How do you prepare for the Dutch Cybersecurity Act?
Begin by confirming the statutory scope and the services, systems and legal entities affected. Assign executive ownership, create a multidisciplinary implementation team and agree how progress and exceptions will be reported.
Use a current all-hazards risk analysis to identify material scenarios, protected interests and critical dependencies. Compare existing governance and controls with the Act and prioritise the gaps that matter most.
Start with a clear executive mandate
The mandate should define objectives, scope, decision rights, resources, reporting, escalation and the relationship with existing programmes such as ISO 27001, enterprise risk, continuity and privacy. This gives the implementation team room to work and keeps accountability visible.
- who is the accountable executive sponsor?
- which entities, services and locations are included?
- which decisions remain with the board?
- which evidence and milestones demonstrate progress?
- when are material gaps or delays escalated?
Decisions that deserve board attention
Boards typically decide on risk appetite, priority scenarios, investment, ownership, acceptance of material residual risk, critical supplier strategy, recovery objectives and significant exceptions. Training helps directors assess the quality and consequences of these decisions.
Operational design choices can remain with the appropriate specialists within the approved direction.
Use a board-level roadmap
Group actions into immediate legal readiness, material-risk reduction, evidence and testing, and structural improvement. For each milestone, show the outcome, owner, due date, dependency, evidence and decision required.
A compact dashboard supports oversight when it explains changes in risk and control rather than only counting completed tasks.
Training clarifies the mandate and follow-up
A Boardroom Briefing creates a shared foundation. The Masterclass deepens governance and risk assessment. The In-company Boardroom Day connects the learning directly with the organisation's risk profile and implementation priorities.
Kynexis Informatiebeveiliging BV can support the separate implementation, audit or CISO assignment after the training.
Frequently asked questions
Who owns NIS2 implementation?
The executive board remains responsible for direction and oversight, with a clearly assigned sponsor and multidisciplinary operational ownership.
What should the board approve?
Scope, priorities, resources, material risk acceptance, key measures, supplier strategy and the reporting and escalation framework commonly require board attention.
Where should implementation start?
Start with scope, critical services, an all-hazards risk analysis, current gaps, ownership and a risk-based roadmap.
Can Kynexis support implementation after training?
Yes. A separate assignment can cover improvement planning, audits, Cyber RI&E, supplier assurance or CISO direction.
Clarify mandate, priorities and reporting
A board session creates shared direction for the implementation roadmap while specialist execution remains a separate assignment through Kynexis.
Discuss the appropriate training route