NIS2 (Cbw) is often underestimated. This can turn out to be costly for organisations.

Cyber Risk Services

By: Arno Kroese

Imagine this: on Monday morning, employees log in, but none of the systems work anymore. Production environments have come to a standstill, email is unavailable, and customer data is inaccessible. The same message appears on all screens: your data has been encrypted. At the same time, executives receive a message from cybercriminals threatening to disclose confidential business data, customer information, and contracts unless a significant amount in cryptocurrency is paid within a few days.
Contents

For many organisations, the likelihood of this happening seems low. Yet daily news reports show that ransomware attacks, data theft, and disruptions of critical IT systems are no longer rare exceptions. Financial damage can run into millions of euros, while reputational harm and loss of customer trust often have even greater consequences.

To mitigate these risks, the European Union introduced the Network and Information Security Directive 2 (NIS2 Directive), which has been transposed into Dutch law as the Cybersecurity Act (Cbw).

Many organisations still regard NIS2 and the Cbw as a cybersecurity project, but NIS2 and the Cbw affect technology, processes, suppliers, employees, and executives alike. This makes cyber resilience a topic that directly impacts the continuity of the organisation.

The preparations required to comply with the Cbw cannot be achieved in just a few months. So now is the time to take action.

What is NIS2 (Cbw)?

NIS2 (Network and Information Security Directive 2) is the successor to the original NIS Directive of 2016. The European Commission concluded that the level of cyber resilience among organisations and member states varied greatly and that existing legislation did not sufficiently address the rapidly evolving threat landscape.

With NIS2, the European Union aims to achieve a higher and uniform level of cybersecurity across all member states. The directive came into effect at the European level on 16 January 2023. Member states were required to transpose the directive into national legislation by 17 October 2024.

In the Netherlands, this is being done through the Cybersecurity Act (Cbw), which replaces the previous Network and Information Systems Security Act (Wbni). Although the full Dutch implementation has experienced some delays, this does not change the fact that organisations face risks and must improve their cyber resilience in accordance with legal requirements.

NIS2 not only introduces additional security measures but also places greater responsibility on executives and management. Organisations must demonstrate that they manage risks, report incidents in good time, safeguard business continuity, and manage risks within their supply chain.

Cbw for cyber resilience and compliance

Notably, many organisations only start taking cyber resilience seriously because the Cbw requires them to do so. This makes compliance the driver for investments in cyber resilience.

In reality, it should be the other way around. Cybercriminals are not concerned with whether an organisation is compliant with the Cbw. They target organisations whose security is inadequate, where processes have not been tested, or dependencies are not properly managed. Moreover, vulnerabilities within a single organisation increasingly affect the entire chain. As a result, organisations are judged not only on their own security but also on the risks they pose to customers and suppliers.

The real objective should therefore not be to become compliant with the Cbw. The goal should be to effectively identify cyber risks, manage them, and minimise the impact of incidents. The Cbw provides a useful framework for this, with compliance as the result of mature risk management and an adequate security approach.

Organisations that focus solely on legislation risk creating a paper reality. Organisations that focus on risk management genuinely build cyber resilience.

How do I make my organisation truly resilient?

Cyber resilience is about much more than technology alone. The most successful organisations invest in a combination of the following factors:

  1. Knowledge, risk insight, and responsibilities of the board
    Cybersecurity is not an exclusive responsibility of the IT department. Executives and senior management must understand the main cyber risks, set priorities, and allocate adequate resources.
  2. Risk-based resilience
    Not all systems and processes are equally critical. Organisations need to identify their crown jewels: the systems, processes, and data essential to business continuity and public interest.
  3. Employee awareness
    Human behaviour remains one of the main causes of security incidents. Regular training, phishing simulations, and clear procedures significantly reduce risks.
  4. Detection and response
    Completely preventing cyber incidents is virtually impossible. Organisations must therefore be able to detect suspicious activities in good time, investigate incidents effectively, and recover quickly to minimise further impact.
  5. Business continuity and crisis management
    An organisation must know in advance how it will continue to operate if systems fail, data becomes unavailable, or a supplier suffers a cyber incident. Recovery procedures, backups, and crisis exercises are essential. Do this not alone but in collaboration with key players throughout the entire supply chain.
  6. Supplier and supply chain management
    More and more cyber incidents originate not within the organisation itself, but via (software) suppliers or other parties in the chain. Ensure that supply chain risks are identified, risk-based agreements are made, and compliance with these agreements is monitored.

The supply chain as the weakest link?

Modern organisations depend on an extensive ecosystem of IT service providers, cloud providers, software vendors, and other external parties. When one party in this chain suffers a cyber incident, the effects can quickly spread to dozens or even hundreds of organisations.

Cybercriminals understand this all too well. Instead of attacking a well-protected organisation directly, they increasingly focus on suppliers with lower security levels to gain access to multiple targets via that route.

The Cbw addresses this risk. Organisations must not only assess their own security but also gain insight into cyber risks within their supply chain. This includes conducting supplier assessments, incorporating security requirements into contracts, and monitoring critical supplier relationships.

To help organisations strengthen digital resilience in the supply chain, various initiatives have emerged focusing on the standardised assessment of suppliers. An example of this is the development of a NIS2 Supply Chain certification in addition to existing SOC2 assurance reports.

The aim of these certifications is to provide organisations with a uniform method to demonstrate their cyber resilience to customers and chain partners. This eliminates the need for organisations to repeatedly complete extensive security questionnaires and gives customers better insight into the security level of their suppliers.

Although these certifications do not relieve organisations of their own responsibility, they contribute to greater transparency, higher security standards, and more efficient management of supply chain risks.

NIS2 also offers opportunities

Organisations that invest in cyber resilience now will benefit from more than just compliance. They gain better insight into risks, strengthen their business continuity, and increase trust among customers, suppliers, and regulators. Cybersecurity thus becomes a competitive advantage rather than a mandatory exercise.

The question is not whether your organisation is compliant with the Cbw, but how well your organisation is prepared for the moment when a cyber incident actually occurs?

Start with insight, not assumptions

The biggest mistake organisations can make is assuming they are already sufficiently prepared. Without an objective analysis, it remains unclear where the most significant risks lie and which measures should be prioritised.

With a NIS2 baseline assessment, you gain immediate insight into your current level of readiness, the most significant vulnerabilities, and the actions needed to take targeted steps towards improved cyber resilience and compliance with the Cbw requirements.

Do you want to prevent the Cbw from turning into an expensive, last-minute compliance project? Contact our Cyber & Risk experts and discover where your organisation stands today.

Contact us