🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Start your free trial
Back to Resource Center

How to build a security awareness culture in Dutch healthcare

No Dutch sector reports as many data breaches as healthcare. In 2024 alone, there were 6,873 reported cases.

Recently, a ransomware attack on Clinical Diagnostics Nederland resulted in a staggering 300GB(!) of stolen data, including social security numbers and medical test results.

Much of this data even ended up on the dark web. The incident also affected Bevolkingsonderzoek Nederland and several hospitals and general practitioners. The cybercriminals gained access to data from 850,000 people. The event was serious enough to trigger parliamentary questions.

News article about a hack at a Dutch healthcare organization.

Clearly, there’s plenty of reason for the healthcare sector to invest seriously in a strong security culture. One in which every employee understands the potential impact of a cyberattack and the role they play in preventing it. Yet, in many healthcare organizations, security awareness remains either a low priority or simply too much of a challenge.

Every hospital, mental healthcare provider, and lab in the Netherlands is one inattentive click away from the same headlines. Not because their systems are weak, but because their people are unprepared.

In this article, we’ll look at the state of security awareness in healthcare, why many initiatives fail to take off, and how to fix that.

First off, what does a healthy security awareness culture look like?

In healthcare, a strong security awareness culture is essential to protect sensitive medical data, maintain patient trust, and ensure continuity of care.

Why? Because a data leak of your medical data can be far more damaging than you might imagine.

As Stefan Behrens, Managing Director at a psychological healthcare organization, put it: “Medical data are among the most sensitive personal data, but I’d rather find my dental X-ray online than my therapist’s notes. That level of vulnerability hits much deeper.”

The best way to combat human error that leads to a data leak is by creating a strong culture. A shared mindset throughout the organization that says security is everyone’s responsibility, not just IT’s.

Here’s what that looks like in practice:

  • Security is part of daily behavior. Employees think twice before clicking a link, forwarding sensitive data, or logging in on a public network. They know what to report and feel safe reporting it.
  • Mistakes are discussed, not punished. In high-stress environments, errors are inevitable. What matters is how they’re handled. In strong cultures, people take ownership and report issues themselves. Not because they’re afraid, but because they care.
  • Awareness is visible in meetings and metrics. Teams regularly review which security themes need more attention, discuss recent risks, and share tips. It’s no longer a tick-the-box exercise. It’s part of the workweek.

Ultimately, a healthy security awareness culture in healthcare is one where everyone, from care teams to admin staff, understands that protecting patient data is part of delivering safe, high-quality care.

Or as Behrens of Psyned puts it: “With all the technical measures in place, wrong human behavior is among our biggest security risks and the security awareness of our people is a critical factor.”

What are the biggest threats to Dutch healthcare?

The latest Cyber Threat Landscape by Z-CERT paints a clear picture of the most pressing cyber threats facing healthcare today:

  • Ransomware attacks, especially on laboratories, hospitals, and youth care organizations
  • Spying on research facilities
  • Ransomware attacks aimed at suppliers
  • DDoS attacks at suppliers
  • Phishing with MFA bypass, as many organizations blindly rely on MFA for safety
  • Malware
  • Insider threats
  • Financial fraud
  • Data leaks caused by misuse of AI tools — for instance, staff entering sensitive patient data into ChatGPT

Some of these threats can only be mitigated by ensuring that your employees have a strong sense of security awareness. No matter how many technical safeguards you implement, a cyber-safe workplace starts and ends with responsible human behavior.

Why security awareness in healthcare is unique

Healthcare differs from other industries in several ways. A cyberattack doesn’t just disrupt business operations, it can directly impact the health of patients. Think of delayed surgeries, incorrect medication, or temporarily halted diagnostics.

News article about a data leak at Caren

There’s also a lot at stake when it comes to trust. When medical data is leaked, it both damages a hospital’s reputation and destroys trust patients place in the safety of their most sensitive information.

Then there’s cost. From recovery to legal claims and regulatory fines, the financial fallout is steep. In many cases, insurance premiums rise dramatically after a breach, if coverage is offered at all.

How healthcare differs from other sectors

Many organizations struggle with security awareness, but healthcare faces its own unique challenges:

  • Continuity: where a bank or factory can pause operations, hospitals can’t — they run 24/7.
  • Privacy-sensitive data: medical data is is very intimate and therefore valuable, making it a prime target for criminals.
  • Work culture: nurses and doctors primarily see themselves as caregivers, not as “employees who must follow cybersecurity protocols.” This mindset makes awareness harder to embed.
  • High workload and stress: during night shifts or crises, people are more likely to make mistakes they normally wouldn’t.

Why security awareness is such a challenge in healthcare

Security awareness is a hot topic across all industries, but healthcare faces its own unique obstacles.

Clinical rhythm vs. office rhythm

Most awareness programs are designed for corporate environments — people working 9-to-5, with flexible schedules, personal computers, and access to e-learning platforms.

In healthcare, that’s rarely the case. Staff work night shifts, move between locations, and face emergencies at any moment. They often don’t have a dedicated computer. Finding the time and place for regular training is tough.

Training doesn’t fit healthcare reality

Many programs assume a corporate context. They don’t address situations specific to healthcare, such as handling patient data, medical confidentiality, or discussing cases with colleagues. These details matter — and ignoring them limits results.

Lack of ownership

Security awareness affects everyone, but accountability must lie with one person or team. That’s where things often go wrong. In many organizations, responsibility is shared between IT, compliance, HR, or department heads — which means no one truly owns it.

Regulatory fatigue

While some small healthcare providers are intrinsically motivated to strengthen security awareness, others show resistance. They view standards like NEN 7510 as bureaucratic red tape. Awareness initiatives add to the administrative burden, on top of other safety requirements like fire safety or aggression management.

Supply chain blind spots

In 2024, Dutch customer communications company AddComm fell victim to a ransomware attack, affecting many of its clients, including ABN Amro and Infomedics. It showed how vulnerable supply chains are and why supplier security must be part of the strategy. Vendors should be required to meet minimum standards.

Internally, there’s often the same blind spot: students and freelancers with access to sensitive data are excluded from awareness programs.

Policy without practice

According to the Dutch Data Protection Authority’s 2024 breach report, 40% of reported cyber incidents didn’t stem from a lack of policy, but from policies not being implemented or monitored.

Often, everything looks good during a compliance audit, but awareness fades once the audit is over. Policies remain on paper. That’s why leadership must see awareness as more than compliance.

How to build a security awareness culture in healthcare

Most healthcare workers are already drowning in protocols, audits, and mandatory e-learning modules. More rules or bigger platforms won’t solve the problem.

What does work is treating awareness as a living product — something that’s delivered regularly, continuously measured, and constantly adapted to real-life healthcare situations.

Weekly, mobile, and role-based training

Healthcare staff don’t have time for long classroom sessions or generic e-learning. Training should be short, practical, and relevant — 3–5 minutes per session — tailored to their role. Doctors and nurses need different scenarios than the average accountant or marketer.

Deliver training where it fits: on mobile, during a break, or directly in Microsoft Teams. Learning should blend seamlessly into daily routines.

→ Learn about Guardey’s security awareness program for healthcare

Behavior-focused KPIs

There are two goals here. First, keep a pulse on the awareness level within your organization. Second, being able to prove compliance with NEN 7510 requirements. Key metrics include:

  • Reporting rate: how many employees actively report phishing or suspicious incidents?
  • Time to report: how quickly do they act after noticing something unusual?
  • Phish-to-report ratio: how many simulated attacks are correctly recognized and reported?

These metrics show whether you’re building a true safety culture.

Easy reporting and instant feedback

Reporting should be as easy as clicking a button. With a built-in report button in Outlook or Teams, employees can forward suspicious emails instantly. Immediate feedback is crucial, not weeks later in a report. Make reporting positive: a success moment, not a reprimand.

Just-in-time coaching

Waiting for semiannual evaluations doesn’t work in a 24/7 environment. When someone clicks on a phishing email — or correctly reports one — feedback should follow fast. Short, personal tips keep people alert, especially against advanced attacks like AiTM or credential theft.

Include the entire ecosystem

Awareness shouldn’t stop at permanent employees. Volunteers, interns, contractors, and vendors often have the same system access. Criminals don’t distinguish — and neither should your program.

Governance that works

Awareness shouldn’t be an IT hobby, but a top-down priority. Assign an executive owner, define clear RACI responsibilities, and discuss progress monthly. That’s how awareness stays alive and part of the leadership agenda.

If we’ve learned anything over the years, it’s that every security awareness program that isn’t fully backed by management fails within a matter of months.

Link to business continuity

An awareness program has real value only when it shows up during a crisis. Run scenarios where awareness plays a key role: what happens if a supplier is hit by ransomware, a DDoS takes down your lab systems, or your EHR is offline for hours?

If awareness isn’t visible in crisis response, it was never truly embedded.

Conclusion: From compliance task to culture shift

Healthcare tops the charts for data breaches and cyberattacks, with consequences that go far beyond fines or bad press. Patient safety, continuity of care, and public trust are at stake.

Security awareness can’t be a yearly checkbox exercise. It requires a culture where staff understand their role, can make mistakes and learn from them, and where leadership treats cybersecurity with the same seriousness as patient care or financial health.

The key lies in small, practical steps: short and relevant training, easy reporting, instant feedback, and embedding awareness in crisis management. That’s how awareness evolves from an obligation into a natural part of professional healthcare.

What you can do today

  1. Adopt a security awareness program – find a program that offers healthcare-specific training content, like Guardey.
  2. Measure behavior, not knowledge – start tracking KPIs like reporting rate and time to report.
  3. Make reporting easy and rewarding – add a report button and give immediate feedback.
  4. Include everyone with access – interns, volunteers, and vendors are part of your chain too.
  5. Assign executive ownership – without leadership support, awareness remains a side project.

Learn more about Guardey’s security awareness program for healthcare

Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo