Executive board and directors
Set risk appetite, approve measures, assign ownership and record decisions.
Governance • responsibility • oversight
NIS2 brings cyber risk firmly into the boardroom. Executive directors approve measures and oversee implementation. Supervisory boards, advisory boards and audit committees use appropriate knowledge to ask focused questions, assess progress and support sound decision-making.
Roles and responsibilities
Executive and supervisory bodies look at the same material cyber risks, yet their responsibilities remain distinct. Executive directors set direction, allocate resources, approve measures and monitor implementation. Supervisory boards assess whether the executive board has organised this responsibility with sufficient quality, urgency and evidence.
An advisory board primarily acts as a sounding board. An audit committee can provide deeper attention to risk, control and assurance. The training makes these differences explicit and gives each role a practical set of questions.
Set risk appetite, approve measures, assign ownership and record decisions.
Assess the risk picture, management information, assurance, progress and escalation.
Strengthen the quality of dialogue, challenge and specialist preparation.
Cybersecurity as a board-level control process
Technology remains important, while board-level control starts with critical services, protected interests and plausible disruption scenarios. From there, the organisation can decide which measures are proportionate, who owns them, how effectiveness is tested and when residual risk is accepted.
Useful reporting connects technical observations with business impact. It shows trends, exceptions, critical supplier dependencies, incident readiness, overdue decisions and the evidence supporting management's conclusion.
Supervisory questions
A supervisory board benefits from questions that reveal the quality of the underlying management process. What could materially disrupt the organisation? Which assumptions underpin the risk assessment? Which measures have been tested? Which suppliers can affect continuity? Which residual risks require explicit acceptance?
When information is incomplete, the next step is a clear request for analysis, evidence or a decision. This keeps supervision constructive and proportionate while maintaining momentum.
Are scenarios, impacts and dependencies current and connected to the organisation's objectives?
Which tests, exercises, audits and assurance support the conclusion that measures work?
Which actions require a decision, additional resources or closer monitoring?
Choose the depth
The Boardroom Briefing creates a shared foundation in approximately 90 minutes. The Boardroom Masterclass adds governance, risk assessment, reporting and cases. The in-company Boardroom Day applies that knowledge to the organisation and produces a board-level cyber risk profile. Advanced Training provides a deeper, multi-day learning route.
Each format can be delivered in English and aligned with the roles represented in the room.
Questions and answers
The specific training duty in the Dutch Cybersecurity Act applies to executive directors of essential and important entities. Supervisory directors still need sufficient knowledge to fulfil their own oversight role effectively.
Reporting should connect material risks, critical processes, incidents, suppliers, progress, exceptions, effectiveness and decisions in a form that supports challenge and follow-up.
Yes. A joint session creates shared language while preserving the distinction between management, supervision, advice and assurance.
Yes. All boardroom formats are available in English for international and mixed-language boards.

Trainer and adviser
Wouter has worked in information security since 2009, with a focus on governance, risk, internal control, supplier assurance and incident management. He translates the legal framework into the decisions and information that boards genuinely need.
About Wouter and his approachBoard session
We align the participants, governance context, learning objective and desired output before confirming the format.