
Episode #11
# Practice for the worst — Kelvin Rorive Live from CybersecNL — Episode 2 of 7
Recorded at the Atos booth, CybersecNL 2026. Kelvin Rorive is CISO at ICT Group and runs the Cyber Chain Resilience Consortium (CCRC), which prepares organisations and their suppliers to handle a crisis together. Hosted by Menno van der Horst with Quint Ketting. ## Timestamps 00:00 Day one, and nobody is quite awake yet 01:12 Kelvin: CISO at ICT Group, and what CCRC does 02:05 Why this conference feels like a family reunion 03:09 The message at the booth: practice for the worst 03:34 Survivability — a word picked up from a Ukrainian speaker 04:03 Weerbaarheid, veerkracht, and a telco under drone attack 05:25 Fine for the top 10. What about everyone below? 06:09 "My IT manager will handle it" — and why he won't 07:00 Quint: I talk about business risk, not about cyber 08:31 Crisis in the chain: rehearse it with your supplier present 10:08 Exercises spill over into day-to-day cooperation 10:28 The factory that has to stop because the trucks don't come 12:02 One organisation escalates 1-2-3. The other runs it in reverse. 13:23 CEOs walking out of the room with a list 13:44 Putting the CEO in the hot seat, and not letting them delegate 15:11 What not to do: questionnaire bombardment, and AI filling them in 15:47 Know the CISOs of your critical suppliers personally 16:21 The security family, and why you don't abuse it 18:14 FI-ISAC: competitors around one table, one shared goal 19:41 Compliance is not security 20:11 An APT campaign where every control was green 20:42 NIS2, and whether Europe adapts fast enough 22:11 The balance is shifting from prevention to resilience 22:40 The most important word is not cyber. It is resilience. ## Key takeaways - Survivability sits one level beyond resilience. It starts from the assumption that everything can be broken: people, buildings, data, networks. - A cyber crisis gets handed to the IT manager and then escalates into a chain crisis long before anyone at board level notices. - A crisis exercise only tests the chain if your critical supplier is in the room. Mismatched escalation ladders, unclear responsibilities and missing contacts surface in minutes. - Supplier questionnaires are close to worthless now. They are answered by AI, approved unread, and can be manipulated with instructions hidden in the document. - What works instead is a real relationship with the CISOs of your critical suppliers, used sparingly enough that a call means something. - Compliance is the floor, not the ceiling. Green controls and a long-running intrusion coexist comfortably. - Preventive measures still matter, but the centre of gravity has moved to resilience. Assume something gets through and train the goalkeeper. ## Mentioned Cyber Chain Resilience Consortium — https://ccrc.nl ICT Group — https://ict.eu FI-ISAC, the financial sector information sharing community CybersecNL 2026 — https://www.cybersecnl.nl ## Also in this series Ramsés Gallego on speed and governance — out now. Martin de Vries on sector differences — publishing 24 September. --- SecurityCafe. Powered by Atos.





