Skip to main content
Man with glasses in white shirt
Our stories

Jeroen‘s story

Head of Digital Security Services

Collaboration and transparency are key

‘I am both the Chief Information Security Officer (CISO) and the head of the Digital Security Services (DSS) department at DNB. In this role, I lead a team that works every day to ensure DNB’s digital security. Cybersecurity is crucial at an institution like DNB. We play a pivotal role in the financial system and must therefore not only protect our own systems, but also contribute to the resilience of the sector as a whole.

For us, transparency and collaboration are key. That is why we make a conscious choice to take an open approach to security, even when it is not the obvious thing to do. A good example: a few years ago, we had ethical hackers test our systems. And yes, they managed to get in. Instead of keeping this to ourselves, we shared their findings with other financial institutions. Because if we are vulnerable in some way, there’s a good chance that others are too. By sharing that knowledge, we help make the whole sector more resilient. Cyber threats are changing at breakneck speed. That calls for agility and continuous learning – not only within our team, but also in collaboration with other organisations.

This kind of openness is not a given in our sector. Nevertheless, I believe it is essential. I once spoke to someone in the aviation industry who told me that airlines always share details of incidents so that others can learn from them. We try to apply that principle as well. Not to point fingers at one another, but to grow stronger together.

Cyber threats are changing at breakneck speed. That calls for agility and continuous learning – not only within our team, but also in collaboration with other organisations.

Legislation, continuous learning and internal awareness

New legislation, such as the European DORA rules, helps in this regard. It requires financial institutions to report cyber incidents. This boosts transparency and makes the work of supervisory authorities such as DNB more effective. But legislation is not enough. Cybersecurity isn’t just an IT issue – it concerns us all.

We have various teams at DSS working on a wide range of threats, from phishing to AI-driven attacks. We keep each other on our toes, share insights and continue to learn. An important part of this is raising awareness within the organisation. We actively keep our colleagues informed about current risks such as phishing, which is becoming increasingly difficult to spot. At the same time, we make sure that everyone feels comfortable reporting incidents, even if they have accidentally clicked on a dodgy link. There is no need to feel ashamed, but rather it is an opportunity to act quickly. Better to have one alert too many than to detect an attack too late.

Cyber security is never a ‘finished product’. But with the right people, an open mind and a willingness to keep learning, we make progress every day. And that is what makes this work so valuable – not only for society as a whole, but certainly for me personally as well.’

View more DNB stories

Want to receive the latest DNB vacancies in your inbox?

Subscribe for job alerts