NL Times, donderdag 8 oktober om 16:10, 1 min lezen
OM needs "considerable amount of time" to make systems fully secure after 2025 hack

Thursday, 8 October 2026 - 16:10
It will take the Public Prosecution Service (OM) a "considerable amount of time" to make its systems fully "fire-safe" following the 2025 cyberattack. The final report by a committee led by Jaap Smit says significant preventive work is still needed before the OM can be considered "fire-safe."
In July, the OM took all of its systems offline after a vulnerability in one of its systems was exploited. It later emerged that several other organizations had also been affected by the vulnerability in Citrix NetScalers.
It is stated in the report that taking the system offline was the right decision after OM had received a tip from the National Cyber Security Centre (NCSC). However, the OM had not adequately secured its systems, and warnings about vulnerabilities were not followed up sufficiently.
The OM leadership acknowledged that the monitoring system should have been in order before the incident and that improvements have since been made. “The OM now has a solid monitoring system and is adequately set up to detect, investigate, and respond to suspicious activities and patterns in a fast and adequate manner.”
Smit added that OM are now working hard on solidifying their digital security, but it still needs improvements. The Smit Commission was ordered by the Ministry of Justice and Security and the Board of Prosecutors-General.
Reporting by ANP