Masterclass · 1 day · live online

Cyber Awareness

The way in is not the technology but the human being. You see which traces you leave online, how an approach is built on them and why it succeeds so often.

✓ No prior knowledge needed  ·  live online  ·  instructors from government practice  ·  CRKBO-accredited

Level
MasterclassThe human as target
Format
1 daylive online
Investment
€ 595VAT-exempt
Institute
CRKBORegistered institute
Certificate
IACAcertificate of attendance

About the masterclass

The human is the way in

In almost every incident the human being plays a part. Not because people are careless, but because whoever wants to get in knows exactly which buttons to press. Long before a single malicious file is sent, the work is already done. Public sources have been combed through and roles and relationships mapped. A credible pretext has been found and a channel chosen to approach you through.

In this masterclass you turn the perspective around. You look over the shoulder of the person approaching you. What do they find about you and your organization within an hour? Who do they pick as the first target, and why? You see how the first contact is built and which psychological mechanisms are used to win trust. Only then do you look back at your own situation.

The masterclass is delivered fully live online, in an interactive virtual classroom. The instructors are highly experienced cyber security experts from government practice. Not e-learning and not a webinar: the instructor is there live and you work on the exercises yourself.

What you learn

From open source to inside

The masterclass follows one continuous line, from the traces you leave to the moment someone is inside:

01
Traces

Your digital footprint

What you and your organization give away unnoticed and how that material becomes the starting point for a targeted approach.

02
Approach

How contact is made

Who is picked first, which cover story goes with it and through which channel the contact runs.

03
Psychology

Why it works

The mechanisms behind a successful approach and why experienced, critical professionals fall for it just as hard.

Afterwards you know which information about you is out in the open and what can and cannot be done about it. You recognize the build-up of an approach at an early stage, well before anyone asks for a file, a link or a favor. And you know where the way into your own organization most likely lies.

The approach is interactive and practical. You work with general examples from public sources and take real approaches apart to find the signals they contained.

Why now

The Dutch Cybersecurity Act makes cyber awareness and training part of the duty of care

The Dutch Cybersecurity Act calls not only for secure systems, but also for people who recognize risks and know how to act. This masterclass makes that awareness concrete and demonstrable.

Since 15 August 2026 more than 8,000 organizations face new cybersecurity obligations. Those obligations are not only about technology. Cyber hygiene, awareness and training are part of the statutory approach as well.

This masterclass helps organizations give concrete substance to that. Staff learn how they can be used as the way in and which signals precede an approach. With this masterclass your organization demonstrably invests in cyber awareness and safe behavior. Participation is demonstrable with the IACA certificate of attendance.

The act in detail

What the act actually requires

For those who want the full picture, the obligations as they are set out in the act and the order in council.

On 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet) and the Critical Entities Resilience Act came into force. The Cybersecurity Act implements the European NIS2 Directive. The Critical Entities Resilience Act separately implements the European CER Directive. Organizations covered by the act are classified as essential or as important entities. Suppliers that do not fall under the act themselves can still be affected through the requirements their clients impose.

The duty of care is set out in article 21 of the act. Organizations take appropriate technical, operational and organizational measures to manage their risks. Cyber hygiene and cybersecurity training are named explicitly among the minimum measures. A reporting duty and a registration duty apply as well.

Staff do not carry a general, personal training and certificate obligation. The responsibility sits with the organization. Article 12 of the Cyberbeveiligingsbesluit covers personnel and other people working within the entity. They must be aware of the risks to the network and information systems, in so far as this is relevant to their role. They must also apply cyber hygiene practices.

The organization additionally designates the people whose roles require knowledge and expertise in cybersecurity. They must receive regular training. According to the official explanatory notes, a course or training program can be used for this.

Executive board members carry a separate, personal obligation, laid down in article 24 of the act. They must have the knowledge and skills to identify risks and to assess risk management measures. For that they follow appropriate training and must be able to show a certificate. Supervisory board members and non-executive directors are exempt.

The term is two years. Board members already in office on 15 August 2026 therefore have until 15 August 2028 at the latest. Anyone appointed after 15 August 2026 has two years from their appointment. From then on the knowledge must be kept demonstrably up to date.

The Cyberbeveiligingsbesluit sets out what that board-level certificate must state as a minimum. That is the name of the board member, the dates of the training, the topics covered and the name of the provider. The certificate is drawn up in Dutch or English.

All of this aligns with basic principle 2 of the Dutch National Cyber Security Centre, Promote safe behavior. The NCSC advises organizations to build a security culture, to support staff with awareness and training and to facilitate safe behavior technically. That is practical guidance rather than a legal standard. The legal basis sits in article 21 of the act and article 12 of the Cyberbeveiligingsbesluit.

Finally, an important caveat: this masterclass is an awareness program, not legal advice. For staff a personal certificate is not a legal requirement; the IACA certificate evidences that the training was completed. For board members a statutory training and certificate obligation does apply. Whether a board-level course meets all legal requirements in a specific situation is for the competent regulator to assess.

The Dutch Cybersecurity Act also calls for appropriate technical, operational and organizational measures, a working reporting process and registration in the entity register of the NCSC. A single training course therefore does not make an organization compliant, but it is a concrete and demonstrable step within the wider approach to cyber resilience.

This information was updated on . Sources: the Dutch Cybersecurity Act (Staatsblad 2026, 187), the Cyberbeveiligingsbesluit (Staatsblad 2026, 189), the Dutch National Cyber Security Centre, the Dutch Authority for Digital Infrastructure and the Dutch government.

Program

The topics

In one intensive day we cover, among others, the following topics.

01

Footprint of the organization: what an outsider finds about you within an hour, from job titles and mail conventions to vacancy texts and document metadata.

02

Your personal footprint: which traces you leave in private life and what they reveal about your habits, your network and your motives.

03

Target selection: why the new employee, the intern or the supplier is approached first rather than the director.

04

The first contact: the cover story, the plausible pretext and the channel, from a message on LinkedIn to a conversation at a conference.

05

Cyberpsychology: the principles of influence behind a successful approach, such as authority, urgency, reciprocity and liking.

06

Online disinhibition: why a direct message gets more out of people than a conversation at the front desk and what time pressure and busyness do to your judgment.

07

From contact to access: small favors that keep growing, the unwitting accomplice and the gradually compromised insider.

08

The human as detection: which signals are actually there and who notices them first in practice.

The masterclass works exclusively with public sources and general examples. We do not search for participants, their colleagues or their own organization. All our instructors are screened and have signed non-disclosure agreements with various government agencies.

The common thread

The path inside

It all starts with you and your organization as the target: the traces you leave online are the material an approach is built with.

Those traces drive the choice of target and the first contact, followed by the psychology that makes trust grow.

Only then comes the request for a file, a link or a favor. Whoever knows the path recognizes the signals long before that request arrives.

CASE FILE · CYBER CYBER
You & organizationtarget
Digital footprinttraces
Approachfirst contact
Cyberpsychologywhy it works
Accessinfiltration
Target selectionwho first
Signalsspotting
Resiliencesafe behavior

Drag a node · hover shows connections

Target group

Who is this masterclass developed for?

The Cyber Awareness masterclass is developed for anyone who can be the way into the organization. That is not just the IT department. Anyone who sends mail, takes calls or is visible online can be approached. No prior knowledge is required.

For organizations that fall under the Dutch Cybersecurity Act this masterclass connects directly to the awareness and training that form part of the statutory duty of care. Board members and managers also get to see where the way into their own organization most likely lies. That is often not where they assume it is. Suppliers who have to meet these requirements through the chain are equally at home here.

The masterclass also fits professionals in investigation and information analysis. OSINT analysts, investigators and specialists working with open sources or operational security (OPSEC) look at their own visibility here instead of someone else's.

Finally, the masterclass suits people with a raised risk profile, because of their role or public visibility. Private individuals are welcome too, for instance because they want to know what can be found about them and how to limit it.

Organizations under the Cybersecurity Act Suppliers in the chain Board members Managers Staff OSINT analysts & investigators Raised risk profile Freelancers No prior knowledge needed

Certification & accreditation

An IACA certificate of attendance

Our training institute has been assessed and registered with the CRKBO, the Central Register for Short Vocational Education. On completion of the masterclass you receive:

  • ✓IACA certificate · Cyber Awareness

The masterclass is taught by highly experienced cyber security experts who work for the government and deal with current digital threats daily.

The IACA certificate makes it demonstrable that the participant completed the Cyber Awareness masterclass. It can be included in your organization's records of awareness and training activities.

Follow-up modules

If you want to master the techniques from this masterclass yourself, you can continue with our accredited programs:

Course formats

Open, private or customized

The masterclass is delivered fully live online, in an interactive virtual classroom with an instructor teaching the session in person. Participants do not have to travel. Teams spread across several locations can take part together.

While this masterclass is usually offered as an open masterclass, we understand that you may need a private setting given the nature of your work. With at least twelve participants we provide a private masterclass in which the examples are tailored to your own organization. We also offer tailored programs based on parts of this masterclass. We are happy to put together a suitable proposal. All our instructors are screened and have signed non-disclosure agreements with various government agencies. A specific non-disclosure agreement for your organization or service can also be arranged.

Participation

Plan your participation

The next open masterclass takes place on Friday 26 February 2027. We also deliver the masterclass privately or customized; from twelve participants we schedule it in consultation.

26 February 2027Open masterclass · one class day
Live online · 09:30 to 15:30
Available
In-houseTo be scheduled
From twelve participants · customization possible
On request

Frequently asked questions

Cyber Awareness: your questions answered

You learn which traces you and your organization leave online. You see how a target is selected from them, through which channel contact is made and which psychological mechanisms make an approach succeed. After that you look back: which step could you have blocked and who could have spotted it?
Yes, but in two different ways. Executive board members carry a personal obligation: they must follow training and be able to show a certificate. Staff do not carry the general, personal training and certificate obligation that board members have; there the obligation sits with the organization. Article 12 of the Cyberbeveiligingsbesluit requires personnel to be aware of the risks and to apply cyber hygiene, and staff in roles requiring cybersecurity expertise must receive regular training. The duty of care in article 21 of the act also names cybersecurity training among the minimum measures.
Board members already in office on 15 August 2026 have until 15 August 2028 at the latest. Anyone appointed after 15 August 2026 has two years from their appointment. From then on the knowledge must be kept demonstrably up to date. The certificate states at least the name of the board member, the dates of the training, the topics covered and the name of the provider.
This masterclass connects directly to the awareness and training that form part of the duty of care. Your participation is demonstrable through the IACA certificate of attendance. For staff the Cyberbeveiligingsbesluit does not prescribe a personal certificate, so it is evidence rather than a legal requirement. For board members a certificate is required, and it is the regulator who judges whether a course meets those requirements. The act also calls for appropriate technical, operational and organizational measures, a reporting process and registration with the NCSC.
The Dutch Cybersecurity Act came into force on 15 August 2026 and applies to more than 8,000 organizations in designated sectors, classified as essential or important entities. Suppliers are affected as well, through the requirements their clients pass down the chain. The current scope is published by the NCSC and the Dutch Authority for Digital Infrastructure.
Cyberpsychology describes why people respond differently online than face to face. Think of online disinhibition, the illusion of privacy in a direct message and principles of influence such as authority, urgency and reciprocity. It explains why experienced, critical professionals are targeted.
The masterclass is delivered fully live online in an interactive virtual classroom, with an instructor teaching the session in person. It is explicitly not e-learning and not a webinar; you take an active part in the exercises.
The masterclass is an intensive, one-day training. The investment is € 595 per participant, VAT-exempt.
For staff, managers and board members of organizations that fall under the Dutch Cybersecurity Act or supply to them, for professionals with a raised risk profile and for private individuals who want to limit their online traces. No prior knowledge is required.
No. The masterclass works with general examples from public sources. We do not search for participants, their colleagues or their own organization.
The masterclass is taught by highly experienced cyber security experts from government practice. On completion you receive the IACA certificate of attendance.

Know what can be found about you

See your organization through someone else’s eyes

Request information without obligation about the Cyber Awareness masterclass, or about a private or customized version for your team.

€ 595 p.p. · VAT-exempt
Enroll →