The KB is a versatile organization: the national library not only has a massive book repository but also a huge physical collection. Additionally, the KB offers various services, such as Delpher, which provides online access to over 2 million Dutch newspapers and magazines.
All of these require their own form of protection, explains crisis management advisor Milou Dekker. ‘We must comply with the cybersecurity law, which, for example, mandates clear agreements about who has access to what information. You also need to have a clear plan for who does what when something goes wrong.’
How does a cyberattack simulation work?
Ideally, you don’t dwell on the latter for too long. However, libraries do get attacked sometimes. For instance, the British Library was hacked a few years ago, resulting in lost files. ‘We try to protect ourselves against such scenarios,’ says Dekker. ‘We do this by training our staff as thoroughly as possible. All KB employees receive an awareness training, teaching them, for instance, how to recognize phishing emails. Additionally, we have a dedicated team that knows what to do when a problem arises.’
How do you best prepare for such a problem? One way is through a simulation exercise: a kind of role-play where you reenact what happens when confronted with a digital threat. ‘Part of the team initiates the problem, for example, by calling the department with an alarming message. Then we observe how the employees respond.’
That role-play is carefully planned in advance, Dekker emphasizes. ‘First, the scenario must be realistic: there has to be a chance that this problem could actually occur. Additionally, it must align with what you want to train, such as whether employees escalate appropriately when the problem becomes clear. Moreover, it should have a high impact: the problem must have significant consequences. And, of course, the problem shouldn’t be too easy to solve.’

How to keep colleagues engaged with cybersecurity?
Developing such a scenario is often already a very good exercise, says Dekker. ‘Not everyone deals with all risks every day. Thinking about them makes you aware of what can go wrong.’
Employees often find such exercises quite exciting, Dekker knows from experience. ‘That’s why we try to make it enjoyable, for instance, by including jokes in the scenario. Additionally, it’s important to create a safe environment: it’s okay to make mistakes; that’s how you learn.’
Recently, her department reenacted a scenario where someone with malicious intent gained access to the network and important systems. ‘Such a person is often not necessarily looking for information but for money,’ Dekker explains. ‘They often threaten to expose valuable data unless you pay a ransom. At such a moment, you look for ways to contain the problem. For example, how do we ensure that our services to the customer remain operational?’
Why should you repeat cyber training?
Unfortunately, this scenario is becoming increasingly common, Dekker observes. ‘All organizations need to protect themselves against this. On the other hand, by doing so, we collectively raise the standard: the more resilient we make ourselves, the harder we all have to work to maintain that standard.’
Such training needs to be repeated frequently: practicing once or twice a year is important to keep the measures fresh in people’s minds. Per team, you determine what is important to train, such as ICT or marketing and communication. ‘It doesn’t have to be complicated,’ Dekker stresses. ‘You can, for instance, use the experiences of other organizations. Additionally, the government offers various standard exercises. You can also do a crisis exercise via the National Cyber Security Centre (NCSC) or the UK’s National Cyber Security Centre. Simply creating a scenario together can also be very helpful. See it as a creative exercise – and cultural institutions often have no shortage of creativity.’
Cyber scenarios for cultural institutions
For each type of cultural institution, the risk of a cyberattack lies in a different area. Consider the following scenarios.
Theater: theaters collect a lot of data from their visitors and thus hold a lot of privacy-sensitive information. What do you do when a data breach comes to light?
Museums: museums often house valuable objects. What do you do when someone gains control over your security systems?
Festivals: what happens when your cash register system suddenly stops working or the website goes offline? It’s important to act quickly in such situations.
What makes a good scenario?
Want to create your own scenario? Consider the following criteria.
Choose a realistic scenario
Practice with a situation that could realistically occur in your organization.
Determine your goal
What do you want to test? Focus on communication, decision-making, or technical knowledge.
Ensure impact
The scenario must have consequences; otherwise, people learn less.
Make it challenging
A good exercise requires thought and collaboration.
Create a safe atmosphere
Ensure an open environment where everyone can learn.
Involve different teams
Cyber incidents often affect multiple departments simultaneously.
Evaluate together
Discuss what went well and what could be improved.
Which parties can you hire?
There are many different parties that can help you with a cyber crisis exercise. Think of Northwave, Fox-IT, Berenschot, and Bureau Veritas. Often, you can choose between a more affordable standard exercise and a larger fully simulated exercise with a custom scenario.
Get started with cyber resilience
- Organize at least one cyber crisis exercise per year.
- Involve different departments in the exercise.
- Choose a realistic scenario that fits your organization.
- Evaluate what went well and what could be improved.
- Use existing exercise scenarios from organizations like the NCSC.
Author: Anne Louïse van den Dool
Work on a secure digital foundation during our online workshop!
Cyberattacks are increasingly common in the cultural sector. Organizations face phishing, ransomware, and data breaches. During our online workshop 'Cybersecurity in the Cultural Sector,' you’ll work through four clear steps to create an action plan for a secure digital work environment. You’ll receive immediately applicable tools and take the first steps toward a digitally resilient organization.
Wed, June 24, 2026: next workshop
More articles per topic
New(s) on DEN

Lunch & Learn: prepared for cyber incidents - in 45 minutes
Does your organization know what to do in case of a phishing attack, data breach, or system outage? Join us during lunch for this free online session and get an easy introduction to creating an incident and recovery plan in just 45 minutes.

Vacature: Office Assistent (tijdelijk)

Lunch & Learn: Your Digital Project: Start Small, Achieve Big Results - in 45 Minutes
Do you have a great idea for a digital project but are unsure if it will resonate with your audience? You don’t need to build everything at once to find out. Join this free online session during lunch and discover in 45 minutes why starting small and testing leads to better digital products.






