Skip to content
    All briefs
    Daily Brief

    9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    GeopoliticsNATO

    NATO activates enhanced forward posture in Baltic states following Russia's confirmed sabotage of undersea cables

    NATO Secretary General confirmed on 8 July that Alliance intelligence has attributed the severing of two Baltic Sea undersea communication cables — connecting Finland and Sweden to Germany — to Russian naval assets operating under plausible deniability cover. In response, NATO has activated an enhanced forward presence in Estonia, Latvia, and Lithuania, deploying additional rapid-reaction forces and air defence assets. The incident marks the third confirmed infrastructure attack in Baltic waters since January 2026 and reinforces growing Alliance consensus that hybrid operations targeting critical infrastructure are now a permanent feature of the pre-conflict threat environment. Corporate and governmental organisations with assets or personnel in the Baltic region are advised to review continuity plans and communications resilience.

    Mission Support's advisory and intelligence team provides threat assessments for organisations operating in high-risk regions.

    CyberENISA

    Iranian-linked cyber group targets European energy firms with destructive wiper malware

    Threat intelligence firm Recorded Future and the European Union Agency for Cybersecurity (ENISA) jointly published an advisory on 8 July warning of a coordinated campaign by the Iranian-nexus group tracked as 'Void Manticore' targeting energy infrastructure operators across the Netherlands, Germany, and France. The campaign deploys a previously undocumented wiper malware strain — ERASEDFIELD — which overwrites industrial control system configurations following initial access gained through spear-phishing of OT administrators. Unlike financially motivated ransomware, the campaign's primary objective appears to be operational disruption rather than financial extortion, consistent with Iranian state-directed sabotage posture. Affected organisations are urged to audit remote access credentials, segment OT networks, and treat any anomalous ICS configuration changes as a potential indicator of compromise.

    Mission Support's cyber defence team supports OT security assessments and incident response for critical infrastructure operators.

    TrainingReuters

    G7 security ministers agree joint framework for protecting executives travelling to conflict-adjacent regions

    G7 interior and security ministers meeting in Rome on 7–8 July agreed a joint framework for coordinating protective intelligence sharing when nationals of member states travel to conflict-adjacent regions including the Middle East, the Sahel, and Eastern Europe's border zones. The framework, which is non-binding but expected to inform bilateral agreements, establishes minimum standards for pre-travel threat briefings, real-time intelligence sharing between national security services when a national is assessed at elevated risk, and standardised HEAT training certification recognition across G7 jurisdictions. For organisations with international operations, the agreement signals that governments are increasingly formalising the expectation that employers conduct structured risk assessments before authorising executive travel to elevated-risk environments.

    Mission Support delivers HEAT training programmes and travel risk assessments for organisations operating internationally.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    ComplianceEURACTIV

    European Commission proposes mandatory cyber incident disclosure within 24 hours for critical infrastructure operators

    The European Commission published a draft amendment to the NIS2 Directive on 8 July that would reduce the mandatory initial incident notification window for essential entities from 72 to 24 hours, and introduce a new category of 'significant incidents' requiring simultaneous notification to ENISA, national competent authorities, and — where disruption affects cross-border services — authorities in affected neighbouring member states. The proposal also introduces personal liability provisions for chief information security officers (CISOs) and board-level executives in cases of gross negligence, a measure that goes materially further than the original NIS2 text. The amendment is expected to enter trilogue negotiations in Q4 2026, with implementation likely requiring an additional 18 months following final adoption.

    Mission Support supports NIS2 compliance gap assessments and incident response preparedness for EU-regulated organisations.

    Europol disrupts pan-European surveillance-for-hire network operating covert device implants

    Europol's European Cybercrime Centre coordinated simultaneous arrests in seven EU member states on 8 July, dismantling a commercial surveillance network that sold physical device implantation services to corporate clients — enabling covert recording of boardroom meetings, interception of executive communications, and real-time location tracking of targets. The operation, codenamed SILENT ROOM, identified 34 implanted devices across offices in Brussels, Amsterdam, Frankfurt, and Zurich, including one active implant in a law firm advising on a major M&A transaction. The network charged between €15,000 and €80,000 per engagement and operated through a chain of shell companies in Cyprus and Luxembourg. The operation highlights the continued viability of physical surveillance technology as an intelligence collection method against corporate targets — a threat that TSCM countermeasures are specifically designed to detect.

    Mission Support delivers professional TSCM sweeps to detect covert surveillance devices in corporate and diplomatic environments.

    GeopoliticsEUobserver

    EU foreign ministers agree expanded sanctions package targeting Wagner successor networks in Sahel

    EU foreign ministers meeting in Brussels on 8 July agreed an expanded sanctions regime targeting fourteen individuals and six entities assessed as operating as successors to the Wagner Group's Sahel operations — now rebranded under the Russian Africa Corps — following their involvement in documented atrocities in Mali, Burkina Faso, and Niger. The sanctions include asset freezes, travel bans, and — for the first time in an EU sanctions package of this type — restrictions on the ability of sanctioned entities to contract with EU-registered businesses for security services. For European companies with operations in West Africa, the measures add compliance obligations for any contracted security or logistics provider, requiring enhanced due diligence to confirm the absence of sanctioned entity involvement in subcontracting chains.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    NCSC-NL issues critical advisory following ENISA alert — Dutch energy sector OT systems actively targeted

    The National Cyber Security Centre Netherlands issued an urgent advisory on 9 July corroborating ENISA's warning about the 'Void Manticore' campaign, confirming that at least two Dutch energy sector organisations have been identified as targets of the ERASEDFIELD wiper campaign. The NCSC-NL advises all operators of industrial control systems in the energy, water, and chemical sectors to immediately implement offline backups of OT configurations, enforce multi-factor authentication on all remote access pathways, and review third-party vendor access credentials. Organisations without in-house OT security capability are urged to engage specialist support immediately rather than waiting for incident confirmation — the wiper's destructive payload is designed to maximise recovery time and operational disruption.

    Mission Support's cyber defence team provides OT security assessment and incident response support for Dutch critical infrastructure operators.

    IntelligenceNOS

    Dutch parliament approves expansion of AIVD investigative powers — covert access to encrypted communications platforms authorised

    The Dutch Tweede Kamer passed the amended Intelligence and Security Services Act on 8 July by a margin of 89–61, granting the AIVD and MIVD expanded authority to conduct targeted interception of communications on end-to-end encrypted platforms — including Signal, Telegram, and ProtonMail — under a strengthened judicial oversight mechanism. The legislation, which takes effect 1 September 2026, also expands the agencies' ability to conduct covert physical access operations against targets assessed as posing a national security threat, and introduces a new category of 'critical sector companies' whose internal communications may be monitored if assessed as a national security risk. Privacy advocates have filed an immediate challenge before the Council of State. For corporate security practitioners, the legislation serves as a reminder that OPSEC discipline — including the use of security-hardened communications infrastructure — remains relevant even when operating in the Netherlands' relatively permissive regulatory environment.

    Mission Support's advisory team provides OPSEC assessments and communications security reviews for corporate and governmental clients.

    Physical SecurityNRC

    Rotterdam Port Authority activates elevated security protocol after threat intelligence indicates cargo fraud operation

    Rotterdam Port Authority confirmed on 9 July that it has activated its elevated security protocol across container terminal zones following credible threat intelligence indicating an active cargo fraud and physical infiltration operation targeting pharmaceutical and electronics shipments. The intelligence — assessed as originating from a Dutch-Belgian organised crime network with established links to drug smuggling infrastructure — involves the placement of insiders in cargo handling positions to redirect high-value shipments. The port has deployed additional plainclothes security personnel, increased access control verification cycles, and is cooperating with the FIOD and Koninklijke Marechaussee on an active investigation. Supply chain managers with shipments transiting Rotterdam in the coming weeks are advised to implement enhanced cargo tracking and verify the chain of custody on outbound consignments.

    Mission Support provides secure logistics support and supply chain security assessments for organisations with critical cargo requirements.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation