On Wednesday 10 September 2025 I spent the first day of Cybersec Netherlands 2025 at Jaarbeurs in Utrecht. It ran on 10 and 11 September. The neighbouring hall 12 hosted Data Expo, a data and AI trade show on the same two days, so I could walk from security vendors to graph databases and back.
This is a throwback built from my photos and two short clips. Iâve kept to what was on the screens and signs and what was said to me. Where a talk touched EU law, Iâve checked the dates against the official EU pages and linked them.

Morning arrival at Jaarbeurs: Cybersec Netherlands in hall 11, Data Expo through the hall 12 entrance.
The main stage: âStronger Togetherâ
I saw the main stage before the sessions started. The set carried the Cybersec Netherlands logo, the line âStronger Togetherâ, and âProgram powered by Computableâ.

The main stage, still empty.
A couple of hours later the same room was full, with people standing at the back. The keynote on screen was about the EUâs cyber crisis set-up. The slide title was âEU Blueprint â The Who (II)â, with a box on the CSIRTs Network, the EUâs network of national computer security incident response teams, and its role in exchanging information about incidents.

Standing at the back for the âEU Blueprintâ keynote.
On the expo floors
Most of my morning went to the stands. A few stood out for my own work.
Neo4j at Data Expo. The Neo4j standâs headline was âBuild GenAI Apps With a GraphDBâ, with the tagline âAccurate | Transparent | Explainableâ and a demo zone. Itâs the same GraphRAG message as at GraphSummit Amsterdam 2025.

Neo4jâs pitch at Data Expo: graphs as the grounding layer for GenAI apps.
OX Security. At the OX Security stand I recorded a short clip with one of their solutions engineers for my channel. According to him, OX Security is an application security platform âfrom code to cloudâ: SAST, SCA and open source scanning, plus pipeline security, container scanning and cloud posture (CSPM) checks. On containers, his point was that they scan the Dockerfile before the image is built, to catch vulnerabilities introduced by build instructions, and then scan the built container as well. He also explained their DAST engine, dynamic application security testing, as the complement to static analysis: it scans the running web application and its APIs, including authenticated sessions.
DIVD. I also stopped at the stand of DIVD, the Dutch Institute for Vulnerability Disclosure. Its mission, in its own words, is to âmake the digital world safer by reporting vulnerabilities we find in digital systems to the people who can fix themâ. Itâs run by volunteers, most of whom work in cybersecurity as their day job.
FME and CCV: the regulatory wave and CYRA
The talk that gave this post its name was in a small inflatable dome theatre in the early afternoon. It was a joint session by FME, the Dutch trade association for the technology industry, and the CCV, the Dutch Centre for Crime Prevention and Safety. The slide footer read âCybersec 10&11 September: The Operation Under Pressureâ.

FME in numbers: 2,200 member companies, 80% of them SMEs.
FME opened with its own numbers. The slide said FME is âthe trade association for the technology industryâ, with 2,200 members ranging from tech start-ups, trading companies and SMEs to large industrial companies and multinationals. The figures were 220,000 employees, 139 billion turnover, 59 billion export, 34 partner branches and 80% SMEs.
The regulatory wave

âRegulatory Waveâ: a surfer labelled FME riding a wave of acronyms while everyone else runs.
The slide I keep coming back to was titled âRegulatory Waveâ, under the heading âCompliance bottlenecksâ. It made two points:
- NIS2, the CRA, the CSA, the AI Act and the Data Act push companies to raise their cybersecurity level.
- There is a risk of duplication, fragmentation and double conformity assessments, eventually leading to rising costs and administrative burden.
Under âNeedsâ it listed five words: clarity, streamlined reporting, consistency, realism, proportionality. The illustration did the rest: a giant wave made of âNIS2â, âGDPRâ, âData Actâ, âDigital Services Actâ and more, a surfer with an FME board on top, and a beach full of people in suits running from it.
For context, hereâs where the two big ones stand, from the European Commissionâs own pages:
- NIS2 is Directive (EU) 2022/2555. Member States had until 17 October 2024 to transpose it into national law.
- The Cyber Resilience Act is Regulation (EU) 2024/2847. According to the Commissionâs CRA page, it entered into force on 10 December 2024. Its reporting obligations apply from 11 September 2026, and its main obligations from 11 December 2027. It covers products with digital elements, from connected hardware to software.
The reporting date is worth noticing. It fell exactly one year after the second day of this conference, so by the time you read this, manufacturers already have to report actively exploited vulnerabilities and severe incidents. Iâve written about how that reporting works separately.
CYRA: a growth model for IT and OT

The CCV half of the session, introduced on its own slide.
The second half was presented by Sanaa van de Pol-Assa. Her slide introduced her as an independent cybersecurity professional and advisor on cybersecurity certification schemes at the CCV, with experience at the NCSC leading OT initiatives. She presented CYRA, short for Cyber Rating.
According to the CCVâs CYRA page, CYRA is an online method that organisations use to map their digital resilience, and the CCV, an independent non-profit, manages it. There are modules for different situations: CYRA-IT is based on ISO/IEC 27001 and 27701, and CYRA-OT, for organisations running operational technology, is based on IEC 62443.

The CYRA growth model for OT: four levels, each building on the one before.
The growth model slide showed CYRA-OT as four steps: Entry level (30%), Basic level (60%), Intermediate level (80%) and Advanced level (100%). Each level was drawn as three sub-levels, and each step adds a row of requirements on top of the previous ones. The CCV page describes those sub-levels as the maturity stages ad hoc, best effort and defined.


From self-assessment to certificate, and the closing call to action.
The process slide was simple. A company runs a self-assessment against CYRA-IT or CYRA-OT through the CCV, gets a PDF report back, and can then go on to certification. The CCV page adds that the self-assessment uses an online tool with an annual fee, and that independent, accredited certification bodies do the certification. The closing slide read âBuild your Digital Resilienceâ and pointed to hetccv.nl/CYRA.
My take: for an SME facing NIS2 in its supply chain and the CRA on its products, the hardest step is the first one. A growth model with a 30% entry level is a better on-ramp than a full ISO 27001 or IEC 62443 programme. It shows how far along you are and what comes next. It isnât CRA conformity, though. The CRA asks for security by design, vulnerability handling and reporting on each product, and no organisation-level rating replaces that. Iâd use something like CYRA to get the basics and the habits in place, then map the product obligations separately.
What I took away
My take on the FME session: the problem it described wasnât the rules themselves, it was the overlap between them. âStreamlined reportingâ and âdouble conformity assessmentsâ were the phrases on the slide, and theyâre the right ones. For engineering teams, the practical answer is to build the evidence once, through SBOMs, vulnerability handling and incident runbooks in the pipeline, and reuse it for every framework that asks.