protection Regulation (GDPR). During an incident, this deadline will pass before you know it, while your focus will be elsewhere at such a time. To comply with this reporting duty, your organisation should be prepared.”
"Avoid unnecessary surprises once an incident happens. The last thing you want in an incident is to end up in a queue." - Erik Jonkman
Jonkman: “This is exactly what we want to emphasize: avoid unnecessary surprises once an incident happens. Strange as it may sound, the course that most cyber incidents take is easy to predict. The upside of this is that you can start outlining scenarios today, for example as a basis for a simulation. In the intake of an incident an external advisor can tell at once whether the organisation affected has ran such simulations or can draw from previous experience with a cyber incident. If that is the case, there will be more peace and quiet and a faster recovery, which saves a lot of money in the end.”
“Do not underestimate the role of the in-house lawyer”, Brand adds. “Their role is essential even if there is support from specialised attorneys. We know the incidents, but the in-house lawyer knows the organisation. This combination works extremely well to mitigate the risks of an incident.”
Jonkman continues: “Besides, at a time when your organisation is down, you do not want to waste unnecessary time on searching for external support. Here too, the experts you want to rely on should be known in advance, so that you can drum them up easily. The last thing you want in an incident is to end up in a queue.”
Data Authority even more active
Since the end of last year, Kennedy Van der Laan notices that the Dutch Data Protection Authority (‘AP’) is stepping up its actions regarding data breaches. “The impression of some parties that the AP ‘does nothing’ with a report is wrong. We see that the AP increasingly follows up incidents and joins the cyber playing field in a more general sense. If your incident hits the headlines, you can practically be sure of coming into contact with the AP during stakeholder management”, Brand says.
This means that as a company, you have to consider ways of dealing with many internal and external stakeholders in a cyber incident. Brand: “We can tell approximately from experience what and who an organisation will be faced with if an incident happens. For high-profile cases we have a roadmap and are prepared to engage certain public and private parties pro-actively if this is in the client's interests. Since we have been meeting these parties in the field for years, we have a basis of trust and a flat structure. This definitely helps to settle incidents in a good way.”
“In our practice, we notice how stakeholder management gains importance every day, probably by an increasing awareness in society of the negative consequences of cyber incidents”, Jonkman says. “Customers, employees and shareholders will no longer be fobbed off and will demand a full explanation, much more so than before. In the end, stakeholders want to be able to rely on you taking their interests seriously and being sufficiently in control, whatever happens. We believe that this expectation is justified.”