Approximately 90 minutes
NIS2 Boardroom Briefing
A shared foundation, the legal framework and a first board agenda.
View this trainingGovernance • risk management • supervision
Our English-language NIS2 training translates the Dutch Cybersecurity Act into board responsibility, risk management, decision-making and supervision. It is designed for executive and supervisory boards, directors, advisory boards and audit committees working in or with Dutch organisations.
NIS2 at board level
The Dutch Cybersecurity Act enters into force on 15 August 2026. Organisations within scope must analyse cyber risks, take appropriate and proportionate measures, report significant incidents and maintain executive oversight. Directors approve the measures and supervise implementation. This requires sufficient knowledge, clear risk appetite and useful management information.
English-language orientation
In 30–45 minutes, executives and supervisory board members receive a focused introduction to the Act, their role and the next practical steps. The webinar is live and can be tailored to a sector or organisation.
The webinar supports orientation. The appropriate statutory training route depends on role, depth and demonstrable learning content.
Live • 30–45 minutes
Available for healthcare, government, food, life sciences, manufacturing, transport, research, the social domain, chemicals and waste management.
View the NIS2 WebinarORIENT → GOVERN → APPLY → DEEPEN
The right format depends on what participants need to do afterwards: establish a shared foundation, assess risk and reporting, apply the framework to their own organisation or work through complex cases in depth.
Approximately 90 minutes
A shared foundation, the legal framework and a first board agenda.
View this training3–4 hours
Governance, compliance, risk assessment, reporting and board decisions.
View this trainingOne full day
Masterclass plus a board-level cyber risk analysis of your organisation.
View this trainingApproximately two days
A deeper learning route with law, cases, assurance and application.
View this trainingDifferent roles, one informed conversation
Executive directors weigh risk, measures, budget and ownership. Supervisory boards need information that enables effective questions, oversight and timely intervention. Advisory boards and audit committees bring their own perspective. The training makes those roles explicit and supports a shared language.
Set risk appetite, priorities, accountability and formal decisions.
Assess KPIs, KRIs, residual risk, assurance and progress through focused questions.
Act as a well-informed sounding board on digital risk, reporting and escalation.

Trainer and adviser
Active in information security since 2009, with a focus on governance, risk and internal control.
Wouter builds each session around the questions boards genuinely face: which risks are material, which information is needed, which decisions require formal approval and how follow-up remains demonstrable.
About Wouter and his approachQuestions and answers
Choose the Briefing for a shared foundation, the Masterclass for governance and risk assessment, the in-company Boardroom Day for application to your own organisation, or Advanced Training for a deeper multi-day route.
The specific statutory training duty under the Dutch Cybersecurity Act applies to executive directors of essential and important entities. Appropriate knowledge also supports supervisory boards, advisory boards and audit committees in their own roles.
The live webinar is a concise orientation. Training provides more time for risk management, board-level assessment, cases, questions and application.
The Boardroom Masterclass explains how to assess cyber risk and measures. The in-company Boardroom Day adds a board-level risk analysis of the organisation, priorities and a follow-up agenda.
Yes. Kynexis Informatiebeveiliging BV can support improvement planning, prioritisation, decision-making, management reporting, coaching and CISO direction after the training.
Personal advice
We will help you select a format that fits the board, the organisation and the required output.