State-sponsored and commercial actors: the two-track threat
The 2026 threat landscape separates into two distinct tracks. State-sponsored operations — primarily attributed to actors from Russia, China, and Iran — target strategic intellectual property, government contractor relationships, and dual-use technology. These operations are patient, well-resourced, and often combine technical surveillance with cultivated insider access built over months or years.
The commercial track is growing faster. Private-sector espionage — competitors hiring former intelligence officers or contracting specialist firms — is being reported at higher frequency across the Benelux and DACH regions. The threshold for commissioning covert intelligence operations has dropped significantly as commercial TSCM tools have become more accessible and cheaper to deploy.
Both tracks increasingly combine physical access (premises infiltration, device implant) with cyber vectors (phishing campaigns targeting executives, firmware compromise of meeting-room hardware). Organisations that treat physical and cyber security as separate disciplines face the largest exposure gaps.
The Netherlands as a high-value target environment
The Netherlands hosts an unusually high concentration of strategic targets relative to its population: ASML, Philips, Shell, ING, and dozens of EU regulatory agencies and diplomatic missions in The Hague make it a priority environment for foreign intelligence services. AIVD (the Dutch General Intelligence and Security Service) has repeatedly flagged the Netherlands as one of Europe's most actively targeted countries for economic espionage.
The Hague's diplomatic quarter — hosting over 150 embassies, consulates, and international organisations including the ICC, Europol, and the OPCW — creates a dense environment where state actors, corporate representatives, and intelligence collectors operate within close physical proximity. Boardroom conversations, legal negotiations, and policy briefings in this zone are subject to active technical collection attempts.
For organisations with operations, legal proceedings, or regulatory engagements in the Netherlands, this threat context is not theoretical — it requires active countermeasures including regular TSCM sweeps, communications hygiene protocols, and personnel security measures for individuals with access to sensitive information.
Indicators of active targeting: what organisations should watch for
Early indicators of corporate espionage targeting are frequently misattributed to technical faults or dismissed as coincidence. Anomalous access patterns on internal networks, unexpected audio feedback in meeting rooms, unfamiliar personnel requesting physical access, and competitive intelligence that appears too precise are all indicators worth escalating to a security review rather than investigating internally.
Human indicators are equally important: approaches by individuals claiming to represent research firms or academic institutions, unusual interest from new contacts in specific project details, and employees who begin demonstrating lifestyle inconsistencies with their compensation are classic recruitment or insider-threat signals. Organisations should have a reporting pathway for these observations that does not require an employee to make a formal accusation before raising concern.
The response protocol for suspected active targeting should begin with a TSCM sweep of the primary meeting and decision-making spaces, a review of physical access logs for the preceding 90 days, and an advisory consultation to assess the breadth of the potential compromise. Acting early — before a confirmed incident — is materially cheaper than post-breach remediation.
TSCM and physical security countermeasures
Technical Surveillance Countermeasures (TSCM) remain the primary active defence against audio and data interception in physical spaces. A professional TSCM sweep uses RF spectrum analysis, non-linear junction detection (NLJD), infrared scanning, and physical inspection to identify listening devices, covert transmitters, and modified infrastructure components. The technology has evolved significantly — sweeps that would have missed GSM-based or frequency-hopping devices five years ago now require more sophisticated detection equipment.
Sweep frequency should match risk exposure. Law firms handling M&A mandates, pharmaceutical companies approaching patent filings, and organisations involved in government contract negotiations should sweep primary meeting spaces quarterly at minimum, and before and after any significant sensitive engagement. Ad-hoc sweeps following a suspected breach or prior to a critical negotiation are standard practice for organisations operating at the highest risk levels.
Physical access control is the complementary layer. Visitor management systems, badge-reader audit logs, and a clear protocol for unescorted access in sensitive zones reduce the window available to physical device implant operations. The combination of active TSCM and tight physical access control provides the most robust defence against both technical and human collection threats.
