Summary
The session’s core message is that the Dutch National Cyber Security Centre needs to scan for vulnerable or compromised systems to warn affected organisations, but must do so within strict legal and non-intrusive boundaries. Chris van Marle opened with a realistic operational scenario: an NCSC partner reports that a specific firewall brand is being compromised by an APT installing web shells. The immediate operational questions are whether Dutch systems are affected, whether any devices are already compromised, and which organisations need to be informed so they can take measures. Because the NCSC is part of the national government, the answer cannot simply be “scan everything”; the team must determine what scanning methods are permissible and how to keep them non-intrusive.
Chris framed the need for scanning against the wider threat landscape. Adversaries routinely scan systems, exploit new vulnerabilities, gain footholds, monitor or manipulate traffic, and may remain inside compromised systems for weeks, months, or longer. The NCSC sees scanning as serving two concrete purposes: first, informing entities that vulnerable systems were found in their networks; second, building a current view of vulnerabilities and exploitation so incidents can be prioritised or deprioritised. He also highlighted why relying only on organisations themselves is difficult: feature development often takes priority over security, shadow IT can fall outside monitoring, and unmaintained systems may still support critical infrastructure such as water supplies.
Remon Rijkeraad then explained why the Dutch legal setting makes this difficult. The NCSC acts as part of the Dutch central government and effectively as the Minister of Justice and Security, so it must stay precisely within legal authority. Dutch cybersecurity law implements the relevant directive closely, but neither the directive nor national law defines “scanning” or “non-intrusion” precisely. The law allows scanning of network and information systems used by essential and important entities for the purpose of informing them about threats or vulnerabilities, and it requires that scanning not cause adverse effects on the services provided by the entity concerned.
The hardest issue, Remon said, is defining intrusion. Dutch criminal law provides some boundaries: intrusion is present when security measures are breached, technical measures are used to gain access, a false signal is used, or a false capacity or identity is assumed. The speakers wanted an objective, scalable way for technical staff to determine whether a proposed scan would cross those lines, but after extensive discussion they did not find a simple technical boundary. Their practical conclusion was to create a policy framework distinguishing clearly non-intrusive actions, such as banner grabbing and port scanning, from more sensitive activities such as looking for web shells on systems in the Netherlands.
Key Topics
5 key topics from Chris van Marle and Remon Wiekeraad at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Define legal scanning boundaries before launching technical checks.
- Prioritise non-intrusive methods like banner grabbing and port scanning.
- Use scan results to notify affected entities quickly.
- Account for shadow IT when assessing national cyber exposure.
- Avoid breaching security measures or assuming false identities.
“we cannot just scan everything and we cannot scan intrusively.”
Up Next



Next in agenda
Unravel Cybercrime: Anti-Phishing and -Ransomware Agenda


Also on cybersecurity
Opening day 2

Also on cybersecurity
Power, Trust, Responsibility in Fragmented Digital World
Miguel De Bruycker