In recent years, Dutch municipalities and government agencies have become prime targets for cyberattacks, exposing critical vulnerabilities in public sector cybersecurity. In 2023 alone, the Dutch Data Protection Authority received over 25,000 data breach reports, with at least 178 ransomware attacks affecting governmental bodies. A particularly alarming case involved a cyberattack on the Dutch police network, attributed to a state actor, compromising work-related details of all officers. The following year, 121 ransomware incidents continued the trend, some targeting municipal systems and critical infrastructure.
These attacks highlight a pressing issue: public institutions need more than compliance-based training to defend against evolving cyber threats. The 2023 cyberattack on the municipality of Buren, which left citizens without access to essential digital services, demonstrated the consequences of inadequate hands-on experience. Similar incidents in Belgium and Germany reinforce the growing need for practical, real-world cybersecurity training. Without it, local governments will remain vulnerable to increasingly sophisticated attacks.
Why Compliance Alone Won’t Stop Cyberattacks
Many cybersecurity professionals in the public sector are well-versed in GDPR, NIS2, and ISO 27001 requirements. They know the regulations, can map out security architectures, and understand theoretical attack methods. But when a real cyberattack unfolds, compliance checklists offer little help.
Take the case of a Dutch government IT specialist who, after experiencing a ransomware attack, admitted: “We had followed all the security guidelines. But when the attack happened, we realized we had never actually practiced responding to a live cyber threat. Everything we had learned was theoretical.”
Just as a firefighter wouldn’t learn to fight fires by only reading a manual, cybersecurity professionals need hands-on experience to effectively counter threats.
The Shift to Hands-On Cybersecurity Training
To build cyber-resilient public sector teams, European governments must move beyond theoretical learning and provide practical training that replicates real-world attack scenarios. The most effective training programs:
- Simulate real-world cyberattacks – Security professionals need to work with realistic cyber ranges, practicing how to detect, mitigate, and recover from active threats, rather than just studying case studies.
- Teach both offensive and defensive tactics – Understanding how attackers operate allows security teams to anticipate their moves and strengthen defenses accordingly. Red and blue team exercises are crucial.
- Reinforce skills through repetition – Incident response drills should be a routine part of cybersecurity training, ensuring that teams instinctively know how to act under pressure when a real crisis occurs.
Lessons from European Cyberattacks
In 2022, a ransomware attack hit multiple hospitals across France, shutting down emergency services and forcing medical staff to rely on manual record-keeping. Some hospitals were able to contain the threat within hours, while others took weeks to recover. The difference? Those with hands-on cybersecurity training could act quickly and decisively.
This incident, along with growing cyber threats in the EU, has led to a renewed focus on practical cybersecurity training for public sector professionals. More municipalities are now investing in cyber ranges, real-world simulation exercises, and proactive incident response drills.
Bridging the Gap Between Knowledge and Action
While cybersecurity frameworks like NIS2 provide essential guidelines, they do not replace the need for hands-on training. European public sector organizations must integrate real-world exercises into their cybersecurity strategies to ensure teams are prepared for evolving threats.
Some governments are already leading the way. In the Netherlands, municipalities are partnering with cybersecurity firms to conduct live cyberattack simulations, helping IT teams develop practical skills in threat detection and incident response.
Strengthen Cyber Resilience
Public sector security teams protect critical infrastructure, essential government services, and citizen data. Without real-world training, they are at a disadvantage against increasingly sophisticated cyber threats.
European governments must act now to provide hands-on cybersecurity training that equips their teams with the skills needed to defend against real attacks. Because in cybersecurity, theory alone won’t stop the next breach. Experience will.
Technical expertise alone isn’t enough to navigate today’s cybersecurity landscape, strong communication, leadership, and problem-solving skills are just as critical. Cyber Security District Academy helps IT and security professionals develop the soft skills they need to collaborate effectively, communicate security risks with stakeholders, and drive a security-first culture within their organizations.







