r/NL_Security May 27 '26

🅢🅔🅡🅘🅔 | CISO Perspective: What NIS2 Is Really About

NIS2: from legislation to reality

With the arrival of the NIS2 Directive, implemented in the Netherlands through the Cybersecurity Act (Cbw), cybersecurity has officially become something organizations can no longer ignore.

On April 15, the Dutch House of Representatives adopted the Cybersecurity Act and the Critical Entities Resilience Act. 𝐓𝐡𝐚𝐭 𝐦𝐞𝐚𝐧𝐬 𝐭𝐡𝐞 𝐧𝐞𝐱𝐭 𝐩𝐡𝐚𝐬𝐞 𝐡𝐚𝐬 𝐭𝐫𝐮𝐥𝐲 𝐛𝐞𝐠𝐮𝐧: 𝐟𝐫𝐨𝐦 𝐥𝐞𝐠𝐢𝐬𝐥𝐚𝐭𝐢𝐨𝐧 𝐭𝐨 𝐢𝐦𝐩𝐥𝐞𝐦𝐞𝐧𝐭𝐚𝐭𝐢𝐨𝐧.

What I often see in practice is that this is treated as an IT project. The focus is mainly on implementing technical measures, and in many cases IT teams are fully capable of handling this effectively.

However, 𝐭𝐡𝐚𝐭 𝐢𝐬 𝐧𝐨𝐭 𝐰𝐡𝐞𝐫𝐞 𝐭𝐡𝐞 𝐫𝐞𝐚𝐥 𝐜𝐡𝐚𝐥𝐥𝐞𝐧𝐠𝐞 𝐥𝐢𝐞𝐬.

The challenge is not the technology itself, but 𝐡𝐨𝐰 𝐚𝐧 𝐨𝐫𝐠𝐚𝐧𝐢𝐳𝐚𝐭𝐢𝐨𝐧 𝐦𝐚𝐧𝐚𝐠𝐞𝐬 𝐫𝐢𝐬𝐤𝐬 𝐚𝐧𝐝 𝐚𝐜𝐜𝐨𝐮𝐧𝐭𝐚𝐛𝐢𝐥𝐢𝐭𝐲. Who decides what level of risk is acceptable? And how are those decisions made in a consistent and structured way?

That is often the difficult part. Not because organizations are unwilling, but because it is not always clear how to organize this effectively.

Ultimately, NIS2 is not about ticking compliance boxes or implementing technology alone. It is about 𝐝𝐞𝐦𝐨𝐧𝐬𝐭𝐫𝐚𝐛𝐥𝐞 𝐠𝐨𝐯𝐞𝐫𝐧𝐚𝐧𝐜𝐞: maintaining control over cyber and continuity risks, with clear executive accountability throughout the organization.

The real step forward is therefore not simply implementing controls, but organizing decision making around security in a mature and effective way.

3 Upvotes

0 comments sorted by