CCRC signs Prometheus manifesto: together faster than AI-driven cyber threats

CCRC signs Prometheus manifesto: together faster than AI-driven cyber threats cover

​Today in The Hague, the manifesto 'Samen sneller dan de dreiging' (Together faster than the threat) was presented to Willemijn Aerdts, State Secretary for Digital Economy and Sovereignty. CCRC is one of the signatories. With this, we join Prometheus, a public-private initiative under the banner of Digital Holland that is building a collective digital defence that grows along with AI.

The attacker operates at machine speed

What long seemed a theoretical scenario became reality this summer. In early July, security researchers documented the first fully autonomous ransomware attack: an AI agent that, without human intervention, scouted a target, gained access, stole credentials and encrypted files. When an attempt failed, the agent corrected itself within 31 seconds. Shortly afterwards came attacks targeting AI models and training data, as well as an attack on Hugging Face's infrastructure involving thousands of actions in a single weekend.

As far as publicly known, no victims of fully autonomous AI attacks have yet been reported in the Netherlands. But the Dutch Cyber Security Council already concluded in March that AI enables attackers to operate faster, at greater scale and with less visibility. No organisation can keep up with that pace on its own, simply because no human can match the speed of a machine.

Organisations in vital sectors fall under the new Dutch Cybersecurity Act, but their resilience also depends on the software and services of their suppliers. A single flaw at one supplier can affect hundreds of organisations at once. That is why Prometheus explicitly focuses on the entire chain, all the way down to SMEs.

What Prometheus will do

Twelve frontrunners are taking the lead: TNO, ESET, AISLE, Hadrian, SIG, Northwave, Schuberg Philis, DIVD, NS, NCSC, NCTV and VUSec (VU Amsterdam). A first pilot focuses on AI-driven software security: discovering, validating and fixing vulnerabilities faster. The first step is mapping what organisations need, what the market already offers and where the real gaps are. Only where a collective approach adds value will something new be developed together. The guiding principle is collective where necessary, commercial where possible.

Why CCRC signed

We are proud that CCRC is a co-signatory of this manifesto. We were involved in Prometheus at an early stage and wholeheartedly support the initiative. By signing the manifesto, we express our intention to actively contribute, from our own role, to the further development, testing and scaling of AI-driven digital defence. As an independent advisor, we do not sell security tooling, SOC services or incident response. That is exactly why the market-neutral approach of Prometheus appeals to us: it is about what works, not about who delivers it.

"AI is fundamentally changing the pace of attacks, and no single organisation can keep up with that on its own. What makes Prometheus strong is that industry, government and academia are not just coordinating here, but genuinely building together. We are proud to have been involved from the very beginning. As an independent party, we want to help make sure that what is developed here actually reaches organisations, right down to the smallest links in the chain," says Jelger Groenland, Director at CCRC.

Broadly shared urgency

The manifesto builds on the call that NCTV, NCSC, AIVD, MIVD, the Public Prosecution Service, CIO Rijk and the Dutch Police jointly made to executives yesterday: prioritise cybersecurity now, make resources available and give experts room to act. Prometheus also aligns with the European Action Plan on Cybersecurity and Artificial Intelligence, presented by the European Commission on 7 July, and is known to ENISA.

Want to know more? As of today, the Prometheus website is live via Digital Holland.

Deel dit bericht via: