Is TU/e prepared for a disaster?

Without power, a digital emergency plan is useless

Floods, power outages, or a cyberattack: in times of climate change and geopolitical tensions, such crisis situations are no longer unthinkable. Behind the scenes, TU/e is preparing for all kinds of scenarios to prevent an incident from turning into a disaster. Read along with a fictional case: a campus flood.

In the event of a major flood, the power may go out: after all, electricity and water are not a good combination. This has potentially major consequences for the functioning of TU/e. Employees and students may not know what their days will look like then, but the university ​​appears to be prepared for all kinds of scenarios.

It has become increasingly ‘normal’ to prepare for emergencies, for example with an emergency kit. Fortunately, most of us have not yet experienced real crisis situations. However, that could change due to more extreme weather, rising geopolitical tensions, and the increasingly far-reaching consequences of cybercrime. TU/e, too, must prepare for potential crises such as a flood, power outage, a hack, or a terrorist attack.

Perfect storm

In this article, Cursor sketches a fictional scenario where several of these scenarios converge. After all, when chaos erupts due to an emergency, that is the perfect moment for criminals to strike—the perfect storm. 

Is TU/e up to the challenge? Should you, as an employee, come to your workplace in such a situation, or not? And where can you find the latest information if the systems stop working due to a power outage?

To inform stakeholders, TU/e ​​has used the website, intranet, and email during previous crises so far. However, if that is no longer possible, or if the crisis has a regional impact, there is Omroep Brabant as the official disaster and emergency broadcaster.

In the event of an emergency, that broadcaster provides direct instructions and updates from the government and emergency services. For this reason, it is recommended to have an emergency radio powered by solar energy or batteries at home. In Southeast Brabant, you can find the Omroep Brabant radio station on 87.6 FM. 

Fictional

Warning: the italicized parts in this story are fictional scenarios, intended to highlight vulnerabilities that an organization like TU/e could have. They are meant to give the reader an idea of ​​what kind of situations the university considers regarding scenario-based crisis training. The question here is not whether such a situation will ever arise, but how the organization is prepared for it.


Short circuits

Flash forward to January 31, 2030. A series of cloudbursts over Eindhoven causes sudden floods that seem to appear out of nowhere. Meteorologists cannot foresee this at a very local level. 

The Dommel, which was already at a high level, bursts its banks, and within half an hour, water flows over the campus. The basements of MetaForum, the Nanolab, Atlas, and Auditorium fill up in no time.

Electrical installations on the ground floor and lower levels fail. Cleanrooms and labs must evacuate immediately and are now anything but ‘clean’. The water cannot be contained and reaches server rooms, resulting in short circuits and inaccessible data. Emergency pumps prove no match for the force of nature.


The result? Chaos. And it is precisely this kind of chaos that the TU/e’s central crisis team trains for. They work with planning and scenarios to prepare for potential disasters.

A completely flooded campus or a major power outage that paralyzes the campus might sound like a distant prospect, but good preparation can indeed limit the damage. This became clear during the hack on the TU/e’s systems in January 2025.

Thanks to the decisive action of an employee, the network was quickly shut down, preventing more serious damage from the hackers. Since then, the university has started investing more in its crisis organization. The central crisis plan has been tightened and more people have been trained to deal with potential incidents.

The TU/e ​​has a central crisis team, but it only comes into effect when there is an organization-wide crisis. At that moment, all decision-making authority also rests with that team, enabling rapid action in a crisis. Members of that team are Head of Security & Strategic Domain Lead  RISC Gijs Spiele and Integrated Security Policy Advisor Rick Krosenbrink.


Opportunity

Back to that dark January day. While the rising water drives everyone off campus, Rowan T. sits in his student room reading through his final preparations. He has dreamed of a career as a hacker for years and is convinced he can make a good living from TU/e's valuable data.

This flood is the opportunity he has been waiting for. The weather warning for heavy rain had already sent his mind racing, but he had never dared to dream of this combination of local cloudbursts over the campus and the subsequent power outage. This chaos is what he needs.

When the campus floods, there is less supervision: access cards do not work, doors are left open for emergency procedures, security is spread across multiple incidents, and emergency responders are busy performing evacuations.

That means free rein. At least, that is what T. thinks. However, the university appears to be aware too of how a disruptive disaster can have consequences for other important organizational processes, and of the risk of a domino effect.


Experience

TU/e has already gained considerable experience with small and large crises. Think of the hack in January 2025, the data leak at campus card supplier ID-Ware in 2022, the flooding in Gemini in 2025, and the Canvas hack in May of this year. Gijs Spiele, looks back with pride on the handling of that last incident.

“When we heard that floor -1 was flooded, everyone rushed over. Even directors were out mopping. It characterizes how people here often do more than is strictly included in their roles. The commitment to our university is great.”

Integrated Security Policy Advisor Rick Krosenbrink was pleased to see that the TU/e’s building management systems and fire detection continued to function as intended during the hack and flooding in 2025.

“That is how it should be, but of course, it is always nerve-wracking when there is a real crisis.” Krosenbrink should know, with the experience he gained in the military during hurricanes, floods, and wartime situations. 

Access passes

Regarding the temporary malfunction of (digital) systems and the associated risks, Spiele has measures in place. “If we see that the access passes are no longer working, the crisis team can immediately take a control measure for that. This happened, for example, at Utrecht University, due to a fire in a data center where the university’s systems were hosted.”

“Temporarily closing buildings or locations is then the last resort to immediately stop the risk. Additionally, you can look at manual checks to facilitate the primary process again.”


Power

Due to the flooding, the power has gone out campus-wide, and it is not expected to be working again quickly. However, the firewalls that T. had expected to fail are still running, because the system hosting has backups. TU/e ​​is not disclosing exactly where for security reasons, but there is a backup, including for the firewalls.


Crisis or not?

Within crisis management, all scenarios are conceivable. It is precisely those things that the average employee or student does not want to think about, that the crisis team must prepare for.

Flooding, such as the recent incident in Gemini, is not a crisis in crisis management jargon, but an incident: something we can handle within regular operations, Krosenbrink notes. “A crisis transcends that. A situation becomes a crisis when it is, or could become, organizationally disruptive.”

TU/e does everything it can to prevent an incident from becoming a crisis. It does not declare a crisis lightly, given the organizational consequences.

“That really does have an impact on the standing organization, you have to free people up from their regular positions, decisions are made through alternative channels, and the associated measures have a huge influence on the community,” Krosenbrink sums up. “You only want to do that if there is no other option.”

Spiele reflects on the COVID-19 period. “That was the ultimate example of this at TU/e. At the same time, it also taught us a great deal about how to adapt to unexpected events. Resilience and adaptability are key.”

Canvas

A recent example of an incident that turned into a crisis was the Canvas hack. “That was initially handled as a cyber incident,” Spiele recalls. “We continued to discuss developments daily and, in doing so, assess whether we needed to escalate. Ultimately, we did proceed to do so. The decisive factor was indications that the situation could have consequences for the primary process: providing education.”

It was also unclear how long it would last, another characteristic of a crisis: uncertainty regarding impact and duration. “Then the central crisis team convened, and we coordinated daily with the six other universities that also use Canvas.”

Krosenbrink: “You are constantly engaged in horizon scanning. What is coming your way, and what is the likelihood that it will impact the primary process? Because we have many experienced people on the team, making that assessment is becoming increasingly easier.”


On his way

Rowan T. strides towards the university. No mask, no hoodie; no cinematic hacker aesthetic. Just someone with a wet coat, a backpack, and a neutral expression. Someone you won't notice when you yourself are standing ankle-deep in water.

He knows that due to the emergency procedure, doors will be left open. He can leave his pass at home. What he is taking with him, however, is a USB drive containing malware that he will place in the Nanolab, the place where knowledge is acquired that can generate a lot of money in Asia.

It is the kind of knowledge in which Eindhoven is at the forefront, and certainly the TU/e. Knowledge that also makes the region vulnerable to malicious actors. T. envisions a golden future for himself, thanks to the virus he carries with him, which will spread via TU/e ​​partners in the Brainport region. 

Given the close collaboration between education, government, and business, T. considers it a realistic chance that he can steal a large amount of knowledge all at once in this way, to subsequently blackmail the university.

It turns out he is not the only one with this idea. TU/e ​​has also considered it. After all, the strength of chain collaboration within Brainport also comes with risks: it only takes one partner to have an unsecured system for you to infect each other with such a virus. 

However, TU/e ​​has invested so much in its own systems that it will be impossible for T. to get his virus into the systems of major partners.


Exercise

Every two years, TU/e ​​participates in OZON, a sector-wide cyber crisis exercise. The next one is scheduled for the spring of 2027. But training also takes place throughout the year. There is an exercise calendar, and everyone has to tick their boxes annually, Krosenbrink notes.

“It is important that someone can act effectively under time pressure. Because that is one of the characteristics of a crisis: time pressure, alongside uncertainty and threat.” All ingredients that also reappear in the campus flood scenario.

The crisis plans themselves are not shared with Cursor for security reasons. Spiele and Krosenbrink do indicate, however, that these are widely available, both digitally and physically, so that a plan is always in place, even in the event of a power outage. “The main goal of the crisis approach is to keep the primary process running: education, research, and valorization.”


Inside

Rowan T. follows a group of employees walking into the Nanolab through an emergency door wedged open. No one asks him anything. No one has the time or attention to concern themselves with who is or is not authorized to enter the building. He walks into a study room where laptops are still open, left behind in haste during the evacuation.

Around him, he notices mainly stress and panic. Mobile networks are overloaded with panic calls and messages. Eduroam, 4G/5G, landlines: everything went down very quickly. But it doesnt bother T. He has prepared for this down to the last detail, and he doesnt need those connections.

When the power comes back on after hours, something happens that occurs in many organizations: systems start up uncontrollably, and security software comes online later than the rest. Rowan T. knows that. The small software program he wrote specifically for this moment, contains code that attacks immediately when the systems start up again.


Calling

There is now more attention being paid to crisis scenarios than in the past. The nature of the risks has also changed, for example due to espionage and the risk of knowledge leakage. The likelihood of domino effects, such as in this scenario by Rowan T., has also increased.

Although much is done digitally, TU/e ​​must certainly look beyond online measures when preparing for a crisis. After all, if the power goes out, communication systems (Wi-Fi, internet) will eventually fail as well.

How do you know what to do or who to call then? “We still have blue binders, building cards, and call lists as a backup,” says Krosenbrink. “And we also have access to external systems if our system is down. You should never put all your eggs in one basket.”

But what if you want to coordinate internally and the phone stops working? “We also have two-way radios,” says Spiele. “Our fire department, security, and the Rapid Response Team are already using them.”

A tender is currently underway for a new two-way radio system. “Once that is finalized, the crisis team may also start using walkie-talkies. In addition, we are working on a crisis app, a communication system where members of the crisis organization can check the latest status in real time, so that everyone has the same picture.”

Spiele is aware that such an app will not work in the event of an internet or power outage. “Dual systems and emergency power supplies are important in this regard. We are prepared for all kinds of scenarios with visible and invisible measures to keep the TU/e ​​safe.”


Arrest team

Malicious actors expect IT teams to focus first on the direct physical damage of a crisis, not on cyber risks. T. hopes for this too, but ultimately it does not come to that. His communication with other hackers online did not go unnoticed by the police either. Even the smartest criminals make mistakes.

When T. leaves the Nanolab to depart quietly, an arrest team is standing by to apprehend him. The USB stick is taken along as evidence, and the mopping of the university buildings can begin.


This article was translated using AI-assisted tools and reviewed by an editor.

Share this article