Infographic titled “Business Continuity Plan (BCP)” with the subtitle “Prepare. Continue. Recover.” It explains why BCP matters: minimising impact, staying resilient, protecting trust and meeting ISO 27001 requirements. The infographic shows a five-step BCP lifecycle: understand, plan, prepare, respond and recover. It also highlights key BCP elements such as business impact analysis, roles and responsibilities, dependencies and resources, data and backup strategy, communication planning, and testing and training. The final section connects BCP to an Assume Breach approach, focusing on compromised systems, immutable backups, verified recovery and secure recovery environments, leading to stronger resilience, lower impact, faster detection, secure recovery and reduced costs.

Assume Breach: Why Business Continuity Planning Must Be Than a Document

Introduction In the first post of this series, I introduced the Assume Breach principle. I also highlighted three areas that often need more attention: Business Continuity Planning, Data Loss Prevention and Cryptography. This post focuses on Business Continuity Planning (BCP). Many organisations have a continuity plan on paper. They may have a policy, a list of key systems and a recovery plan. But documents alone do not keep a business running. The plan must work during a real crisis. ...

25 July 2026 · 4 min · 845 words · Arnold
Network Diagram of connected networks between HomeLAB and RoadLAB and the VPN tunnel.

RoadLAB & HomeLAB Connected

A couple of years ago I created a IPSec tunnel betweem my RoadLAB and HomeLAB so I could access my home network and use my home as a my breakout online. In effect I was home. However it turned out to be a fragile setup. More often then not did it not really work. I never got the traffic from my Apple TV to go really go through the tunnel. We want to use the Delta TV Apple TV app also from our remote location. Using the iPad app works, when using the tvOS app, it complains that it needs to be on the Delta network. Annoying and this has to be solvable. ...

24 July 2026 · 4 min · 817 words · Arnold
Image depicting the flow from BCP, DLP & Cryptography through the ISO 27001 alignment into the result: Reduced impact, faster detection & response and greater operational resilience

Assume Breach: Strengthening Security with BCP and DLP

Introduction In the past year, I have performed numerous internal audits. Across many of these audits, I observed a recurring pattern: three important security domains are often either limited in scope or insufficiently implemented: Business Continuity Planning Data Loss Prevention Cryptography In most cases, an initial effort has been made. However, the actual coverage, maturity and operational effectiveness of these implementations are often lacking. In my view, these controls do not always receive the level of attention and organisational weight they deserve. ...

25 May 2026 · 4 min · 823 words · Arnold

Leaving CAN

A little over a year ago I started at CAN in the role of Senior Consultant Information Security. The role demands a lot of travel and gives me the chance to visit many different organizations, where I can help identify gaps in ISO 27001, ISO 9001 and NEN 7510 compliance, when performing internal audit. I also helped some organization in implementing an ISMS according to ISO 27001. Reflection In the past couple of months I have reflected on whether the role is the right fit and what I want to do for a living. ...

20 May 2026 · 2 min · 351 words · Arnold

Coming to terms with the diagnoses of autism (ASD)

As some of you know, a couple of years ago our son was diagnosed with Autism Spectrum Disorder (ASD). During this process the characteristics of autism triggered a sense of recognition, not just regarding my son, but also for myself. We talked about this topic for a very long time and I have started the process, mid 2022, of diagnosing if I also might have ASD. Due to the long waiting list in (mental) healthcare and the specialized nature of diagnosing ASD in adults in the Netherlands the process started in April 2023, with the formal diagnoses Summer 2023. First the general practitioner transferred me for diagnoses of ADD or ADHD. For me that did not resonate well. It took some convincing and finding the right organization for me to get a transferral to them. ...

17 November 2025 · 8 min · 1646 words · Arnold

Starting at CertificeringsAdvies Nederland

Although I joined Trustforce (in May of 2024) with the best intentions and high expectations, it became clear over the course of the year that the position was not the right fit for me. The nature of the projects and roles in outsourcing did not align with my professional interests and long-term goals. While I greatly appreciated the welcoming and supportive team environment, we mutually agreed that it was in the best interest of both parties to end the collaboration. ...

21 July 2025 · 3 min · 513 words · Arnold

Adding another certificate: CCSP

Another year and a another certificate to pursue. This time round a addition to my CISSP certificate, trying to achieve CCSP. According to ISC2 a nice combination that is in demand. This are my experiences and opinions. Course & Preparation In preparation I bought the set of books earlier this year. Just to get a feel of the course material. And lo and behold, it is, a bit expected, quite similar to CISSP, a nice overlap in domains and it seems slightly easier. The type of questions and chosen language is the same. This is quite tough. ...

24 July 2024 · 3 min · 528 words · Arnold

Upgrading Home Router (again)

Upgrading the platform Last December I bought a mini PC, a Intel N100 CPU with 6 LAN ports. The other router did not really perform anymore and it was time to upgrade. Although I ordered the device without RAM and storage, the order was received with 16GB of RAM and a 256GB NVME SSD installed. Nice gift. I had ordered a 16GB DDR5 and another SSD. So what to do with the extra SSD? ...

26 May 2024 · 11 min · 2153 words · Arnold

Securing HomeLab with Private PKI

Running applications on TrueNas Scale All of the application that run on the TrueNas Scale, run default unencrypted. When accessing it just from the same network and if you control access to that network, it is a reduced risk. Nevertheless I prefer the communication to and from services to be encrypted. It fits in the layered security and defense in depth strategies. Creating the PKI When creating the Public Key Infrastructure (PKI) there are different solutions. Digicert has a nice series of white papers on what it is and how to use. However the scalable solution is a bit overkill for just one server with a load of services to secure. ...

19 May 2024 · 8 min · 1609 words · Arnold

Opportunities in life

Sometimes a opportunity presents itself and I would be stupid not to jump on it and change direction once more. In the last year I have learned a lot, from the effort it took to achieve my CISSP status to the uncertainties that being a freelancer brings and also I learned a lot on what I like and do not like. Downsides I encountered Let me start with the downsides, trying to get any assignment is tough. There are a lot of recruiters out there, they all claim to have the best opportunity for me. However a lot of times the role does not fit into my skill set at all. The requirements for the role are not even close to my skill set or are not for a role I am looking for. Next the majority claims to want to have a personal connection with the candidate. Like they are my best friend. Sadly I am the product they have to sell. And with ghosting me when the opportunity does not move forward is more and more the “norm”, if this is how one treats it’s “friends”, damn what is the world changing into? The, for me, common decency to call back or give a response should be the norm, not the exception. ...

1 May 2024 · 4 min · 645 words · Arnold