Skip to Content
Pavan Geraedts
  • Practice
    • Working With Pavan Geraedts
    • Our Principles
    • About
    • FAQ
  • Services
    • Fiscal Advice
    • Juridical Advice
    • Digital, Data & IP
    • Company Structure & Governance
    • Transactions & Business Change
    • Business Mediation
  • Library
  • Academy
  • Contact
  • 0
  • 0
  • Nederlands English (US) Italiano
  • CLIENT AREA
Pavan Geraedts
  • 0
  • 0
    • Practice
      • Working With Pavan Geraedts
      • Our Principles
      • About
      • FAQ
    • Services
      • Fiscal Advice
      • Juridical Advice
      • Digital, Data & IP
      • Company Structure & Governance
      • Transactions & Business Change
      • Business Mediation
    • Library
    • Academy
    • Contact
  • Nederlands English (US) Italiano
  • CLIENT AREA
  • All Blogs
  • Governance
  • Faster AI Attacks Raise the Cost of Slow Business Decisions
  • Faster AI Attacks Raise the Cost of Slow Business Decisions

    AI is reducing the time businesses have to respond to cyber weaknesses. Small firms need clear authority over patches, access, payments and recovery before technical disruption reaches customers and cash.
    September 21, 2026 by
    Paolo Maria Pavan

    Small firms need clear authority on access, patches and recovery before technical trouble reaches cash.

    At 08:20, an IT provider warns a small installation company about a serious software weakness. Installing the patch will interrupt planning and field-service access for perhaps two hours. The founder is visiting a customer. The office manager cannot authorise downtime. Nobody knows whether the supplier may act without approval.

    The patch waits.

    That ordinary delay sits behind AFM’s June warning on advanced AI. Stronger models can identify and combine vulnerabilities faster, leaving organisations less time to repair weaknesses and contain incidents. Smaller firms with older systems or less developed security may carry greater exposure.

    This is not mainly a story about futuristic attacks. It is about whether a company can decide before a technical weakness reaches customers, invoices, wages or cash.

    The shrinking decision window

    De Nederlandsche Bank sharpened the warning in July. Frontier AI can help malicious actors find and exploit vulnerabilities faster, more cheaply and at greater scale. It can link weaknesses that once seemed manageable on their own into a more damaging chain.

    For a small company, the important word is faster. Many firms know they should install updates, review access rights and test backups. The weakness often lies elsewhere. Nobody has settled who may interrupt the working day when action is urgent.

    This is a governance problem before it is a technology problem. Security software cannot decide whether the planning system may go offline before lunch. It cannot settle a vague arrangement with an IT provider. It cannot explain why a former employee still has administrator access.

    The attack window may be shrinking while the company still follows old habits: wait for the owner, avoid disruption, trust the supplier and discuss the paperwork later. That mismatch raises the price of delay.

    The legal setting has moved as well. The Cyberbeveiligingswet entered into force on 15 August 2026. Organisations within its scope must register, take appropriate and proportionate risk-management measures and report significant incidents under the applicable rules.

    Their boards must approve the relevant measures, oversee implementation and maintain enough knowledge to assess cyber risks. The law applies to defined sectors and organisations. Its wider governance lesson is clear: cyber responsibility cannot disappear into an outsourced helpdesk.

    Small firms carry thinner protection

    CBS puts the issue in proportion. Four percent of Dutch businesses reported at least one external cyber incident with consequences in 2024, down from 11% in 2016. That long-term movement is welcome. On an inconvenient morning, however, resilience still depends on the controls that actually work.

    The difference in control coverage is revealing. In 2025, 13% of businesses with 2 to 10 workers had adopted at least ten of twelve surveyed cybersecurity measures. Among businesses with at least 250 workers, the share was 86%.

    Data encryption shows the same distance. It was used by 33% of the smallest group and 91% of the largest. Small firms often operate with less depth around the systems that keep ordinary work moving.

    One person may hold most passwords, supplier knowledge and recovery experience. One cloud account may connect customer records, project work and invoicing. An external provider may have broad access that the owner has never reviewed.

    Return to the installation company. If its planning system fails, technicians may still have vans and tools. Yet addresses, work orders, customer notes and completed-job records may be unavailable. Invoicing slows. Staff rebuild the day through messages and memory. A technical incident becomes a service and cash problem.

    That is why cyber insurance cannot carry the whole burden. CBS reported that 19% of Dutch businesses held cyber insurance in 2025. Insurance may finance part of a loss. It does not restore unclear access rights or recover information that the company never tested.

    Control starts with authority

    A small firm does not need to imitate a bank’s security department. It does need answers that survive an inconvenient morning.

    Who receives an urgent warning? Who may approve downtime? Which systems can be reached from the internet? Which employees, former colleagues and suppliers have administrator rights? If the main decision-maker is unavailable, who takes over?

    The most important question is whether the business can restore a critical service without relying on one person’s memory. That question belongs with the systems that carry sales, delivery, payroll, invoicing and payment approval.

    A focused conversation with the IT provider should clarify patching, monitoring, alerts, backups, logging and recovery tests. Responsibilities need to be clear enough for another responsible person to use when the usual contact is absent.

    Payment routines deserve equal attention. AFM has warned that generative AI can strengthen social engineering, including voice spoofing and deepfakes. A familiar voice or a well-written supplier message may no longer deserve automatic trust.

    A bank-detail change or unusual payment request merits confirmation through a known, independent contact route. That is not distrust. It is a sensible separation between a request and the authority to release money.

    The company’s own AI use belongs in the same conversation. CBS found that 13.8% of Dutch microbusinesses used at least one surveyed AI technology in 2025. Marketing and sales were the most common uses, followed by administration and management.

    Governance means knowing which tools staff use, what information enters them and where human review still matters. Commercial software was the most common route by which AI-using microbusinesses obtained the technology. That makes ownership and boundaries more important.

    The calm advantage

    Good cyber governance is not a thick policy prepared for an inspection. It is the ability to act without confusion when normal work is interrupted.

    For organisations covered by the Cyberbeveiligingswet, that responsibility has direct legal weight. For other firms, the commercial logic is sufficient. Customers expect continuity. Staff need clear authority. Suppliers need boundaries. The ledger needs reliable records. The owner needs a route from warning to decision.

    The installation company does not need certainty about every attack. It needs permission to install the urgent patch, a current list of privileged access and confidence that the planning system can be restored.

    AI may make the attacker quicker. The sensible response is neither panic nor expensive theatre. It is to remove hesitation inside the business before somebody else learns how to use it.

    Clarify who can authorise urgent cyber action before delay becomes an operational and financial problem.

    DISCUSS YOUR CYBER GOVERNANCE

    The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.

    References

    • Snellere AI-aanvallen vragen om sterkere weerbaarheid
    • De Nederlandsche Bank - Later supervisory confirmation of the changed threat model
    • Rijksoverheid - Cybersecurity law and explicit board responsibility
    • Centraal Bureau voor de Statistiek - Observed resilience gap between small and large firms
    • Centraal Bureau voor de Statistiek - AI adoption inside small firms
    • Autoriteit Financiële Markten - Control evidence, monitoring and outsourced ICT
    • Autoriteit Financiële Markten - Systemic concentration and AI-enabled social engineering
    • Autoriteit Financiële Markten
    in Governance
    # AI GOVERNANCE Risk management business continuity cybersecurity small business
    Paolo Maria Pavan September 21, 2026
    Share this post

    Share

    Tags
    AI GOVERNANCE Risk management business continuity cybersecurity small business
    Our blogs
    • Market Pulse
    • Ledger & Tax
    • Human Resources
    • Compliance
    • Governance
    • Real Estate

    Read Next
    When Cash Tightens, Dutch Directors Need Decisions They Can Defend
    When cash is tight, Dutch directors need current figures, timely formal action and a visible record of the reasoning behind difficult decisions.

    Upcoming Events

    Explore what’s happening next and join the moments that matter.

    See All
    Your Dynamic Snippet will be displayed here... This message is displayed because you did not provide enough options to retrieve its content.

    Pavan Geraedts Adviseurs

    Altroverso VOF trading as Pavan Geraedts Adviseurs. A boutique professional practice in Amersfoort for fiscal advice, juridical advice and business mediation.

    Chamber of Commerce: 56530021
    VAT: NL852171936B01
    BECON: 746393

    Complaints
    Email pg@altroverso.nl
    We acknowledge complaints as soon as possible and make reasonable efforts to find a satisfactory solution. Telephone and postal details are listed opposite.

    2012-2026 © Altroverso VOF
    All rights reserved.

    Practice

    About Pavan Geraedts
    Working With Pavan Geraedts
    Our Professional Principles
    Frequently Asked Questions
    Contact

    Areas of practice

    Fiscal Advice and Tax Matters
    Juridical Advice and Contracts
    Business Mediation
    Company Structure and Governance
    Digital, Data & IP
    Transactions & Business Change

    Knowledge and contact
    • Library
      Academy
      Client Area
    • Professional updates and invitations are shared with clients and contacts when they are relevant to the work of the practice.
    Pavan Geraedts
    • +31 (0)85 40 12 459

    • Rigaweg 9
    • 3825 PP Amersfoort
      The Netherlands
    Legal
    • Terms and Conditions
    • Privacy Manifesto
    • Cookie Policy
    • Salary and Employment Policy

    Your privacy matters.

    May this website use cookies in this browser?

    Essential cookies support the operation of the website. With your permission, additional cookies may be used to improve your experience. Further information is available in our Cookie Policy and change your choice later.

    Allow all cookiesAllow essential cookies only