The Hof van Twente hack (2020): 5 lessons for municipalities
In December 2020, the municipality of Hof van Twente was hit by a ransomware attack. The attackers encrypted not only the files but also the backups. For weeks, services were at a standstill and the damage rose to around four million euros. The attack became a textbook example of what goes wrong when basic security and governance are not in order. Five lessons for municipalities.
What happened
The attackers got in through a weak password on an administrator account, for which two-factor authentication had moreover been switched off. In addition, a server's access gateway (RDP) had been open to the internet for a long time. This allowed the criminals to encrypt the systems and, crucially, to render the backups unusable as well.
Recovery from a clean backup was therefore not an option. The municipality had to rebuild a great deal; services to residents were disrupted for weeks. The total damage was estimated at around four million euros, while the attackers had demanded a much lower ransom. The municipality did not pay.
Lesson 1: Backups are only backups when they are offline
The most painful lesson: if your backups are connected to the same network, ransomware encrypts them too. Ensure backups that are offline or immutable and that cannot be reached from the ordinary network.
Moreover, test regularly whether you can genuinely restore from a backup. A backup you have never restored is an assumption, not a certainty.
Lesson 2: Getting the basics right prevents most of the misery
The attack was no feat of sophistication. Things went wrong at the basic level. Those basics are achievable for every municipality.
- Strong, unique passwords and mandatory two-factor authentication, especially on administrator accounts.
- No administrative access (such as RDP) open directly to the internet.
- Patching in good time and switching off unnecessary services.
- Network segmentation, so that an infection cannot spread everywhere.
Lesson 3: Communicate with residents about services that are down
For residents, what matters is not the technology but the question: can I apply for my passport, my benefits, my permit? Be quick and honest here: which services are down, what alternatives there are and when there will be more news.
Where possible, offer an emergency desk or a telephone route. And repeat the message consistently across all channels. Uncertainty increases dissatisfaction more than the outage itself.
Lesson 4: Involve legal and privacy from minute one
In a hack, personal data has often been stolen. That makes it not only an IT crisis but also a privacy matter. So involve the data protection officer and legal expertise immediately, and assess whether there is a data breach.
A data breach must be reported within 72 hours to the Autoriteit Persoonsgegevens, and in the event of high risk you inform the residents concerned. External forensic experts assist with the investigation; record who does what and when.
Lesson 5: Governance and reporting obligations (NIS2, BIO2, GDPR)
An important conclusion at Hof van Twente was that warning signs about information security did not reach the executive sufficiently. So make information security a matter for executive level, with a CISO and a dedicated budget, and make sure risks are visible.
Municipalities operate under the BIO2 and the GDPR and fall under the Cybersecurity Act (NIS2). A cyber incident must be reported to the NCSC and the sectoral CSIRT; a data breach within 72 hours to the Autoriteit Persoonsgegevens. Call in the Informatiebeveiligingsdienst (IBD) for municipalities and record all reports.
How CrisisRadar helps
CrisisRadar brings management, the CISO, the data protection officer, communications and external experts together in a shared crisis picture. You record facts with their source, draft a message to residents and a report to the regulator within minutes, and use reporting-obligation timers to keep track of the GDPR and NIS2 deadlines. External forensic parties collaborate via secure, temporary guest access.
Would you like to see how a cyberattack with a data breach unfolds step by step in the platform? Then take a look at the accompanying practice scenario.
Stappenplan
Put backups offline and test the restore
Ensure offline or immutable backups that are separate from the network, and practise regularly whether you can genuinely restore from them.
Get the basic security in order
Make two-factor authentication mandatory, close off administrative access to the internet, patch in good time and segment the network.
Make information security an executive responsibility
Appoint a CISO with a dedicated budget and ensure that risks and warning signs reach the executive.
Practise a cyber crisis
Train the team with a ransomware scenario, including communication to residents and the reporting obligations to the Autoriteit Persoonsgegevens and the NCSC.
Veelgestelde vragen
How could the municipality of Hof van Twente be hacked?
The attackers got in through a weak password on an administrator account without two-factor authentication, while an administrative gateway (RDP) was also open to the internet. This allowed them to encrypt the systems and even the backups.
Why could the municipality not simply restore from a backup?
Because the backups were connected to the same network and were therefore encrypted along with everything else. This shows why backups must be offline or immutable and why you should test the restore regularly.
Which reporting obligation applies to a cyberattack on a municipality?
A data breach must be reported within 72 hours to the Autoriteit Persoonsgegevens; in the event of high risk you inform residents. A cyber incident is reported under the Cybersecurity Act (NIS2) to the NCSC and the CSIRT. Municipalities also call in the Informatiebeveiligingsdienst (IBD).
Sneller en beter communiceren tijdens een crisis?
CrisisRadar helpt u dit in de praktijk te brengen — van voorbereiding tot de eerste minuut.
Meer gidsen
What is crisis communication?
The basics: what crisis communication is, why it matters and how to get started.
How do you draft a crisis statement?
A clear crisis communication guide in six steps, with a handy example.
Drawing up a crisis communication plan
What should a crisis communication plan include, and how do you draw one up?