Summary
The core message of the provided transcript excerpt is that Dutch cybercrime leadership is being forced to redesign how it allocates attention, people, and investigative capacity as online crime grows faster than traditional police and prosecution structures can absorb. Moderator Matthijs Jaspers frames the panel around leadership in an environment of AI-fueled attacks, hybrid threats, rapid technological change, and public-private collaboration. The panel brings together leaders from the Dutch National Police and Dutch Public Prosecutor’s Office: Fieke Miedema emphasizes data-driven evaluation and impact; Caroline Sander highlights the value of multiple perspectives from her journalistic background; Christa de Pagter focuses on allocation and selection of cybercrime investigations; and Esther Sachs brings experience from financial, fraud, and organized crime to stress that cybercrime operates within a broader criminal landscape.
The discussion first identifies capacity and expertise as a central day-to-day problem. Christa states that online crime is almost half of criminality in the Netherlands and still rising, while only a small dedicated group of prosecutors currently handles these crimes. Her leadership priority is increasing the number of colleagues able to fight cybercrime effectively. Esther agrees, adding that even people not fully specialized in cybercrime need stronger “antenna” for cybercrime and must learn to think like cybercrime specialists. She warns that current ways of prosecuting and investigating will not remain sustainable, especially as AI accelerates the pace and volume of criminal activity.
The panel then turns to high-impact incidents such as hacks, ransomware, and the Odido case, where large amounts of personal data are stolen and societal pressure rises. Caroline notes that these incidents affect not only society but also how law enforcement conducts investigations. Esther corrects the assumption that prosecutors alone select cases, stressing that police and prosecutors choose together. Because they face “100 cases” that are all important, the old model of investigating, prosecuting, and supporting victims in each case is no longer viable. She explains that they are developing a triage model to make painful but necessary choices and to clarify what the public can expect from law enforcement versus where citizens and organizations must strengthen their own resilience.
Finally, Fieke expands the challenge from individual cases to hybrid threats and criminal ecosystems. She argues that law enforcement must ask what its role becomes if threats affect the whole of government or society, not just isolated companies or services. Cyber incidents are not separate offenses but interconnected ecosystems of actors, services, service providers, support functions, and attack stages. Christa closes the provided excerpt by introducing mass victimization as another unresolved issue: there is no settled definition, and even within a single investigation, authorities must choose which victims can realistically be served without allowing one case to grow endlessly.
Key Topics
5 key topics from Caroline Sander, Fieke Miedema, Esther Sachs, Christa de Pagter and Matthijs Jaspers at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Expand cybercrime awareness beyond specialist teams.
- Use triage models to prioritize unavoidable case choices.
- Define victim scope early in mass-impact investigations.
- Treat cybercrime as an interconnected criminal ecosystem.
- Clarify public expectations and resilience responsibilities.
“we need to get to kind of model, like a triage model, to make these choices.”
Up Next


Next in agenda
Sovereignty by Design: Europe's SaaS Resilience Playbook



Also on ransomware
Unravel Cybercrime: Anti-Phishing and -Ransomware Agenda

Also on ransomware
Flatline vs. Recovery: Responding to Ransomware Attacks on Healthcare
Marina Bochenkova