Summary
The core message of the session is that DICTU’s move from a traditional SOC mindset to a Cyber Defense Center is meant to centralize security functions, raise detection and response maturity, and combine defensive, intelligence, and offensive capabilities in one organizational unit. Robin de Haas and Martijn Peijer frame the shift with a checkers-versus-chess analogy: a SOC monitors and responds, while a CDC thinks ahead strategically, uses more pieces, and actively reduces attackers’ options. DICTU’s context makes this urgent: it is one of the largest IT suppliers in the Dutch central government, monitoring more than 40,000 devices, more than 1,500 applications, and more than 6,000 servers, with a yearly revenue of €400,000,000.
Key Topics
5 key topics from Martijn Peijer and Robin de Haas at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Centralize fragmented SOC functions before scaling advanced capabilities.
- Align CDC priorities with business and cybersecurity strategies.
- Combine CTI, red teaming, and monitoring to improve detection.
- Use purple teaming to turn missed attacks into new rules.
- Plan ambitiously, but account for daily operational workload.
“it's no longer a nice to have, it's a must have.”
Up Next

Next in agenda
Beneath Arrakis:Unmasking Hydra Saiga's Covert Operation
Pol Thill
Also on purple teaming
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten


Also on threat intelligence
