The takeover was blocked and the danger gone. Or so I thought. Until I pulled at one loose thread.
The headline I almost mistook for an ending
On 26 May 2026 I read the headline. The Dutch government had blocked the takeover of Solvinity, the supplier of the infrastructure that DigiD runs on, by the American IT company Kyndryl. To protect the public interest. For readers outside the Netherlands: DigiD is the national digital identity system, the login Dutch citizens use for taxes, healthcare and almost every other government service. I felt what most people felt: relief. Good, sorted.
And then I almost moved on.
That is exactly the moment this piece is about. Because the word ‘blocked’ feels like a full stop. A headline suggests the matter is closed. And most people never read past the headline. I caught myself almost doing the same. Until I looked closer. And the problem turned out to be bigger than the headline suggested.
Three lines, one bigger problem
The ban solves one problem: this takeover will not go ahead. But the more important question is whether the dependency disappears with it. The honest answer: not really. DigiD remains the property of the Dutch state and is directed by Logius, the government agency that runs it. Solvinity only manages the infrastructure DigiD runs on and cannot take independent decisions about it. So the dependency does not sit in who owns DigiD but in the parties that keep the service technically running.
The first line: wasn’t the company already foreign? Correct. Solvinity has been owned by the British investment fund Vitruvian Partners since 2014. An analysis on iBestuur, a Dutch platform on digital government, calls the ‘Dutch ownership’ at the 2020 contract award a legal shell: Dutch on paper, economically and strategically already British.
The second line: so is the British route closed? Not necessarily, argued privacy lawyer Jeroen Terstegge. Even through the British owner, the United States could in theory already reach the data. Although that would be a narrow route for serious criminal investigations, not a licence to secretly read everything. He himself calls it a loose end that someone still needs to investigate.
The third line: this is where the problem grows. Solvinity is not only involved in DigiD. Dutch parliamentary documents show that MijnOverheid, the portal where citizens receive official government messages, also runs on the infrastructure platform Solvinity manages. Digipoort (the data gateway between businesses and government) and the Berichtenbox message service also recur in documents about that same Logius infrastructure and the migration towards it. Parliamentary questions additionally brought services for the justice system and the CJIB, the central agency that collects fines, into view. Every line makes it clearer that the problem is bigger than DigiD alone.
More than 17 million users with one key
Put that next to the scale. DigiD has more than 17 million users and was used more than 646 million times to log in during 2025. Behind that number sits something concrete: it is the key a citizen uses to file a tax return, arrange healthcare and check a pension. If that key falters, no ‘system’ stands still. A person stands in front of a closed door at the tax office or the hospital. As my co-author Arko van Brakel and I wrote in our book Help! Mijn chatbot wil opslag: you can only give your data away once and after that it is gone, strategically, legally and practically.
An important nuance belongs here. Logius stresses that DigiD only passes on the BSN, the Dutch national identification number, that this happens encrypted and that Solvinity cannot simply access it. That nuance deserves its place. And the ban did achieve something: it removed the immediate American ownership risk and brought the visible risk profile back to the existing British ownership structure. But it is not the end of the discussion. Because the question is not about one technical packet of data. The question is about control. That distinction was made, again and again, by Pieter van Oordt, the privacy officer who sounded the alarm.
The deal is off the table. The dependency is not.
Power
Power does not travel only through a server location or a single data request. It also travels through ownership, jurisdiction, management rights, updates, support, staff, contracts and the question of how quickly you can leave when things go wrong. A foreign server is about where your data sits. A foreign owner is about who, over time, has influence over the controls. And a supplier you cannot quickly walk away from is no longer a supplier but a strategic dependency. That is what digital sovereignty means.
The real decision, moving the management to a Dutch or European party, only comes around 2028. You may feel relieved. You are not finished.
And none of this is new. Experts have been warning for years about the digital stranglehold governments find themselves in. Yet that debate, strikingly, is mostly about the United States, about American clouds and American laws. The British owner of Solvinity received far less public attention. In practice, ‘sovereign’ has too often come to mean ‘not American’. And precisely because of that, another foreign owner can slip through the checks too easily while everyone watches the American takeover being turned away.
The civil servant who kept asking the question
One element stands out and it is not technical. It is People, the first element of P-SEP, the lens I use for cases like this: People, Security, Ethics, Privacy.
Because the difference is not in the ban, it is in the curiosity. The leader who clicks on in relief at ‘blocked’ is exactly the leader who will be caught off guard later. Not because they are ignorant, but because they mistook a headline for a conclusion. Curiosity here is not a personality trait, it is a discipline: asking the second and the third question when everyone else has already moved on. In the book we call that slowing down to speed up.
And there is a second human being in this story. Pieter van Oordt warned internally, got nowhere, went public and was suspended and eventually dismissed. A member of the Dutch parliament called him a whistleblower who showed courage. The uncomfortable question for any leader is not whether someone like that was right. The question is: what do you do with the employee who looks past the headline? Do you reward curiosity or calm?
There is a privacy layer underneath as well. Regulators point out that remote management from outside the EU by a separate party can qualify as a transfer of personal data under European privacy law, so ‘the data sits in the Netherlands’ is not automatically the end of the discussion. But the main question here is human, not technical.
Four questions for your own supply chain
These are not IT questions. They are boardroom questions that happen to be about IT. Four to ask today:
- Who is the ultimate owner of our critical suppliers and which legal system do they fall under? Not the name in the business register, the party behind it.
- Which of our vital services hang on one and the same supplier at the same time?
- Can someone in another country reach our systems remotely for management or support and what does that mean legally?
- And the most important one: who in our organisation keeps looking when the headline says ‘solved’ and how do we treat that person?
And the next door is already open
While everyone looked in relief at the blocked takeover, I read about DigiD’s intended successor: NL Wallet, the government’s digital identity app. An investigation by Follow the Money, a Dutch platform for investigative journalism, shows that in its current form the app leans on software from Apple and Google. Anyone without an account at one of those two American tech giants cannot use it. All this while the current DigiD app has worked on phones without Google since 2023.
Read that again. We said a loud no to one American owner of DigiD and at the same time we are building a new dependency on American tech into its successor. The front door locked, the back door wide open. The ministry says it is ‘studying’ the dependency and stresses that the app is voluntary. But parliament is now asking questions and experts point to exactly the pattern of this piece: we solve the visible incident and miss the structure underneath.
That is not a coincidence. That is the habit. And that is exactly why, after every reassurance, you have to keep asking, again and again: is the problem really gone, or only the news about it?
Through the P-SEP lens
People: the most important signals often come from people who keep asking uncomfortable questions. Whoever waves that curiosity away risks cutting the wire of their own alarm bell.
Security: know who can reach your systems remotely from outside and under which jurisdiction that falls, because the reassurance that the servers are on home soil says nothing about who is allowed at the controls.
Ethics: be open about what you do and do not know about your own dependencies. Presenting a ban or a press release as an endpoint is often more comfortable than honestly admitting that the underlying problem has not gone away.
Privacy: map which sensitive data sits with which supplier and who can reach it, because ‘it has always gone fine’ is not a retention period and not an access policy.
In your organisation: make supplier ownership and jurisdiction a standing item in the boardroom instead of a footnote in procurement, so that supply-chain risk becomes a leadership choice and not something the IT department quietly handles on the side.
Getting the basics right: an up-to-date overview of your critical suppliers, their real owners and the jurisdiction they fall under, plus one person with the authority to keep asking.
You may feel relieved. You are not finished.
Finally
The lesson is the same for suppliers, AI tools and digital identity: people need to understand what they are connecting, who controls it and what happens when trust is misplaced. Everyone in your organisation is already experimenting with AI. So are your suppliers. So are your partners. And cybercriminals know it and make use of it. That is why my co-author Arko van Brakel and I developed an inspiring and activating talk: working safely with AI as a colleague. Want to turn this duo talk into a complete experience? Order the tailored edition of the book with it, with your logo on the cover, your own foreword and your AI policy as chapter zero. Your people go home with inspiration and a guide that matches the talk exactly. When you order the books, you also receive up to 20 per cent off the duo talk.
In-house cyber resilience masterclass
Practical, no jargon and tailored to your organisation. By cyber expert and RESET! author Erik Jan Koedijk, trained by his late friend Kevin Mitnick, the world’s most famous hacker. In Curaçao, The Netherlands, Aruba, Bonaire, Barbados, Sint-Maarten, France, Belgium and the UK 3000+ professionals already joined the masterclasses hosted by Erik Jan.
Cyber resilience is not an IT topic. It is a team skill. In one inspiring four-hour session your people learn how attackers really work, how to recognise manipulation and how to protect the organisation and themselves, at work and at home. No technical background needed.
Tailored before we even start
Every masterclass begins with a thorough intake conversation. Together we map how your organisation communicates, where the human risks sit and what an attacker would try first. The social engineering exercises in the masterclass are then built on your reality, not on generic examples. Your people will recognise the situations, because these could happen tomorrow.
Learned from the master himself
Erik Jan was trained by his late friend Kevin Mitnick, the social engineer who proved that the easiest way into any organisation is through people. Those same techniques are demonstrated live in the masterclass, then turned into practical defences your team can apply the very same day.
You leave with more than awareness
Directly after the masterclass you receive a concrete overview of the processes in your organisation that can be tightened, based on what surfaced during the session. Not a generic checklist, but a starting point for real improvement, ready to discuss with your leadership team.
Included
✅ Intake conversation, so the social engineering exercises match your organisation
✅ Live demo: how freely available online tools reveal which systems expose your organisation, often without anyone knowing
✅ Inspirational knowledge quiz and a certificate for every participant
✅ Direct post-session overview of processes to tighten
✅ Private and in-house, exclusively for your organisation, with up to 20 participants per session
Book now: choose your preferred date and request more information.

