Overig · Overig
Cybercrime costs Dutch companies millions, why IAM is more important now than ever
Research by ABN AMRO and MWM2 shows that one in five companies suffered financial damage due to cyber attacks in 2024. In many cases, this is caused by account misuse, insufficient access management, or incorrect offboarding. By automating IAM, such as with Joinly, accounts, permissions, and access are centrally secured, and damage is prevented.

Mike Fraanje · 4 min read
The figures are shocking, but unfortunately not surprising: Research by ABN AMRO and MWM2 among 788 Dutch companies shows that about one in five organisations reported damage after a cyber attack in 2024, with an average damage of €300,000 per incident. This involves not only data breaches or ransomware, but increasingly misuse of accounts, credentials and access rights.
This trend is directly related to the core of Identity & Access Management (IAM). At Joinly, we see daily how vulnerable organisations become if identities and access are not strictly organised — and how quickly damage can occur when this is not in order.
The main cause: misuse of accounts and weak access
Cyber attacks are no longer about hacks or breaches on systems but breaches on accounts, most incidents arise from:
Accounts without Multi-Factor Authentication
Excessively broad access rights
Unused accounts that are still active
Shared accounts without monitoring
Incorrect offboarding upon departure or internal change
Criminals don't need complex malware when they can simply gain access via an old account or unsafe login.
And this explains why the average damage per incident is so high:
once inside, you can access everything.
Why this is particularly an issue in the Netherlands
Dutch organisations have relatively quickly embraced cloud systems, SaaS services and hybrid environments. This is positive for flexibility but also increases attack vectors, especially when IAM does not keep pace.
Additionally, many companies have multiple suppliers in the chain who receive (temporary) access to systems. If those accounts are not properly monitored or revoked, they remain a risk.
The main question is not:
"Are we ever interesting to hackers?"
but:
"How many doors are ajar without us knowing?"
IAM is the solution, but it must be structural and automated
IAM is not a project, not an implementation and not a one-time measure. It is a continuous process.
And that's where it often goes wrong.
An organisation can implement MFA, but if former employees still have active accounts, that solves nothing. Identity governance can be set up, but if rights are not automatically withdrawn upon role changes, it remains a patchwork.
What is needed is:
Automatic onboarding & offboarding
HR-driven provisioning to ensure identities are always correct
Automatic withdrawal of rights during changes or departure
Consistent policy between AD, Entra ID, cloud apps and on-premises systems
Insight into who has access to what
This must not be done manually, must not rely on IT emails, and must not be scattered across different departments.
How Joinly protects companies from such damages
Joinly automates the entire identity lifecycle management — ensuring the basics are always in order.
With Joinly:
Accounts are automatically created, modified and deleted based on smart rules.
Processes are reliable, reproducible and not dependent on manual work.
No ‘forgotten accounts’ are left behind that can be exploited.
You can easily enforce strict MFA, Conditional Access and governance rules.
You can migrate from AD to Entra ID without rebuilding IAM processes.
Every organisation working with Joinly reduces the risk of the most common cyber incidents in one fell swoop.
And that is not a luxury — but an urgent necessity, given the figures.
Conclusion
The reality is: cybercrime is increasing in the Netherlands and costs companies hundreds of thousands euros on average per incident. In almost all cases, identity and access management plays a key role.
By automating and professionalising IAM, you prevent weak access and forgotten accounts from leaving the front door wide open.
With Joinly, we help organisations to make that foundation strong, secure and future-proof so that cybercriminal opportunities are minimised.
Explore more blogs

Segregation of Duties (SoD): wat het is en hoe je het afdwingt
Wat is segregation of duties (functiescheiding)? Uitleg, voorbeelden en waarom het vaak misgaat. Plus hoe je SoD-conflicten automatisch tegenhoudt.
Marcel van Beek · 4 min read

How do you apply AGDLP in a hybrid Entra/AD environment? (And why you shouldn't want to anymore)
Short answer: preferably not. AGDLP (Accounts → Global groups → Domain Local groups → Permissions) is a concept from the era of manual management. The entire nesting construction exists for one reason: to allow a human to assign permissions with as few mouse clicks as possible. As soon as an agent assigns group memberships directly based on HR data, this reason disappears and only the complexity remains. Moreover, in a hybrid environment, this complexity actively works against you, because Entra ID completely ignores nesting for licences and app assignment. In this article, you can read how AGDLP works and why it was once smart, where it breaks down in a hybrid environment, and what the modern alternative looks like: direct memberships, managed by automation.
Marcel van Beek · 5 min read

How do I set up role-based access control (RBAC) and least privilege for a municipality?
Start with the roles in your HR system and map them to roles, not to individual permissions per person. Group each role with precisely the access required for the job, adhering to the principle of least privilege. Manage these roles centrally and let an orchestration layer automatically assign and revoke them. This keeps access predictable, limited and demonstrable.
Mike Fraanje · 4 min read
See what Joinly can do for your organisation?
Start a free trial today or get in touch for advice on your HR and Microsoft environment.