A boardroom session for two care-related organisations with sensitive client information, digital ambitions and growing AI risks.
Organisations
Two closely cooperating civil society organisations support vulnerable clients and their representatives in the youth care and care sector. They perform an independent trust function and work with sensitive client, case and management information.
The reason
There were several initiatives around client-oriented digital support, a client portal, Microsoft Copilot, transcription, an AI knowledge bank, an internal AI agent and links with communication channels.
Which digital and AI risks are we willing to accept, which do not and what information do governance and oversight need to decide on responsibly?
The contract
Kynexis Information Security was asked to prepare and provide a boardroom session on information security, AI, NIS2, NEN 7510, ISO 27001, governance, board-level decision making and risk readiness.
Preparation by documentation review
The review showed that digitisation was being seriously addressed. Positively visible were strategic information plans, project holders, existing information security policies, MFA, secure mailing, device management, home working, supplier agreements and sector-specific support.
The main development issues
Insufficient evidence
The documentation showed limited evidence of how measures were tested, how they were found to work, who followed up on deviations and when residual risks were formally accepted.
No full cyber risk analysis
Measures and development points were identified, but no full analysis with assets, threats, vulnerabilities, opportunity, impact, residual risk, owner and treatment plan.
No explicit GAP analysis on standards frameworks
The organisations referred to NEN 7510, ISO 27001 and governance codes, but without an overview of what was demonstrable and what requirements were still missing.
Roles and ownership
The ownership of information security, AI governance, incident response, supplier management and continuity was not sufficiently sharp.
The AI case
A specific incident involving automated transcription provided a recognisable starting point. The broader questions concerned permitted AI applications, data use, human oversight, source quality, DPIAs, suppliers and decision-making.
Coherence of standards
- Governance code Care: board-level framework for quality, safety, role purity and accountability.
- NEN 7510: relevant where personal health information and healthcare related processes are displayed.
- ISO 27001: An ISMS framework for structure, ownership, risk management and demonstrability.
- NIS2 and Dutch Cybersecurity Act: relevant for risk management, board member responsibility, chain security and continuity.
- Governance code Social Work 2025: Additional connecting points for digital transformation, cybersecurity, data and AI.
The board-level risk dialogue
The discussion was about crown jewels, maximum acceptable outages, sensitive client information, critical suppliers, risk acceptance, project prioritisation and the information needs of the Supervisory Board.
The role of the Supervisory Board
The Supervisory Board was given a practical framework of what it should want to know, ask and test: Top priorities, chain dependencies, accepted residual risks, incident escalation, periodic reports, budget choices, functional separation and follow-up of findings.
Post session advice
- conduct a cyber risk management session;
- launch a GAP analysis on standard and governance frameworks;
- prioritize digitalisation initiatives on the basis of risk;
- explicitly define AI governance;
- formalise ownership and RACI;
- set up periodic board-level reporting;
- assess supplier and supply-chain risks demonstrably.
The result
- an independent picture of the documentation;
- a governance-specific explanation of NEN 7510 and ISO 27001;
- an board-level explanation of NIS2;
- a broader approach to AI governance;
- a targeted risk dialogue with the Board and the Supervisory Board;
- concrete questions for oversight;
- direction for the strategic information plan.
Why this approach worked
The session was based on concrete plans, documents and incidents. AI, information security, privacy, suppliers, digitisation and governance were treated as one coherent governance issue.
Also a boardroom session about AI and information security?
- Information security in healthcare
- AI governance and AI risks
- NEN 7510 and ISO 27001
- NIS2 and the Dutch Cybersecurity Act
- Digital resilience and risk appetite


