The ANVS online portal malfunction has been solved. This means the portal is open for use once again. Previously, it had been unavailable since last Friday. This was the result of precautionary measures we had to make in response to certain Citrix vulnerabilities (in Dutch). We took these measures in order to protect the data of portal users and to protect our systems.
Tests and implementation
After rigorous testing, we have implemented security updates developed by Citrix. This solves the vulnerabilities in their software.
Further investigation
Currently, we are looking into the possible consequences the Citrix vulnerabilities may have had for our systems and – most importantly – the data of our portal users. At the moment there is no indication of any incidents. But if it becomes clear there were, we will let affected parties know and we will report our findings to the Autoriteit Persoonsgegevens, the Dutch data protection authority.
The ANVS stands for transparency and accountability. Which is why – in case of incidents, such as data theft – we will publish a statement on our website.
Furthermore, we will evaluate our response to this particular situation in order to improve business and service practices.