// BRIEFING

NIS2 & DORA. The law now names the board. NIS2 & DORA. De wet noemt nu het bestuur.

Two European rules moved cybersecurity from the IT department to the boardroom — in plain language: what changed, what it means for the people at this table, and what has to be in place. Twee Europese regels verplaatsten cyberbeveiliging van de IT-afdeling naar de bestuurskamer — in gewone taal: wat er veranderde, wat het betekent voor de mensen aan deze tafel, en wat er moet staan.

// CHANGE 01VERANDERING 01

The board is now personally accountable. Het bestuur is nu persoonlijk aansprakelijk.

management body liability / in the Netherlands: Cyberbeveiligingswet aansprakelijkheid bestuursorgaan / in Nederland: Cyberbeveiligingswet
THE BOARDROOMDE BESTUURSKAMER
🔨
👔CFO
👔COO
👔CEO
👔CIO
👔CHAIRVOORZITTER

Until now, a cyber incident was an IT failure with a business consequence. NIS2 changes the subject of the sentence. The management body must approve the cybersecurity risk measures, oversee their implementation, and can be held liable when it does not. In the Netherlands the directive arrives as the Cyberbeveiligingswet; DORA applies directly to banks, insurers, investment firms and their critical ICT providers. Delegating the work is allowed. Delegating the responsibility is not.

Business impact: this is a governance question before it is a technical one. Regulators can impose fines that scale with turnover, can order remedies, and for essential entities can temporarily bar individuals from management roles. “We hired a good CISO” is not a defence if the board never saw, questioned or approved what that person did.

Tot nu toe was een cyberincident een IT-storing met een bedrijfsgevolg. NIS2 verandert het onderwerp van de zin. Het bestuur moet de maatregelen voor cyberrisico's goedkeuren, toezien op de uitvoering, en kan aansprakelijk worden gesteld als het dat niet doet. In Nederland komt de richtlijn als de Cyberbeveiligingswet; DORA geldt rechtstreeks voor banken, verzekeraars, beleggingsondernemingen en hun kritieke ICT-leveranciers. Het werk delegeren mag. De verantwoordelijkheid delegeren niet.

Bedrijfsimpact: dit is een governancevraag voordat het een technische vraag is. Toezichthouders kunnen boetes opleggen die meeschalen met de omzet, herstelmaatregelen afdwingen, en bij essentiële entiteiten personen tijdelijk uit bestuursfuncties weren. “We hebben een goede CISO aangenomen” is geen verweer als het bestuur nooit heeft gezien, bevraagd of goedgekeurd wat die persoon deed.

NAMED IN LAW · FINES SCALE WITH TURNOVER · PERSONALGENOEMD IN DE WET · BOETES NAAR OMZET · PERSOONLIJK FIX: ONE ACCOUNTABLE EXECUTIVE + BOARD-APPROVED FRAMEWORKOPLOSSING: ÉÉN VERANTWOORDELIJKE BESTUURDER + GOEDGEKEURD KADER
// CHANGE 02VERANDERING 02

Reporting runs on a clock. Melden gaat op de klok.

incident notification deadlines / confirm the exact regime with legal meldtermijnen incidenten / laat juridische zaken het exacte regime bevestigen
FROM THE MOMENT YOU KNOWVANAF HET MOMENT DAT JE HET WEET
T=0 · AWARET=0 · BEKEND
~24H · EARLY WARNING~24U · VROEGE WAARSCHUWING
~72H · NOTIFICATION~72U · MELDING
~1 MONTH · FINAL REPORT~1 MAAND · EINDRAPPORT

A significant incident is no longer something you disclose when the dust settles. Under NIS2 the sequence is roughly: an early warning within about 24 hours of becoming aware, a fuller notification within about 72 hours, and a final report within about a month. DORA has its own tight timelines for financial entities. Exact deadlines, thresholds and the regulator you report to depend on which regime you fall under — legal must confirm that in advance, not on the day.

Business impact: twenty-four hours is shorter than it sounds. It has to cover detecting the incident, deciding it is “significant”, getting the facts straight enough to write down, and finding the person authorised to send it — possibly at night, possibly on a weekend. Companies that have not rehearsed this miss the window or report wrongly, and the late or inaccurate notification becomes a second offence on top of the incident.

Een significant incident is niet langer iets dat je meldt als het stof is neergedaald. Onder NIS2 is de volgorde ongeveer: een vroege waarschuwing binnen circa 24 uur nadat je ervan weet, een uitgebreidere melding binnen circa 72 uur, en een eindrapport binnen ongeveer een maand. DORA kent eigen strakke termijnen voor financiële instellingen. De exacte termijnen, drempels en de toezichthouder aan wie je meldt, hangen af van het regime waaronder je valt — dat moet juridische zaken vooraf bevestigen, niet op de dag zelf.

Bedrijfsimpact: vierentwintig uur is korter dan het klinkt. Daarin moet het incident worden ontdekt, worden besloten dat het “significant” is, moeten de feiten voldoende op een rij staan om ze op te schrijven, en moet de persoon worden gevonden die bevoegd is om te melden — mogelijk 's nachts, mogelijk in het weekend. Bedrijven die dit niet hebben geoefend, missen de termijn of melden verkeerd, en de late of onjuiste melding wordt een tweede overtreding bovenop het incident.

~24H · ~72H · ~1 MONTH · NIGHTS AND WEEKENDS COUNT~24U · ~72U · ~1 MAAND · NACHTEN EN WEEKENDEN TELLEN MEE FIX: CLASSIFICATION + REPORTING PROCESS, REHEARSED AGAINST THE CLOCKOPLOSSING: CLASSIFICATIE + MELDPROCES, GEOEFEND OP DE KLOK
// CHANGE 03VERANDERING 03

Your suppliers' security is your duty. De beveiliging van je leveranciers is jouw plicht.

supply chain oversight / ICT third-party risk toezicht op de keten / ICT-derdenrisico
WHO ANSWERS FOR WHOMWIE STAAT VOOR WIE IN
🏢
UsWij
🏭
SupplierLeverancier
🔧
Their supplierHun leverancier
BREACHEDGEHACKT
OUR RESPONSIBILITYONZE VERANTWOORDELIJKHEID

Both rules make you responsible for the security of the parties you depend on: the software vendor, the hosting provider, the payroll bureau, the managed-service partner. You are expected to know who they are, to assess their risk, to put obligations in the contract, and — under DORA in particular — to have an exit plan for the ones you cannot afford to lose. When their weakness becomes your incident, “it was the supplier” is an explanation, not an excuse.

Business impact: most organisations cannot produce a complete list of their ICT suppliers today, let alone say which contracts contain security, audit and notification clauses. Building that register is unglamorous procurement and legal work. It is also the first thing a regulator asks for after an incident that started at a third party.

Beide regels maken je verantwoordelijk voor de beveiliging van de partijen waarvan je afhankelijk bent: de softwareleverancier, de hostingpartij, het salarisbureau, de managed-servicepartner. Je wordt geacht te weten wie het zijn, hun risico te beoordelen, verplichtingen in het contract vast te leggen en — vooral onder DORA — een exitplan te hebben voor de partijen die je niet kunt missen. Als hun zwakte jouw incident wordt, is “het lag bij de leverancier” een verklaring, geen excuus.

Bedrijfsimpact: de meeste organisaties kunnen vandaag geen volledige lijst van hun ICT-leveranciers produceren, laat staan zeggen welke contracten clausules over beveiliging, audit en melding bevatten. Dat register opbouwen is onopvallend inkoop- en juridisch werk. Het is ook het eerste waar een toezichthouder om vraagt na een incident dat bij een derde partij begon.

UNKNOWN SUPPLIERS · SILENT CONTRACTS · NO EXITONBEKENDE LEVERANCIERS · ZWIJGENDE CONTRACTEN · GEEN EXIT FIX: SUPPLIER REGISTER + CONTRACT CLAUSES + EXIT PLANSOPLOSSING: LEVERANCIERSREGISTER + CONTRACTCLAUSULES + EXITPLANNEN
// CHANGE 04VERANDERING 04

You have to prove it, not assume it. Je moet het bewijzen, niet aannemen.

mandatory training and resilience testing verplichte training en weerbaarheidstesten
EVIDENCE, NOT ASSURANCEBEWIJS, GEEN GERUSTSTELLING
Board followed cybersecurity trainingBestuur volgde cyberbeveiligingstrainingRECORDEDVASTGELEGD
Full restore from backup performedVolledig herstel vanaf back-up uitgevoerdHOURS MEASUREDUREN GEMETEN
Incident exercise run against the clockIncidentoefening gedaan op de klokGAPS LISTEDHIATEN GENOTEERD
Threat-led test on the live organisationDreigingsgestuurde test op de echte organisatieFINANCIAL ENTITIESFINANCIËLE INSTELLINGEN

The rules do not accept a policy document as evidence. Members of the management body must follow cybersecurity training so they can judge the risks they are approving. Measures must be tested: does the backup restore, does the failover work, does the incident process hold under pressure. Financial entities face the strongest version — regular resilience testing, and for the larger ones advanced threat-led testing in which specialists attack the live organisation with the board's knowledge.

Business impact: this is where the cost sits, and where the value sits. An untested control is a belief. Testing converts beliefs into either confidence or a to-do list, and both are worth more than the belief. For the board the practical change is small: training on the calendar, and test results — not assurances — on the agenda.

De regels accepteren een beleidsdocument niet als bewijs. Leden van het bestuur moeten cyberbeveiligingstraining volgen, zodat ze de risico's die ze goedkeuren kunnen beoordelen. Maatregelen moeten worden getest: herstelt de back-up, werkt de failover, houdt het incidentproces stand onder druk. Financiële instellingen krijgen de zwaarste variant — periodieke weerbaarheidstesten, en voor de grotere partijen geavanceerde dreigingsgestuurde testen waarbij specialisten de echte organisatie aanvallen, met medeweten van het bestuur.

Bedrijfsimpact: hier zitten de kosten, en hier zit de waarde. Een ongeteste maatregel is een overtuiging. Testen zet overtuigingen om in vertrouwen of in een actielijst, en beide zijn meer waard dan de overtuiging. Voor het bestuur is de praktische verandering klein: training in de kalender, en testresultaten — geen geruststellingen — op de agenda.

UNTESTED = UNKNOWN · POLICY IS NOT EVIDENCEONGETEST = ONBEKEND · BELEID IS GEEN BEWIJS FIX: BOARD TRAINING + TESTING PROGRAMME + RESULTS ON THE AGENDAOPLOSSING: BESTUURSTRAINING + TESTPROGRAMMA + RESULTATEN OP DE AGENDA
// CONTROLSMAATREGELEN

What has to be in place. Wat er moet staan.

governance and paperwork done properly — most of it is not technical governance en administratie op orde — het meeste is niet technisch
GOVERNANCE STACKGOVERNANCELAGEN
SCOPEREIKWIJDTE NAMED OWNEREIGENAAR BIJ NAAM RISK FRAMEWORKRISICOKADER REPORTING DRILLMELDOEFENING SUPPLIER REGISTERLEVERANCIERSREGISTER
ControlCoversIn one line
ScopeAll fourConfirm with legal which regime applies: essential or important entity under NIS2, financial entity under DORA, or both. Everything else follows from this.
Named ownerAccountable (01)One executive accountable for cybersecurity by name, reporting to the board on a fixed cadence. Not a committee.
Risk frameworkAccountable (01)The set of measures, the reasoning behind them, and the board's approval — written down and dated.
Reporting drillThe clock (02)An incident classification, a decision tree for “significant”, pre-drafted notifications, and a rehearsal against the clock at least yearly.
Supplier registerSuppliers (03)Every ICT supplier, its criticality, its contract clauses on security, audit and notification, and an exit plan for the critical ones.
Board trainingProve it (04)Cybersecurity training for the management body, recorded and repeated. Also the fastest way to make the other rows land.
Testing programmeProve it (04)A schedule of tests — restores, failovers, incident exercises, and for financial entities threat-led testing — with results reported to the board.
EvidenceAll fourMinutes, approvals, test reports, training records, supplier assessments. If it is not documented, to a regulator it did not happen.
MaatregelDektIn één zin
ReikwijdteAlle vierBevestig met juridische zaken welk regime geldt: essentiële of belangrijke entiteit onder NIS2, financiële instelling onder DORA, of beide. Alles volgt hieruit.
Eigenaar bij naamAansprakelijk (01)Eén bestuurder die bij naam verantwoordelijk is voor cyberbeveiliging en op vaste momenten aan het bestuur rapporteert. Geen commissie.
RisicokaderAansprakelijk (01)De set maatregelen, de onderbouwing en de goedkeuring van het bestuur — opgeschreven en gedateerd.
MeldoefeningDe klok (02)Een incidentclassificatie, een beslisboom voor “significant”, voorbereide meldingen, en minstens jaarlijks een oefening op de klok.
LeveranciersregisterLeveranciers (03)Elke ICT-leverancier, de kritikaliteit, de contractclausules over beveiliging, audit en melding, en een exitplan voor de kritieke.
BestuurstrainingBewijs het (04)Cyberbeveiligingstraining voor het bestuur, vastgelegd en herhaald. Ook de snelste manier om de andere rijen te laten landen.
TestprogrammaBewijs het (04)Een kalender van testen — herstel, failover, incidentoefeningen, en voor financiële instellingen dreigingsgestuurde testen — met resultaten aan het bestuur.
BewijsAlle vierNotulen, goedkeuringen, testrapporten, trainingsregistraties, leveranciersbeoordelingen. Wat niet is vastgelegd, is voor een toezichthouder niet gebeurd.
The board-level point: compliance is the floor, not the goal — the rules describe what a well-run organisation already does. The real decision is who in this room owns it by name, and when the board last saw evidence rather than assurances. If nobody can answer either question today, that is the first finding. De kern voor de directie: compliance is de ondergrens, niet het doel — de regels beschrijven wat een goed geleide organisatie al doet. De echte beslissing is wie in deze kamer het bij naam bezit, en wanneer het bestuur voor het laatst bewijs zag in plaats van geruststellingen. Als niemand vandaag een van beide vragen kan beantwoorden, is dat de eerste bevinding.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Being in scope is a fact for most mid-sized and large organisations in the covered sectors. The risk is being in scope and not knowing it.Onder de regels vallen is een feit voor de meeste middelgrote en grote organisaties in de betrokken sectoren. Het risico is eronder vallen zonder het te weten.

ImpactImpactHighHoog

Fines that scale with turnover, remedial orders, temporary bans on management functions, and a public enforcement decision on top of the incident itself.Boetes die meeschalen met de omzet, herstelmaatregelen, tijdelijke uitsluiting van bestuursfuncties, en een openbaar handhavingsbesluit bovenop het incident zelf.

Residual after controlsRestrisico na maatregelenLowLaag

With scope confirmed, a named owner, an approved framework and rehearsed reporting, what remains is the incident itself — which the other briefings address.Met bevestigde reikwijdte, een eigenaar bij naam, een goedgekeurd kader en geoefend melden blijft het incident zelf over — en daar gaan de andere briefings over.

Risk ownerRisico-eigenaarCEO / General CounselCEO / General Counsel

The law names the management body. Legal confirms scope and deadlines; the CEO owns that it gets done.De wet noemt het bestuur. Juridische zaken bevestigt reikwijdte en termijnen; de CEO is eigenaar van de uitvoering.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

Scope decision dated and signed (yes / no) · months since the last board training · days since the last reporting rehearsal · % of critical ICT suppliers with contract clauses and an exit plan.Reikwijdtebesluit gedateerd en ondertekend (ja / nee) · maanden sinds de laatste bestuurstraining · dagen sinds de laatste meldoefening · % kritieke ICT-leveranciers met contractclausules en exitplan.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Failure to meet NIS2 or DORA obligations leads to fines, remedial orders and personal liability for the management body, and turns any security incident into a compliance breach as well.”“Het niet nakomen van NIS2- of DORA-verplichtingen leidt tot boetes, herstelmaatregelen en persoonlijke aansprakelijkheid van het bestuur, en maakt van elk beveiligingsincident ook een compliance-overtreding.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Risk management measures approved and overseen by the management body, incident reporting on the roughly 24-hour, 72-hour and one-month schedule, supply chain security, and training for management.A supplier's own NIS2 status does not discharge your duty. Ask for their measures, their incident notification commitment to you, and who their regulator is.The incident and the notification are judged separately. A late or missing notification is its own offence, even if the incident was handled well.
DORAAn ICT risk framework, incident classification and reporting, resilience testing including threat-led testing for larger firms, and a register of ICT third-party arrangements with mandatory contract clauses and exit strategies.Critical ICT providers fall under direct oversight. Your register of information must list them and the contract must contain the mandatory clauses. A report does not replace the clauses.Major ICT incidents go to the financial supervisor on DORA's own timelines. The classification criteria decide what counts, so have them written down before you need them.
SOC 2Nothing directly — it is an assurance report, not a law. But NIS2 and DORA expect you to assess suppliers, and SOC 2 is the evidence most suppliers offer.Read the scope, the period, the exceptions and the complementary user entity controls. A clean SOC 2 covers what was tested, not everything you rely on.An incident at a SOC 2 supplier appears as an exception in their next report — long after your notification deadline passed. Contract clauses, not the report, get you told in time.
ISAE 3402Nothing directly — same logic as SOC 2, and common in Europe for outsourced financial processes.Check that the controls tested are the ones your compliance depends on, and that the period covers your reporting year.A control failure at the service organisation is disclosed to user auditors. Your own regulatory notification duty runs regardless, and much sooner.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Risicobeheersmaatregelen die door het bestuur zijn goedgekeurd en worden bewaakt, incidentmelding volgens het schema van circa 24 uur, 72 uur en een maand, ketenbeveiliging, en training voor het bestuur.De eigen NIS2-status van een leverancier ontslaat u niet van uw plicht. Vraag naar hun maatregelen, hun meldtoezegging aan u, en wie hun toezichthouder is.Het incident en de melding worden apart beoordeeld. Een te late of ontbrekende melding is een eigen overtreding, ook als het incident goed is afgehandeld.
DORAEen ICT-risicokader, incidentclassificatie en -melding, weerbaarheidstesten inclusief dreigingsgestuurde testen voor grotere instellingen, en een register van ICT-derdenovereenkomsten met verplichte contractclausules en exitstrategieën.Kritieke ICT-leveranciers vallen onder direct toezicht. Uw informatieregister moet ze vermelden en het contract moet de verplichte clausules bevatten. Een rapport vervangt de clausules niet.Ernstige ICT-incidenten gaan naar de financiële toezichthouder volgens de eigen termijnen van DORA. De classificatiecriteria bepalen wat meetelt; leg ze vast voordat u ze nodig hebt.
SOC 2Niets rechtstreeks — het is een assurancerapport, geen wet. Maar NIS2 en DORA verwachten dat u leveranciers beoordeelt, en SOC 2 is het bewijs dat de meeste leveranciers aanbieden.Lees de reikwijdte, de periode, de afwijkingen en de aanvullende maatregelen die van u als gebruiker worden verwacht. Een schoon SOC 2-rapport dekt wat is getest, niet alles waarop u vertrouwt.Een incident bij een SOC 2-leverancier verschijnt als afwijking in hun volgende rapport — lang nadat uw meldtermijn is verstreken. Contractclausules, niet het rapport, zorgen dat u tijdig wordt geïnformeerd.
ISAE 3402Niets rechtstreeks — dezelfde logica als SOC 2, en in Europa gebruikelijk voor uitbestede financiële processen.Controleer of de geteste maatregelen de maatregelen zijn waarvan uw compliance afhangt, en of de periode uw rapportagejaar dekt.Een tekortkoming bij de serviceorganisatie wordt aan de auditors van de klanten gemeld. Uw eigen meldplicht aan de toezichthouder loopt onverminderd door, en veel eerder.