De ROI van opleiden aantonen: een rekenmodel voor je businesscase

CISO en controller bekijken samen een rekenmodel voor de ROI van een opleidingsinvestering op een laptop in een vergaderruimte.

De ROI van opleiden wordt zelden berekend, en dat is precies waarom opleidingsvoorstellen sneuvelen bij finance. Een aanvraag die stelt dat het team beter wordt, verliest het van een aanvraag met een terugverdientijd erin. Beide voorstellen kunnen kloppen. Alleen een van de twee is beoordeelbaar, en de ROI van opleiden is beoordeelbaar te maken met [โ€ฆ]

Open klas of in-company training: welk model past bij je team

Securityteam volgt gezamenlijk een in-company cybersecurity-training in een leslokaal met laptops en een docent bij het scherm.

De keuze tussen een open klas en in-company training wordt meestal op prijs gemaakt, en dat is precies de verkeerde volgorde. Beide modellen leveren dezelfde inhoud. Wat verschilt is wie er naast je medewerker zit, wanneer het traject start, en wat er van de opleiding overblijft in je organisatie zodra de deelnemer terug is. Die [โ€ฆ]

Vulnerability Management as a Team Discipline: From Scan to Action

The vulnerability management team is really important.

Every Monday morning, a vulnerability management team receives a 4,000-line report. Critical, high, medium, low. The scanner did exactly what it was purchased to do. What happens in the hours that follow determines whether that report reduces risk or merely fills up an archive. The bottleneck for a vulnerability management team rarely lies in detection. [โ€ฆ]

Business Email Compromise: The Attack That Doesn't Require Malware

Business email compromise is one of the most dangerous situations.

Business email compromise is the type of attack that your EDR doesnโ€™t detect, your spam filter doesnโ€™t flag, and your SOC doesnโ€™t receive an alert about. Thereโ€™s no attachment, no malicious link, and no unusual connection. It contains a request that seems legitimate: the right tone, the right timing, and references to ongoing projects. The Internet Crime Report 2025 [โ€ฆ]

Ransomware Preparedness: How to Prepare Your Team for the Day It Happens

Ransomware Preparedness in Practice: Crisis team meets during a cyber incident.

Ransomware preparedness rarely fails due to technical issues. It fails because of the question of who is authorized to decide at 3:00 a.m. that the production environment should be taken offline. Organizations invest in backups, segmentation, and detection, only to discover during an actual incident that no one knows who has the authority to make that decision. The NCSC notes that the initial response is often [โ€ฆ]