Highlighted event Workshop: Shift Your UEMS into High Gear More info
Highlighted event Workshop: Shift Your UEMS into High Gear More info
Highlighted event Workshop: Shift Your UEMS into High Gear More info
Highlighted event Workshop: Shift Your UEMS into High Gear More info

NIS2 & Dutch Cybersecurity Act: Who Is Responsible?

The Dutch Cybersecurity Act is now in force. Do you know who is responsible for what? Find out what has changed for each role.

The Dutch Cybersecurity Act (Cyberbeveiligingswet, or Cbw) has been in force since 15 August 2026. This means the European NIS2 Directive has now been implemented into Dutch law. More than 8,000 organisations in the Netherlands are subject to new requirements aimed at strengthening their digital resilience.

This has consequences for IT and security, but certainly not just for them. The Dutch Cybersecurity Act explicitly places responsibilities at board level and requires organisations to manage cyber risks on an ongoing basis. From the board and CISO to IT managers and administrators, different roles across the organisation are involved.

So who is responsible for what? And perhaps more importantly: how do you make sure that policy, technology and day-to-day operations are aligned?

What changes with the Dutch Cybersecurity Act?

The Dutch Cybersecurity Act applies to essential and important entities across 18 sectors, including government, energy, transport, healthcare, digital infrastructure and ICT service management.

Organisations that fall within the scope of the Act are subject to requirements including registration, a duty of care and incident reporting. Significant incidents must be reported within the applicable timeframes. Organisations must also take appropriate and proportionate measures to manage risks to their network and information systems and to prevent or minimise the impact of incidents.

The exact measures required will therefore differ from one organisation to another. A hospital faces different risks from an IT service provider. The principle, however, remains the same: understand your risks, take appropriate measures and verify that those measures actually work in practice.

The board: cybersecurity cannot simply be delegated to IT

An important part of the Dutch Cybersecurity Act is the role of the board. Board members must approve the measures taken to meet the duty of care and oversee their implementation. They are also subject to training requirements, ensuring they have sufficient knowledge to assess cyber risks and the measures taken to address them.

This does not mean every board member needs to become a security specialist. It does mean the board needs to understand the risks the organisation faces and the decisions being made to mitigate them.

This requires answers to questions such as:

  • What are our most important cyber risks?
  • What measures have we taken to address them?
  • Where do gaps still exist?
  • Who is responsible for addressing those gaps?
  • How do we know that our measures actually work?

A report that simply states that MFA, endpoint security and patch management are in place does not provide enough insight. The board needs to be able to assess the organisation's actual security position.

The CISO or Security Manager: does reality match the policy?

For the CISO or Security Manager, one of the main challenges lies in the gap between policy and practice.

You may, for example, have a policy stating that accounts with elevated privileges require additional protection. But are all privileged accounts known? Is MFA actually enforced? Are permissions adjusted when someone changes roles? And are accounts that are no longer required removed in time?

The same applies to other areas of security. Having a vulnerability management process is one thing. Knowing how many critical vulnerabilities remain open, why they are still open and how quickly they are being resolved is another.

The role of security therefore goes beyond creating policies. There also needs to be visibility into how those policies are implemented and whether the measures are effective.

The CIO and IT Manager: turning policy into practice

While the CISO defines the framework and monitors risks, the IT organisation has to make many of those measures work in practice.

This touches almost every part of the IT environment. Think of identity and access management, endpoint management and security, vulnerability management, monitoring, logging, backup and recovery, and incident detection.

This is also where a false sense of security can easily arise. Simply purchasing a solution does not mean the underlying risk has been addressed.

Take patch management. Are all endpoints visible? Are critical patches actually deployed on time? Are there systems that fall outside standard management processes?

Or take identity. Which accounts have administrative privileges? When were those privileges last used? Is strong authentication enabled everywhere it needs to be?

For CIOs and IT managers, the challenge is therefore not just having the right tools, but maintaining control over the environment.

IT operations: where policy becomes reality

For IT administrators, much of what the Dutch Cybersecurity Act requires will sound familiar.

Endpoints need to be updated. Vulnerabilities need to be resolved. Accounts and permissions need to be managed. Logs need to be available. Anomalies need to be investigated, and backups should not only exist but also work when they are actually needed.

The difference is that these activities now form part of a broader risk management process. It is not enough for something to be done; the organisation also needs visibility into what is being done and whether it is sufficient.

That requires oversight. What assets do we have? Which are centrally managed? Where do critical vulnerabilities remain open? Which systems deviate from policy? Where have risks been accepted, and why?

This makes effective IT management an important part of an organisation's demonstrable digital resilience.

And what about employees?

Employees are also part of the organisation's security. The duty of care under the Dutch Cybersecurity Act covers areas including basic cyber hygiene, access control, personnel security and training.

This goes beyond watching an awareness video once a year. Employees need to know how to use systems and information securely, how to recognise phishing and other suspicious activity, and where to report a potential incident.

Technology can reduce many risks, but not every risk starts or ends at a firewall or endpoint.

What does the duty of care mean in practice?

The Dutch Cybersecurity Act identifies ten areas that organisations must at least address as part of their duty of care. Risk analysis forms the foundation.

These areas include incident handling, business continuity, supply chain security, cyber hygiene and training, access control, asset management, authentication and assessing the effectiveness of security measures.

That last point is important. Implementing a measure once and then considering it finished is not enough.

An organisation needs to know whether a measure is still appropriate and whether it continues to do what it is supposed to do in practice.

From policies on paper to control in practice

The Dutch Cybersecurity Act does not simply call for more security tools. For many organisations, the first improvements can be found in making better use of what is already there.

Start with visibility.

Where are the gaps?

Identify where policy and practice do not align. This could include endpoints that are not centrally managed, critical vulnerabilities that remain open for too long, accounts with unnecessary privileges or security settings that have not been applied consistently across the environment.

Which gaps have priority?

Not every issue has the same impact. A forgotten administrative account on a critical system requires a different level of priority from a configuration deviation on a low-risk system.

Assessing risk helps IT and security teams determine where their time and resources should be focused first.

Can you demonstrate that you are in control?

Resolving an issue is not the end of the process. Can you see whether measures remain active? Are deviations detected? Is it clear which risks remain unresolved? And can you report on this to security teams and the board?

This is where technology, security and governance ultimately come together.

Cybersecurity is not the responsibility of a single department

With the Dutch Cybersecurity Act now in force, it is clearer than ever that digital resilience cannot simply be left to IT or the CISO.

The board must approve measures and oversee their implementation. Security teams need to translate risks into policy and verify that measures are effective. The IT organisation needs to make those policies technically achievable. IT administrators ensure that many of those measures are actually applied every day.

The question, therefore, is not simply whether you have enough security measures in place.

Do you know where the risks and gaps in your environment are, are they being addressed systematically, and can you demonstrate that you have them under control?

That is what digital resilience ultimately comes down to in practice.

Where does your organisation stand?

CBA helps organisations identify and reduce security gaps. This includes identity and privileged access, endpoint management and security, vulnerability management, monitoring and incident detection.

Want to know where the most important areas for improvement are within your IT environment? Contact us. We will be happy to take a closer look with you.

Nieuwsbrief

Sign up for our newsletter

Stay updated with our latest products and offers by subscribing to our newsletter