Wouter Parent of Kynexis Information security was a guest at NCOD Audit on 13 August 2026 to discuss the Dutch Cybersecurity Act, NIS2 and concrete follow-up steps for organisations. The main message: start with the organisation and its risks. From that point of view, appropriate technical, organisational and board-level measures will be followed.
Watch the broadcast
Dutch Cybersecurity Act and NIS2 in practice
Wouter Parent was guest speaker at NCOD Audit on 13 August 2026. The video will only be loaded from YouTube when you choose it.
NIS2 starts with knowing what your organisation is critical of
The Dutch Cybersecurity Act enters into force on 15 August 2026. This will transpose the European NIS2 Directive into national law in the Netherlands. Organisations governed by the law are subject to a registration obligation, reporting obligation, duty of care and explicit board-level responsibility.
An organisation can introduce dozens or hundreds of security measures. The first question should lie with the business management: What processes remain available to allow the organisation to do its job? The RDI states that the duty of care begins with a risk analysis. On this basis, the organisation shall choose measures that reflect its situation.
- determine whether the organisation is covered by the Dutch Cybersecurity Act and whether an essential or important entity is involved
- identify critical business processes
- perform a risk analysis for these processes
- determine the systems, information and suppliers needed
- assess how risks are currently controlled
Start with the question of which processes remain available. Then, picture risks, systems, information, suppliers and current control in coherence.
The Dutch Cybersecurity Act also means governance
A demonstrable NIS2 approach consists of technical, operational and organisational control. The organisation has clear who is responsible for what risk, who may accept a residual risk, what information the board receives and how the functioning of measures is assessed.
Clear roles, responsibilities, contractual agreements and reportings make this control manageable. A RACI model can help to make it clear who is responsible, responsible, advisory or informed. The Board remains ultimately responsible, even when work is delegated to a CISO or IT partner.
A firewall and IT contract are not board-level reporting
Digital dependencies directly affect service provision, turnover, security, privacy and continuity. Therefore, the answer that there is a firewall and a good contract with an IT service provider does not provide a very good insight into the actual control of cyber risks.
Board-level information supports decisions. This requires insight into risks, critical processes, suppliers, measures, residual risks, incidents, recovery capability and progress. This makes information security a regular part of board-level risk management.
- the main digital risks and critical dependencies
- current management measures and residual risk mitigation measures
- incidents, near-incidents, continuity and recovery
- necessary improvement measures, ownership and progress
Make cyber risks understandable to board members
A CISO, security manager or IT manager can know exactly where a technical vulnerability is. For board-level decision-making, you translate that information into the implications for the organisation.
What happens when a production line stops for three weeks, a critical supplier fails or necessary data is not available? Clear language and examples from the company's own business will help board members assess risk performance, prioritise and make resources available.
Mandatory NIS2 board member training: knowledge must be demonstrable
The Dutch Cybersecurity Act makes board-level knowledge demonstrably relevant. Executive board members subject to this obligation should have sufficient knowledge and skills to assess cyber risks and security measures. They shall be given appropriate training and must be able to show a certificate.
According to the current RDI explanation, existing board members must comply with these requirements within two years of the entry into force of the Dutch Cybersecurity Act. New board members will be given two years from their appointment. The RDI clarifies that supervisory directors, supervisory directors and non-executive directors are excluded from this specific obligation. For them, knowledge of digital risks from their supervisory role remains valuable in terms of content.
Risk analysis, NIS2 GAP analysis and improvement plan
When the critical processes, risks and dependencies are known, the question arises as to where the organisation is now in relation to the desired situation. An NIS2 GAP analysis or baseline assessment makes that difference visible.
A good analysis results in more than a list of points of interest. The outcome is translated into a manageable improvement plan with priorities, owners, proof and realistic planning. The key questions are clear: Where are we now, where do we want to stand and how do we get there?
In summary: make NIS2 controlable
The Dutch Cybersecurity Act is ultimately about controlling digital risks that may affect the organisation. Therefore, start with the critical processes, associated threats, systems, information, suppliers and responsibilities.
From there, a logical route to NIS2 advice and implementation is created: To determine scope, analyse risk performance indicators, organise governance, assess current control and improve it step by step. Kynexis Information Security approaches the Dutch Cybersecurity Act as part of professional digital risk management.
Sources and deepening
Based on official frameworks and practical implementation
The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.


