Skip to content
    All briefs
    Daily Brief

    Published · 9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics
    Reuters

    US-China diplomatic meeting collapses over Taiwan Strait incident; security agencies warn of elevated cyber espionage tempo

    Planned talks between senior US and Chinese officials in Singapore collapsed on 11 July after a confrontation in the Taiwan Strait. Chinese coast guard vessels had shadowed and briefly blocked a US naval resupply mission to an allied Philippine outpost. In response, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cyber Security Centre (NCSC) and the Australian Cyber Security Centre issued a joint advisory. It warns of a probable near-term rise in Chinese state-sponsored cyber espionage against Western government contractors, defence supply chain firms and semiconductor manufacturers. The advisory flags spear-phishing that impersonates trade association emails, exploitation of VPN vulnerabilities, and Living-off-the-Land (LotL) techniques that hide in legitimate administrative traffic. If you work in these sectors, enforce phishing-resistant MFA and check that VPN firmware is current. Set behavioural baselines on your network so that unusual lateral movement of the LotL kind stands out.

    Our advisory and intelligence team assesses what the US-China tensions mean for organisations with international operations.

    Ransomware group Fog claims attack on three European private security firms, leaks employee security clearance data

    On 11 July the ransomware group Fog published what it claims are data archives from three European private security companies, two in Germany and one in Poland. By Fog's account, the roughly 2.4 GB of files include employee personnel records, security clearance applications, client site access protocols and guard patrol schedules. If the breach is confirmed at that scale, it would be a significant operational security incident. Guard schedules and site access protocols in hostile hands could help plan physical intrusions, and clearance documents expose individual staff to targeted recruitment or coercion by foreign intelligence services. It points to a weakness across the security industry: security firms are valuable targets precisely because their operational data reveals client premises. Security organisations should protect their own data as carefully as their clients' sites, with regular penetration testing, minimal access rights and air-gapped storage for the most sensitive operational records.

    Our cyber security team runs security assessments and penetration tests for organisations that hold sensitive operational data, security firms included.

    Physical Security
    WHO

    WHO declares mpox variant Clade Ib a Public Health Emergency of International Concern for the second consecutive year

    The WHO Director-General declared on 11 July that mpox Clade Ib remains a Public Health Emergency of International Concern (PHEIC), extending the emergency status first declared in 2025. The variant was first identified in eastern DRC in 2024 and has since been detected in 14 countries. The decision follows data showing sustained community transmission in DRC, Uganda, Kenya and Burundi, plus imported cases in Belgium, Sweden and the United Arab Emirates in June and July 2026. Clade Ib transmission in Europe is still limited and linked to travel. Even so, the European Centre for Disease Prevention and Control (ECDC) has issued new guidance on contact tracing and protective equipment for healthcare and response workers. If you deploy staff to sub-Saharan Africa, update your travel health risk assessments with Clade Ib exposure procedures, a check of vaccination status before deployment and monitoring after return.

    Our hazardous-environment training includes biological threat procedures for staff deploying to regions affected by Clade Ib.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Geopolitics
    EURACTIV

    European Parliament passes AI Weapons Systems Oversight Resolution, calling for human-in-the-loop mandate

    On 10 July the European Parliament adopted a non-binding resolution by 412 votes to 189. It calls on EU member states and NATO allies to adopt legally binding human-in-the-loop requirements for autonomous weapons that can select and engage targets without direct human authorisation. The resolution is driven by concern over reported use of AI-enabled drones in the Ukraine conflict and in Middle Eastern operations. It asks for an EU-level treaty framework to be proposed to the UN by the end of 2026. The resolution is not binding, but it puts strong political pressure on the European Commission to speed up its stalled regulatory initiative on lethal autonomous weapons systems (LAWS). The debate matters further down the line for private security. Autonomous surveillance and deterrence systems are likely to face closer regulatory scrutiny as the EU moves toward broad oversight of autonomous systems in military and civilian settings. That includes perimeter AI cameras with automated alerts and drone-based monitoring. Factor that into procurement decisions for such systems.

    Intelligence
    Europol

    Europol reports 40% rise in organised crime groups exploiting EU diplomatic mail channels for contraband trafficking

    Europol published an update to its Serious and Organised Crime Threat Assessment on 10 July. It documents a 40% year-on-year rise in detected cases of organised crime groups abusing diplomatic mail and pouch channels. These channels enjoy international legal immunity under the Vienna Convention, and the groups use them to move narcotics, weapons components and precursor chemicals across EU borders. The main way in has been corruption of mid-level diplomatic staff: criminal groups combine money with coercion to recruit couriers inside missions. Several EU member states are named as both origin and transit points. For embassy and diplomatic security teams, this calls for internal vetting, checks for anomalies in mail handling, and documented chain of custody for everything that enters or leaves the mission. It also shows why TSCM and physical security at diplomatic premises must cover threats from inside as well as outside.

    For embassies and missions in the Netherlands and the EU, our security and TSCM support covers threats from inside the mission as well as outside.

    Compliance
    ENISA

    NIS2 enforcement: German BSI issues first cross-border corrective orders to non-compliant critical infrastructure operators

    On 10 July Germany's Federal Office for Information Security (BSI) issued corrective orders to seven critical infrastructure operators, including three companies headquartered in the Netherlands and Belgium. It is the first use of the cross-border enforcement powers created by the NIS2 Directive's rules on regulatory coordination within the EU. The operators must set up mandatory vulnerability disclosure programmes, obtain certification equivalent to Cyber Essentials Plus and undergo independent penetration testing within 90 days. Non-compliance risks fines of up to 2% of global annual revenue under NIS2. The message is that NIS2 enforcement is no longer theoretical and regulators will use cross-border powers. Being based outside Germany does not protect you from BSI action if your infrastructure serves the German market. Dutch legal and compliance teams should map their NIS2 obligations in every EU jurisdiction where they run critical infrastructure or provide essential services.

    Our advisory team maps NIS2 obligations in every EU country where Dutch critical infrastructure operators are active, and builds the compliance roadmap.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Intelligence
    AIVD

    AIVD detects foreign intelligence operation targeting Dutch semiconductor supply chain firms in Eindhoven region

    On 11 July the AIVD issued a sector-specific threat notification to semiconductor equipment makers and their suppliers in the Eindhoven-Brainport corridor. It warns that a sustained foreign intelligence operation, attributed with high confidence to a state actor in the Asia-Pacific region, is actively targeting their intellectual property, recruitment pipelines and customer lists. The operation combines three methods. Technical intrusion uses watering-hole attacks on industry association websites to reach engineering workstations. Human approaches involve unsolicited contact with Dutch engineers at international conferences. Academic collaboration offers research funding with IP transfer obligations attached. The AIVD recommends briefing engineering and business development staff on the threat and setting up a formal way to report unsolicited foreign approaches. Firms should also review the security of collaboration agreements with international academic and commercial partners. The warning follows last year's disclosure that a major Dutch semiconductor component maker suffered a two-year undetected network intrusion attributed to the same actor.

    For Brainport firms, our specialist operations team gives engineers and business development staff counter-intelligence briefings on approaches like these.

    Physical Security
    ANP

    Rotterdam port authority completes first hazardous-materials mass-casualty exercise involving 400 emergency responders

    The Port of Rotterdam Authority, working with the Veiligheidsregio Rotterdam-Rijnmond, GHOR Zuid-Holland-Zuid and the Dutch Ministry of Infrastructure and Water Management, completed a two-day hazardous-materials mass-casualty exercise on 11 July. About 400 emergency responders simulated a combined chemical and radiological release at a container terminal. The exercise, 'DELTAFORCE 2026', tested how port security teams, fire services, medical first responders and hazardous-materials specialist units work together during a mass-casualty event with partly degraded communications. An after-action report is expected within 60 days. Ports handle hazardous cargo at large scale right next to dense urban areas. Dutch critical infrastructure policymakers increasingly see them as a credible setting for a hazardous-materials mass-casualty incident that needs regular full-scale rehearsal. If you operate in the port or provide security or emergency services to port clients, review your own hazardous-materials response and how it links up with local emergency services.

    We train port security teams and emergency responders in the Netherlands to handle hazardous-materials incidents like the one DELTAFORCE simulated.

    Physical Security
    ANP

    Den Haag municipal police report 28% increase in corporate vehicle break-ins near Scheveningen conference district

    On 10 July the Den Haag police district issued a crime pattern advisory. Break-ins into corporate and diplomatic vehicles parked in the Scheveningen conference district, the Internationale Zone and nearby streets between 17:00 and 23:00 are up 28% year on year. Analysis of 84 incidents from January to June 2026 points to a coordinated criminal operation using signal boosters to relay keyless entry signals, so vehicles can be opened without the key. Most targets were premium German cars and modified security vehicles recognisable by their equipment (roof antennas, blackout glass, reinforced panels). Thieves were mainly after laptops, executive briefing papers and personal valuables. The police advise security drivers and fleet operators to use physical key shields and to switch off keyless entry when a vehicle is left for long periods. They should also vary where they park near conference venues. Protection teams should brief principals on document security before and after each conference.

    Our security drivers and protection officers look after principals and their briefing papers at conferences in The Hague and elsewhere in the Netherlands.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation