Your firewall, VPN server and router are the front door to your network. And that front door is set to come under attack more often. That is the expectation of the Dutch intelligence services AIVD and MIVD, which on 7 October published a security advisory on so-called edge devices together with the NCSC. The message is not new, but it is sharper than before: the services expect attacks through these devices to increase considerably over the coming years.
What is going on
Edge devices sit at the boundary of your network: the firewall, remote access VPN for staff working from home, the router and any portals reachable from the internet. According to the AIVD, Chinese hackers in particular know these devices extremely well. They study Western hardware and software in detail and sometimes even have access to the source code. That lets them find weaknesses before the manufacturer does. AI also helps attackers find and exploit flaws faster.
This is not only about espionage against governments and large enterprises. Dutch organisations have already been breached through such devices, and other criminal groups use the same route. A compromised firewall is often the first step in a ransomware attack.
What this means for your organisation
The NCSC puts it plainly: almost every organisation connected to the internet has at least one edge device. That includes a twenty-person business. If you do not know which devices those are, you do not know which doors are open. Sometimes a device is even exposed to the internet by accident, such as an old router or a management page that was once opened up temporarily.
The services raise a second point: after an incident, usable logs are often missing. Logging is switched off, kept only briefly or stored solely on the device itself. An attacker who has taken over the device can simply wipe those traces. Afterwards it is then almost impossible to establish what happened and which data was accessed.
What you can do now
- Make a list. Which firewalls, VPN servers, routers and portals do you have, which are reachable from the internet, and which data and systems sit behind them?
- Include them in your patching policy. Install security updates for these devices as quickly as possible, and agree in advance how to handle a brief interruption while patching.
- Build several layers. Two-factor authentication on VPN and management access, no management interfaces open to the internet, and a segmented network so an intruder cannot reach everything at once.
- Keep logs centrally. Send logs to a separate, protected location and retain them long enough to investigate an incident.
- Plan for the worst case. The services say not every attack can be prevented. Agree who does what during an incident, and practise it.
What Qteco does for clients
For clients with managed networks, we keep central oversight of firewalls and VPN access: we know which devices are in place, which firmware they run and which management ports are open. We schedule and carry out security updates, with two-factor authentication on management and VPN access as a standard. Following this advisory, we are checking for our clients whether any devices are unintentionally reachable from the internet and whether logs are kept long enough and away from the device itself.
Not sure which doors are open in your organisation? Book a conversation with one of our engineers and we will map it out together.
Sources
- MIVD en AIVD verwachten toename Chinese cyberaanvallen via edge devices — AIVD (2026-10-07)
- Cyberadvies Edge devices structureel doelwit van Chinese cyberactoren — AIVD (2026-10-07)
- Veiligheidsdiensten verwachten toename Chinese cyberaanvallen — NCSC (2026-10-07)
- AIVD waarschuwt voor Chinese cyberaanvallen op vpn-servers en firewalls — Security.nl (2026-10-07)
Read also
NCSC warns: critical WordPress flaw actively exploited
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
