“Our organisation wants to get started with Copilot.”
You have heard that sentence in your boardroom. Maybe you said it yourself. It sounds like progress and in many ways it is. But before you nod, let me ask the question nobody asks out loud: what if that sentence, spoken in your organisation, this year, is the beginning of the end? The end of something, at least. Perhaps the end of the comfortable illusion that your data is under control.
After more than twenty-five years in cybersecurity I can tell you something uncomfortable. In the large majority of organisations I visit, it takes me minutes, not days, to reach the most confidential information. Not by hacking. Simply by looking at what everyone can already access. And that is exactly what you are about to switch on for your entire workforce at once.
The mess nobody wants to own
Here is the part that rarely makes it into the Copilot business case. In virtually every organisation, years of collaboration have produced a tangle of access rights that nobody fully oversees anymore. Folders once shared with the whole department for a single project. Sites set to everyone in the organisation because that was faster. Files from people who left years ago, still readable by half the company. The problem is not that the locks are broken. The problem is that the rights behind the locks have been too broad for years.
The numbers back this up at a global scale. In one data risk report by security firm Concentric AI, around 16 percent of business-critical data was found to be overshared, with an average of roughly 800,000 at-risk files per organisation, about 400 at-risk files per employee. Most of that oversharing is internal: files visible to colleagues who never needed them. Microsoft itself, in its official Copilot deployment guidance, names overshared content as the single biggest risk to address before rollout. Read that again. The vendor selling you the AI assistant is warning you about your own access rights.
AI does not break your security. It reveals it
This is the insight every board needs to internalise before signing anything. Microsoft 365 Copilot neatly respects your existing permissions and policies. That is not the problem. The problem is what those permissions actually are. Copilot does not judge whether access was ever intended, it simply accelerates what is already possible. Put an AI on top of a permission tangle and it reads through everything in seconds. Your old mistakes become findable in one stroke, for anyone who dares to ask.
Zero-click attack on an AI assistant
And asking is getting easier. In June 2025, researchers at Aim Security disclosed EchoLeak, which they describe as the first known zero-click attack on an AI assistant. One carefully crafted email was enough. No click, no attachment. Microsoft 365 Copilot read a hidden instruction, dug into the business data it could reach and leaked it outward. Microsoft patched the flaw and no abuse in the wild is known. But note what the weapon was: nothing more than text, aimed at access that was already too broad.
Update June 2026!
And it did not stop at EchoLeak. In June 2026 security firm Varonis showed with SearchLeak that Microsoft 365 Copilot Enterprise Search was vulnerable too. This time a single click on a trustworthy-looking Microsoft link was enough. No malware, no strange attachment, no complicated hack.
The link carried a hidden instruction. It made Copilot search everything the user could reach: email, calendar, OneDrive, SharePoint. The information it found could then be routed out through Bing, and so through Microsoft’s own infrastructure. Even still-valid MFA codes could surface this way.
Microsoft fixed it on the back end and there is no evidence the attack was ever exploited for real. But the lesson matters. The technical flaws underneath were not new. They were old web problems in a new jacket. What is new is that AI suddenly makes them far more powerful. The prompt is the new weapon. The open door is the same as it always was.
Lilli, the internal AI platform of McKinsey
Then February 2026 happened. Security startup CodeWall says it pointed an autonomous AI agent at the internet and let it pick a target. It chose Lilli, the internal AI platform of McKinsey, one of the most security-conscious firms on the planet. According to CodeWall and subsequent reporting, in roughly two hours, without credentials or human guidance, the agent reached the production database behind the platform: tens of millions of chat messages, hundreds of thousands of files. The entry point was a SQL injection flaw, an attack class documented in 1998. McKinsey patched within hours of the responsible disclosure and no malicious access is known.
The lesson is not about McKinsey. The lesson is that attackers are now software, they work at machine speed and the doors they walk through are the oldest ones we never closed. Gartner has been cited as expecting the share of enterprise applications with task-specific AI agents to rise sharply, from below 5 percent in 2025 to as much as 40 percent by the end of 2026. Meanwhile, the identity problem for agents is still immature: most organisations are only beginning to treat agents as identities with scope, lifecycle and accountability. More autonomous software, more access, less oversight. You see where this is going.
The numbers from one of the most digitised countries on earth
UPDATE May 28, 2026: If you think this is theory, look at the Netherlands, my home market and one of the most digitised economies in the world. The national statistics office CBS published its Cybersecurity Monitor in May 2026 with a reassuring headline: the lowest share of companies with a cyber incident in nine years, 4 percent in 2024.
Then you open the sector tables, as I did, and one line jumps out. In financial services, the share of companies hit by an outside attack doubled from 3 percent in 2023 to 6 percent in 2024, the sharpest rise of all thirteen sectors. Incidents that actually cost money tripled there from 1 to 3 percent. The sector with the most sensitive client data, the strictest supervision and the most security measures in place is the one moving the wrong way. More locks on the door and more uninvited visitors. That may well be a sign that attackers are shifting their attention to where the data is worth the most.
Dutch city recently had to report a data breach
And while that is happening, what are employees doing? In our Dutch book Help! Mijn chatbot wil opslag, we describe anonymised measurements by security firm MindYourPass at Dutch municipalities in 2025. Shadow AI is not a hypothesis there, it is daily reality. ChatGPT dominates, Microsoft Copilot is growing fast, Google Gemini, Canva AI and Claude follow. At position twelve in the top twenty sits Gamma.app, an American presentation tool into which civil servants upload documents that may include sensitive citizen data. As founder Merijn de Jonge puts it: shadow AI is the new shadow IT, unseen, uncontrolled and everywhere. Official policy says no. Actual behaviour said yes a long time ago. One Dutch city recently had to report a data breach after employees pasted over a thousand documents containing personal data into public AI tools. Your organisation is not different. You just have not measured it yet.
Job boards: the most honest strategy documents there are
Since 2023 I have been reading job postings as an early-warning system. Strategy decks tell you what organisations want to believe. Vacancies tell you what they are actually doing, because every posting represents budget, a hiring manager and a deadline. Watch the Dutch financial sector through that lens and you can see the collision described in this article happen in real time. While the sector’s incident numbers doubled in the CBS statistics, its job boards filled with Copilot adoption specialists and AI engineers. Even De Nederlandsche Bank, the country’s central bank and prudential supervisor, has been hiring along the full curve: a Copilot adoption specialist in October 2024, a Microsoft 365 Purview solution architect in October 2025 and a Power Platform engineer to build Copilot Studio agents in February 2026.
Pattern
To be clear, this is not a reproach. Hiring a Purview architect is exactly what good governance looks like and a supervisor that builds hands-on AI experience will supervise better. The signal sits in the pattern across the whole market: adoption roles outnumber clean-up roles many times over. Everyone is hiring people to switch AI on. Almost nobody is hiring people to first map who can already access what. The sector that is moving the wrong way on incidents is wiring AI deepest into its client data, and you can read it happening, vacancy by vacancy.
Paradise is not a perimeter
Now let me take you to the part of the Kingdom I care deeply about: Aruba, Curaçao, Sint Maarten and Bonaire and of course outside the Kindom Barbados. If anyone there still believes cyber risk is something for the big economies, the islands’ own history says otherwise. In November 2019, ransomware took down large parts of the IT systems of the Horacio Oduber Hospital in Aruba. Care fell back to paper, attackers reportedly demanded a quarter of a million dollars and the government activated a national crisis plan under the Calamity Act, as its own press statements at the time confirm.
On Sint Maarten, the BlackByte ransomware group struck NV GEBE, the island’s only water and power utility, in March 2022. The entire customer database, financial data and other business data were encrypted, the public prosecutor later reported to government, and a year on the company was still rebuilding its customer and billing systems.
Recent cyberattacks across Aruba, Bonaire, Curaçao and Sint Maarten
In the summer of 2025, ransomware hit Curaçao’s tax authority, disrupting services for days, while a virus forced the Joint Court of Justice (the court serving Aruba, Curaçao, Sint Maarten, Bonaire, Sint Eustatius and Saba) to take its network offline.
Separately, Aruba’s parliament also confirmed that it had experienced a security issue involving its internal email. A hack had taken place: one of the official email accounts of a parliamentary employee had been compromised. The warning to the public was unambiguous:
“Have you received suspicious or unexpected messages that appear to come from us? Do not open any links or attachments. We are conducting a thorough investigation and are taking measures to fully restore the security of our systems. Until then, please use other contact channels where necessary.”
Even the supervisor itself was not spared: the Central Bank of Curaçao and Sint Maarten suffered a cyberattack in 2021, traced back to a vulnerability in a remote working solution.
The regulators see it clearly
In its Financial Stability Report 2026, the CBCS names cybercrime and artificial intelligence among the top emerging threats to financial stability in the monetary union, citing global cybercrime cost estimates of around 10 trillion dollars in 2025, and it is developing new supervisory guidance on cybersecurity, third-party technology, operational resilience and AI. On Aruba, the director of the security service VDA, Juri Nicolaas, said it better than I ever could: cyber resilience must no longer be an IT file, it is a governance issue. He also named the islands’ particular exposure: small scale, import dependence and an economy where everyone understands what it means when the reservation systems go down. One hotel chain offline is an incident. Tourism infrastructure offline is a national crisis.
Ransomware attack Bonaire 2026
Bonaire shows how recent and how close to home this is. On 17 February 2026, the island’s secondary school community SGB was hit by an international ransomware attack in which part of an archive server’s files were stolen; the cyber team of the Caribbean Netherlands police and Europol joined the investigation. The school had the usual measures in place, multi-factor authentication and firewalls included, and it did several things right: it reported the crime, notified the data protection authority and informed the public.
Publishing your full ‘secure cloud’ landscape in the press
Yet one detail in its press statement deserves a gentle observation, because the whole region can learn from it. To reassure the public, the statement listed by name the systems that were not affected. Understandable and well-intended. But publishing your full ‘secure cloud’ landscape in the press hands the next attacker a free map of your environment. Mature crisis communication reassures without sharing the floor plan. I say this with respect, not judgement: the islands are learning fast and incidents like these are exactly why that learning has to accelerate.
And here is what makes the Caribbean situation sharper, not softer. European organisations are getting a legal push: the EU’s NIS2 directive, implemented in the Netherlands through the Cyberbeveiligingswet expected in mid 2026, makes boards personally accountable for approving and overseeing cyber risk management, training obligations included. That exact accountability framework does not automatically extend to the autonomous Caribbean countries within the Kingdom, such as Aruba, Curaçao and Sint Maarten. For the islands, boardroom accountability cannot wait for Brussels or The Hague to force the issue. Which means one thing: on the islands, the board is the safety net. There is no other.
The inheritance no director wants
So let us name the real issue, because it is not Copilot. For two decades, access rights, data hygiene and identity management were treated as technical chores. IT asked for time and budget to clean up, the business asked for speed and the business usually won. I refuse to blame IT alone for that. Every postponed clean-up was a governance decision, made or waved through at board level, often without anyone realising a decision was being made.
That neglected estate is now being inherited. By you. The director who signs the Copilot rollout this year inherits twenty years of unmanaged access in the same signature. And the timing is merciless: regulators from The Hague to Willemstad are moving accountability upward to the boardroom precisely as AI multiplies the blast radius of every overshared folder. You can be the board that quietly passed the mess on. Or the board that finally opened the books. There is no third option anymore, because the AI you are about to deploy will open them for you.
I have seen this movie before
That inheritance is not a theory for me. During the pandemic era I worked as crisis manager ICT and data security at GGD GHOR Nederland, the national umbrella of the Dutch public health services, while the country ran the largest public-health data operation in its history. At the peak we operated what was, in our own words at the time, one of the largest call centres in the world, with tens of thousands of temporary employees testing, tracing and vaccinating.
In February 2021 the media reported that GGD workers had stolen the personal data of millions of Dutch citizens. I was brought in to handle the aftermath end to end: investigation, communication, security. The facts turned out to be more specific than the first headlines suggested. A handful of temporary employees had taken screenshots of personal data, around 1,250 citizens affected, every one of them one too many.
We filed police reports, informed and apologised to every affected person and later came back with a financial gesture. Then we hardened everything: modernised training and a Security Operations Center that flags it when a logged-in employee browses files in a way that makes no sense, with zero tolerance and a police report when the behaviour cannot be explained.
Here is the lesson that never left me
Those systems had been built, as the organisation’s own annual report put it, on the unspoken assumption that most people are decent. Most people are. But that breach did not need a hacker. It needed nothing more than legitimate access and a phone camera. Now replace the phone camera with an AI assistant that reads everything that access allows in seconds, and you understand exactly why this article exists.
A year later, in September 2022, the organisation’s own magazine on information management, Verbinden & Versterken, interviewed me under a title that says it all: first define your dream goals, then design secure information systems to serve them.
Reading that interview back today is uncomfortable in the best possible way. I warned then that we were still carrying “an inheritance of twenty years of bad internet topology”. That IT failing to serve the user is “the biggest design flaw there is”. That if you block WeTransfer without offering an alternative, employees simply push large files through their private webmail and free tools. Replace WeTransfer with ChatGPT in that 2022 sentence and you have, word for word, the shadow AI measurements of 2025. Human behaviour did not change. Only the speed and the blast radius did.
Behaviour
I also argued back then that the real risk of tools like WhatsApp was never the encryption but the behaviour around it, that fragmented data means losing sight of security and that you are only as strong as your weakest link, because we are all in one big digital building. Four years later, every floor of that building is getting an AI assistant that can instantly use whatever keys people already have. And the remedy I proposed in 2022 is the remedy I teach in 2026: goals first, a common language, security and privacy by design and systems that serve people instead of the other way around. That is not hindsight. It is the same sequence, applied to a much bigger wave.
If you sit on the board: five moves this quarter
The good news: this is fixable and faster than you fear. Weeks and months, not years. But the sequence matters more than the speed. And this conversation has three seats at the table, so whoever you are in the organisation, the next three lists include one for you.
- Demand the map before the rollout. Who can access what today and was that ever intended? If nobody can answer, the Copilot decision is premature by definition.
- Measure real behaviour, not policy. Find out which AI tools your people already use and what data flows into them. You cannot govern what you refuse to see.
- Treat the rollout signature as what it is: a risk acceptance. Ask for the risk analysis in writing before you sign, the same way you would for any acquisition.
- Train the foundation, not the buttons. Prompt courses are everywhere, understanding is rare. Teach your people what these systems actually do with data before teaching them shortcuts.
- Fix the sequence: resilience first, then AI. An organisation that cannot survive a ransomware Tuesday has no business wiring an AI into everything on Wednesday.
If you own the Copilot rollout: five questions to put to your board
- Will you sign the risk analysis before you sign the rollout, in that order and in writing?
- If the access-rights map shows red, do I have your mandate to delay the next phase without it costing me my credibility?
- Which budget pays for cleaning up twenty years of permissions? The licence budget does not cover the inheritance.
- Who owns AI risk at this table, by name, and how often do you want me to report on it?
- What is our definition of ready: which criteria, not which date, decide when the next group gets switched on?
If you are an employee: five questions you are allowed to ask
- Which AI tools are we actually allowed to use and where can I read that in plain language?
- If I stumble on a file tomorrow that I was never meant to see, what do you want me to do and is it safe for me to report it?
- What training will I get before Copilot lands on my desktop, beyond a one-hour clicking instruction?
- Whose data am I allowed to put into an AI tool: clients, citizens, colleagues or none of them?
- When delivery pressure and the rules collide, which one do you want me to choose?
Three perspectives, one conversation. If all three start asking this month, the rollout will be better for it.
The sequence underneath all three lists is the same and it is not a slogan, it is how I run my own practice. It is why I deliver the in-house Cyber Resilience Masterclass first, getting the basics, the behaviour and the crisis muscle in place, and only then the RESET! the Workplace with AI Masterclass, built on the P-SEP model (People, Security, Ethics, Privacy), where teams learn to think about AI before they touch the tools. Transformation without foundation becomes chaos. Hype without preparation becomes a crisis. I have stood in enough crisis centres during my career in crisis management, including inside the national public health system in the pandemic era, to know which of the two I prefer.
Back to that sentence in your boardroom
“Our organisation wants to get started with Copilot.” Good. It probably should. AI done well is a genuine competitive advantage and the islands and the Netherlands alike cannot afford to sit it out. But Copilot is not the beginning of the end. Deploying it on top of twenty years of unmanaged access rights might be. The organisations that will win with AI are not the fastest starters. They are the ones who dared to take one step back first, opened the books on their access rights and then moved forward with their eyes open.
You can wait until an incident forces that conversation. Or you can start it yourself, this quarter, on your terms. One of those options you control.
In-house masterclass RESET! the Workplace with AI
From overwhelmed to in control. A strategic, practical and human AI masterclass by Erik Jan Koedijk, author of RESET!, together with co-trainer and AI scientist Jort Koedijk. No technical background required.
AI will transform every workplace, but transformation without foundation becomes chaos. In one engaging in-house session your people stop being overwhelmed by AI and start using it deliberately: safely, ethically and effectively, with the unique P-SEP model (People, Security, Ethics, Privacy) as their compass.

Everyone is already working with AI
Your people are not waiting for permission. They are already experimenting with AI tools, each in their own way, with all the consequences that brings. That makes a shared understanding essential: one common language for what AI can do, where the risks sit and what your organisation does and does not want. And it is often just as much about unlearning as learning, because habits people developed on their own rarely match what is safe and smart for the organisation.
Tailored before we even start
Every masterclass begins with a thorough intake conversation. Together we map how your organisation works, where AI can genuinely save time and which risks deserve attention first. The cases and exercises in the masterclass are then built on your daily reality, not on generic examples. Participants recognise their own work in every exercise. During the session we get hands-on with those use cases and hold each one up to the P-SEP lens before it earns a place in your way of working.
Boardroom experience meets the latest AI science
What happens when you combine deep boardroom experience with the latest academic insights in AI? Erik Jan brings decades of leadership in cybersecurity and digital transformation. Co-trainer Jort Koedijk, (MSc Artificial Intelligence at Utrecht University, NL), brings the newest academic insight and the perspective of generation Z. Strategy and science in one room, translated into what your team can do tomorrow.
You leave with more than inspiration
Together we build an AI assistant in 15 seconds and then create your own, without any coding. You learn what an AI agent is and what it is not, see the risks of agents demonstrated live and discover how to integrate assistants and agents safely into your organisation. And everyone goes home with a ready-to-use prompt pack, one or two concrete actions for their own work, a certificate and a boost of energy.
Included
✅ Intake conversation, so the cases match your organisation
✅ Hands-on with your own use cases, each one tested through the unique P-SEP model
✅ An AI assistant built in 15 seconds, then build your own, no coding needed
✅ What an AI agent is and what it is not, including the risks and safe integration
✅ Ready-to-use prompt pack with practical instructions
✅ One or two concrete actions per participant, a certificate and a boost of energy
✅ Private and in-house, in groups of up to 20 people, applicable for everyone
Our most popular in-house masterclass, consistently rated highly by participants.
Book now: choose your preferred date and request more information.
Starting with AI? First check your foundation
Working with AI only accelerates an organisation whose cybersecurity foundation is in order. And that foundation is about more than technology. Even when your technical security is well arranged, criminals still find a way in through people, via social engineering. That is why this masterclass pairs naturally with the in-house cyber resilience masterclass below: first a solid foundation, then responsible acceleration with AI.
Also available: In-house cyber resilience masterclass
Practical, no jargon and tailored to your organisation. By cyber expert and RESET! author Erik Jan Koedijk, trained by his late friend Kevin Mitnick, the world’s most famous hacker. In Curaçao, The Netherlands, Aruba, Bonaire, Barbados, Sint-Maarten, France, Belgium and the UK 3000+ professionals already joined the masterclasses hosted by Erik Jan.
Cyber resilience is not an IT topic. It is a team skill. In one inspiring four-hour session your people learn how attackers really work, how to recognise manipulation and how to protect the organisation and themselves, at work and at home. No technical background needed.
Tailored before we even start
Every masterclass begins with a thorough intake conversation. Together we map how your organisation communicates, where the human risks sit and what an attacker would try first. The social engineering exercises in the masterclass are then built on your reality, not on generic examples. Your people will recognise the situations, because these could happen tomorrow.
Learned from the master himself
Erik Jan was trained by his late friend Kevin Mitnick, the social engineer who proved that the easiest way into any organisation is through people. Those same techniques are demonstrated live in the masterclass, then turned into practical defences your team can apply the very same day.
You leave with more than awareness
Directly after the masterclass you receive a concrete overview of the processes in your organisation that can be tightened, based on what surfaced during the session. Not a generic checklist, but a starting point for real improvement, ready to discuss with your leadership team.
Included
✅ Intake conversation, so the social engineering exercises match your organisation
✅ Live demo: how freely available online tools reveal which systems expose your organisation, often without anyone knowing
✅ Inspirational knowledge quiz and a certificate for every participant
✅ Direct post-session overview of processes to tighten
✅ Private and in-house, exclusively for your organisation, with up to 20 participants per session
Book now: choose your preferred date and request more information.

