Summary
The core message of the panel was that cybercrime and state activity increasingly overlap, making response a shared responsibility across business, law enforcement, national cyber agencies, and intelligence services. The moderator framed the issue by asking what happens when an incident is both a crime and a state attack: who is actually in charge? The panel’s value came from placing those blurred responsibilities side by side, with perspectives from NCSC, Randstad, the police, and MIVD. Stan summarized the collaboration imperative directly: cybercrime is a team sport, and no single organization has an individual solution for combating it.
The early discussion focused on moments when the blurred line became tangible. Matthijs described a ransomware investigation where the absence of ransom notes suggested a state actor rather than a purely criminal operation, changing what responders needed to consider, including what information they had already exposed by entering the incident. Jessica recalled a crisis exercise in which board members debated whether to pay, before legal asked who would actually receive the money: a nation state or a criminal organization. Stan pointed to the 2024 police data breach, where the police were both victim and investigating agency, and where the case ended with attribution to Laundry Bear, a state-sponsored group. Marcia described a broader trend rather than a single incident, noting that China formally uses parts of society, individuals, and organizations to pursue national goals by gathering intelligence abroad.
The panel then moved into the operational reality of faster exploitation. The moderator referenced frontier models and NCSC reporting that vulnerabilities become public and are exploited at greater speed and scale. Matthijs said that, for NCSC response, the identity of the actor initially does not matter because the kill chain looks similar: initial access, consolidation, and exfiltration. Attribution belongs to intelligence agencies and police, while NCSC focuses on what happened, collecting indicators of compromise and TTPs, preventing new victims, and identifying organizations already affected. Marcia explained that naming an actor such as Laundry Bear is intended both to hold that actor responsible and to raise awareness so others can detect or prepare for similar activity.
The business and communications discussion emphasized preparation under uncertainty. Jessica stressed that even extensive tabletop and crisis testing cannot cover every scenario, so organizations need the right decision-makers in the crisis room: legal, finance, communications, and business leaders able to assess impact and decide. She warned that withholding information can create panic outside the organization, making communication planning part of crisis balancing. Stan added that cybercrime remains difficult for society to understand because it is not easily tangible, so police, government, and private industry should share stories and explain what is happening. The excerpt closed with the panel asking who benefits from blurred lines; Marcia argued that states benefit because hiding behind criminal actors complicates attribution and response.
Key Topics
5 key topics from Matthijs van Amelsfort, Stan Duijf, Madelein van der Hout, Marcia de Veij and Jessica Conquet at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Build crisis teams with legal, finance, communications, and business decision-makers.
- Share incident stories to make cybercrime understandable for wider society.
- Collect IOCs and TTPs early to prevent follow-on victims.
- Treat initial response similarly until attribution becomes reliable.
- Communicate deliberately; silence can create external panic.
“cybercrime is a team sport and we don't have an individual solution for combating cybercrime”
Up Next


Next in agenda
A Room With a View


Also on cybersecurity
VShell: Tracking a State-Actor C2 Framework in the Wild



Also on incident response
