Skip to content
    All briefs
    Daily Brief

    Published · 9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics
    NATO

    NATO activates enhanced forward posture in Baltic states following Russia's confirmed sabotage of undersea cables

    The NATO Secretary General confirmed on 8 July that Alliance intelligence has attributed the cutting of two Baltic Sea communication cables to Russian naval assets operating under cover of plausible deniability. The cables connect Finland and Sweden to Germany. NATO has responded by activating an enhanced forward presence in Estonia, Latvia and Lithuania, with extra rapid-reaction forces and air defence assets. It is the third confirmed infrastructure attack in Baltic waters since January 2026. It also strengthens the Alliance's growing consensus that hybrid attacks on critical infrastructure are now a permanent part of the pre-conflict threat environment. If you have assets or staff in the Baltic region, review your continuity plans and backup communications.

    For organisations with people or assets in the Baltic states, our advisory and intelligence team provides threat assessments.

    Cyber
    ENISA

    Iranian-linked cyber group targets European energy firms with destructive wiper malware

    Threat intelligence firm Recorded Future and the European Union Agency for Cybersecurity (ENISA) jointly published an advisory on 8 July. It warns of a coordinated campaign by the Iran-linked group tracked as 'Void Manticore' against energy infrastructure operators in the Netherlands, Germany and France. The attackers gain initial access by spear-phishing OT administrators, then deploy ERASEDFIELD, a previously undocumented wiper that overwrites industrial control system configurations. Unlike financially motivated ransomware, the main aim appears to be operational disruption rather than extortion, in line with the pattern of Iranian state-directed sabotage. Affected organisations are urged to audit remote access credentials, segment OT networks and treat any unexplained ICS configuration change as a possible sign of compromise.

    Our cyber defence team runs OT security assessments and supports incident response for energy and other critical infrastructure operators.

    Training
    Reuters

    G7 security ministers agree joint framework for protecting executives travelling to conflict-adjacent regions

    G7 interior and security ministers met in Rome on 7 and 8 July. They agreed a joint framework for sharing protective intelligence when their nationals travel to regions near conflict, including the Middle East, the Sahel and Eastern Europe's border zones. The framework is non-binding but is expected to shape bilateral agreements. It sets minimum standards for pre-travel threat briefings and for real-time intelligence sharing between national security services when a national is assessed as higher-risk. It also covers recognition of HEAT training certification across G7 jurisdictions. For organisations working internationally, the signal is clear: governments increasingly expect employers to carry out a structured risk assessment before approving executive travel to high-risk destinations.

    We run HEAT training and pre-travel risk assessments for organisations sending staff to high-risk regions.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Compliance
    EURACTIV

    European Commission proposes mandatory cyber incident disclosure within 24 hours for critical infrastructure operators

    On 8 July the European Commission published a draft amendment to the NIS2 Directive. It would cut the mandatory initial incident notification window for essential entities from 72 to 24 hours. It would also create a new category of 'significant incidents'. These must be reported at the same time to ENISA and to national competent authorities and, where cross-border services are disrupted, to authorities in the affected neighbouring member states. The proposal adds personal liability for chief information security officers (CISOs) and board-level executives in cases of gross negligence, which goes materially further than the original NIS2 text. Trilogue negotiations are expected in Q4 2026, and implementation will likely take another 18 months after final adoption. Now is a good time to test whether your team could report within 24 hours.

    We run NIS2 gap assessments and help EU-regulated organisations prepare to report incidents within tighter deadlines.

    Europol disrupts pan-European surveillance-for-hire network operating covert device implants

    Europol's European Cybercrime Centre coordinated simultaneous arrests in seven EU member states on 8 July and dismantled a commercial surveillance network. The network sold physical device implantation to corporate clients, enabling covert recording of boardroom meetings, interception of executive communications and real-time location tracking of targets. The operation, codenamed SILENT ROOM, found 34 implanted devices in offices in Brussels, Amsterdam, Frankfurt and Zurich. One was an active implant in a law firm advising on a major M&A transaction. The network charged between €15,000 and €80,000 per engagement and worked through a chain of shell companies in Cyprus and Luxembourg. The case shows that physical bugging still works against corporate targets, and this is exactly the threat TSCM sweeps are designed to detect.

    Our TSCM sweeps look for exactly this kind of covert implant in boardrooms, offices and diplomatic premises.

    Geopolitics
    EUobserver

    EU foreign ministers agree expanded sanctions package targeting Wagner successor networks in Sahel

    EU foreign ministers meeting in Brussels on 8 July agreed an expanded sanctions regime against fourteen individuals and six entities. They are assessed as successors to the Wagner Group's Sahel operations, now rebranded as the Russian Africa Corps. The measures follow their involvement in documented atrocities in Mali, Burkina Faso and Niger. They include asset freezes and travel bans. For the first time in an EU sanctions package of this type, they also restrict sanctioned entities from contracting with EU-registered businesses for security services. European companies operating in West Africa take on extra compliance duties for every contracted security or logistics provider. They need enhanced due diligence to confirm that no sanctioned entity sits anywhere in their subcontracting chains.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    NCSC-NL issues critical advisory following ENISA alert — Dutch energy sector OT systems actively targeted

    The Dutch National Cyber Security Centre (NCSC-NL) issued an urgent advisory on 9 July backing ENISA's warning about the 'Void Manticore' campaign. It confirmed that at least two Dutch energy sector organisations have been identified as targets of the ERASEDFIELD wiper. NCSC-NL advises every operator of industrial control systems in the energy, water and chemical sectors to make offline backups of OT configurations now. Operators should also enforce multi-factor authentication on all remote access paths and review third-party vendor credentials. Organisations without in-house OT security skills are urged to bring in specialist support straight away rather than wait for a confirmed incident. The wiper is built to maximise disruption and recovery time.

    If you run industrial control systems without in-house OT security, our cyber defence team can assess your set-up and support incident response.

    Intelligence
    NOS

    Dutch parliament approves expansion of AIVD investigative powers — covert access to encrypted communications platforms authorised

    The Dutch Tweede Kamer passed the amended Intelligence and Security Services Act on 8 July by 89 votes to 61. The law gives the AIVD and MIVD wider powers to intercept communications on end-to-end encrypted platforms, including Signal, Telegram and ProtonMail, under strengthened judicial oversight. It takes effect on 1 September 2026. It also widens the agencies' ability to carry out covert physical access operations against targets assessed as a national security threat. A new category of 'critical sector companies' is introduced, whose internal communications may be monitored if they are assessed as a national security risk. Privacy advocates have filed an immediate challenge before the Council of State. For corporate security teams, OPSEC discipline and security-hardened communications still matter, even in the Netherlands' relatively permissive regulatory environment. Check which channels your staff use for sensitive discussions.

    Our advisory team reviews OPSEC and communications security for corporate and government clients who handle sensitive discussions.

    Physical Security
    NRC

    Rotterdam Port Authority activates elevated security protocol after threat intelligence indicates cargo fraud operation

    Rotterdam Port Authority confirmed on 9 July that it has activated its heightened security protocol across the container terminal zones. The trigger was credible threat intelligence about an active cargo fraud and physical infiltration operation targeting pharmaceutical and electronics shipments. The operation is assessed as coming from a Dutch-Belgian organised crime network with established links to drug smuggling infrastructure, and involves placing insiders in cargo handling jobs to redirect high-value shipments. The port has deployed more plainclothes security staff, checks access credentials more often and is working with the FIOD and the Koninklijke Marechaussee on an active investigation. If your shipments pass through Rotterdam in the coming weeks, step up cargo tracking and verify the chain of custody on outbound consignments.

    We assess supply chain security and support secure logistics for organisations moving high-value cargo through ports like Rotterdam.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation