Skip to content or footer

NIS2 and the Cybersecurity Act

The implementation of NIS2 and the Dutch Cybersecurity Act is changing the way organizations view cybersecurity. What was an IT issue for many years is now becoming a strategic responsibility for executives.

Regulatory Services NIS2

NIS2 and the Cybersecurity Act: Why Cybersecurity Resilience Is Now a Board-Level Responsibility

For years, cybersecurity was primarily on the agenda of IT departments. As long as systems were running and incidents did not occur, the topic often remained outside the boardroom. With the introduction of the European NIS2 Directive and the Dutch Cybersecurity Act, this is changing fundamentally.

For thousands of organizations, cyber resilience is no longer viewed as a technical challenge, but as a business-critical issue that directly impacts business continuity, governance, compliance, and reputation. Moreover, the impact extends far beyond just the organizations that are directly subject to the legislation.

What is NIS2?

The NIS2 Directive (Network and Information Security Directive 2) is the successor to the original European NIS Directive. Its goal is clear: to strengthen Europe’s digital resilience and better protect organizations against the growing threat of cyberattacks.

Whereas the first directive focused primarily on critical infrastructure, NIS2 significantly broadens its scope. Organizations in sectors such as government, healthcare, energy, transportation, digital services, and media will face stricter requirements regarding cybersecurity, risk management, and incident response.

In the Netherlands, NIS2 is being implemented through the Cybersecurity Act. Once this law takes effect, many organizations will need to demonstrate that they actively manage cyber risks and that executives are involved in decision-making regarding digital security.

From IT Responsibility to Board Responsibility

The biggest change brought about by NIS2 lies not in technology, but in ownership.

Under NIS2, board members are explicitly responsible for cybersecurity policy, risk management, and oversight of implementation. This means that cybersecurity is given the same status as financial reporting, compliance, and operational risk management.

Many organizations have traditionally delegated cybersecurity to vendors or IT teams. According to Anouk van der Gracht, our Director of Regulatory Services, that is no longer sufficient.

“NIS2 is about ownership. You can’t pass security responsibilities on to your supplier, but as a supplier, you can’t just sit back and do nothing either.”

Board members must understand the risks, be able to demonstrate what measures have been taken, and be prepared for incidents when they occur.

Why Organizations Outside the Scope Are Also Affected

A common misconception is that NIS2 is only relevant to large organizations or critical infrastructure. In practice, this is not the case.

NIS2 requires organizations not only to ensure their own digital resilience but also that of their suppliers and supply chain partners. This creates a ripple effect in which software vendors, technology partners, and service providers are increasingly required to demonstrate how they manage cybersecurity.

For example, a municipality may have hundreds of suppliers. If that municipality falls under NIS2, questions will arise such as:

  • Where is our data stored?
  • Who has access to our systems?
  • Which software is business-critical?
  • How are cyber risks managed?
  • What happens if a supplier goes down?

As a result, even organizations that are not directly subject to the law are increasingly facing security assessments, audits, and compliance requirements.

Cyber resilience starts with your crown jewels

Many organizations view NIS2 as a massive compliance project. In practice, that doesn’t have to be the case. A successful approach starts with one fundamental question: What are your organization’s crown jewels? In other words: Which systems, processes, and data are essential to continuing your service delivery? By first gaining insight into business-critical processes, you create a clear foundation for:

  • Risk analyses
  • Prioritization of measures
  • Business continuity planning
  • Supplier management
  • Investments in cybersecurity

This pragmatic approach prevents organizations from getting bogged down in complex compliance projects without a clear goal.

Why the Urgency Is Growing

Cyber threats are evolving faster than ever. Supply chain attacks, ransomware, and phishing campaigns are becoming increasingly sophisticated. Moreover, the rise of AI makes it easier for malicious actors to create credible phishing emails, deepfakes, and targeted attacks.

That’s why the discussion within many organizations is shifting from:

“Can we prevent being hacked?”

to:

“What do we do when it happens?”

After all, digital resilience isn’t just about prevention, but also about detection, response, recovery, and continuity.

VFrom Paper-Based Compliance to Demonstrable Resilience

One of the biggest challenges surrounding NIS2 is that organizations often approach compliance as a documentation project. But policy alone is not enough. NIS2 requires organizations to demonstrate that security measures are actually effective. Consider:

  • Security governance
  • Risk management
  • Incident response processes
  • Vulnerability management
  • Business continuity plans
  • Security awareness training
  • Monitoring and detection
  • Vendor assessments

Compliance should therefore not be an end goal, but a logical consequence of a mature cybersecurity strategy.

How Dawn Technology Helps Organizations

At Dawn Technology, we believe that cyber resilience isn’t achieved through more paperwork, but by aligning technology, processes, and people.

Our Regulatory Services specialists help organizations translate complex laws and regulations into practical and actionable measures. We combine in-depth knowledge of compliance frameworks such as ISO, NEN, MDR, and NIS2 with extensive technical expertise in software development, cloud, infrastructure, and security.

  • Our approach always starts with gaining insight:
  • Which systems are business-critical?
  • What risks are present?
  • Which suppliers create dependencies?
  • What measures are already in place?
  • What steps are needed to achieve demonstrable compliance?

By breaking down complex issues into manageable steps, we help organizations not only become compliant but, above all, more digitally resilient. As Anouk puts it: “We make it manageable and keep it small.”

Cybersecurity Resilience Doesn’t Wait for Legislation

Many organizations are still waiting for the Cybersecurity Act to be fully implemented. However, the pressure often comes from customers, partners, and suppliers rather than from regulators.

The question, therefore, is not whether cyber resilience will become important, but how quickly your organization will start addressing it. Because in a digital economy, your organization’s resilience is ultimately only as strong as the weakest link in your chain.

Is your organization ready for NIS2?

Schedule a no-obligation consultation with Dawn Technology.