Compliance is not the same as security.
You can check every box and still be vulnerable.
I talk about the gap, and what it takes to close it.
"De CISO die niet met de board praat, zit op de verkeerde plek. Het gesprek moet gaan over risico, niet over regels."Justin Post, Cyberweerbaar Nederland 2026
Running a NOC, SOC, and CSIRT under one roof sounds efficient. In practice it surfaces every gap in your processes, tooling, and culture. A practitioner-level account of what goes wrong at scale, and what to fix first.
Most Dutch organisations treat NIS2 as a compliance target. That is the wrong frame. Resilience requires intent, not checkbox completion. Drawing on the Cyberweerbaar Nederland 2026 research and what it reveals about the gap between compliance and actual readiness.
Complex attacks do not respect organisational boundaries. SOC-NL connects monitoring capabilities across the Dutch security ecosystem. The what, the why, and what it means for your organisation's threat posture, from the person who built and presented the initiative.
Designing, operating, and evolving MSSP capabilities across SOC, NOC, CSIRT, and Identity. What the org chart does not tell you about how these teams need to work together.
NIS2, DORA, ISO 27001: regulations set a floor. Resilience is what you build beyond it. How to stop optimising for audits and start optimising for survival.
Not the hype version. Practical application of AI in detection, triage, and response workflows. What is working in production today, and where the real limits are.
Building and leading technical security teams. Accountability structures, board communication, org design. The things they do not teach in CISSP prep.
Je kunt alle hokjes afvinken en toch kwetsbaar zijn. De vraag is niet: voldoen we aan de eisen? Maar: zijn we ook echt weerbaar?
For Cyberweerbaar Nederland 2026 I interviewed ten security professionals. Three things kept surfacing, and I use them in every presentation I give.
Complex attacks do not respect organisational boundaries. Here is the case for a connected security ecosystem over isolated operations.
| 2026 | KPN NLSecure[ID], 10th Edition |
SOC-NL: Strengthening the Dutch Digital Ecosystem | NBC Nieuwegein, NL |
| 2026 | Cyberweerbaar Nederland 2026 |
Host & Interviewer for 10 Security Leaders | Podcast series, NL |
| 2025 | KPN Healthcare Security Webcast |
Digital Resilience in Healthcare | Online, NL |
| 2025 | Z-CERT Incident Response Partnership |
Critical Infrastructure Cyber Response | Netherlands |
Justin Post is Director of Networking & Security Services at KPN, where he leads one of the Netherlands' largest managed security portfolios. His remit spans Identity, Network Security, Critical Communications, and a combined NOC/SOC/CSIRT operation serving hundreds of Dutch enterprises and critical infrastructure organisations.
Before KPN, Justin spent nearly a decade at Accenture leading Identity & Access Management and Privileged Access Management practices across the Netherlands, Belgium, France, and EMEA. He built and led security consulting teams in Dutch financial services, including DORA compliance work at ABN AMRO.
He was the host and interviewer for the Cyberweerbaar Nederland 2026 podcast series: ten conversations with the Netherlands' leading security professionals. He speaks at industry events on the intersection of managed security operations, digital resilience, and the gap between regulatory compliance and real security.
Based in Weesp. Available for keynotes, panel discussions, podcasts, and workshops in Dutch and English.
Available for keynotes, panel discussions, podcasts, and roundtables. Primarily Dutch and European events, with select international engagements. Talks in Dutch and English.
Response within 48 hours.
Speaker kit available on request: bio, headshot, talk abstracts, and technical requirements.