Technical audit · 2026-06-16

ncsc.nl

Website of the Dutch National Cyber Security Centre

Ncsc.nl is the website of the Dutch National Cyber Security Centre. Homepage scan: 42 requests, 4 domains. The configuration is exemplary, which is particularly fitting for a cybersecurity center. There are two external services, both restrained: the government's centralized web-statistics platform, Piwik PRO, running in anonymized mode, and self-hosted error monitoring. The scan shows no Google Analytics, no Facebook, no advertising, no session recording, and no third-party commercial trackers. Not a single cookie was set during the session. The policy explicitly states that consent is not requested for the statistics, since it falls under an exemption in the telecommunications law. No violations were recorded.

Timeline of the leak

1020 ms · error monitoring
Self-hosted error monitoring fires — a technical tool tracking failures on the site's own infrastructure.
1384 ms · government web statistics
The government's centralized web-statistics platform loads, built on Piwik PRO in anonymized mode.
1770 ms · pageview sent
The statistics tool sends pageview data without parameters tied to a visitor identifier, consistent with anonymized mode.
statistics anonymized, no cookie set
The statistics tool is configured anonymously and, per the explicit statement of the policy, is exempt from consent. Not a single cookie was set during the session.

Declared versus actual

Piwik (statistics) — заявлен
Error monitoring — заявлен

Detected trackers

Context

www.ncsc.nl is the website of the Dutch National Cyber Security Centre (Nationaal Cyber Security Centrum): threat warnings, security recommendations, incident response. The data controller is NCSC, a government organization. The site is informational.

Scan: 42 requests to 4 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The technical stack is minimal.

Who receives the data

There are no third-party commercial recipients.

There are two external services, both restrained: the government’s centralized web-statistics platform, built on Piwik PRO in anonymized mode, and self-hosted error monitoring — a technical tool for tracking failures. The scan shows no Google Analytics, no advertising networks, no social media pixels, and no session recording.

A full banner for the statistics is not required here: it is configured anonymously. The policy explicitly states that consent is not requested for these cookies, since they fall under the telecommunications law’s exemption for privacy-friendly statistics. Not a single cookie was set during the entire session.

Only anonymized statistics and technical monitoring. Before any interaction, the government’s centralized, anonymized statistics and self-hosted error monitoring fire. The scan contains no Google analytics, no advertising domains, no social plugins, and no session recording.

Conclusion

Ncsc.nl is a model of a restrained configuration, well suited to the nature of a cybersecurity center. There are two external services: the government’s anonymized web statistics and self-hosted error monitoring. There is no third-party advertising, no Google analytics, no social media pixels, and no session recording whatsoever, and no cookies are set. The key takeaway for the reader: a cybersecurity center can manage with anonymized government statistics and its own monitoring alone, and here that is achieved without a single third-party commercial tracker, with the exemption of the statistics explicitly confirmed by the policy. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/ncsc-nl-2026-06-16.har
SHA-256: 82baf9c9d77e1854ece473cd42078a17f9ab3d04d37240deff760c428cb48064
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.