Dossier Secure
Cyber GovernanceGovernance Evidence Infrastructure
Governance Evidence Infrastructure

Cyber Governance Evidence

Cybersecurity is no longer only an IT issue. It is a board evidence problem.

Under the Dutch Cyberbeveiligingswet — the national implementation of NIS2, expected to take effect around 1 July 2026 — cybersecurity becomes an explicit board responsibility, with individual liability possible in cases of gross negligence. The measure itself is rarely the issue under scrutiny. What is examined is whether the board can show it was informed, trained, and acted on the risk.

Board Training EvidenceRisk Analysis RecordIncident Decision TrailSupervisory Readiness
Cyber risk register and board oversight documents on a dark conference table
What the Cbw tests

Not whether a measure existed, but whether the board can show it was informed, trained, and acted on the risk.

The core problem

Documentation, not the breach, is the usual failure point

Supervisors increasingly examine board meeting minutes, not only technical logs. Enforcement action typically follows patterns — delayed reporting, poor documentation, gaps in audit readiness — not a single technical failure.

What changed under NIS2

Cyber risk oversight is now a direct board-level accountability, not a delegated IT function.

The Cyberbeveiligingswet introduces three core obligations: registration duty, incident-reporting duty, and a duty of care (zorgplicht) requiring documented risk analysis and incident-response policy.

Board members are required to complete cybersecurity training and demonstrably maintain that knowledge — a requirement that itself generates an evidence obligation.

What this requires

Four conditions for defensible cyber governance

1

Risk analysis record

A documented risk analysis, current at the time decisions were made — not reconstructed after an incident.

2

Leadership sign-off

Evidence that leadership reviewed and accepted specific cyber risks, recorded at the time, not assumed from silence.

3

Board training evidence

Demonstrable record that board members completed required cybersecurity training and maintained that knowledge.

4

Incident decision trail

A record of board-level decisions during an incident — what was known, when, and what was decided — not just the final report.

Where it goes wrong

How cyber governance evidence fails in practice

Policy without sign-off record. A cybersecurity policy exists, but no record shows leadership reviewed or approved it at a specific point in time.
Training without proof. Board members attended training, but no demonstrable record exists to show to a supervisor.
Incident response reconstructed afterwards. The board acted during an incident, but the sequence of decisions is pieced together from memory once scrutiny begins.
Risk acceptance undocumented. A risk was discussed and accepted verbally, but never entered the formal record.
How Dossier Secure addresses this today

A structured evidence foundation, built for today's pressure

Standard — Structured Dossier Foundation

Organizes cyber governance facts, evidence, decisions and obligations into a defensible case structure. The documents are the output of that structure — not the product itself.

Pro — Governance & Integrity Layer

Adds governance and integrity controls around decision responsibility, evidence integrity and access-audit boundaries, strengthening the record of board-level cyber oversight.

Enterprise — In Active Development

Dossier Secure Enterprise is being engineered to connect events, actors, policies, decisions, evidence bundles, outputs and audit trails into a defensible reconstruction chain — including cyber incident decisions and board oversight evidence. This layer is in active development.

The Cyberbeveiligingswet is expected to take effect around 1 July 2026, pending final legislative steps. Organisations should track the current legislative status rather than rely on any single date.
Frequently asked questions

Cyber governance evidence, explained

What is the Cyberbeveiligingswet and when does it take effect?

The Dutch implementation of NIS2, expected to take effect around 1 July 2026, replacing the current Wbni and covering 18 sectors.

Why does NIS2 make cybersecurity a board responsibility?

NIS2 places direct accountability for cyber risk oversight at senior management and board level, rather than treating it as a purely technical function.

Can individual board members be held personally liable under the Cbw?

Individual board members can face personal liability in cases of gross negligence, distinct from organizational fines.

What records should organizations keep to prove cyber risk oversight?

Records showing risk assessments, leadership sign-off, incident response decisions, and board-level review of cyber risk over time.

Is Dossier Secure Enterprise fully live for cyber governance evidence?

Dossier Secure Enterprise is in active development and is being engineered as forensic governance infrastructure. Current Dossier Secure layers provide a structured evidence foundation, while the full Enterprise reconstruction chain is being built step by step.

Next step

Test where your cyber governance evidence is incomplete today

The 48-hour governance test shows exactly where the link between cyber risk and board-level evidence is missing — before scrutiny exposes it under pressure.