Clean Networks

Clean Networks comprises two pillars: a threat intelligence platform for digital infrastructure providers and a code of conduct through which those providers commit to preventing and actively detecting and removing abuse on their networks.

By 2025, project management had been further professionalised to effectively steer the Clean Networks initiative within an increasingly complex regulatory landscape. The focus was on the structural organisation of work packages, intensive coordination with stakeholders and a fundamental review of content considering NIS2 and the Digital Services Act (DSA). We also actively contributed to national policymaking, such as the exploratory study into tackling ‘bad hosting’ in collaboration with the Ministry of Justice and Security.

Technical implementations

The technical foundations for data analysis have been further developed, with a focus on supporting abuse reports and the methodological development of the sector benchmark. This activity is highly operational in nature, comparable to the abuse follow-up processes, and involves the continuous improvement of existing analytical methodologies. The emphasis was on improving the internal data structure, validating legitimate information sources and setting up scalable reporting architecture. Work was carried out on a Proof of Concept (PoC) for the combination of MISP and AbuseIO. In addition, exploratory steps were taken towards automatic compliance validation, such as checking for references to Acceptable Use Policies (AUPs) and notice-and-takedown procedures in the context of the forthcoming implementation of the Dutch Cybersecurity Act. This act is the Dutch implementation of the European NIS2 Directive.

Clean Networks has continued to develop as an operational platform for abuse follow-up, fulfilling its role as a strategic information hub. As part of the NBIP’s CSIRT working method, reports concerning vulnerabilities, abuse and breaches of code of conduct and notice-and-take-down obligations were received, assessed and, where necessary, forwarded to participants. In parallel, work was carried out to improve the reporting structure, validation logic and reporting formats. Informal checks were also carried out on references to abuse policies, AUPs and NTD procedures.

In addition, the abuse follow-up has been linked to work on the new codes of conduct and preparatory actions towards automated compliance validation. The reporting structure was strengthened as an integral part of Clean Networks as a coordinating platform for abuse response within the Netherlands.

Market positioning

Over the past year, we have continued to invest in positioning Clean Networks within the Dutch and European markets. We have actively participated in industry events, including CloudFest, the Anti-Abuse Network, meetings organised by the Dutch Cloud Community (DCC), ATKM coordination, and the working groups on bad hosting and trusted notifiers. Partnerships have been established with, amongst others, Connect2Trust, SIDN, VvR, DCC and TU Delft. Clean Networks has also contributed to drawing up the blueprint for the Cyber Resilience Network, specifically within the ‘Information Sharing’ function.

Furthermore, the duration of the Clean Networks project has been extended until 31 December 2027. This was necessary due to the delayed initial grant award and the time required to recruit specialist staff. Preparations have also begun for the publication of Code of Conduct 3.0, the benchmarking process with TU Delft and the technical foundation of the Clean Networks platform. These steps mark the transition to an implementation phase in 2026 and 2027.


The Clean Networks initiative has been made possible thanks to a grant from the European Union and grants from the Digital Trust Centre and the SIDN Fund.

Figures Clean Networks 2025

Clean Networks provides information about security vulnerabilities and abuse to digital infrastructure providers. These alerts are tailored to individual participants who have subscribed to Clean Networks’ threat intelligence feed, enabling them to take targeted action.

In 2025, we shared 18,553 notifications relating to a total of 287,007 IP addresses. In 2024, there were 8,367 notifications relating to a total of 254,132 IP addresses.

Top 10 Threat Types 2025 (measured in number of notifications)

1
NTP-version
0
2
Open-RDP
0
3
SSL-Poodle
0
4
Vulnerable-HTTP
0
5
Sinkhole-HTTP
0
6
Accessible-MSRPC
0
7
Open-Postgres
0
8
Sinkhole
0
9
DNS-Open-Resolver
0
10
PHP-Info
0
1
Event sinkhole HTTP
0
2
Vulnerable exchange server
0
3
CERT Bund malware
0
4
Open DNS
0
5
Open SDDP
0
6
Open SNMP
0
7
Exchange version vulnerability
0
8
NTP version vulnerability
0
9
FortiGate plugin vulnerability
0
10
Open LDAP TCP
0