Cybersecurity is no longer only an IT issue. It is a board evidence problem.
Under the Dutch Cyberbeveiligingswet — the national implementation of NIS2, expected to take effect around 1 July 2026 — cybersecurity becomes an explicit board responsibility, with individual liability possible in cases of gross negligence. The measure itself is rarely the issue under scrutiny. What is examined is whether the board can show it was informed, trained, and acted on the risk.
Supervisors increasingly examine board meeting minutes, not only technical logs. Enforcement action typically follows patterns — delayed reporting, poor documentation, gaps in audit readiness — not a single technical failure.
Cyber risk oversight is now a direct board-level accountability, not a delegated IT function.
The Cyberbeveiligingswet introduces three core obligations: registration duty, incident-reporting duty, and a duty of care (zorgplicht) requiring documented risk analysis and incident-response policy.
Board members are required to complete cybersecurity training and demonstrably maintain that knowledge — a requirement that itself generates an evidence obligation.
A documented risk analysis, current at the time decisions were made — not reconstructed after an incident.
Evidence that leadership reviewed and accepted specific cyber risks, recorded at the time, not assumed from silence.
Demonstrable record that board members completed required cybersecurity training and maintained that knowledge.
A record of board-level decisions during an incident — what was known, when, and what was decided — not just the final report.
Organizes cyber governance facts, evidence, decisions and obligations into a defensible case structure. The documents are the output of that structure — not the product itself.
Adds governance and integrity controls around decision responsibility, evidence integrity and access-audit boundaries, strengthening the record of board-level cyber oversight.
Dossier Secure Enterprise is being engineered to connect events, actors, policies, decisions, evidence bundles, outputs and audit trails into a defensible reconstruction chain — including cyber incident decisions and board oversight evidence. This layer is in active development.
The Dutch implementation of NIS2, expected to take effect around 1 July 2026, replacing the current Wbni and covering 18 sectors.
NIS2 places direct accountability for cyber risk oversight at senior management and board level, rather than treating it as a purely technical function.
Individual board members can face personal liability in cases of gross negligence, distinct from organizational fines.
Records showing risk assessments, leadership sign-off, incident response decisions, and board-level review of cyber risk over time.
Dossier Secure Enterprise is in active development and is being engineered as forensic governance infrastructure. Current Dossier Secure layers provide a structured evidence foundation, while the full Enterprise reconstruction chain is being built step by step.
The 48-hour governance test shows exactly where the link between cyber risk and board-level evidence is missing — before scrutiny exposes it under pressure.