What Ter Laak Orchios learnt from a phishing attack

Our sector is facing cyber incidents with increasing frequency. It's hardly a question of if you'll be affected, but when. For example, Ter Laak Orchios was hit by a phishing attack this spring, which, fortunately, was nipped in the bud fairly quickly.

Floris Kloeg, IT specialist at Ter Laak Orchios, received a message from a colleague at a quarter past six in the morning on Wednesday 8 April 2026. He had received an email from a member of staff at Riza Growers, the growers' collective of which Ter Laak Orchios is a part. The sender's name, email address and layout were all fine. Even so, Floris's colleague thought: something isn't quite right. "He never has any contact with that member of staff. The content of the email was also vague," says Floris. And indeed: it wasn't right. It was a case of business email compromise: an attack in which criminals use a hacked account to try to deceive others. There was no targeted cyberattack on the horticultural sector as a whole, but the entire sector could easily have been affected. This results in economic and reputational damage for growers, buyers and the entire sector. Floris shares five tips on cybersecurity.

Tip 1: Set up two-factor verification

Two-factor authentication (2FA) is mandatory at Ter Laak Orchios. With 2FA, you can verify a user's identity using multiple independent forms of proof. For example, a password combined with a passkey, code, token, fingerprint or facial scan. Floris: "Think of it as an extra barrier, in case cybercriminals have breached the first one." It is also important to set out what steps need to be taken if they do manage to breach all the barriers. And to establish clear agreements with the IT partner and other suppliers who have access to the systems.

Tip 2: Train your staff

Ter Laak Orchios trains staff in cyber security awareness. Floris: "We regularly send fake phishing emails. The idea is that colleagues should forward emails to me. I also give internal presentations. Additionally, we show short videos about cybersecurity on the digital screens in the canteen. I am very pleased that my colleagues are taking this issue so seriously."

Tip 3: Stop, check, report

Royal FloraHolland uses the 'Stop-check-report' principle to help growers and buyers deal with suspicious situations. Does anything feel a bit off? Stop what you're doing, check it again and report what you see. Floris: "The sooner you report a suspicious situation, the better. Partly thanks to the prompt reporting, we were able to minimise the damage. For ourselves and the sector."

Tip 4: Use common sense

Even if you've got everything sorted, you could still fall victim, says Floris. "It can happen to anyone. We're all human beings. Don't feel embarrassed if you've clicked on a link or if hackers have got into your system. Phishing emails used to be full of spelling mistakes and come from a strange email address. Partly thanks to AI, they are becoming increasingly realistic. It's important to use your common sense and intuition. Bear in mind: in what context is this email being sent? And does that make sense?"

Tip 5: Collaboration makes all the difference

"Certainly when it comes to cyber security, we are not competitors, but colleagues. We need to work together to protect the sector," says Floris. This can be done directly, or via Royal FloraHolland. "Great opportunities to exchange information with other companies," says Floris. Ter Laak Orchios also has Royal FloraHolland's free Cyber Subscription, which is available exclusively to members. "We receive threat intelligence specific to the sector and can take part in webinars. That is incredibly valuable and helps to make the floriculture sector cyber-resilient."