
How do you handle a cyberattack? The process and our key takeaways.
Azure cost compass
op onze IT-scans
From the Golden Path principle and our core values, we want to be transparent about our successes and our failures. This is something we also convey to our clients during workshops and implementations. Our starting point is that we are never 100% secure, but that based on the Golden Path principles, we know what to do the moment something goes wrong. We have a process for that as well, and everyone takes their responsibility in it.
The misery that is a cyberattack
It is safe to call it a nightmare. As an IT organization, you naturally want to avoid any contact with a cyberattack. You have your processes and security in order. Or so you think. You might use external suppliers, and how long has it been since you performed an internal check on your processes, business rules, and data management?
Homerun announced via RTLnieuws yesterday that a criminal was able to access hundreds of thousands of resumes after hacking the job application platform. You can read more about it here . Two weeks ago, a hacker gained access to Homerun's database. We were informed that our applicants' data may also have been accessed.
Homerun CEO Willem van Roosmalen told RTL Nieuws: "These are difficult choices, but we did not want to take any risk that the data would be published somewhere. The interests of our clients and their candidates come first." The Dutch Data Protection Authority (AP) has been notified, vulnerabilities in the server have been fixed, systems have been updated and reinstalled, and together with Northwave, Homerun is currently working hard on further communication.
The leaking of where you have applied and how can certainly have a negative impact, for example with your current colleagues, employer, or on your career. We are all aware of that, which is why no one has been sitting still. And neither have we. At TeamValue, we have also performed a number of checks, and we will continue to do so to keep your personal data secure.
Monitoring the data security process
A GDPR Data Processing Agreement. We have those with external suppliers. However, we have to hold ourselves accountable here, because we relied too much on the supplier to ensure that the retention policies we activated were also applied automatically. Some candidates should have already been removed from the system. That is why we offer a big sorry from us to you. After it was announced on October 29th that a data breach had occurred, we also immediately notified the Dutch Data Protection Authority. Because organizations that use Homerun are required to inform (former) applicants about the hack, but also because it is our moral duty and we feel responsible for the security of your data, we are informing you about the potential consequences this may have for you.
The data of candidates that may have been compromised? Name, email address, phone number, date of application and date of follow-up appointments, the vacancy applied for, and the conclusion of interviews. Action required, therefore! What have we done so far?
- After Homerun's notification, we consulted with a fellow Homerun user in the region, ConnectingTheDots, and decided to take action
- Immediately afterward, during Friday evening dinner, we determined the impact and looked at the short-term actions we needed to take. In doing so, we applied the four-eyes principle ourselves
- We have filed a report with the Dutch Data Protection Authority
- As a precaution, we have changed all passwords
- A track record of actions has been created according to our own monitoring and management system at Bizure
- We asked Homerun for a report on what was (potentially) included in the data breach
- Immediate cleanup of our files containing residual data from (former) applicants
- All contacts who were in our system before October 26 (the moment of the cyberattack) have received a message from us
This is what we call teamwork from management, HR, marketing, and our CTO.
The importance of internal audits
This just goes to show how important it is to have your internal audits in order. In this specific case, it means that we have limited the storage of personal data to a minimum. How?
- Since we started using Homerun, we haven't been asking for CVs. We do this to practice data minimization, but also because we believe in character over skills, so we prefer to just have a personal conversation with you
- Only those with HR responsibilities within our company have access to the recruitment system
- Homerun is a secure platform, but we relied too much on its security and did not perform sufficient audits on it.
- Interview notes in our own systems, appointments in Outlook, and occasionally CVs that are emailed. These are detected and deleted from our mailboxes by our staff once the procedures are completed.
- Based on this attack, we have increased our frequency. Instead of an annual check, we now conduct an internal audit every quarter, which also includes our external suppliers.
We want to say A big sorry to those who received a message from us, and we hope that everyone learns from this case and takes appropriate measures. Because even if you have most things in order, you can still become a victim of a cyberattack, and this involves personal data.
Do you have any questions? Please contact Xander Kuiper at [email protected]
Scanpakket: Azure cost compass
1 juli t/m 30 september
Frequently asked questions (FAQ)
Fancy a chat?
Do you have a question, or would you like to know what we can do for your organization? Feel free to get in touch with us. We’re happy to help!

